Forum Discussion
LTM Design - BIGIP on a Stick
An F5 is a deny by default device, hence your need for the 'routing' VIP which I assume allowed you to manage the servers 'behind' the F5 from somewhere else on the network.
You obviously need at least one SVI on your core to allow traffic to be routed to the F5 via the external VLAN.
What routing have you setup within LTM.
I don't see why you would have issues with the server connectivity from a application perspective:
Client > network device > Core SVI > F5 external floating IP > server on internal VLAN
- This would require the core to route your VS range to the F5 (and perhaps the 'real server ranges' for your other (management?) traffic
- The F5 would need a default route back to the core
- The servers would need a default route back to the F5 internal floating IP
The 'routing' Virtual would be required only for traffic not handled by a Virtual Server or S/NAT - in other words, outbound server traffic for patches, inbound management traffic etc.
Hope this makes some sense.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com