Forum Discussion
nekau_65641
Nimbostratus
Apr 07, 2008Using same LB for servers on multiple subnets
We are soon putting our newly purchased BIG-IP 3400's into production is a redundant configuration.
I have used Cisco LB's before, and the inside interface where the servers are only supports one subnet.
As we are using these LB's in a firewalled and highly secure environment, can we securely use the same LB pair for multiple DMZ's?
Regards,
Steve
24 Replies
- The_Bhattman
Nimbostratus
Hi Steve, - Jacob_Harres
Nimbostratus
We have a secure, firewalled hosting environment as well. I am using our BigIPs to do LB on several different applications in several DMZs. What I've done is isolate our BigIPs in their own DMZ and route to the subnets where our load balanced servers sit. I've had no problems with this setup either in terms of security or reliability. It also has the added bonus of making the BigIPs incredibly scalable. - Chris_Seymour_1Historic F5 AccountSteve,
- Les_54346
Nimbostratus
Hi everyone, - L4L7_53191
Nimbostratus
I'll try and roll some feedback up in a way that will contribute to both questions in this thread. - hoolio
Cirrostratus
Hi Matt, - L4L7_53191
Nimbostratus
Aaron - as usual, your description is dead on: "logical slicing" of the BigIP. Thanks for pointing it out in that context. - Les_54346
Nimbostratus
Hi Aaron, Hi Mat, - dennypayne
Employee
This thread (Click here) has a good discussion about similar architecture to what Matt describes as well. - Josh_41258
Nimbostratus
A bit late in this thread.. sorry. Say I already have a pair of 6400's with all virtual servers on one VLAN (lets call it, OUTSIDE) and all back-end servers on another VLAN (INSIDE).
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects