Forum Discussion
sketchie_85427
Feb 02, 2012Nimbostratus
Secure inter-vlan routing
External firewall routes to LTM for 6 application vlans that are behind the LTM. The LTM is the def gateway for each of the 6 vlans and it def routes to the firewall. Typically I would have an IP Forwarding VS to enable routing and if no direct inter-vlan traffic is required could filter so that no intervlan communications were allowed.
But the client wants to allow some inter-vlan traffic but would like to force all traffic from each of the 6 internal vlans up to the firewall for all routing decisions so that the firewall is used to secure the inter-vlan traffic.
Can you force all internal vlans directly connected on the LTM to go up to external firewall to secure local traffic between vlans?
- nitassEmployeeis route domain feature applicable?
- HamishCirrocumulusI do this with a dedicated network virtual server for the vlansvthat need to go via a firewall. You could also use routing domains to seggregate the two environments but to force the firewall for inter dmz traffic you need that vs...
- Ernesto_27816NimbostratusHi Hamish,
- HamishCirrocumulusFor the network VS's? Basically to route across the BigIP you need a VS to do the forwarding, In order to make all inter-dmz traffic pass through the firewall, you have 2 VS's to manage the two interfaces used to route to/from a DMZ.
- sketchie_85427NimbostratusThanks for your help!! As suggested, I was able to provide the users requested security with dedicated virtual servers. On the outside interface I used a typical IP Forwarding virtual, then on inside vlans I applied virtual servers such as the following to forward to my outside firewall. A separate virtual for each vlan, all using same pool to the firewall.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects