Forum Discussion
Management routes accessible from TMM? Are we crossing the streams?
The separation of device management and data has always been a core architectural component of TMOS, however as of v12.x, HSL will be able to access syslog servers which are only accessible via the management (mgmt) interface.
Is the ability of a mgmt reachable device via a TMM pool, only for pools assigned to HSL publishers, or this now a general ability to place mgmt-only accessible devices within reach of the data plane? Are there any other implications of this?
3 Replies
Ew. Sounds like a generally bad idea to use unless using a license limited by throughput and you're really desperate to save those bytes.
/Patrik
- IheartF5_45022
Nacreous
Oh yes, I agree. I don't think F5 think it's a very good idea either - I feel they were pressured by those who just 'like' to keep syslog on the management interface, however I'm concerned that by doing this they have changed a fundamental construct of TMOS and (potentially) removed a security control.
Interested to see what others think.
- jgranieri
Nimbostratus
well if security is your concern i would recommend creating route domain and placing the HSL server pool there. I believe this will isolate this traffic and should provide some protection in the sense of routing. you would need specific data-plane interfaces to be assigned into the route domain to isolate it from the other traffic.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com