Forum Discussion

Shakeeb_174352's avatar
Shakeeb_174352
Icon for Nimbostratus rankNimbostratus
Dec 11, 2014
Solved

'clone pool' for security functions

Dear All,

 

There is a need to mirror traffic to a security appliance and there is a feature in F5 called ‘Clone Pool’ that we think we might be able to leverage. For ingress traffic, it might be easy to configure an inbound VIP to have a clone pool that mirrors traffic to a security appliance, such as Palo Alto. For egress traffic, I’m to understand that we can create a VIP for outbound that would perform this same mirror function. I’m not clear exactly how to configure a VIP for both this inbound and outbound purpose.

 

Thanks and Regards, Shakeeb

 

  • Hi,

     

    Clone pools can be configured to copy client-side traffic, server-side traffic, or both. A client-side clone pool causes the virtual server to replicate client-side traffic (prior to address translation) to the clone pool member. A server-side clone pool causes the virtual server to replicate server-side traffic (after address translation) to the clone pool member.

     

2 Replies

  • Hi,

     

    Clone pools can be configured to copy client-side traffic, server-side traffic, or both. A client-side clone pool causes the virtual server to replicate client-side traffic (prior to address translation) to the clone pool member. A server-side clone pool causes the virtual server to replicate server-side traffic (after address translation) to the clone pool member.

     

    • Shakeeb_174352's avatar
      Shakeeb_174352
      Icon for Nimbostratus rankNimbostratus
      Thanks Vitaliy. Could you also point me to the server-side clone pool configuration details