Forum Discussion
Jun 06, 2011
Moving ASM to Standalone Configuration
Can anyone please assist me on this.
We have an exisitng HA Pair of 3600's running LTM and ASM on Version 9.4.8, we want to split the functionaility and run ASM on an additional HA pair of 6...
Mike_Maher
Nimbostratus
Jun 06, 2011Similar but actually our external and internal LTMs are physically seperate devices. The externals live in a DMZ behind our firewall and the internals, obviously live behind a firewall on our internal network.
Yes our ASMs are both Active behind the external LTM.
I guess it would depend how you feel about the security of VLANing if you wanted to use the design concept in this document. Personally I prefer the physical separation of the 2 LTMs. From a security perspective having the external LTM out in a DMZ allows us to only allow the ASMs access to the internal LTM. I would rather have the external traffic stop in the DMZ and be proxied by the ASM, that way the external requests are never directly going to a device on our internal network.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
