Forum Discussion
F5 Migration between DCs
I have couple of F5's in a data center and want to migrate to single F5 in different DC. All the F5 configurations including the VIP's, Profile, certificate needs to be consolidated into single F5. What approach need to be taken to migrate the config's. Would GUI or CLI migration approach or advise the best way forward. Any help Appreciated.
5 Replies
The SSL certs and keys might be the most time consuming but using the SCF file might be the easiest way to migrate a large portion of the configuration, this is assuming IPs are probably changing. Alternatively, you can log into each F5 and do a list for all the configuration, update the IPs as necessary, and then use the "load system config from-terminal merge" to paste in the output you collected and updated. It's very important to make sure SSL profile names and the cert/key file names match otherwise it will generate a lot of errors.
- arvindia7
Altostratus
Thanks , I figured there are Route Domain configured on the existing F5's and need input if any specific consideration needs to be taken regarding the Interface, Routes, Self IPs, Route Domain, Vlan considerations. One thing I would check if there is no overlapping IPs, name which might conflict whilst these are migrated to Single F5 in different DC. If the Route domain ID is same i.e. 1, 2 on most of the F5's I might think to renumber while preparing the configurations. Any Input would be appreciated for other aspects as well.
use gui and tmsh.
network layer config using gui shouldnt be a lot.
for ltm, copy pasting "list ltm recursive all-properties one-line" output to the new f5 is usually sufficient.- arvindia7
Altostratus
Thanks ,
On a high level -
- should I keep the VIP, Nodes, Self IPs and Vlan identical on new DC as per existing F5 configurations.
- The new F5 would have Inside, Outside and Mgmt IPs from the new DC subnet.
- The Nodes/ Server would still be in old DC until migration of the Server takes place.
In order for the new F5 with new Inside/ Outside Interface and new subnet to reach the nodes/ server in the old DC, any additional network, interface, route configuration I should take into account.
I would ensure to check the routing from the new F5 to the nodes/ server in the old DC where the server would reside.
Any additional checks/ routing requirements and the design should be working on the new setup.
Thanks for your help on this in advance.
- Melissa_C
Moderator
Hey arvindia7
Noticed it had been a bit since any update, wanted to check if you were able to get any of the additional information you were looking for and could provide an update or if you needed assistance still.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com