Forum Discussion

danielo303_1961's avatar
danielo303_1961
Icon for Nimbostratus rankNimbostratus
Aug 15, 2012

How to source outbound traffic from VIPs

We have approximately 100 virtual servers on our Big-IP 1500 running 9.4.3. A few weeks ago our upstream Cisco 7613 routers and the internal firewall modules rebooted simultaneously. The routers were back online in minutes, but many of our virtual servers were unavailable for almost two hours after that event.

 

 

The firewall modules are an HA pair, and they translate the private IP's from the F5 to the public IP address. What happened was that when the firewall modules came up, they both must have been active briefly, and a number of VIP's became associated with the inactive firewall's MAC address (on the outside interface). A "clear arp" on the router fixed this, but we suffered too much downtime before hitting on this.

 

 

 

I am looking for a way to source outbound traffic from the virtual server IP every 10 or 15 seconds, to ensure that it's ARP entry will constantly be refreshed. It could be a ping, or UDP packet or whatever - just something that will generate traffic, and thereby refresh the ARP entry in the upstream router.

 

 

 

Anybody have any thoughts on how to make this happen?

 

 

 

Thanks!

 

-Daniel

 

No RepliesBe the first to reply