Forum Discussion

shopkeeper56_23's avatar
shopkeeper56_23
Icon for Cirrostratus rankCirrostratus
Dec 22, 2015

LTM Load Balancing to separate APM appliance

I have a hypothetical that I have been considering implementing for a customer, but have never attempted in practice.

 

Essentially the customer has some existing physical LTM appliances which are managed by another provider. In their existing solution which uses Firepass, they are using the LTM to load balance between these Firepass appliances. To try and get the most out of the APM VE licenses they have procured, I had planned to use the same architecture with the APM VE’s. I would use their LTM environment to load balance to the virtual servers on the APM VE’s. On the LTM I would also use pool connection limit so that licensing is not breached, and use some form of source ip persistence I guess.

 

The flow would essentially be...

 

  1. Client traffic arrives at LTM
  2. Client traffic is load balanced to pool of APM VE hosted Virtual Servers
  3. Authentication & Resource Assignment occurs
  4. Resource acquired through APM internal interface and passed back to client via LTM

Does anyone see any reason why this wouldnt work in practice?

 

Thanks

 

1 Reply

  • You mean APMs are standalone, right? What about policies? Sync-Only group is made or you duplicate manually the configuration from one to another? It should work, but what if you have an outage on one? Users must then authenticate again (new session).