For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

tbutton_261326's avatar
tbutton_261326
Icon for Nimbostratus rankNimbostratus
May 02, 2016

Running gtm_add on New GTM Fails

I have three GTMS: two old ones running 10.2.3 and one new one running 11.5.3. I am attempting to add the new one to the synchronization group by running gtm_add against either of the two old ones. It seems to run for a while and then gives me one error. This is what I see:

 

==> Running 'bigstart shutdown gtmd' on the local system

 

==> Running 'bigstart shutdown zrd' on the local system

 

==> Running 'bigstart shutdown named' on the local system

 

Retrieving remote and installing local BIG-IP's SSL certs ...

 

Enter root password if prompted

 

Password:

 

Rekeying Master Key...

 

Verifying iQuery connection to 74.205.253.198. This may take up to 30 seconds

 

Retrieving remote GTM configuration...

 

Syncer failed to retrieve configuration:

 

Restarting gtmd

 

Restarting named

 

Restarting zrd

 

I can't find any information on the syncer error. I checked the logs and see this error:

 

May 2 15:34:17 GTM-name err iqsyncer[17338]: 011a005e:3: Error error:00000005:lib(0):func(0):DH lib while attempting to read SSL data.

 

I can't find any information about this error either.

 

Each GTM has been added to the others' data centers and servers groups, and they all look green. Their certificates are current and have unique common names. I ran big3d_install against the old GTM's so that they all are now running the same version. I've also confirmed network connectivity by telnetting between the GTM's over ports 22 and 4353. I think I have covered all my bases, but the gtm_add operation still fails. Does anyone have any ideas?

 

4 Replies

  • Hello,

     

    Before add new GTM, you have to create The new GTM Object in the the old one. Then enabling syncronisation. run the gtm_add script on the new BIG-IP GTM system that you are integrating. It's very important to follow these steps. More information don't forget to open 4353 and ssh (ssh just while adding GTM).

     

    Then from your local GTM you can run the bigip_add script from your curent GTM to the new one (if the new one embeded ltm services)...

     

    keep me update if you follow the above procedure to add you new gtm... Regards,

     

  • Can you try upgrading one of the GTMs to a recent 10.2.4 (or later) hotfix, then point gtm_add at that unit? Note that even 10.2.4 goes End of Technical Support this year so best to get them upgraded anyway.

     

  • Can you try upgrading one of the GTMs to a recent 10.2.4 (or later) hotfix, then point gtm_add at that unit? Note that even 10.2.4 goes End of Technical Support this year so best to get them upgraded anyway.