Aaron1121_669
Feb 05, 2009Nimbostratus
Implemenation Advice
I'm new to the forums here, and I wanted to see if I could get some advice on an implementation. I’ve worked a lot with the Cisco LD’s, CSM’s, and ASA’s, as well as Radware Applications directors, but my F5 experience is somewhat limited.
I’ve been put on a project to consolidate some old load balancing equipment, to use two new redundant F5 devices.
Here is the logical layout of what I’ve got:
Internet
|
CheckPoint Cluster
|
-----------------------------------------------------------------
| | | |
DMZ1 DMZ2 DMZ3 Internal
Old F5 520 (1) Old F5 520 (2) Radware Appdir Network
One IP/ Int Config One IP/ Int Config L2 Mode
I have setup L2 trunking so that everything is accessable from the new F5's, and I've almost got the failover setup.
From what I've seen, we really have three options for deployment. Can you guys let me know your thoughts on the options, and maybe any of the pro's and con's that I missed? One of the things I am worried about is that we are trying to use smaller F5 boxes, so we are looking at options that reduce traffic through them.
We currently use the firewall as the default gateway on all the hosts. Our backups take place accross the network, and I'm a little concerned about running all that traffic through the F5's.
Option 1-
Trunk out all three DMZ vlans to the F5 cluster. Setup each DMZ in a one IP config. This would be similiar to the way it is setup now. It also keeps the default gateway on the servers setup as the firewall, so most of the traffic does not have to traverse the F5.
Any major drawbacks? It also may require an I-Rule to deal with some of the routing implications??.......
Option 2-
Trunk out all three DMZ vlans to the F5 cluster. Use N-Path Routing for each DMZ. Return traffic would use the firewall, same as now......
Option 3- Trunk out all three DMZ vlans to the F5 cluster. Insert a new network in each of the DMZ's. Setup the F5 cluster with logical internal and external network connections for each DMZ. Setup the hosts default gateway as the F5.
This is the textbook way to do it, but I'm a little concerned about the overall throughput, and the amount architecture changes.
I really appreciate your input and your thoughts. I know that each of these methods would probably work, but each has it's own implications. I rather know some of them up front, before I get halfway throught he project and find a "gottcha".
Thanks in advance for your comments!