Forum Discussion
xiaofan_lu_1135
Nimbostratus
Feb 08, 2010How do I block ping for vs
When the pool member does not respond , how to refuse to ping, Irules can solve this problem? thanks
4 Replies
- hoolio
Cirrostratus
Hi,
It isn't possible do disable ICMP to a virtual address with an iRule on a virtual server. You can check this post for details:
vserver ALWAYS replies to ping
http://devcentral.f5.com/Default.aspx?tabid=53&view=topic&postid=55930&ptarget=55932
Aaron - JRahm
Admin
Faced similar issue when migrating from GSS to GTM. Changed the monitor to TCP from ICMP and build iRule to drop requests if no active pool members are present. - marker_58064
Nimbostratus
Jason,
I'm having a similar issue at this time but we are still using a GSS to monitor our F5 Virtuals. I can't figure how we can accurately monitor the health of the Virtual if it responds to Ping and TCP port are responsive. Any suggestions? - hoolio
Cirrostratus
I assume you'd need to configure the GSS to check for a specific string in the response--not just that a TCP connection is completed. With the iRule you could send a reset in CLIENT_ACCEPTED if [active_members [LB::server pool]] == 0. The GSS health check should then fail when the VS's pool is down.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
