Forum Discussion
GTM: https monitor
Hi, I've configured an https control on a BIGIP1600 GTM pool member for a service configured on BIGIP3600 LTM, it fails with the following error:
Jun 11 14:59:05 gtm2 gtmd[1894]: 011ae0f2:1: Monitor instance yyy.yyy.yyy.102:443 UNKNOWN_MONITOR_STATE --> DOWN from yyy.yyy.yyy.161 (state: protocol mismatch)
If I launch "telnet yyy.yyy.yyy.102 443" from the GTM the connection goes up.
Should I change cypher list on the GTM?
Thank you for your attention
23 Replies
- Cory_50405
Noctilucent
The LTM should be added under Global Traffic -> Servers as a BIG-IP System. Then under the LTM server object itself, you add a virtual server for your yyy.yyy.yyy.102 service on port 443.
GTM will run iQuery with the LTM to determine the health of its virtual servers.
- luigi_avella_10
Nimbostratus
I've made a capture on the LTM to catch the GTM monitor traffic:
tcpdump -i any host yyy.yyy.yyy.161 and port 443 tcpdump: listening on any 15:58:49.443234 802.1Q vlan4093 P0 yyy.yyy.yyy.161.34108 > yyy.yyy.yyy.102.https: S 449817390:449817390(0) win 5840 (DF) 15:58:49.443978 802.1Q vlan4093 P0 yyy.yyy.yyy.102.https > yyy.yyy.yyy.161.34108: S 3570641870:3570641870(0) ack 449817391 win 4380 (DF) 15:58:49.444944 802.1Q vlan4093 P0 yyy.yyy.yyy.161.34108 > yyy.yyy.yyy.102.https: . ack 1 win 5840 (DF) 15:58:49.444950 802.1Q vlan4093 P0 yyy.yyy.yyy.161.34108 > yyy.yyy.yyy.102.https: P 1:119(118) ack 1 win 5840 (DF) 15:58:49.445507 802.1Q vlan4093 P0 yyy.yyy.yyy.102.https > yyy.yyy.yyy.161.34108: P 1:123(122) ack 119 win 4498 (DF) 15:58:49.446407 802.1Q vlan4093 P0 yyy.yyy.yyy.161.34108 > yyy.yyy.yyy.102.https: . ack 123 win 5840 (DF) 15:58:49.446411 802.1Q vlan4093 P0 yyy.yyy.yyy.161.34108 > yyy.yyy.yyy.102.https: P 119:162(43) ack 123 win 5840 (DF) 15:58:49.446903 802.1Q vlan4093 P0 yyy.yyy.yyy.102.https > yyy.yyy.yyy.161.34108: . ack 162 win 4498 (DF) 15:58:49.447872 802.1Q vlan4093 P0 yyy.yyy.yyy.161.34108 > yyy.yyy.yyy.102.https: P 162:190(28) ack 123 win 5840 (DF) 15:58:49.448158 802.1Q vlan4093 P0 yyy.yyy.yyy.102.https > yyy.yyy.yyy.161.34108: R 123:123(0) ack 190 win 4569 (DF)
It seems that the LTM sends a reset
- Cory_50405
Noctilucent
Luigi, the proper setup is to configure iQuery between the GTM and LTM, and LTM will report the health of the virtual server to GTM through the iQuery connection. You would build your GTM pool to include the virtual server configured under the LTM server.
Check out section "Defining BIG-IP LTM systems" in this document:
http://support.f5.com/kb/en-us/products/big-ip_gtm/manuals/product/gtm-implementations-11-3-0/7.html
- luigi_avella_10
Nimbostratus
Hi Cory, of course I've already made all the necessary operations to configure the LTM and GTM appliances like explained in the link you've posted.
- Cory_50405
Noctilucent
Then you will not need to apply a monitor to the GTM pool, as the GTM is inheriting the health status from LTM.
- luigi_avella_10
Nimbostratus
Ok, I've taken off the monitor from pool, but I've the same result. Anyway on the LTM the status is OK.
Should I remove the monitor from the pool member too?
- Cory_50405
Noctilucent
Only remove the monitor from the GTM pool.
So is the pool member not being reported as up after removing the GTM pool monitor?
- luigi_avella_10
Nimbostratus
Yes, just the pool member, because the ather one in the same pool is up
- Cory_50405
Noctilucent
So your pool contains two members. One is a virtual server on the LTM, and what is the other one?
Could you post your GTM pool configuration?
- luigi_avella_10
Nimbostratus
Yes, the otherone is a virtual server on a remote LTM, the GTM contact it by routing. The same monitor on this last member (the virtual server on the remote LTM) works great.
- Cory_50405
Noctilucent
Would it be possible to not have a monitor applied to your GTM pool, and just apply a monitor to the virtual server on the remote LTM? Doing this should enable both members to be marked up without any pool level monitoring.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com