For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

bojan_sukalo_20's avatar
bojan_sukalo_20
Icon for Nimbostratus rankNimbostratus
May 13, 2015

F5 cluster not syncing connections

Hello,

 

I have F5 cluster with active/active config and two traffic groups.

 

The first problem I see is that there is no syncing for firewall rules, only config related to LTM is being synced. The second problem is there's no syncing of connection states between devices. Every time I do a fail-over connections are being dropped because the state is not good.

 

I'm fairly new with F5 so anything can be of importance here. I have some feeling that everything related to firewall function is not being synced.

 

Here's the info on the devices and OS:

 

Platform Name BIG-IP vCMP Guest Software Version BIG-IP v11.6.0 (Build 4.0.420)

 

Thanks!

 

Bojan

 

8 Replies

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    Bojan,

     

    When you say firewall rules do you mean AFM rules? This should get synced across devices. If you mean ASM then you need to create a specific Synchronisation Group in the ASM part of the GUI.

     

    In regards connections been dropped on failover. By default the connection table is not mirrored to another LTM. To enable this you need to do this on a per-virtual server basis. Check the properties of a virtual server and you should see a connection mirroring check box. There is a warning, however, about increased network traffic.

     

    Hope this helps,

     

    N

     

  • Hello Nathan,

     

    Thank You very much for your prompt answer.

     

    When I say firewall rules, I mean the rules under Security, Network Firewall, Active rules.

     

    I could not find the option for syncing connection on vhosts.

     

    These are resources provisioned if that means anything to you.

     

    AFM Nominal AM None APM None ASM None AVR None FPS None GTM Nominal LC None LTM Nominal SWG None

     

    In any case, I appreciate the effort you took so far to answer me.

     

    Bojan

     

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    is AFM provisioned on both boxes? any errors in the logs when doing a config sync?

     

  • Hello Nathan, yes it is.

     

    vBIG-IP1 BIG-IP 11.6.0 4.0.420 HD1.2 AFM, GTM, LTM Active No vBIG-IP2 BIG-IP 11.6.0 4.0.420 HD1.2 AFM, GTM, LTM Active No

     

    What baffles me is that I don't know whether also physical hosts need to be in sync state. They are now working as standalone.

     

    As for v hosts, everything seems fine Failover_Group[In Sync] 2Sync-FailoverManual device_trust_group[In Sync] 2Sync-OnlyAuto

     

    Both devices are "green". Anything done under LTM is synced to both nodes.

     

    Cheers!

     

    Bojan

     

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    What baffles me is that I don't know whether also physical hosts need to be in sync state. They are now working as standalone.

    The vcmp hosts will be standalone, you pair up the guests on the two hosts.

    Any errors on the other vcmp guest during a sync?

    N

  • No, there's no errors at all. At least from what I can see on the "Device Management ›› Overview"

     

    I don't see anything in the system logs regarding this.

     

    Bojan

     

    • nathe's avatar
      nathe
      Icon for Cirrocumulus rankCirrocumulus
      hmm, might need to refer you to this askf5 sol: https://support.f5.com/kb/en-us/solutions/public/13000/900/sol13946.html, bit generic but might help