Forum Discussion

Muhammad_57196's avatar
Muhammad_57196
Icon for Nimbostratus rankNimbostratus
Jun 17, 2009

Active Active Datacenter design

We are going through design phase of the our project that involves the following:

 

 

1. Two datacenters (apart 15 km) running active/active.

 

2. We have layer 2 connectivity at each zone for the servers to have the same subnet over two datacenter.

 

 

We have one F5 in one datacenter and one F5 in other datacenter. The question is that whats the best design approach regarding F5s connectivity between two datacenters. Which one is the better approach Active/Standby or Active/Active.

 

 

Is there anyone who have implemented active active datacenter with F5s. Is there any issues we need to look for. Is there any whitepaper that talks about active active datacenter design using F5s.

 

 

Thanks for answering.

 

 

Regards,

 

 

Dr. Muhammad Malik
  • Hi Dr. Muhammad,

     

    I am running a similiar configuration where I have a pair of F5s in one datacenter and another pair in another datacenter. Each F5 grouping is active/passive. We used the GTM to essentially serve traffic accross both datacenters as an active/active scenario. This design worked, but you must keep in mind of the drawback which is that if one datacenter's LTM reached above 50% capacity based on traffic, the other datacenter could would not be able to cope with a datacenter loss. Thus we have to upgrading in any manner to keep the capacity below 50% because our requirement was that each datacenter needed to be redundant.

     

     

    I hope this information helps you.

     

    CB

     

     

     

  • Posted By CB on 06/17/2009 12:42 PM

     

     

    Hi Dr. Muhammad,

     

    I am running a similiar configuration where I have a pair of F5s in one datacenter and another pair in another datacenter. Each F5 grouping is active/passive. We used the GTM to essentially serve traffic accross both datacenters as an active/active scenario. This design worked, but you must keep in mind of the drawback which is that if one datacenter's LTM reached above 50% capacity based on traffic, the other datacenter could would not be able to cope with a datacenter loss. Thus we have to upgrading in any manner to keep the capacity below 50% because our requirement was that each datacenter needed to be redundant.

     

     

    I hope this information helps you.

     

    CB

     

     

     

     

     

     

    With this design - what are some methods of ensuring configs are syncrhonized with both pairs (datacentre pair and DR pair)?
  • Since both pairs basically have different IP addresses between DR and active pairs so we cannot 100% guarantee they are perfectly synchronized. Our only method for now is tightly controlled deployment and maintenance strategy. For example we add new vips and pools in the Active and DR environments and then follow up with a montly audit to ensure process and procedure is followed.

     

     

    CB

     

  • Active/Sandby is best practice for BigIP.

     

     

    With a design like yours, just keep in mind (an obvious point) that the L2 connectivity between centers is absolutely critical. It works very well overall, but I've seen at least one case where the heartbeat VLAN was clobbered for whatever reason (user error, etc.), which caused a 'split brain' deal where both of the BigIPs went active. Whenever a BigIP goes active it'll issue a GARP on each VLAN it is connected to, which can be bad when the systems are both claiming ownership of all of the floating resources (VIPs, Self-IPs, etc.).

     

     

    Be sure and use MAC masquerade, etc. as well...

     

     

    -Matt
    • Rabbit23_116296's avatar
      Rabbit23_116296
      Icon for Nimbostratus rankNimbostratus
      Is L2 absolutely critical to have an Active/Standby automatic failover design?
  • Dr. Malik,

     

     

    I am just getting into designing two active/active failover DR sites. These two sites are already in place. We are looking into complete Business Continuity from IT perspective. I cam across your post and it appears to me that we are trying to design the same infrastructure as you probably have already implemented. I would very much appreciate it if I can discuss about your network architecture that you have implemented as an active/active failover DR sites.

     

     

    I will be glad to call you if you would be kind enough to share your contact information with me. I am in Tennessee, USA. Please see below my contact information. By the way, we have an office in Sydney, Australia, connects us through IPSec Tunnel. We have about 14 such tunnels connecting to one of these sites, these sites are also need be to ported to other site during the outage. Please respond to my email address below. I hope to hear from you soon.

     

     

    I also noticed that few others in the forum have posted some solution and advice. I would very much like to contact them as well and get their feed back. I am considering GTM and Enterprise DNS service solution from provider like UltraDNS, dnsMadeEasy, etc.

     

     

    Bets Regards,

     

     

    Ahmed Shakil

     

    Elan Polo, Inc.

     

    1+(615) 844-2367 [off]

     

    1+(615) 957-1309 [mobile]

     

  • I am in the process of designing similar DR sites, active/active. Any help will be greatly appreciated. As I metioned to Dr. Malik, I will be glad to call you if you would share your contact information. Please see below for my contact information.

     

     

    Ahmed Shakil

     

    Elan Polo, Inc.

     

    ashakil@elanpolo.com

     

     

    1+(615) 844-2367 [off]

     

    1+(615) 957-1309 [mobile]
  • Hi Matt,

     

     

    I am in the process of designing similar DR sites, active/active. Any help will be greatly appreciated. As I metioned to Dr. Malik, I will be glad to call you if you would share your contact information. Please see below for my contact information.

     

     

    Ahmed Shakil

     

    Elan Polo, Inc.

     

    ashakil@elanpolo.com

     

     

    1+(615) 844-2367 [off]

     

    1+(615) 957-1309 [mobile]