Physical LTM migration to VE and design
Hello,
We are currently in the design phase of migrating off of BIG-IP 6900s to 1Gb-VEs. My question is regarding "collapsing" internal and DMZ functionality onto one single pair. Our existing environment had two pairs of F5 LTMS, one in the DMZ, and one in the Core. I'm trying to wrap my mind around bringing it all into one pair of LTMs. I've heard about route domains, I know we can have multiple NICs on a VE. I don't want to sacrifice security in any way, but I have to imagine many engineers have deployed LTMs doing both DMZ web and Core only Web.
We have the DMZ and CORE VLANS broken out into different VRFs. The DMZ LTMS tie off our DMZ firewall. Then the DMZ firewall routes back to our top of rack switch, which does the layer 3 routing. The DMZ and the CORE VRFs are separated by an ASA firewall.
Hoping someone offer some guidance here. My preference would be to keep the DMZ off of the Core and vice versa, which would mean doubling the amount of F5 VE best bundle licenses we'll require.
Thanks