Forum Discussion
Fotios_30046
Nimbostratus
Jul 11, 2007Layout of BIP-LTM
We are upgrading our existing IIS 5 and Cisco CSS to IIS 6 and BIP-LTM, but have several questions as far as network configuration and layout.
Currently we have the following:
CSS has one leg in dmz and one leg on public network.
Web farm is in its own dmz, 192.168.168.0/24
Web servers default gateway is CSS.
Going forward, we would like to keep the BIP within our private network behind the firewall and wanted to gather some information on what everyone is doing.
Thanks Again
- Ryan_Korock_46Historic F5 Accountfmagoufis,
- I too agree the BIG-IP LTM on a private network behind the firewall is a common and secure architecture. The only exception which makes up the remainder of the implementations in my experience is those that wish to provide some of the same functionality for their firewall(s) as the LTM provides for their servers.
- Fotios_30046
Nimbostratus
Thank you for the updated information, I was getting worried my question would go unanswered. To add to my original post, we purchased two LTM 3400's and will be initially setting them up as primary/secondary. My initial thoughts were to put the bigip into dmzFE, but have all the webservers in dmzBE. - JRahm
Admin
This is a standard configuration and will work just fine. You can map your translations on the firewall instead of the BigIP to keep your security zones well defined. In most environments I've worked in, the F5 device between fe & be dmz's is not considered a security boundary and therefore the translations occur before or after the BigIP. Ultimately your security policy should guide the final solution.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects