Forum Discussion
Does F5 VE trail version 11.3 support device service cluster(DSC) feature?
Hello,
Does F5 VE trail version 11.3 support device service cluster(DSC) feature?
I downloaded VE trail version 11.3, and deployed 2 VEs and want to configure the DSC feature. I fllowed the document to configure it. But the communication between the 2 servers are failed. Device trust has already been configured. Form the /var/log/ltm, I saw the problem is VE can not connect the peer's port 6699. In fact, the network communication is OK, because the port 22 is ok on the sync IP. But it failed on port 6699. First say connected to port 6699, and then it says the connection removed by peer right away.
28 Replies
- What_Lies_Bene1
Cirrostratus
Do you see any messages in the logs on the other VE?
- nathe
Cirrocumulus
The release notes don't mention that you can't cluster VEs, although I didn't actually think you could (perhaps that was when it was at v10).
Anyway, your scenario suggests a configuration/setup issue as it's obviously trying to add the peer device.
I would re-check your steps in setting up the DSC.
Hope this helps,
N
- shihongshan1982
Nimbostratus
Yes, I have seen that V10 do not support this kind of redundant service. But I can not find the release note of this V11.3. So I am not sure I can setup DSC on VE trail 11.3.
I setup like the following: 1. specifying the IP address for the config sync 2. Specifying the IP address for the connection mirroring 3. Establish the device trust. After setup the device trust, VE1 can see VE2 in the device list, and VE2 can also see VE1 in the device list. 4. Create a sync-failover device group. I selected Sync-Failover and also selected Network Failover. 5. From VE1, In Device Management -> Overview. I can see that VE2 is disconnected. From VE1's log: May 8 16:21:54 bigip1 notice mcpd[5347]: 0107143c:5: Connection to CMI peer 198.18.31.102 has been removed May 8 16:21:59 bigip1 notice mcpd[5347]: 01071431:5: Attempting to connect to CMI peer 198.18.31.102 port 6699 May 8 16:21:59 bigip1 notice mcpd[5347]: 01071432:5: CMI peer connection established to 198.18.31.102 port 6699 May 8 16:21:59 bigip1 notice mcpd[5347]: 0107143c:5: Connection to CMI peer 198.18.31.102 has been removed May 8 16:22:04 bigip1 notice mcpd[5347]: 01071431:5: Attempting to connect to CMI peer 198.18.31.102 port 6699 May 8 16:22:04 bigip1 notice mcpd[5347]: 01071432:5: CMI peer connection established to 198.18.31.102 port 6699 May 8 16:22:04 bigip1 notice mcpd[5347]: 0107143c:5: Connection to CMI peer 198.18.31.102 has been removed May 8 16:22:09 bigip1 notice mcpd[5347]: 01071431:5: Attempting to connect to CMI peer 198.18.31.102 port 6699 May 8 16:22:09 bigip1 notice mcpd[5347]: 01071432:5: CMI peer connection established to 198.18.31.102 port 6699 May 8 16:22:09 bigip1 notice mcpd[5347]: 0107143c:5: Connection to CMI peer 198.18.31.102 has been removed
The same kind of log we can see in VE2. From the above the log. I think the network connection is OK, as you can see the connection is established; but it removed by the peer right away. There is no route problem, because if I tried use telnet to the peer server port 22, it is OK.
- shihongshan1982
Nimbostratus
Yes, I have seen that V10 do not support this kind of redundant service. But I can not find the release note of this V11.3. So I am not sure I can setup DSC on VE trail 11.3.
I setup like the following: 1. specifying the IP address for the config sync 2. Specifying the IP address for the connection mirroring 3. Establish the device trust. After setup the device trust, VE1 can see VE2 in the device list, and VE2 can also see VE1 in the device list. 4. Create a sync-failover device group. I selected Sync-Failover and also selected Network Failover. 5. From VE1, In Device Management -> Overview. I can see that VE2 is disconnected.
From VE1's log:
May 8 16:21:54 bigip1 notice mcpd[5347]: 0107143c:5: Connection to CMI peer 198.18.31.102 has been removed May 8 16:21:59 bigip1 notice mcpd[5347]: 01071431:5: Attempting to connect to CMI peer 198.18.31.102 port 6699 May 8 16:21:59 bigip1 notice mcpd[5347]: 01071432:5: CMI peer connection established to 198.18.31.102 port 6699 May 8 16:21:59 bigip1 notice mcpd[5347]: 0107143c:5: Connection to CMI peer 198.18.31.102 has been removed May 8 16:22:04 bigip1 notice mcpd[5347]: 01071431:5: Attempting to connect to CMI peer 198.18.31.102 port 6699 May 8 16:22:04 bigip1 notice mcpd[5347]: 01071432:5: CMI peer connection established to 198.18.31.102 port 6699 May 8 16:22:04 bigip1 notice mcpd[5347]: 0107143c:5: Connection to CMI peer 198.18.31.102 has been removed May 8 16:22:09 bigip1 notice mcpd[5347]: 01071431:5: Attempting to connect to CMI peer 198.18.31.102 port 6699 May 8 16:22:09 bigip1 notice mcpd[5347]: 01071432:5: CMI peer connection established to 198.18.31.102 port 6699 May 8 16:22:09 bigip1 notice mcpd[5347]: 0107143c:5: Connection to CMI peer 198.18.31.102 has been removed
The same kind of log we can see in VE2. From the above the log. I think the network connection is OK, as you can see the connection is established; but it removed by the peer right away. There is no route problem, because if I tried use telnet to the peer server port 22, it is OK.
- nathe
Cirrocumulus
perhaps changing the mcp logging level to debug might give you more info in the logs too. - shihongshan1982
Nimbostratus
where to change this log level - nathe
Cirrocumulus
in the GUI in the Logs - Options section, or at the command line with this command modify /sys db log.mcpd.level value debug
- What_Lies_Bene1
Cirrostratus
I'd agree with nathan and suggest you break the trust and start again. However, I suspect this will be a limitation of the VE trial. Worth one more go though.
I've not thought about troubleshooting in detail too much at this point but if it helps any, these CLI commands may be more revealing as you work through the issue;
[tmsh] show cm device-group [tmsh] run cm watch-sys-device [tmsh] show cm device [tmsh] run watch-devicegroup-device [tmsh] show sys ha-status [tmsh] show sys failover [tmsh] show cm sync-status [tmsh] show cm failover status [tmsh] show cm traffic-group - bboyjnr_8532
Cirrus
hi guys,
my understanding is that there is still HA limitations in the 11.3 trial version, this is coming from a comment on one of the linked in F5 groups by an f5 employee.
would be good to get an official statement from F5 on this similar to the limitations of the LAB VE license.
Thanks,
B
- nathe
Cirrocumulus
Thanks bboyjnr
anyone got an update from F5 or such? anyone opened a ticket to check?
- ut03550
Nimbostratus
Anyone knows something about this question? I'm trying to configure sync behavior in VE Trial v11.3 and it was impossible.
- nitass
Employee
is there VE 11.3 trial edition? is it production edition but evaluation license?
i am not sure but i think i have run ha pair in VE 11.3 before. i am now running ha pair in 11.5.1. i do not think it is limitation in VE 11.3. you may open a support case to verify.
- ut03550
Nimbostratus
Yes, there is a VE Trial 11.3:
https://www.f5.com/trial/secure/big-ip-ltm-virtual-edition.php
And with Evaluation License, I cannot get working Config Sync....
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com