Forum Discussion

Amr_Esmat_24704's avatar
Amr_Esmat_24704
Icon for Nimbostratus rankNimbostratus
Mar 01, 2017

no restriction between vlans behind F5

I have many vlans direct connect to F5 LTM, default forwarding VS is configured to allow external communication to the published services behind F5. is there a way to isolate vlans behind F5 not to be able to communicate with each other except with access list or policy?

 

3 Replies

  • F5 is a default deny device so unless you explicitly allow it, any flow between directly connected VLANs will not pass through.

     

    In your forward VS settings, make sure you didn't allow it to listen on all VLANs. For this, you need to set the "VLAN and Tunnel Traffic" parameter to Enabled on your external vlan only.

     

  • If you have multiple server vlans behind the F5 and need to control access between the multiple server vlans, you can explore a few options:

     

    • Packet Filters - No licensing fee but these are not stateful from my understanding.
    • Route Domain - No licensing fee but management & troubleshooting can get complicated.
    • AFM Module - Stateful and easy to manage but you would have to pay for extra licensing.