For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

dave_keitges_20's avatar
dave_keitges_20
Icon for Nimbostratus rankNimbostratus
May 07, 2014

gtm listener on a gibp ve with ltm and other modues active.

On a 11.5 system is says to put the GTM DNS listener on the floating ip of a ha pair. The ve we are running has ltm, ap, afm and asm also running. I was thinking you just use an ip on the external vlan because whichever one is active will be used but the support page says to use the floating ip of I assume is the external vlan and I don't have a seperate vlan for the dns part. Does this seem right?

 

6 Replies

  • By all means, you can create a new vlan and associated self IPs (non-floating and floating), and then setup your listener on your new floating self IP. Or you can use an existing floating self IP. All a matter of personal preference, but technically either approach should work. Assuming the underlying network configurations are there to support of course.

     

  • Ok that makes sense. My question is why do you need to use the floating ip of the external subnet at all? I would think if you give a ip on the external subnet it shoud reolve to which ever active bigip is up. kind of like a virtual server that is a .20 on the same subnet as the .10 floating ip and selfips. I don't want to create a new selfips and a floating but I really don't understand why you would use the floating ip since whatever ip on the subnet will be available on which ever bigip is active.

     

  • I haven't tested what you are thinking, but in theory it should work unless there's some limitation that I'm unaware of. Creating a listener creates a corresponding virtual server, and as long as that virtual server is in a vlan with the appropriate self IPs, then gratuitous ARP should work in the event of a failover.

     

    I'm going to mock this up in the lab tomorrow to test it out.

     

  • That is what I thought, but the documentation says differently. Thanks for checking it out.

     

  • Maybe more of a 'best practices' type thing to use the floating self IP. But it'll certainly work the way you want.