Forum Discussion
K14823198: ASM guided configuration not synced to peer device after upgrade impact
Hello,
after Upgrade an active/standby cluster to 16.1.2.2 I ran into this:
https://support.f5.com/csp/article/K14823198
now I've 2 questions:
1. do I have to run this commands on active or standby?
2. what impact have this commands? I'm afraid of both units are active for a minute or so.
Thank you
Solution:
F5-Support provided me a Script "ha-sync" and after run
/var/tmp/ha-sync --force -H 192.168.97.2 -D device-group-failover-21b78xxxx
everything's ok now
restjavad restnoded are not critical processes related to F5 REST-API so it shouldn't cause big impact but still do this in a maintainance window:
https://support.f5.com/csp/article/K48615077
Also read the bug articles as they specify to run the commands first on the active then sandby
https://cdn.f5.com/product/bugtracker/ID860245.html
- kgaiglCirrocumulus
thank you, but my concern is, that if the device-trust is reset, then for a (very short) time both units are active and so there would be IP Adress Conflict when the same VIP's on both units are active.
I think about the commands restcurl -X DELETE...
I will try after Office Hours
If you are worrying about split brain you can make the standby in offline mode this way it will not take over as active even when the trust is broken between the HA pair.
- kgaiglCirrocumulus
oh, didn't think about this, thank you
Hello,
After the upgrade please share if everything is ok and if you saw any issues so we can close the question.
- kgaiglCirrocumulus
I'm in contact with the support, they told me to change in Ressource Provisioning the Management from Small to Large, now:
[root@ldb-ara31-brz-00:Standby:In Sync] ~ # restcurl shared/gossip |egrep '\"status\"|\"gossipPeerGroup\"' "status": "ACTIVE", "gossipPeerGroup": "tm-shared-all-big-ips",
in the overview of the Security Policies the Policies are present and attached to the VS, but under Guided Configuration, the Policies are still not present.
It looks like a displaying Error.
tried to export/import the Policies, get an Error, Policy already exists
tried to create a new Policy, this will also not displayed on the standby
- kgaiglCirrocumulus
after running the described actions, it's still the same on the standby-unit:
[root@ldb-ara31-brz-00:Standby:In Sync] ~ # restcurl shared/gossip |egrep '\"status\"|\"gossipPeerGroup\"' "status": "UNPAIRED", "gossipPeerGroup": "tm-shared-all-big-ips",
- kgaiglCirrocumulus
Solution:
F5-Support provided me a Script "ha-sync" and after run
/var/tmp/ha-sync --force -H 192.168.97.2 -D device-group-failover-21b78xxxx
everything's ok now
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com