Forum Discussion
F5 cluster not syncing connections
Hello,
I have F5 cluster with active/active config and two traffic groups.
The first problem I see is that there is no syncing for firewall rules, only config related to LTM is being synced. The second problem is there's no syncing of connection states between devices. Every time I do a fail-over connections are being dropped because the state is not good.
I'm fairly new with F5 so anything can be of importance here. I have some feeling that everything related to firewall function is not being synced.
Here's the info on the devices and OS:
Platform Name BIG-IP vCMP Guest Software Version BIG-IP v11.6.0 (Build 4.0.420)
Thanks!
Bojan
8 Replies
- nathe
Cirrocumulus
Bojan,
When you say firewall rules do you mean AFM rules? This should get synced across devices. If you mean ASM then you need to create a specific Synchronisation Group in the ASM part of the GUI.
In regards connections been dropped on failover. By default the connection table is not mirrored to another LTM. To enable this you need to do this on a per-virtual server basis. Check the properties of a virtual server and you should see a connection mirroring check box. There is a warning, however, about increased network traffic.
Hope this helps,
N
- bojan_sukalo_20
Nimbostratus
Hello Nathan,
Thank You very much for your prompt answer.
When I say firewall rules, I mean the rules under Security, Network Firewall, Active rules.
I could not find the option for syncing connection on vhosts.
These are resources provisioned if that means anything to you.
AFM Nominal AM None APM None ASM None AVR None FPS None GTM Nominal LC None LTM Nominal SWG None
In any case, I appreciate the effort you took so far to answer me.
Bojan
- nathe
Cirrocumulus
is AFM provisioned on both boxes? any errors in the logs when doing a config sync?
- bojan_sukalo_20
Nimbostratus
Hello Nathan, yes it is.
vBIG-IP1 BIG-IP 11.6.0 4.0.420 HD1.2 AFM, GTM, LTM Active No vBIG-IP2 BIG-IP 11.6.0 4.0.420 HD1.2 AFM, GTM, LTM Active No
What baffles me is that I don't know whether also physical hosts need to be in sync state. They are now working as standalone.
As for v hosts, everything seems fine Failover_Group[In Sync] 2Sync-FailoverManual device_trust_group[In Sync] 2Sync-OnlyAuto
Both devices are "green". Anything done under LTM is synced to both nodes.
Cheers!
Bojan
- nathe
Cirrocumulus
What baffles me is that I don't know whether also physical hosts need to be in sync state. They are now working as standalone.The vcmp hosts will be standalone, you pair up the guests on the two hosts.
Any errors on the other vcmp guest during a sync?
N
- bojan_sukalo_20
Nimbostratus
No, there's no errors at all. At least from what I can see on the "Device Management ›› Overview"
I don't see anything in the system logs regarding this.
Bojan
- nathe
Cirrocumulus
hmm, might need to refer you to this askf5 sol: https://support.f5.com/kb/en-us/solutions/public/13000/900/sol13946.html, bit generic but might help
- bojan_sukalo_20
Nimbostratus
Thanks mate, I'll look into it!
Bojan
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com