Introduction

Purpose

Enable CloudStack's ability to put one firewall device in front of one load balancing devices. 

Document History

Glossary

Feature Specifications

Use cases

  1. Configure F5 and SRX.
    1. Refer to Juniper SRX config information and F5 Device Installation Instructions.
  2. Add SRX and F5 to CloudStack's one zone.
    1. Choose "per zone" source NAT when adding SRX.
    2. Uncheck "dedicated" when adding F5.
  3. Enable these devices.
  4. Create a network offering(e.g. named "SRX-F5-inline") using SRX as provider for Firewall, PortForwarding, SourceNat, StaticNat; using F5 for Load Balancing; using VirtualRouter for DNS, DHCP, user data. VPN is not supported in this combination.
    1. And SELECT INLINE mode option for network offering.
  5. Start a new VM with the new network offering.
  6. Add Firewall rule and load balancing rule as usual.

Architecture and Design description

web services APIs

list changes to existing web services APIs and new APIs introduced with signatures and throughout documentation

UI flow

Appendix

Appendix A:

Appendix B: