For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

wng_98840's avatar
wng_98840
Icon for Nimbostratus rankNimbostratus
May 11, 2015

Config sync/Device Groups

All,

 

Not sure if I am posting in right group. I have having issues getting the config sync/device groups working. I have 2-7250 chassis running as vCMP hosts. I have interface 1.1 plugged into a switch with the VLANs setup and I have interface 1.4 crossed over between the 2 chassis to be used as the config-sync/HA cable. I also have a guest setup on each of the vCMP hosts and trying to setup the Device groups on them, but the device groups show up as disconnected. Will this type of network setup work or does the HA need to be layer 2 to the switch?

 

Thanks in Advance,

 

Bill

 

17 Replies

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    Bill, your setup seems fine. Have you configured the configsync and network failover settings on both guests? Presume when you did the device trust and added the other guest as a peer this all worked?

     

    We probably need more info to fully help.

     

    N

     

  • Bill,

     

    I had this same issue on my pair of 7250v. What I ended up doing is to reset the device trust under Device Management ›› Device Trust : Local Domain. I generated a new self signed authority and the established the peering relationship again.

     

    Hope this helps.

     

    Robert

     

  • Here are the details of the configuration. Let me know if more detail is needed.

     

    ***vCMP host 1

     

    Interface 1.1 hooked into datacenter switch. Setup as trunk with VLANs Interface 1.4 hooked directly into vCMP host 2 interface 1.4 via crossover cable. HA VLAN setup as untagged going to 1.4 interface. All other internal VLANs(201,201,203) setup as tagged going to internal trunk hooked up to interface 1.1 Created Guest 1 on vCMP host 1. HA VLAN and other internal VLANs on list for Guest 1.

     

    ***vCMP host 2

     

    Interface 1.1 hooked into datacenter switch. Setup as trunk with VLANs Interface 1.4 hooked directly into vCMP host 1 interface 1.4 via crossover cable. HA VLAN setup as untagged going to 1.4 interface. All other internal VLANs(201,201,203) setup as tagged going to internal trunk hooked up to interface 1.1 Created Guest 1 on vCMP host 2. HA VLAN and other internal VLANs on list for Guest 1.

     

    ***Guest 1 on vCMP host 1(hostname: dev01, management IP 10.1.1.36)

     

    ConfigSync config set to use 192.168.11.100 Network Failover Unicast Address set to use 192.168.11.100 Primary Local Mirror Address set to use 192.168.11.100

     

    Added Guest1 from vCMP host2(hostname: dev02) using management IP(10.1.1.37) to Peer list. Peer list retrieved proper info from Guest1 on vCMP host2.

     

    Created Device Group List named test-device-group. Group type: Sync-Failover Added both members, dev01 and dev02 to list

     

    Clicked on Device management, overview. test-device-group says awaiting Initial Sync with 2 devices. dev01 has blue ball saying awaiting initial sync dev02 has red ball saying disconnected

     

    ***Guest 1 on vCMP host 2(hostname: dev02, management IP 10.1.1.37)

     

    ConfigSync config set to use 192.168.11.101 Network Failover Unicast Address set to use 192.168.11.101 Primary Local Mirror Address set to use 192.168.11.101

     

    Checked Peer list on Guest1 from vCMP host2(hostname: dev02). I see dev01 in list.

     

    No Device Group List setup on dev02

     

    Clicked on Device management, overview. No Device Groups listed on dev02

     

    • Robert_Luechte2's avatar
      Robert_Luechte2
      Icon for Cirrus rankCirrus
      Bill, did you try configuring a new device trust certificate? Your configuration and your issue sound exactly like mine and that was what I did to resolve it.
    • wng_98840's avatar
      wng_98840
      Icon for Nimbostratus rankNimbostratus
      Robert, I clicked on Reset Device Trust and then added the management IP of dev02 back into the Peer List. I also had to add it back into the test-device-group. Unfortunately it made no difference. So your setup is working fine? Am I missing something simple?
  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    Two things. Silly one first. You did select network failover as part of the device group setup? Secondly, I believe it's best practice to add the mgmt lan as an additional failover object. In vcmp environments I think you add this to the multicast section. Might be wrong. If it doesn't work try the mgmt address in the unicast config.

     

    N

     

  • Hi Robert,

     

    I tried again and generated new self-signed Authority on both vCMP guests. Still the same results. The Device group only needs to be on dev01 correct?

     

    Bill

     

    • nathe's avatar
      nathe
      Icon for Cirrocumulus rankCirrocumulus
      The device group will populate itself on both when all working
  • I have the device group defined on both of my guests, and I think that may be required.

     

    You wouldn't think this would be so difficult, would you. It usually works pretty simply, but it was a pain for me too.

     

    • Robert_Luechte1's avatar
      Robert_Luechte1
      Icon for Nimbostratus rankNimbostratus
      Also, are you synced to a NTP time source? I know that can be an issue.
    • wng_98840's avatar
      wng_98840
      Icon for Nimbostratus rankNimbostratus
      I agree. This shouldn't be rocket science, but I feel like I am missing something easy. I found out I had regular cable plugged between the 2 1.4 interfaces. I have since swapped it out for a regular crossover and still getting the same results.
    • Amresh008's avatar
      Amresh008
      Icon for Nimbostratus rankNimbostratus

      I hope the issue has been resolved. @wng, please confirm what was done to fix it.

       

  • I have the device group defined on both of my guests, and I think that may be required.

     

    You wouldn't think this would be so difficult, would you. It usually works pretty simply, but it was a pain for me too.

     

    • wng_98840's avatar
      wng_98840
      Icon for Nimbostratus rankNimbostratus
      I agree. This shouldn't be rocket science, but I feel like I am missing something easy. I found out I had regular cable plugged between the 2 1.4 interfaces. I have since swapped it out for a regular crossover and still getting the same results.
    • Amresh008's avatar
      Amresh008
      Icon for Nimbostratus rankNimbostratus

      I hope the issue has been resolved. @wng, please confirm what was done to fix it.