Forum Discussion

carl_townshend_'s avatar
carl_townshend_
Icon for Nimbostratus rankNimbostratus
Sep 19, 2018

Can you have nodes in a deifferent network than the virtual server

Hi All as the title says, if I have my virtual server IP hosted on a DMZ interface, could i have another interface/vlan in a different subnet with the actual nodes on them? what is best practice ?

 

1 Reply

  • Hamish's avatar
    Hamish
    Icon for Cirrocumulus rankCirrocumulus

    Absolutely.

     

    The most common scenario is to have VS addresses one subnet and pool members 'behind' the big on another subnet.

     

    You can configure it either way, though usually using the BigIP as the router between the two subnets (And inline between the client and the pool members) is the more common.

     

    Bets practice? Debatable, but IMO inline is better. If you're doing single-armed then you'll either have to do SNAT, or policy routing in your network or on the hosts, and that can get messy.