Forum Discussion
Management of Hosts directly attached to an F5
Hello,
We are faced with a problem which we did not have before the new architecture. In our new architecture, we have attached directly to the F5 Apache servers (using a switch). We need to apply patches to these machines (antivirus, application patches etc). How can this be done without affecting the ASM / LTM policies ?
Tx BR
4 Replies
- Kevin_Stewart
Employee
You may have a few options here:
-
Temporarily disable the ASM policy (and perhaps take the server out of service)
-
Allow ASM to learn these traffic patterns
-
Bypass ASM policy evaluation for a given set of IPs (the address of the client systems you're using to admin the servers)
The third option is probably the best.
-
- cmard_195831
Nimbostratus
Hello,
Many thanks for the answer. Can you pls advise as how the ASM policy can be by-passed, or what is the recommended way of doing so ?
Tx BR
- afedden_1985
Cirrus
If the Servers are using the F5 as their default Gateway and you want direct access to the servers via their own IP addresses you will need An ingress forwarder Virtual and for server calls out to your infrastructure you will need a egress Forwarder for the Vlan that the servers are on.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com