Forum Discussion

hrx_354229's avatar
hrx_354229
Icon for Nimbostratus rankNimbostratus
Feb 27, 2018

FIPS validated F5 load balancer to work with AWS ELBs

Hi, We recently found out that the AWS ELBs are not FIPS 140-2 validated. We plan on continuing to use ELBs for their AZ failover, ASG etc features but we now need to come up with a solution where the public end-points for our apps would be FIPS validated. As a note, our entire infrastructure is on AWS. Is there an F5 solution that we can stand it up in front of ELBs and have it accept external connections and route those back to ELBs? Also noteworthy is that the ELBs may change their IPs over time so this solution will need to be handle that without causing traffic disruption.

 

Thank you.

 

  • JG's avatar
    JG
    Icon for Cumulonimbus rankCumulonimbus

    This would seem easy to do: Define the ELB hostname as the fqdn pool member of your F5 virtual server fronting the user. See Configuring the BIG-IP System to Auto-Populate Pools.

     

    There are currently a couple of bugs with this functionality, though. But you can always use an irule to get around them.