For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Aaron_33366's avatar
Aaron_33366
Icon for Nimbostratus rankNimbostratus
Feb 13, 2015

F5 sync options

I am looking for some help on F5 sync’ing options. I have opened an F5 support ticket with the below opening notes. However I thought I would reach out to the this forum as well. I wonder if this is even possible?

 

---F5 opening case notes---

 

I have some questions about config syncing on the F5s that I would like to discuss. We currently have 2 F5s in an active/standby failover config in our Minneapolis (MSP) location and we also have 2 F5s in the same setup in our Madison (MSN) location. The MSP location is production location and the MSN is our DR location. I would like to take the config that we have on our MSP location and sync it to the MSN F5s. However I don’t want the MSP and the MSN devices to be a failover group. I believe this is possible but I wanted to discuss this with F5 support. We already have the active/standby sync-failover group created in MSP and in MSN so that we have device redundancy in each location. What I believe we need to do now is to add all 4 devices to the trust list and then create a sync-only group and this will allow us to manually sync our config from MSP to MSN.

 

---End F5 opening case notes---

 

I have found some links that sort of show this as being possible.

 

https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/tmos-redundant-systems-config-11-1-0/5.html https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/bigip-device-service-clustering-11-2-1/6.html

 

In addition to the above info I have create a diagram of what I am looking to do. It is below.

 

16 Replies

  • Hi Aaron,

     

    the "sync-only" feature is not designed to synchronize LTM configuration changes.

     

    That´s why from my perspective your setup will not work as you expect it to.

     

    I´m not aware of a built-in method to synchronize configuration between units not part of the same "sync-failover" group.

     

    What kind of configuration changes you want to replicate?

     

    Will both sites use the same addressing schema for virtual IPs, floating self IPs, SNATs and NATs?

     

    Will they use the same VLAN names?

     

    If yes, how about using the iControl REST API (supported since TMOS v11.4) to apply config changes and just send duplicated commands to the two independent "sync-failover" device groups?

     

    Thanks, Stephan