For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

stephiez_239090's avatar
stephiez_239090
Icon for Nimbostratus rankNimbostratus
Jan 17, 2016

How chatty is connection mirroring?

I have a U-shaped topology, 2 F5s to 2 routing-switches:

          +---------+             +---------+
          |         |             | LB2     |
          |   LB1   |             |         |
          +---------+             +---------+
            |    |                   |    |
            |    |                   |    |
            |    |                +---------+
          +---------+             |         |
          |         |             |  RS2    |
          |  RS1    +-------------+         |
          |         |             +---------+
          +---------+                   ^
               |  |                     |
               |  |                     |
    svr1 <-----+  |                     |
                  v                     +
                                        requests
                svr2

LBs are config-sync enabled, VIP is configured, and announced to each RS with a shared floating IP with LB1 as active LB. Vlans between server and clients (where requests come) are extended via link between RS1 - RS2. EBGP sessions are established between each LB - RS link. Tests conducted fine requests to VIP is forwarded to svr1,2. But to keep the TCP connections between clients and servers, connection mirroring is enabled to test LB failover. However, every time i have connection mirroring enabled, the server vlan becomes very chatty between LBs, thus the link RS1 - RS2 now carry extra traffic. The failover works just fine, but I see the throughput: OUT = 2xIN due to this. Is this expected behavior? If it is, what's the alternative? a separate link directly between LBs?

Thanks!!

1 Reply

  • Connection mirroring is extremely chatty because each connection to the active unit is mirrored to the standby. So, what you are seeing is the natural behavior. There's few alternatives, the best and recommended one is to have a dedicated mirroring VLAN carried in a direct link between the nodes, or at least through dedicated switch interfaces.