Forum Discussion
ethomas_116508
Nimbostratus
May 22, 2013VLANs and Firewalls and things
2 seperate ISP's, each with its own Cisco ASA 5520 and VPN termination
BIGIP 4000 in HA Active/Standby
What is the correct/perferred method of implementation...ISP>>Firewall>>F5 or ISP>>F5 ...
What_Lies_Bene1
Cirrostratus
May 23, 2013You'd typically find this design in place: ISP > Firewall > F5
From an IP perspective: ISP:Firewall would be one subnet, Firewall:F5 would be another subnet and you'd then have another subnet for the 'inside' of the F5. They shouldn't be on the same subnet ideally.
Of course, this depends on how your ISP does it's addressing and how you are terminating the ISPs lines/equipment etc.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects