# How can developers manage nodes having F5 as gateway?

**URL:** <https://community.f5.com/t/how-can-developers-manage-nodes-having-f5-as-gateway/74596>\
**Category:** Technical Forums\
**Tags:** awaf, application-delivery\
**Created:** [June 3, 2024, 10:38am UTC](https://community.f5.com/t/how-can-developers-manage-nodes-having-f5-as-gateway/74596 "2024-06-03T10:38:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![The\_Nirvana](https://avatars.discourse-cdn.com/v4/letter/t/97f17d/32.png) [@The\_Nirvana](https://community.f5.com/u/The_Nirvana)\
**Post date:** [June 3, 2024, 10:38am UTC](https://community.f5.com/t/how-can-developers-manage-nodes-having-f5-as-gateway/74596/1 "2024-06-03T10:38:41Z")

</div>

Hello Team,

I have a BIG-IP F5 with AWAF module (version 17.1.1.1) whose floating IP address is configured as the gateway IP for all the nodes. I have created a standard virtual server to host HTTPs services with SSL bridging and AWAF policies. However, our web developers need to administer the content of the web servers via SSH and RDP.

Can you advise what is the best way to provide management access to the several nodes?

When attempting to SSH or RDP, the nodes are forwarding the response to the BIG-IP which in turn is not forwarding the response to the edge firewall. Can you advise if a forwarding L2 or L3 virtual server can be useful in this scenario and how it can be used?

---

<div class="post-metadata">

**Author:** ![zamroni777](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/zamroni777/32/1473_2.png) [@zamroni777](https://community.f5.com/u/zamroni777)\
**Post date:** [June 3, 2024, 11:16am UTC](https://community.f5.com/t/how-can-developers-manage-nodes-having-f5-as-gateway/74596/2 "2024-06-03T11:16:22Z")

</div>

you can simply create standard TCP virtual server which the pool member are server’s SSH port or RDP port.

if you have f5 apm license, you can use f5 as vpn server.  
you can check the license using below guide:

> **[myF5](https://my.f5.com/manage/s/article/K15032#p1)**

---

<div class="post-metadata">

**Author:** ![The\_Nirvana](https://avatars.discourse-cdn.com/v4/letter/t/97f17d/32.png) [@The\_Nirvana](https://community.f5.com/u/The_Nirvana)\
**Post date:** [June 3, 2024, 11:55am UTC](https://community.f5.com/t/how-can-developers-manage-nodes-having-f5-as-gateway/74596/3 "2024-06-03T11:55:33Z")

</div>

We attempted this and found that eventually, a large number of VIPS needs to be created. It is not very practical when the number of nodes are large. In addition, our developers get confused when dealing with different IP addresses for different purposes, as this is not really their field of work.

Any other ideas?

---

<div class="post-metadata">

**Author:** ![boneyard](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/boneyard/32/20419_2.png) [@boneyard](https://community.f5.com/u/boneyard)\
**Post date:** [June 4, 2024, 6:16pm UTC](https://community.f5.com/t/how-can-developers-manage-nodes-having-f5-as-gateway/74596/4 "2024-06-04T18:16:53Z")

</div>

dual homed servers an option? so with a second nic in a management network.

---

<div class="post-metadata">

**Author:** ![The\_Nirvana](https://avatars.discourse-cdn.com/v4/letter/t/97f17d/32.png) [@The\_Nirvana](https://community.f5.com/u/The_Nirvana)\
**Post date:** [September 11, 2024, 9:53am UTC](https://community.f5.com/t/how-can-developers-manage-nodes-having-f5-as-gateway/74596/5 "2024-09-11T09:53:14Z")

</div>

Hello all,

This issue was solved by creating a Forwarding (IP) virtual server which allows all clients to reach all hosts on all ports on the BIG-IP.
