For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

kgaigl's avatar
kgaigl
Icon for Cirrocumulus rankCirrocumulus
Jul 04, 2023

how to find out where an old IP Adress is used

Hello,

a few months ago we changed the vlan for a management-IP Adress, now i observed on the firewall the F5 tries to connect to the old management IP, but I can't find the IP in Config.

On ihealth I searched the Log for the old IP and I found a lot of entries like

 

 

makeRestCall (external) {"protocol":"https:","slashes":true,"auth":null,"host":"192.168.2.70:443","port":"443","hostname":"192.168.2.70","hash":null,"search":null,"query":null,"pathname":"/mgmt/tm/asm/policies/9E4OvTih1_P4Vau7wFUGVg","path":"/mgmt/tm/asm/policies/9E4OvTih1_P4Vau7wFUGVg","href":"https://192.168.2.70:443/mgmt/tm/asm/policies/9E4OvTih1_P4Vau7wFUGVg"}

 

 

where 192.168.2.70 is the old MGMT IP.

other Logs:

 

 

POL-xxx (ASM-Policy) connect ECONNREFUSED 192.168.2.70:443

 

 

could you give me a hint, where to look for in Configuration?

Reason:

trying to find out, why sometimes there's a failover to secondary machine and losing connection to pool-members

thank you

Karl

4 Replies

    • Paulius's avatar
      Paulius
      Icon for MVP rankMVP

      kgaigl Typically that command is used when upgrading HA pairs of BIG-IQs but that's good that it resolved your issue. This might be worth bringing to the attention of F5 to see if they have a bug related to this specifically.

  • Have you done a cd into the /config directory and performed a grep on all files? Also consider creating a QKView, loading into F5 iHealth, and performing a search for the IP address.

     

  • kgaigl's avatar
    kgaigl
    Icon for Cirrocumulus rankCirrocumulus

    I created already a qkview and in Ihealth I found the Log-Entry.

    But I did not found the IP Adress in Config Explorer