01-27-2013 04:09 PM
Cannot seem to find the answer to this question for what the Best practice is or would be. Should the VIP privet ip be NATed at the firewall for internet access? IE, Internet firewall NAT ------> Privrt WEB server farm VIP.
thanks
01-28-2013 12:26 AM
Yes, VIP private IP should be NATed at the firewall for internet access. You can point the default gateway on ACE as firewall interface IP address.
Also in order to accept the incoming connection you may have to use NAT on firewall.
01-28-2013 04:41 AM
Thank you, However, will this not effect incomming sticky using source IP? Firewall will be seen as the source, not the public IPs access the WEB site?
Having a Public DMZ using all public IPs , protected by a firewall, but not preforming "NAT", Just for a layer of security , this seems the way to go.
thank you
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide