Forum Discussion

cjunior_138458's avatar
cjunior_138458
Icon for Altostratus rankAltostratus
Jul 10, 2017

APM Session - "not_started" discard

Hi, I have a policy that are not killing "not_started" sessions. And, the session list is daily increasing because of these "not_started" and "in_progress" sessions. Should not the policies, kill those uninitialized sessions when session timeout values were reached? Need I to put some "Windows Cache and Session Control" to a session control?

 

I'm talking about policy on "LTM-APM" profile type and BIG-IP v11.6.1.

 

What I forgot to do?

 

Thank you in advance.

 

  • Hi,

     

    In-progress session stop after reaching the timeout that maange the access policy evaluation. You can configure it within the access profile itself.

     

    Yann

     

  • Hi,

     

    In-progress session stop after reaching the timeout that maange the access policy evaluation. You can configure it within the access profile itself.

     

    Yann

     

    • cjunior's avatar
      cjunior
      Icon for Nacreous rankNacreous

      Thank you Yann,

       

      This is my setup on policy:

       

       

      I have a pair Active/Active that process internal and external traffic to this vdi policy. I can realize that issue only occurs on internal traffic box, specially to zabbix monitor ip address.

       

      External traffic (OK)

       

       

      Internal traffic (NOK). It have policies living more than a day. I run a own script to clean the older ones occasionally. I have thinking to schedule this as daily job, if it don't have a solution.

       

       

      Here the "not_started" policies:

       

       

      Any suggestion? What is wrong here?

       

      Thanks again!

       

    • Yann_Desmarest's avatar
      Yann_Desmarest
      Icon for Cirrus rankCirrus

      Hi,

       

      I had the same kind of issue somewhere. Did you know that Active/Active is not supported on APM module. It was my issue in a previous deployment.

       

      You should think about switching Active/Active deployment to Active/Standby or you can do Active/Active with two APM standalone units and a DNS Load Balancing in front.

       

      Yann

       

    • cjunior's avatar
      cjunior
      Icon for Nacreous rankNacreous

      Wow man,I forgot this detail, but anyway, peers are not set to mirroring the connections. I'll first try move the internal ip address to external traffic group and keep all running on same box to get a result. I unfortunately can't turn it an Active/Standby pair and the global load balance is not interesting now because of lan2lan latencies. If solution don't give me luck, I'll suggest to customer a correct sol Active/Standby pair or a workaround to clear old sessions.

       

      Thanks again.

       

  • Hi,

     

    In-progress session stop after reaching the timeout that maange the access policy evaluation. You can configure it within the access profile itself.

     

    Yann

     

    • cjunior's avatar
      cjunior
      Icon for Nacreous rankNacreous

      Thank you Yann,

       

      This is my setup on policy:

       

       

      I have a pair Active/Active that process internal and external traffic to this vdi policy. I can realize that issue only occurs on internal traffic box, specially to zabbix monitor ip address.

       

      External traffic (OK)

       

       

      Internal traffic (NOK). It have policies living more than a day. I run a own script to clean the older ones occasionally. I have thinking to schedule this as daily job, if it don't have a solution.

       

       

      Here the "not_started" policies:

       

       

      Any suggestion? What is wrong here?

       

      Thanks again!

       

    • Yann_Desmarest_'s avatar
      Yann_Desmarest_
      Icon for Nacreous rankNacreous

      Hi,

       

      I had the same kind of issue somewhere. Did you know that Active/Active is not supported on APM module. It was my issue in a previous deployment.

       

      You should think about switching Active/Active deployment to Active/Standby or you can do Active/Active with two APM standalone units and a DNS Load Balancing in front.

       

      Yann

       

    • cjunior's avatar
      cjunior
      Icon for Nacreous rankNacreous

      Wow man,I forgot this detail, but anyway, peers are not set to mirroring the connections. I'll first try move the internal ip address to external traffic group and keep all running on same box to get a result. I unfortunately can't turn it an Active/Standby pair and the global load balance is not interesting now because of lan2lan latencies. If solution don't give me luck, I'll suggest to customer a correct sol Active/Standby pair or a workaround to clear old sessions.

       

      Thanks again.