Forum Discussion
Network topology
Hi,
I have to shape the network to offer business continuity for several webservices and I thought about two options:
1) Using a GTM, but I have too few network interfaces
2) using an LTM to switch services between two Data Center (For business continuity), particularly the pool members will be VIP from the other LTM (each one situated in a different Data Center) all in the same extended VLAN.
So my questions are:
a) Does a module exist to expand network interfaces on GTM?
b) Has anyone ever used the 2) topology? Could it present problems?
Thank you
14 Replies
- luigi_avella_10
Nimbostratus
It's a good Idea, but the application on N2 uses the external address and I can't change it. Anyway this Idea could be useful in other situations, thank you thousand.
- What_Lies_Bene1
Cirrostratus
You're welcome.
- Elias_O_16228
Nimbostratus
Hi I have implemented a similar scenario as you described on your diagram.
option 1: PBR on R1 and R2 is to police the traffic from R2 to LTM 172.23.2.1/24, and configure SNAT on LTM. SNAT is required if the pool member is not using LTM as gateway.
option 2: Implement static route on R1 and R2 to statically route traffic to 172.23.2.x/24
Then because N2 172.23.3.4/24 network with gateway is 172.23.3.1, you must have static route on the N2 server to return traffic back to LTM.
Elias
- luigi_avella_10
Nimbostratus
Hi Elias, In first instance I would implement option 1, but finally I decided to use a PAT on R3, which is a cisco ASA, using the LTM VIP (10.254.34.25) like translation address. It's the simpliest solution because it doesn't imply routing changes neither on the nodes nor on the routers or LTM, however it will generate asymmetric traffic.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
