For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

pentax_120347's avatar
pentax_120347
Icon for Nimbostratus rankNimbostratus
Jun 20, 2013

HA problem v11.2.0

Hi all,

 

 

I’m pretty new in F5, so I’m a bit losing with configuration and troubleshooting with two boxes in v11.2.0. My problem is trying to create a HA pair.

 

 

I have one pair (A & B) with the following configuration

 

 

F5-A

 

Interface management= 1.1.1.1

 

Interface 1.1 = 2.2.2.1, vlan x untagged external, traffic-group-local-only

 

Interface 1.2 = 3.3.3.1, vlan y tagged internal, traffic-group-local-only

 

Interface 1.3 = 192.168.1.1 , vlan z untagged for sync, traffic-group-local-only

 

Floating IP=1.1.1.3 , traffic-group-1

 

Floating IP=2.2.2.3 , traffic-group-1

 

 

F5-B

 

Interface management= 1.1.1.2

 

Interface 1.1 = 2.2.2.2, vlan x untagged, traffic-group-local-only

 

Interface 1.2 = 3.3.3.2, vlan y tagged, traffic-group-local-only

 

Interface 1.3 = 192.168.1.2 , vlan z untagged, traffic-group-local-only

 

Floating IP=1.1.1.3 , traffic-group-1

 

Floating IP=2.2.2.3 , traffic-group-1

 

 

This configuration was created with the setup wizard. Both devices are directly connected via ports 1.3 (I’ve read this is possible)

 

 

In F5-A I can see this log message:

 

Attempting to connect to CMI peer 192.168.1.2 port 6699

 

CMI reconnect timer: enabled

 

Can't connect to CMI peer 192.168.1.2, port:6699, Transport endpoint is not connected

 

 

In F5-B I can see this log message:

 

Attempting to connect to CMI peer 192.168.1.1 port 6699

 

Can't connect to CMI peer 192.168.1.1, port:6699, Transport endpoint is not connected

 

 

Any idea?

 

Thanks in advance!

 

 

7 Replies

  • Have you reviewed this document?

     

     

    sol13946: Troubleshooting ConfigSync and device clustering (11.x)

     

    http://support.f5.com/kb/en-us/solutions/public/13000/900/sol13946.html?sr=30172557
  • Yes I do.

     

    If I go to F5-A I can see in the Device management the box A Up and the B offline (but I can see his managemnt addres, his hostname and his version)

     

    If I go to F5-B I can see in the Device management the box B Up and the A unknow state (I cannot see his managemnt addres, his hostname and his version)
  • Can you:

     

     

    1. Run netstat -pan | grep -E 6699 on each device and confirm that the list looks the same on each, and

     

     

    2. Run a tcpdump and see if either of the devices is rejecting any traffic on any port between the two.
  • kinda miss the old HA configuration :(

     

     

    try to get the second box off the cluster (device mgmt menu) and then add it again.

     

    Also try changing the port lockdown settings to Allow All, while troubleshooting this issue.

     

     

     

     

    good luck
  • Dear,

     

    Open a case, F5 engineers will help you. read below links you might miss something.

     

    http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/tmos_management_guide_10_1/tmos_high_avail.html

     

    http://support.f5.com/kb/en-us/products/big-ip_ltm/releasenotes/product/relnote-ltm-11-2-0.html