Kemp Load Master in between External Firewall and Internal Firewall

0

I have read somewhere, to place a LM in a between a external firewall and a internal firewall, you have to create a Virtual Service 2 times.

  • The external VS is assigned to the External NIC, and a internal VS is created for the internal NIC.
  • On the external VS you the configure as real server the IP address of the internal VS.
  • Then the LM will proxy the traffic from external to internal and vice versa.

Is this the way to go when setting up a LM between a external and internal firewall?

6 comments

Avatar
0
Derek Kiely

What you have mentioned is possible. However to provide the best solution please provide more details of what you are trying to achieve. Is there a reason that you need to place the LoadMaster in between the two firewalls?

Avatar
0
matts

I have the same question.  We need to have a 3 pronged LM.  WAN/DMZ/LAN.   We think for this situation the LM would sit between the firewalls since it will need to be used to load balance servers in the DMZ (from WAN) and on the LAN.

Avatar
0
Justin Federico

In this scenario where are the clients connecting from? WAN, internal, or both? Are the real servers ever acting as the client?

Avatar
0
matts

Both.  The real servers are not clients.We'd like to utilize the appliance for internal and external use.

 

Outlook Web Access Client (WAN) -> FW -> LM -> FW -> Real Servers

Outlook Web Access Client (LAN) -> LM -> Real Servers

 

Avatar
1
omar

Matt what did you end up doing with this configuration?

 

Avatar
0
matts

We ended up doing the same thing I mentioned in my previous post.

For OWA, for example...

1 OWA VS for the External NIC (subnet A).  I had to specify the Default Gateway in the VS manually to point to the FW.

1 OWA VS for the Internal NIC (subnet B).

Both VS's have the same real server IP's specified.

 

External DNS for OWA points to the public IP on the FW.  Traffic goes from FW -> LM External VIP -> FW -> Real Server

Internal DNS for OWA points to the internal VIP on the LM.