Forum Discussion

Abbas_Mirza_128's avatar
Abbas_Mirza_128
Icon for Nimbostratus rankNimbostratus
Nov 19, 2015

Network Architecture for AFM

Hi,

 

We have a pair of Big IP F5 ADC (LTM + AFM), and would like to know where i should place the device in the network.

 

The idea is to use the LTM feature to load balance application servers and AFM module as data center firewall to allow access only from dedicated user subnet to the application servers and at the same time restrict access from the same user subnet to the DB servers under the server farm switch. I am attaching network layout and would appreciate if anyone can help me with the placement of the Big IP F5 device in the network.

 

Regards,

 

Abbas Mirza

 

 

1 Reply

  • I can't tell if your picture is L2 or L3 or both. Which switch stack you plug into is up to you but I would suggest making your BigIP the default gateway for the networks you plan on putting behind it. Your BigIP can participate in a VPC trunk so you can cable it with switch redundancy as well.