For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Bhums_186567's avatar
Bhums_186567
Icon for Nimbostratus rankNimbostratus
Feb 10, 2015

F5 mac being learned for my nodes

There are few of my nodes which are down, however I am still able to get the mac address for those device and that mac address is the address for F5 interface.

 

Issue happens when one of my node which is down comes up on the network.

 

Can anyone please suggest why this happens and how can I avoid that.

 

5 Replies

  • shaggy's avatar
    shaggy
    Icon for Nimbostratus rankNimbostratus

    can you describe how the f5 is a part of this environment? is the f5 the default gateway of those nodes? is the device learning the F5's mac-address in a different network than those nodes?

     

    if i recall correctly, i've enable that functionality in the past when enabling ARP for a network virtual address that i use for a network virtual server

     

  • yes F5 is the default gateway for my servers. The nodes which are down are showing the F5 MAC.

     

  • Hi Bhums,

    as shaggy already mentioned, a network virtual address may cause the issue.

    Would you please provide the output of the following command:
    tmsh list ltm virtual-address one-line
    

    Perhaps you accidentially enabled ARP for a network virtual server?

    Second reason may be using VLAN groups in opaque mode. In case of a loop I can imagine a symptom like this.

    Thanks, Stephan
  • PS: In case you don´t want to reveal your IPs to the world the output should be anonymized. 🙂

    tmsh -q -c "cd /; list ltm virtual-address one-line recursive" | sed -r 's/(\/|address )([0-9]+\.){3}[0-9]+/**anonymized**/g'  
    
  • PS2: For whatever reason I cannot edit/delete the previous post.

    Here is a more verbose version and small fix:
    tmsh -q -c "cd /; list ltm virtual-address one-line all-properties recursive" | sed -r 's/(\/|address )([0-9]+\.){3}[0-9]+/\1**anonymized**/g'