Forum Discussion
Ty__Trabosh_946
Nimbostratus
Aug 09, 2007Multiple VLAN Groups
I've been working on a deployment with a pair of 6400's in a layer2 deployment. There is a requirement that SNAT not be used or the LTM become the gateway. It is being deployed directly connected to a firewall for DMZ services. Also a pair of switches (3750 stack) for internal servers to add more port density.
I'm wondering what a best practice design for this would be with it all being layer2 at the LTM. The current plan is as follows.
Each of the LTM's will connect to one firewall. These connections will be tagged for (Vlans 140,141). Then there will be one connection to each of the two inside switches (VLAN 240,241) that will also be tagged. Since the two 3750's are connected VIA the stack cable all is good at this point.
My question is should I break the Stack cable and just build tagged interface between the two LTM's for the Firewalls to see each other. Or should I leave the interconnection on the inside stack for the flow.
9 Replies
- Frank_J_104756Historic F5 Account2 questions
- Ty__Trabosh_946
Nimbostratus
Yes the firewall has some free interfaces on it. - Frank_J_104756Historic F5 Accountso they're using VRRP to present 1 address to the LTM's to use as an external gateway?
- Ty__Trabosh_946
Nimbostratus
That is correct. There is an VRRP session running between the firewalls. In this deployment since we are tagging to the interfaces there are 2 VRRP sessions. One in VLAN 240 and one in 241 - Frank_J_104756Historic F5 AccountWould adding another physical connection to the LTM's and tagging it for 241 and 240 accomplish what you're looking for ?
- Frank_J_104756Historic F5 Accountsorry I meant 140 and 141...I just read back and noticed that 240/241 were internal...
- Frank_J_104756Historic F5 Accountalso, is there a security problem with setting up a 3rd isolated switch, not the 3750(s) and plugging the LTM / FW's into it ? that's certainly the simplest solution
- Deb_Allen_18Historic F5 AccountI'd consider trunking the LTMs only on the external VLAN over a dedicated link, and leave the internal trunk in place on the existing switches:
/debfw fw |--------------| <<< trunk external vlan between LTMs ltm ltm | | switch---------switch <<< leave existing switch trunk in place | | | | | | | | | | servers servers
- Ty__Trabosh_946
Nimbostratus
Deb thanks for the input on that.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects