Forum Discussion

Norrz_350468's avatar
Norrz_350468
Icon for Nimbostratus rankNimbostratus
Feb 07, 2018

Big-IP and DirectAccess

Hello, we're using Big-IP for loadbalancing our DirectAccess cluster. DirectAccess use SSL traffic on TCP 443 with no encryption. So we've configured Ciphers: DEFAULT:NULL, and we get clients connecting. For loadbalancing method we have "Least Connections" (but the two test-clients are always connecting to the same available node...) The problems arise when we try to failover. We tried failover by disabling node in Big-IP and terminating connections and it worked all the time. But when we simulate failover by shutting down the DirectAccess-server:

 

  • The first time it always works
  • For each subsequent failover the clients are then unable to connect and DirectAccess is not receiving any traffic.
  • What's curious is that updating/refreshing the VIP always get's it working again immediately.

We have tried with/without persistence and tried reject/reselect as actions when node is down. The node that is shut down is correctly turning red in Big-IP.