Forum Discussion

AP_129594's avatar
AP_129594
Icon for Nimbostratus rankNimbostratus
Oct 09, 2013

LTM load balance antivirus scanner

I noticed F5 recommended to use ASM module for a solution to integrate antivirus scanning via ICAP. We only have LTM license and want to load balance the antivirus scanning on port 9053. Has anybody done this before and please provide your feedback. Thank you.

 

5 Replies

  • ICAP support was integrated into LTM 11.3:

     

    http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm-implementations-11-3-0/12.html?sr=32405617

     

    Here are the steps to recreate:

     

    1. Create an ICAP profile that defines the ICAP URI and other request parameters.

       

    2. Create an "internal" virtual server that uses the ICAP profile and pools to the ICAP server(s).

       

    3. Create a Request Adapt (and optionally Response Adapt profile) that uses the internal VIP.

       

    4. Apply the Request/Response Adapat profile/s to the application VIP.

       

    The internal VIP load balances the ICAP servers. The application VIP sends the client request to the internal VIP and then forwards request to application server based on the (potentially adapted) response from the internal VIP.

     

  • Our internal F5 is a virtual license on 11.2 HF2, and does not have iCAP service. Is there a way to work around this?

     

  • Technically yes if you consider that the ICAP process is similar to a GUI-configurable sideband call.

     

  • Yes, an AV proxy would certainly be an option, but then so would upgrading to 11.3 and using the built-in ICAP capability. A sideband-based custom iRule would also technically work, but it's definitely the more complicated option.