Forum Discussion

dipta_03_149731's avatar
dipta_03_149731
Icon for Nimbostratus rankNimbostratus
Jul 23, 2015

Pool members are not reachable from LTM after creating self IP and VLAN

I have created a new LTM set up where the servers belong to 172.17.48 subnet.

 

I created a new VLAN on F5 , this is the same VLAN on which server subnet is defined.

 

Next created self IP and Floating IP in 172.17.48 subnet.

 

But after creating pool I see members are marked Down.

 

IS there something missing I created. I am unable to telnet or ping the servers from LTM, wheres from outside I can ping or telnet to the servers.

 

6 Replies

  • Richard__Harlan's avatar
    Richard__Harlan
    Historic F5 Account

    There not a lot of information but I would start with some simple checks. First check the VLAN and make sure it is attached to the correct interface. Then check if you should be using VLAN tagging, finally check the subnet mask is correct on the self IP and the IP is not used anywhere else on the network.

     

    You can check the VLAN issues with a simple TCPdump on the vlan itself if all the traffic you see is just f5 ARPing for the servers mac address then most likely the VLAN is setup incorrectly. If it is a virtual check your virtual switch and make sure the interface is on the correct VLAN.

     

  • I took a tcpdum pointing to the vlan and I could only see ARP packets saying " whoever has server IP provide to F5 Self Ip" in the pcap. The servers are behind a FW and in THe FW I could see Directly connected routes. Also I am able to ping the servers from Firewall but unable to ping Self IP.

     

  • Yes I could see that FW can see the arp requests

     

    kan-asa1/sec/kan-portal-qa/act sh arp | i 172.17.48 Portal-QA1-RWS 172.17.48.x 0050.56b1.0def 248 Portal-QA1-RWS 172.17.48.x 0050.56b1.0dee 717

     

  • Hi, As per log history it seems there is no reverse traffic allowed from firewall to F5. Please open firewall port.

     

    F5 Self IP--> Backend server--> ICMP & backend server PORT. Issue will resolved

     

  • Thanks SAmir for responding. The FW rules was not required since all IPs were in same subnet and allowed. What I figured out wsa the LTM on which I did the set up was a Guest LTM and it had a HOST on which this LTM was created as a VCMP guest. So I deleted the VLan, Self and Floating IP from guest and created same on Host. Next I had to create a Routing Domian in the guest LTM with the FW IP as the Gateway. Then I created the pool and virtual and then I could ping the servers.