Keith,
I've done a good amount of testing. I found no glaring
issues in deploying and managing it. All this in a test
environment. Now for the real world...
What are you looking to accomplish. Where are you
looking at placing it?
It's one of those catch-22 issues. If you place it in
front of the firewall, well you sorta spent a lot of $$
on a firewall, only to have the BigIP do all the dirty
work, so your firewall is a waste.
If you place it behind, then it can do the job it was
meant to do - load balance, not packet filter(which it
is going to do anyways, based on how you set it up.)
As you may know, BigIP can be used as a packet
filter(it's running xBSD), but F5 does not market it
as a security device(firewall), just a screaming load
balancer.
If performance is they key issue(and usually is for most
sites), then you can just leave it in front all by itself (uh-oh).
Anyone else care to add to this or tell us how they're
using one(or similar products)?
Robert
- -
Robert P. MacDonald, Network Engineer
e-Business Infrastructure
G o r d o n F o o d S e r v i c e
Voice: +1.616.261.7987 email: [EMAIL PROTECTED]
>>> "Keith Hearn" <[EMAIL PROTECTED]> 8/21/00 11:56:22 AM >>>
>
>Has anyone setup FW-1 in conjunction with Big IP? Are there any issues I
>should be aware of?
>
>Keith
================================================================================
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
================================================================================