Forum Discussion
One-Arm Mode Migration
- Jan 23, 2023
Sounds ok to me. Just check that the ARP is enabled on the virtual address of the VIP. By default it is, but to be sure please check.
In case you have issues make sure you check the arp table on the firewall and the vip ip is pointing to the right mac address. Probably it be good to check this before you migrate a vip , and record the mac address so you can compare it.
- Jan 24, 2023
Sri_Narasimha_05 the UCS restore overrides all configuration of the new device when imported last I had to do one with the exception of validating various difference between platforms when you use the platform migrate. You might try a UCS restore on a virtual appliance first in a sandbox to see exactly what happens.
Sri_Narasimha_05 Based on previous experience of migrating thousands of VIPs in a similar manner the better option, if you have the IP space for it, is to create the same virtual servers on the new F5s but with new destination IPs. For testing you can create one public to private NAT so that each group can test one at a time and all you have to do is change that one NAT for testing. On the you migrate a virtual server/s you would change the existing NAT/s for your production traffic to now NAT to the new virtual server/s IPs. Making the changes this way allows you one location to make changes and you will not have to mess with clearing any ARPs. About the only issue I can think that you might have is if your firewall uses the real IP to allow traffic rather than the mapped IP for security policies (SP) or access-lists(ACL). In order to get around the SP and ACL issue you can configure new SP and ACL with the new real IPs which should get rid of every possible issue. As applications are migrated you can update your documentation for the public to private mapping and virtual server association. Once you have finished the entire migration you can remove that single testing NAT because it is no longer necessary.
Now I do want to say that your plan will work it just requires you to deal with ARP, firewall issues, and F5 issues where the process I put forward would be one location and that's it.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com