Forum Discussion

Simon_Edwards_2's avatar
Simon_Edwards_2
Icon for Nimbostratus rankNimbostratus
Dec 11, 2015

Redirecting traffic using iRules or Root Domains

Hi All,

 

So we have an F5 BigIP LTM with two interfaces, DMZ & Inside. The traffic flow required is from external>DMZ>F5>DMZ>Palo Alto. The Palo Alto has an Inside interface.

 

So to be clear we do not want the traffic to flow via the F5 Inside Interface but back out of the DMZ interface to the Palo Alto DMZ Interface.

 

So what should I used... Can I use an iRule or do I have to introduce another Root Domain?

 

Thanks

 

Simon

 

2 Replies

  • Hi Simon,

     

    An iRule could be used to overwrite the source IP and also next hop, when forwarding the traffic from your DMZ to your internal network.

     

    But i would recomment to use different route domains for each security zone (e.g. Internal and dmz). It would simplify your setup to a great extend, make it more robust and less error phrone. In this case you wouldnt need iRule to route the trafic accordingly, since each route domoin would have an independent routing table.

     

    Cheers, Kai