Forum Discussion
Does f5mku rekeying work across different BIGIP versions?
If you have an old HA cluster you can extract the master key from any of the old F5s with:
f5mku -K
Example:
[root@f5bigip:Active:Disconnected] config # f5mku -K
aVNFRwSdF2Q38L9fw7jzlC==
You can then reset the master key on the new F5 device:
f5mku -r aVNFRwSdF2Q38L9fw7jzlC==
After that you should be able to load the UCS file without getting the encrypted object errors.
I've done these between different BigIP versions (12.x-->14.x, 14.x-->15.x) and from hardware to VE and viceversa. I don't remember doing it from version 11.x, but I guess it should work ass well since that command existed in that version.
Hope that helps.
- CA_ValliNov 10, 2021MVP
F5MKU rekeying was possible but the problem is that I could not run v11.5 on (required for ucs file import) since it was not supported on new hardware.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com