Forum Discussion
F5 UAG SharePoint 2010 (NO DIRECT ACCESS)
Hi Guys,
I cannot find any info on using UAG with F5 in non integrated NLB mode and without DirectAccess. We are using UAG to publish SharePoint sites.
Just to share my config and get feedback on how to optimize it:
here is my config:
F5 VIP (UAG VIP) => 2 UAG servers (Array with Non integrated NLB) => F5 VIP (SharePoint) => 2 SharePoint servers
So connections to UAG servers are load balanced by the first UAG VIP and The Connections from the UAG servers are load balanced by the second SharePoint VIP to the sharepoint servers.
My concerns are about the NLB setting and VIP configurations needed to make this setup as optimized as possible.
So far we only created basic VIPs and monitors. The setup is working.
I read here (http://blogs.technet.com/b/edgeacce...dered.aspx) that the OneNetProfile is to be avoided on UAG vips.
So any advices, hints or links about this config are welcome.
Thanks.
- Ryan_Korock_46Historic F5 AccountHey Joe... The BIG-IP uses several pieces of data to track (and separate) connections. The most basic is the information found in the TCP & IP headers (source port/source IP - destination port/destination IP). In your case, since everything is coming from the same proxy and destined for the same VIP:Port, 3 out of those 4 will be identical. However your proxy will (most likely) be sending the traffic to the BIG-IP using different TCP source ports for each user based connection. This is enough information for the BIG-IP to understand that these are separate connections and load balance them independantly of eachother.
- Ryan_Korock_46Historic F5 AccountLazar, I believe cookie insert persistence, being based off a simple hash, has a couple advantages.
- Lazar_92526NimbostratusRyan,
- Kevin_StewartEmployeeThe biggest differences will be content inspection (or lack of), and the ability to persist user connections with anything other than client source addresses. With SSL passthrough you all lose iRules, protocol optimizations, and acceleration techniques native to LTM.
- JoeTheFifthAltostratusPosted By Ryan Korock on 03/22/2013 11:41 AM
Will go for cookie persistence since we're loadbalancing http traffic.
Will also stick to decryption/encryption of the SSL traffic.
- JoeTheFifthAltostratusIssues over here :-(
- JoeTheFifthAltostratusSolved the problem by enabling SNAT on both VIPS. UAG and SPS servers live in the same DMZ and are not forced to go through the F5 when communicating whith each other. We did have a similar issue which was solved by enabling SNAT on the UAG VIP but this was because we were trying to connect to the UAG portal (VIP) from a server which was in one of the the UAG internal routes.
- JoeTheFifthAltostratusanother issue here :-)
- Kevin_StewartEmployeeYou said this is a single VIP, yes? http://webapp01 and http://webapp02 resolve to the same VIP, and UAG01 and UAG02 are nodes in a single pool?
- JoeTheFifthAltostratussetup is like this:
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com