Forum Discussion
Public IP as external VIP on LTM
If I may add, AFM is a stateful firewall, very much like the Juniper firewall you're using now, and ASM is a Web Application Firewall so not something a typical (packet filtering) firewall would handle. Since you have a firewall you don't really need another one (AFM) - though you may at some point want to question which is better. And ASM is something you'd definitely want to consider too protect your web resources. But to your question, it is absolutely okay to use public addresses in a BIG-IP VIP. Even without AFM, as Vernon stated BIG-IP is a default-deny hardened security device and is ICSA certified (a firewall certification).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com