Forum Discussion
mjaved_62370
Nimbostratus
Nov 13, 2008GTM/LTM Active Active 3400s
Hi
Need some help on the below.
We have 2 3400s running LTM/GTM feature set.
Both are configured in one sync group and running GTM function. Recently we want to achieve firewall load balancing via the LTM funtion on both boxes only having 1 vip as a default gateway to half of servers in dmz and remaining servers have other vip as default gateway.
So for half of servers in dc1 traffic goes out via gtm/ltm_dc1 - vip 10.1.1.1
and for other half of servers in dc2 traffic goes out via gtm/ltm_dc2 - vip 10.1.1.2
Incase of failure of gtm/ltm_dc1 all traffic routes via gtm/ltm_dc2 - takes vip 10.1.1.1
both 3400 will have a transparent virtual server 0.0.0.0 pointing to firewalls_pool
To accomplish this we are thinking of running active/active on both 3400s hosting gtm/ltm functionality.
Just wandering is this a good idea?
And once done how does the gtm function gets impacted by this?
Thanks.
- The_Bhattman
Nimbostratus
I have never ran a GTM and LTM feature set on a single redundant unit. My reasons were unique to my situation because the GTM served not only as a relay but a lookup for other servers outside LTM. Thus I didn't want them to be mutually exclusive for the sake of redundancy and scalability. - mjaved_62370
Nimbostratus
Many thanks guys makes perfect sense. 1 down 1 more problem to go. Please help. - dennypayne
Employee
Yes you need to use the translation option...keep in mind on GTM you're not actually adding the IP's to that device when you define virtual servers, you're just defining the resources that it knows about so it can hand out a DNS resolution. So it needs to know the private IP so it can monitor the availability of the virtual server, but it needs to hand out the public address. The translation option just correlates the private with the public so that GTM knows it's the same object. - dennypayne
Employee
Oh, and as far as services go, again, GTM is handing out a DNS resolution. It doesn't care about ports. The only reason there are port definitions on the virtual servers is to make it easier to manage a long list of them when you add a Wide-IP (ie, if you tell GTM the port is 80 in the WIP definition, it will only show you virtuals also listed on port 80 in the config). - mjaved_62370
Nimbostratus
Many Thanks Denny so what you are saying - Just to clarify
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects