Forum Discussion
Using the WAF instead of a jump server for ssh-tunneling?
Hello everyone,
This is how it works at the moment:
We go from server A, in the internal network, with a public IP via ssh to a jump server in the DMZ.
From the jump server we then go on to server B in the secure zone.
I am relatively new to this and have been given the task of seeing if the WAF can replace the jump server.
We use Advanced Web Application Firewall, r2600 with BIG-IP 17.1.1.3
Is this possible and what do we need for it?
Thank you in advance for your help !
Best regards.
- Jeffrey_GranierEmployee
WAF is going to be used for HTTP traffic. If you're simply looking for a connectivity option without security, then you can configure a SSH Virtual Server and you pool member would be the server in the DMZ. If you're looking for SSH security, then you might consider adding on AFM which can do SSH protocol inspection amongst other options. Secure SSH traffic with the SSH Proxy (f5.com)
If no security is needed, you can restrict source IP;s on the LTM VS your configuring to access the DMZ jump server.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com