Keith,

I've done a good amount of testing. I found no glaring
issues in deploying and managing it. All this in a test
environment. Now for the real world...

What are you looking to accomplish. Where are you
looking at placing it?

It's one of those catch-22 issues. If you place it in
front of the firewall, well you sorta spent a lot of $$
on a firewall, only to have the BigIP do all the dirty
work, so your firewall is a waste.

If you place it behind, then it can do the job it was
meant to do - load balance, not packet filter(which it
is going to do anyways, based on how you set it up.)

As you may know, BigIP can be used as a packet
filter(it's running xBSD), but F5 does not market it
as a security device(firewall), just a screaming load
balancer.

If performance is they key issue(and usually is for most
sites), then you can just leave it in front all by itself (uh-oh).

Anyone else care to add to this or tell us how they're
using one(or similar products)?

Robert

- -
Robert P. MacDonald, Network Engineer
e-Business Infrastructure
G o r d o n   F o o d    S e r v i c e
Voice: +1.616.261.7987 email: [EMAIL PROTECTED]

>>> "Keith Hearn" <[EMAIL PROTECTED]> 8/21/00 11:56:22 AM >>>
>
>Has anyone setup FW-1 in conjunction with Big IP?  Are there any issues I
>should be aware of?
>
>Keith




================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to