Forum Discussion
I need help in completing this configuration
Hi my company bought a service contract with f5 the code is F5-SVC-BIG-PRE-L1-3, im trying to configure two BIG IP LTM devices but it seems after i have done all the configurations i cannot ping any of the self ip addresses or the virtual servers. My setup is like this CiscoASA G0/1 & G0/2 (192.168.15.5) ! ! --------------------------------------- ! ! ! (floating 192.168.15.1) ! bigip1 (ext-vlan192.168.15.2) bigip2 (ext-vlan192.168.15.3) ! ! ! (floating 10.10.168.1) ! bigip1 (int-vlan10.10.168.2) bigip2 (int-vlan10.10.168.3) ! ! ----------------------------------------
! ! Cisco switch ! ! HP-SERVER1 (10.10.168.13)---------------HP-SERVER2 (10.10.168.14)
Cisco ASA G0/1 & G0/2 bundled interfaces with IP Address 192.168.15.5. After configuring all the basic configs i cannot get my servers to ping any of my self IPs or even the Cisco ASA. I have also uploaded my qkview on ihealth case_number_C1431792_support_file(1).tar.
If you can help me please you can email me on kudakwashet@compulink.co.zw you can include the steps to configuring the device to basic connectivity even to get my data centre up my situation is critical, i have configured the rest of the network equipment im now only left with the BIG IPs. I have gone through a lot of the documentation found online but the staff is very confusing.
Regards
Kudakwashe Tayo
36 Replies
- Cory_50405
Noctilucent
If you can't ping the self IP addresses from your HP servers, then I suspect you've got a switching/vlan issue since they are in the same subnet. Do you have the appropriate vlan applied to your F5 interfaces, and is it tagged or untagged? Also, are the switch ports access ports or trunk ports?
- kudakwashet_154
Nimbostratus
They were access ports at first but i have changed them to be trunk ports now. One other thing i have noticed is that i had created a route domain and i mistakenly assigned the same ip address on the default route domain 0 and the other route domain 2 the IP addresses are 10.10.168.2 for route domain 0 and 10.10.168.2%2 for route domain 2 can this also cause my servers to not be able to ping the self IPs. i have tryed to delete and try to change the IP on one of the domains its not working it says its being used by mirroring how do i correct this.
Regards
Kudakwashe Tayo
- Cory_50405
Noctilucent
If you are using trunk ports on the Cisco switch, then you need to use tagged vlans on the BIG-IP. If using access ports on the switch, then use untagged vlans on the BIG-IP.
To change the mirroring IP, navigate to Device Management -> Devices -> self, then Device Connectivity tab, then Mirroring.
- kudakwashet_154
Nimbostratus
Hi i have put trunk on the cisco switch and i have tagged the vlans on my BIG IP but still no luck in pinging any of the self IPs. But my virtual server, nodes and pool are working correctly, does it mean if they are working even if i cannot ping that everything is working as it should.
Also if you can give me a link to some videos on how to configure the BIG IP in HA mode i would very much appreciate it coz i only got 2 videos from youtube the configuring high availability and the configuring route domains but if i can get a video that shows a configuration were you end testing pings i would be happy.
Regards
Kudakwashe Tayo
- kudakwashet_154
Nimbostratus
hi i have tried to upgrade my firmware now to 11.4 which was already preinstalled on the BIG IP but i cannot seem to be able to activate the new license i have tryed to send the dossier to f5 and they gave me every but still it is not activating can you help me
- Cory_50405
Noctilucent
Have you followed this solution and license reactivation fails? http://support.f5.com/kb/en-us/solutions/public/7000/700/sol7752.html
- Cory_50405
Noctilucent
When you say your virtual server, nodes and pool are working correctly, does this mean your pool health monitor is succeeding and client traffic through the virtual server is reaching your pool members?
There are some solutions detailing HA setup. Here are a couple:
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/tmos_management_guide_10_1/tmos_high_avail.html
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/tmos-implementations-11-4-0/2.html
- kudakwashet_154
Nimbostratus
I have managed to activate the device licenses thank you very much, but my issue was my management interface on the big ip devices are in a vlan that does not have internet access on my cisco switch.So i had to do a manual activation.
Thank you soooo much for your help
- Cory_50405
Noctilucent
Are there any other lingering problems or is everything working as intended now? HA setup all good and traffic flowing as expected?
- kudakwashet_154
Nimbostratus
Just finished on the activation i had to reconfigure everything but still i cannot ping the IP addresses although my nodes and everything are now showing green and they are said to be available.
Another issue im now facing after the upgrade is although my devices are sayed to be insync when i try to synchronise new configuration changes one of the devices is showing as disconnected. But im still to test on HA setup and traffic flow can you tell me how i can test these.
Will keep you informed.
- Cory_50405
Noctilucent
Make sure both units are configured to use the same corresponding address for config sync/failover. For example if you are using vlan 100 self IP on LTM A for config sync, set LTM B to use its corresponding vlan 100 self IP.
- kudakwashet_154
Nimbostratus
even on the statistics dashboard it shows that traffic is coming in and out from the interfaces could this mean all is well.
- Cory_50405
Noctilucent
Sounds like it, yes. If you can initiate a connection to the virtual server and it gets load balanced appropriately to your pool members, then it sounds like you have a working configuration.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
