For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

akqadm_158140's avatar
akqadm_158140
Icon for Nimbostratus rankNimbostratus
Jul 10, 2014

health check status different in GUI and tmsh solved

Hi, ich have a working ha cluster based on version 11.5.1. Further I do have several working VS on it. But I have one VS whith 2 Nodes. In the Gui of one cluster member both nodes show status=green. In the gui of the second cluster member one node shows=black.(Offline (Enabled) /Common/icmp: Failed to succeed before deadline) Its a very simple ICMP Host Check.

 

When I do look into the tmsh on both cluster members everythings is up and running.

 

9 Replies

  • Two things I'd check:

     

    1. Are the cluster members in sync? And if not, has one of them been set to force down that member (pool member or individual node)?

       

    2. From the shell of the device that shows the node down, do a tcpdump and see if icmp traffic is getting returned to this device.

       

  • Hi,

     

    the cluster is definately in sync and I do see ICMP echo request from its self IP and a reply back to it. So as I already stated a "list pool ..." on the tmsh looks fine. But the Gui states the host is not reachable.

     

  • Questions:

     

    1. The green/black status you are referring to, are you looking at the node status or pool member status?

       

    2. Does the icmp monitor have "manual resume" or "time until up" enabled?

       

    1. the Node availability is red and the health monitor for it is Black(Mouseover: Monitor Instance disabled) pool member status is just red
    2. i deal with the default common icmp monitor with "Time until up = 0" and no manual resume
  • I'm not sure what would cause the monitor itself to be black. Is it a black circle or black diamond?

     

    Back in v9.x monitor instances could be disabled but that setting is no longer available. It might be time to open a support case with F5.

     

  • akqadm,

     

    I was able to partially duplicate your issue in my lab (using v11.4.0) and it seems like it might be a bug. Here is my configuration and the steps I took:

     

    1) BIGIPA and BIGIPB in HA and in sync

     

    2) Force a node offline on BIGIPA. LTM will stop the monitor when a node is forced offline resulting in the monitor status reporting black circle and "Monitor instance disabled". Node status will be black diamond.

     

    3) Step 2 causes changes pending for config sync so sync BIGIPA to BIGIPB. Now BIGIPB displays same monitor and node status as BIGIPA.

     

    4) On BIGIPA enable the node that was forced offline in step 2. Now monitor and node status are both green circles on BIGIPA.

     

    5) Step 4 causes changes pending so sync config BIGIPA to BIGIPB. I now see that even though the BIGIPs are in sync they are displaying different status for the node. BIGIPA shows node and monitor green. BIGIPB shows node red diamond and monitor status black circle. In my tests tmsh reported the same status as the gui for both BIGIPs.

     

    6) I was able to get the node/monitor status back in sync by selecting "Overwrite configuration" and then synchronizing A to B. Now both BIGIPs show node/monitor status as green circles.

     

    Scott

     

  • I now tryed to synch the active machine to the standby(which has the problem) including config overwrite. I shouldn´t have done it -.- now my cluster is out of synch! Error message: Sync error on lbname: Load failed from lbname 01020060:3: IP Address 255.255.255.255 is invalid, must not be all ones.

     

  • Looks like you have device group communication or configuration problems. This article may help SOL13946.

     

    Open a case with F5 support.

     

  • So i did opened a Case at F5. The reason for Cluster out of synch was a remaining ltm virtual-address /Common/255.255.255.25 in the tmsh config which was not visable in the gui. After deleting this entry config synch was possible again and also did resolved the root cause with difference between gui und tmsh.

     

    You can read more here: ID421985

     

    Thank you guys for your support