Forum Discussion
LTM: Moving from one armed setup to fire-walled interfaces
your solution will work but you’ve built your self an overly complex network with servers having different default gateways not being ideal.
If I were you, I would move the three VLANs to the FW, and route to them using a transit VLAN.
Your F5 doesn’t need to be directly connected to a VLAN in order to connect to your pool members.
Simply add routes to the three VLANs on the F5, pointing towards the FW and ensure auto-snat is enabled and that’s all you need to do.
With this solution your servers will all have the same default gateway of your firewall.
Return traffic to your F5 will route via the transit VLAN as source IP would be a self-IP of the F5 on the transit VLAN.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com