Forum Discussion

Unmesh_375545's avatar
Unmesh_375545
Icon for Nimbostratus rankNimbostratus
Oct 29, 2018

ASM Virtual server vlan configuration.

Hello All,

 

We are planning to deploy ASM to monitor application traffic. Application servers are in internal VLAN. No app server in DMZ. Only option I think is VIP(virtual server) to be created in internal vlan and map app servers to VIP so that both are in same VLAN. Hence, External user uses public IP which is NAT to F5 VIP(internal VLAN) and from F5 VIP to internal APP server. But risk here is we can not allow externals to access internal VLAN directly. If F5 VIP(internal VLAN) compromised it will risk entire internal network.

 

  1. we have other applications in DMZ VLAN for which we don't face any issue. But for this particular application servers in DMZ is not an option.

Is this understanding correct or am I missing anything here? Please help.