For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

The_Engima_Code's avatar
The_Engima_Code
Icon for Nimbostratus rankNimbostratus
Aug 27, 2015
Solved

Replacing F5 in HA

Hi,

 

We are running F5 HA (Say Member A and Member B) in Active-Active mode. Member A had a h/w issue and is currently in offline/in sync mode. We are planning to replace Member A over the weekend. I just want to confirm the process for replacing F5. I have checked other solutions on F5 but couldn't really see something that would explain everything.

 

In my mind, the process is

 

  1. Member B which is active at the stage, Update Device groups, traffic groups, Device trust, etc..by removing references for faulty Member A. This will force the box to go in Active/Standalone
  2. Shutdown faulty member A.
  3. Put new box New-Member-A (it is already configured with mgmt IP, self IP, VLANs, license, default routes)
  4. Switch on New-Member-A. It should be Standalone mode
  5. Re-establish Device Groups, device trust, etc...
  6. Sync New-Member-A to the group.

Please correct me if I have missed anything.

 

Cheers, MP

 

6 Replies

  • Thanks. The interesting part is I couldn't find any specific instructions on F5 site which would confirm how it is exactly done.

     

  • I agree it is rather strange. I also searched for a while and couldn't find any resources on replacing 1 device in an Active-Active setup.

     

  • Please once you are done give feedback here. I am interested to see if our logic was correct.

     

  • Hi Tyron,

     

    We tried the swap on Wednesday night and it failed. After talking to F5, we realized that the replacement box needs self IP, VLANs,route domains, etc... configuration for all partitions whereas it was only done on the common partition. Doing this manually would've been difficult so we left the config on the replacement box as is. It had basic configuration.

     

    Here are the steps I did.

     

    1. Uploaded the UCS file of member-A on the replacement box new-member-A

       

    2. Disabled the switch ports connected all interfaces except for management interfaces. This isolated New-Member-A from Member-B(Active).

       

    3. On Member-B, run f5mku -K and copy the key on New-Member-A run f5mku -r

       

      As we were replacing a box in HA, the key to manage configs and HA is shared between both members. This key is required to restore config.

       

    4. Restore the config of Member-A on New-Member-A. tmsh load /sys ucs no-license

       

    5. This step is optional but I did.Remove HA config from New-Member-A and force it to go offline. Above steps you can perform w/o a change window as you are isolating the replacement box from Active one.

       

    6. Now on Member-B (Active), remove HA config and make it Active/Standalone

       

    7. Enable switch ports(disabled in step 2)for New-Member-A, the box will be in Forced Offline/Standalone mode.

       

    8. Rebuild the trust, configure device groups, etc.. Once the boxes were in in-sync, I did sync device to group with overwrite option on Member-B which was active.

       

    9. Once the config is synced, force New-Member-A to go online.

       

    This did the trick for me. I have mentioned the steps that worked for me and the assumption is both F5 members are backed up, network maps, and other screenshots are taken for rollback.

     

    I hope this helps. Feel free to ask any questions.