Forum Discussion

Ijaz_37879's avatar
Ijaz_37879
Icon for Nimbostratus rankNimbostratus
Aug 20, 2009

Proxy on LTM

Hi All:

 

 

I have been asked to setup proxy on LTM for inbound and outbound connection. Following is the logical setup:

 

 

Internet

 

|

 

|

 

|

 

External Firewall

 

|

 

|

 

|

 

F5 6900

 

|

 

|

 

|

 

Internal Firewall

 

|

 

|

 

Servers

 

 

For inbound proxy I was thinking of setting up virtual server for each server. Virtual server IPs would public IPs. Please let me know if this is the correct approach.

 

 

For outbound proxy the connections would be initiated by servers towards hosts on Internet. For this setup I am thinking of setting up virtuals for Internet hosts with SNAT automap on (external IP on LTM is a public IP). Please confirm if this is a correct approach.

 

 

I cannot use SNAT for inbound and outbound connections because of PCI compliance issues, it has to be to proxy as per PCI.

 

 

Please let me know of your opinions on this.

 

 

Thanks,

 

Ijaz
  • Hi Ijaz,

     

     

    Will the proxy be something that involves a pacfile or static entry on a browser for internet traffic? or will it be something that will be completely transparent?

     

     

    CB