Forum Discussion

Fernando_Carran's avatar
Fernando_Carran
Icon for Nimbostratus rankNimbostratus
Dec 04, 2018

Link Controller sync issues

Hi Folks.

We tried to configure LC from standalone to HA (Active-Standby). When we run gtm_add the objects of LC was synced. After, when we try to sync from Device Management only LTM objects are synced. Other issue is that the monitors mark down (Links and wideips) on Standby Unit.

We followed the next steps ( https://support.f5.com/kb/en-us/products/lc_9_x/manuals/product/lc-implementations-11-6-0/4.html😞

-Build cluster with HA vlan and failover connection.

-Sync using HA VLAN. Secondary using MGM.

-Network failover using HA VLAN.

-Create Sync failover group.

-Configure NTP.

-Add the floating IPs and Sync.

-Configure Port-lockdown allow default.

-Enable Golbal traffic Sync.

-Run gtm_add tool.

-Test to add LC object and is not synced. Only works when run again gtm_add tool

Note: For one ISP we have one public IP available (used only for outbound traffic). The self-IP is configured on Active Unit.

F5 active

ISP 1 .- Self IP and floating IP (Vlan 2)

ISP 2.- Self IP and floating IP (Vlan 3)

ISP 3.- Self IP and floating IP (Vlan 4)

ISP 4.- Self IP ( Vlan 5) (We have 1 public IP)

F5 standby

ISP 1.- Self IP and floating IP (Vlan 2)

ISP 2.- Self IP and floating IP (vlan 3)

ISP 3.- Self IP and floating IP (Vlan 4)

ISP 4.- No self IP

  • Please verify whether device certificates are in sync and are upto dat. if device certificate is not in sync between active and standby, wideip's will go down.

     

    • Fernando_Carran's avatar
      Fernando_Carran
      Icon for Nimbostratus rankNimbostratus

      Hi RaghavendraSY.

       

      Thank you for you advice. We resolved the issue with the next steps (with help of F5 ticket):

       

      • Rebuild the cluster. Ensure that ISP4 only using for outbound traffic. As we can see, the LC objects synced through selfi-ip, the ports we configured in port lockdown "default". The LTM objects synced through HA VLAN.

         

      • Add snat pool for outbound traffic (using self-ip for ISP4 and floating for the others ISPs). Automap create route issues when you use floating and selfips for outbound traffic. Reference: K7336

         

  • Please verify whether device certificates are in sync and are upto dat. if device certificate is not in sync between active and standby, wideip's will go down.

     

    • Fernando_Carran's avatar
      Fernando_Carran
      Icon for Nimbostratus rankNimbostratus

      Hi RaghavendraSY.

       

      Thank you for you advice. We resolved the issue with the next steps (with help of F5 ticket):

       

      • Rebuild the cluster. Ensure that ISP4 only using for outbound traffic. As we can see, the LC objects synced through selfi-ip, the ports we configured in port lockdown "default". The LTM objects synced through HA VLAN.

         

      • Add snat pool for outbound traffic (using self-ip for ISP4 and floating for the others ISPs). Automap create route issues when you use floating and selfips for outbound traffic. Reference: K7336