Forum Discussion
Difference between LTM Mgmt IP and Self IP
Hi all, why are we able to configure the F5 LTM using either F5 Mgmt or Self-IP address ?
I understand the Mgmt IP is solely use to configure the F5 at the inital stage and then later I start to use the Self-IP Floating IP to do any further configuration to avoid making the changes on the inactive node. But does it matter if we configure the LTM on either Mgmt IP or Self-IP ?
To go deeper into Self-IP I read up the link below, but I still can't understand F5 Self-IP completely. I only can understand that it's used as a default route to my VIPs which are on a different VLAN. https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/tmos-routing-administration-11-6-0/5.html
3 Replies
- Samir_Jha_52506
Noctilucent
. Basically management is use to manage f5 device configuration, Monitoring snmp, etc. Self IP address is an IP address on the f5 system that you associate with a VLAN, to access hosts in that VLAN. Most organization restrict self-ip to access LB device & don't segregate mgmt traffic to self-IP & avoid mess during troubleshooting.Its your choice how you are managing f5 device - hari_126827
Cirrus
Hi,
In my view, Mgmt Int. have its security reasons so that it will be in trusted network., and TMM interface could have LB traffic ( if needed + mgmt. traffic)
So yes (but not recommended), there is no issue observed in using self IP with confirming that "port lockdown" settings allowing SSH and 443 (whish is there in "allow default" port lockdown option)
please see if below links to see if it could help to reach the conclusion:
sol13284: Overview of management interface routing (11.x - 12.x)
sol13250: Overview of port lockdown behavior (10.x - 11.x)
sol7312: Overview of the management port
- Jinshu
Cirrus
You can access BIG IP GUI via self IP address (Consider it is not locked down) or management IP address.
I strongly suggest to aviod self IP address to use for any management related activities. There are situations like device offline etc where only management address will be active on system.
-Jinshu
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com