Forum Discussion
Routing Between DMZ & LAN using F5
Hello Everybody,
I'm new on the F5 world, and I have a question about a configuration that I'll want to simulate using F5.
This is related to Vmware View architecture, that's the security server must reside on the DMZ network.
But all the rest of the servers reside on the LAN network.
So for that I want to use F5 with its functions, plus routing the traffic between the two networks.
I hope that I give an approach scenario of my issue.
Thanks in advance
45 Replies
- Thomas_Gobet
Nimbostratus
Hi,
Your F5 can act as a "router" between your DMZ and LAN networks.
You just have to create a VS with a wildcard as destination address and choose the right type of VS that's all. - Jimb2k_159873
Nimbostratus
Hello,
Thank you for your reponse.
Can you please provide me a tutorial to do that.
Thank you in advance.
- Domai
Altostratus
From tmsh run this -
create virtual ip_forward { destination 0.0.0.0:any ip-forward ip-protocol tcp mask any profiles { fastL4 { } } translate-address disabled translate-port disabled vlans-disabled }
- Jimb2k_159873
Nimbostratus
Hello Domai,
Can you excuse my ignorance about the product cause I can't understand very well.
My purpose is to have a network architecture as shown below :
Can I use the port of virtual appliance as gateway for my servers to communicate between those on DMZ and the others LAN.
Thank you.
- nitass
Employee
bigip is default deny device. to allow traffic across vlans, object listener has to be created such as virtual server, snat or nat. in short, create wildcard ip forwarding virtual server to allow traffic between appand web tiers.
sol7595: Overview of IP forwarding virtual servers
http://support.f5.com/kb/en-us/solutions/public/7000/500/sol7595.html - Jimb2k_159873
Nimbostratus
Thank you for your indications,
I have created Vlans and associated them to proper Nic cards.
My servers can ping those IPs as gateway.
I configured the VS on the F5 part to allow communication between vlan as shown below :
This is still not working, my server on DMZ cannot ping server on LAN and the opposite is true too.
Can you help me please.
Thank you again.
- Domai_23823
Nimbostratus
And also since these are 2 diff VLANs can you enable "Source address translation" to AutoMap and test? We can refine you settings once we can get a working model. - Domai_23823
Nimbostratus
What is your APP tier server's gateway?
- Domai
Altostratus
Can you allow it to all and test....make your destination to any for now instead of specifying 192.168.2.0/24 Use 0.0.0.0 and mask as any and test first? See if this works?
- Jimb2k_159873
Nimbostratus
Hello,
I updated the settings as required, but still not working.
Thank you.
- Domai
Altostratus
Can you give me your f5 device self ips. Please mask the original values if you are using public ips.
- Jimb2k_159873
Nimbostratus
There is the self Ips,
I'm just on lab environnement.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
