Forum Discussion

nikzin1985_3413's avatar
nikzin1985_3413
Icon for Nimbostratus rankNimbostratus
Nov 18, 2017

BigIP in multiple vlans: Possible security issue

Hello, i have a question because of a possible security issue. A BigIP with two interfaces is connected to an internal an external firewall. In the same internal and external VLANs are multiple application server. The default gateway of these app server is the internal or external firewall. If i change the DG of the app server (because of a configuration mistake or consciously), so the new DG is the internal or external ip of BigIP. What happens with the whole traffic (not only loadbalanced traffic) ? Is all traffic going through BigIP and is not restricted and controlled by the firewalls ? Hope it is clear, what i want to describe.

 

1 Reply

  • If a bigip is in different dmz networks, you should configure route domains for every vlan.

     

    If you don't configure route domains, all dmz server will be routed on the same outgoing dmz (you can prevent this behavior with vlan filter on forwarding vs, but you have to think about this every times you create a vs)

     

    Another security issue is a virtual server in dmz1 can forward to pool members in dmz2...