Forum Discussion
Setup F5 as Outbound Proxy
I have on my infrastructure today the following scenarios,
1) A Service Bus that connects to the internet thro a proxy server. The Proxy server is Apache (which is supported by Public IP/Domain name mappings in the host file).
I need to replace the Apache server with F5 Big IP.
I know that the Apache Server's Local IP will now become a virtual Server on Big IP (especially as it has been configured for outbound traffic on the Firewall).
How do I configure this to work?
See my architecture below:
Internet
|
|
External Firewall
|
|
|
F5 3600
|
|
|
|
|
Servers
2) I have a server which runs IIS and has a couple of web services on it, those services are accessible over the internet.
There are also some windows services which Connect to external etities over the internet.
The IP of this server is configured to connect to these entities on the firewall.
I need to make this server get proxied by F5 and also have all the services work normally by pushing traffic out via F5.
Can any one advise on these 2 scenarios?
9 Replies
- What_Lies_Bene1
Cirrostratus
OK, for 1) Can I assume it's the servers in your 'diagram' that need to be proxied out? Do there need to be any restrictions? Are the servers able to do their own DNS lookups? I assume we need to SNAT source IPs to the previous Apache proxy IP right? - TosinS_68494
Nimbostratus
Hi Steve, - TosinS_68494
Nimbostratus
Hi Steve, - nitass
Employee
I need to replace the Apache server with F5 Big IP. - TosinS_68494
Nimbostratus
I need to replace the Apache server with F5 Big IP. - TosinS_68494
Nimbostratus
Hello all, - Birddog_17215
Nimbostratus
If you make the F5 your default gateway, you might need to add a forwarding IP vitrual server with destination 0.0.0.0 and enabling on your internal vlan(s) only. (vlans behind the F5) - TosinS_68494
Nimbostratus
Thanks, I understand this part, If you make the F5 your default gateway, you might need to add a forwarding IP vitrual server with destination 0.0.0.0 - marco_octavian_
Nimbostratus
He is correct. You just need the ip forwarding virtual server. As for the "enabling your internal vlans", this is by default. You don' have to change anything to make this happen. This article will walk you through it.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com