Hi, sorry the title is a little confusing but I couldn't think of a brief explanation. :-)
Ok here's my Situation:
We have a PI (Provider Independent) Network /24. At the moment our ISP routes this Network directly to our ASG.
I have a couple of Additional Addresses configured and send to our Web Application Firewalls via Server Load Balancing .
We now would like to have a Transfer network between our ISP and our ASG and do the routing of our Network by ourself.
In short we want to build a DMZ.
My question:
Is the ASG capable of having some of the addresses of the PI Network set as additional addresses and still send the requests to the Web Application Firewalls and additionally route my PI Network into my DMZ?
I just want to make sure my Web Servers will still be accessible when we make the changes. If this works I would be able to do the changes step by step.
I hope you understand my Question.
In short.
The new Setup should be.
ISP routes all traffic for our PI Network over the transfer network.
I have a couple of addresses from the PI Network set as additional addresses in the ASG an forward these via Server Loadbalancing to my Web Application Firewalls.
Additionally my ASG should route my PI Network into my newly created DMZ.
I don't know what is proccessed first. The Additional Addresses or the Network Routes.
I had the idea of subnetting and only route the subnets to my dmz. But the serves are scattered all over the network IPs. So theres no way of subnetting. :-(
Thanks.
This thread was automatically locked due to age.