Forum Discussion

jomedusa's avatar
Icon for Altostratus rankAltostratus
Dec 13, 2023

BIG IP DNS Upgrade questions

We are planning an upgrade of our BIG IP DNS cluster to 16.1.4 with the latest hotfix, we have already upgraded our LTM's to this version.  I am following the upgrade guide of and it seems pretty straight forward.  One of my questions is the step referring to

"Update the big3d processUpdate the big3d process on all BIG-IP devices on all BIG-IP devices"

I am confused as if the DNS devices are upgraded won't they be running the same version?  I have found other posts that they have waited until the entire upgrade is completed then they "install" the updated version.  Any insight or clarification on this step would be greatly appreciated.



2 Replies

  • So, nothing matters here expect that all devices NOT EQUAL to DNS/GTM must have a version of big3d equal or newer. So, generally one would run big3d install script if a) you upgraded DNS/GTM first and now you need to run this on the LTM or b) want to protect against backward compatibility issues broken due to BIG-IP update. Please see the following:

    If you have upgraded the LTMs first (correct order), and now you are upgrading the DNS/GTM (to the same BIG-IP version) then correct, the version of big3d should be the same. You can check this a few ways: a) via /usr/sbin/big3d -v in advanced shell or b) iqdump. You can check both client and server BIG3D versions in the iQuery communications. See the following:



  • Hi Jomedusa,

    BIG-IP DNS documentation asserts that the DNS device firmware version must be equal to or older than the big3d client version that is installed on the LTM "clients".   (big3d clients are backwards compatible with older versions of firmware on a BIG-IP DNS installation.

    But in my test environment i saw no issues when my DNS was on 15.x and my LTMs were still on to 12.x and i do not saw any issues to be very frank, but you should follow the F5 DNS documentation.

    When upgrading a multi-module network environment where BIG-IP DNS (formerly GTM) and BIG-IP LTM (and other modules) are configured as big3d clients, there is a concern about the correct order to upgrade the devices.   The quick answer, is that it depends on the timing.   The big3d environment that underlies the communication between BIG-IP DNS and it's BIG-IP LTM Clients, is only backwards compatible.

    With that being said, there are 2 preferred methods that are commonly used to upgrade environments with DNS and LTM.

    If you are staggering your upgrades, where at any time the BIG-IP DNS will have a newer version of firmware than the LTM devices:

    Upgrade DNS devices first, immediately followed by upgrading the big3d version on all 'client' devices.
    Upgrade BIG-IP DNS First 
    Upgrade the big3d client on each LTM device  to bring the big3d client version up to the DNS version.
    (see K13312: Overview of the BIG-IP DNS big3d_install, bigip_add, and gtm_add utilities (11.x - 16.x))
    At a future time, upgrade the BIG-IP LTM devices, to the same version the BIG-IP DNS device is on.

    Otherwise: Upgrade LTM Devices first, Then upgrade the DNS devices. 
    Upgrade all LTM devices -  the .iso includes the matching big3d client for that firmware release.
    this ensures the big3d client is 'newer or equal to' the BIG-IP DNS device version.
    at a future time, as required, upgrade the BIG-IP DNS device to match the BIG-IP LTM version.
    big3d version management

    To facilitate proper iQuery communication in your environment, you should be aware of the following big3d version management information:

    F5 recommends that all devices communicating over iQuery run the same big3d version
    When installing big3d on devices in the iQuery mesh, install the big3d agent from the BIG-IP DNS (formerly BIG-IP GTM) or Enterprise Management system that is running the latest software version, to the other devices in the iQuery mesh. For example, if the devices in the iQuery mesh are running different BIG-IP software versions, install the big3d agent from the device running the newest BIG-IP version to the other devices. This ensures that a device in the mesh does not run a big3d version that is older than its installed software version.
    Note: big3d is designed to be backward-compatible; therefore, you can upgrade big3d without having to upgrade the other monitored devices in the iQuery mesh TMOS version to match the TMOS version on BIG-IP GTM. You can check the big3d version by entering the big3d -v command. For additional information on updating big3d see K13312: Overview of the BIG-IP DNS big3d_install, bigip_add, and gtm_add utilities (11.x - 17.x) .

    BIG-IP DNS synchronization group communication
    Sync group members must run the same big3d version to avoid unexpected behavior such as big3d timeouts.
    DNS/GTM/BIG-IP communication
    Monitored BIG-IP systems must run the same or newer big3d version as the DNS / GTM devices that are monitoring them.
    Enterprise Manager/BIG-IP communication
    Managed BIG-IP systems must run the same or newer big3d version as the Enterprise Manager devices that are collecting data from them.

    Note: The big3d (iQuery) SSL cipher suite is currently hard-coded in the BIG-IP system and cannot be modified administratively.

    You can run iquery comand on your GTM/DNS box to see the Local BIG3d version and on the LTM by Remote BIG3d version as follows also you can check the latest COMMIT ID

    [root@Test-DNS02-external-mgt:Active:Standalone] config # tmsh show gtm iquery





    Server                                                                Test-DNS01-external-mgt

    Server Type                                                                BIGIP-DNS

    Data Center                                                                Test-DNS01-DC01

    State                                                                      connected

    Reconnects                                                                         0

    Backlogs                                                                           0

    Bits In                                                                       519.9K

    Bits Out                                                                       61.1K

    Bytes Dropped                                                                     42

    Cert Expiration Date                                               08/19/28 15:49:12

    Configuration Time                                                 01/11/23 10:06:44

    Configuration Commit ID                                                          159

    Configuration Commit Originator

    Local TMOS version                                                            12.1.3

    Remote TMOS version                                                           12.1.3

    Local big3d version                                           

    Remote big3d version                                        


    You  can also try to run iqdump  to check the big3d version


    [root@TEST-GTM-dns01:Active:In Sync (Sync Only)] config # iqdump
    <!-- Local hostname: -->
    <!-- Connected to big3d at: ::ffff: -->
    <!-- Subscribing to syncgroup: default -->
    <!-- Fri Nov 18 09:52:13 2022 -->
    <big3d>big3d Version</big3d>
    <!-- Fri Nov 18 09:52:15 2022 -->
    <!-- Fri Nov 18 09:52:25 2022 -->


    K13703: Overview of big3d version management

    Hope this helps