Forum Discussion
palekafa_69933
Nimbostratus
Feb 16, 2009Self IP and Mgmt IP Question
Scenario is that we have a class B network with one VLAN ( flat VLAN ). I cant configure the Mgmt IP and the Self IP ( as it shares the network ).
Questions:
1) Apart from creating another VLAN ( our network bit is outsourced so takes ages for these kind of requests ) , is there any other way out?
2) Why does it not allow for mgmt IP and self IP to be on the same network ( e.g mgmt ip = 10.161.10.xxx and I try and give a self ip of 10.161.153.xxx will not work with 255.255.0.0 subnet )
Thanks
24 Replies
- The_Bhattman
Nimbostratus
True. What I suggested was something different.
Suppose you configure the management address as 192.168.1.100/255.255.255.0 and if you configure another PC 192.168.1.101/255.255.255.0, since you are in a single VLAN, they should be able to see each other. Again it's something I wouldn't do but it's something that I have seen done before. I would probably talk with the network folks to see if they will allow something like this to atleast inform them based on the limitation that is set upon you.
CB - dennypayne
Employee
Posted By palekafa on 02/17/2009 6:53 AM
Looks like I have to get that VLAN sorted to put the mgmt port on it. GUI is needed as well as console ( for obvious reasons ).
There is no other way out is there?
Well as cmbhatt originally suggested, you don't *have* to manage the device through the mgmt port. You can use the GUI and SSH into the command line on the self-IP address, so long as it is set to "Allow Default" or "Allow Custom" with 443 and 22 enabled.
The only thing you really need to do through the mgmt port is upgrades, and for that you can also do what cmbhatt is suggesting with putting it on an unused IP network that you can hook up to a laptop directly when you need to upgrade.Posted By hoolio
I think the issue might be that there would be a conflict between TMM which handles the switch ports and Linux which handles the mgmt port. I don't remember ever getting a clear explanation of this restriction though.
Mainly because the mgmt port (run by Linux, as you say) is not part of the switch fabric; it is simply a NIC.
Denny - The_Bhattman
Nimbostratus
Here is my process of configuration and upgrading
1) License and first time configure the LTM through the management port via directly connected laptop
2) Once it's on the wire I abandon the management port and do my upgrades using the combination serial console (Remote Terminal server) and GUI and SSH via self-addresses (through the network)
From that point that is how I manage them and it hasn't failed me yet.
Unfortunatly, I have seen picular things with the management port in the past. One of the main things (outside the Lights Out piece) is that it shares the same routing table with the rest of the OS. In my world that is a no-no.
CB - Balachandar_797
Nimbostratus
Hello There,
I am working on trying the F5 BIG IP LTM VE and stuck on the configuration screeen with the error "01070392:3: Self IP IP Address/Netmask: This IP shares a network with the Management IP (IP Address / Netmask).
I am trying to use an IP not in use under Self IP.
Please help.
BTW, Iam using the VM Workstation version.
Regards,
Bala - hoolio
Cirrostratus
Hi Bala,
You'll want to create a management IP which is on a separate subnet from the switch VLANs. If you only have one routable subnet on the host, I'd just assign a "Host only" network for the management and use that to connect locally. You can assign a bridged adapter for the main LTM VE VLAN.
Aaron - Balachandar_797
Nimbostratus
Thanks Aaron. Much appreciated. It worked like a charm.
Playing around with Virtual servers and pools now. The VIP I provided (on same subnet as the external IP) when accessed through browser gives page cannot be displayed. Tried adding it to trusted sites. No luck :-(
Regards,
Bala - hoolio
Cirrostratus
Can you enable SNAT automap on the VIP and see if that works for you?
Aaron - Balachandar_797
Nimbostratus
Hi Aaron,
Yes I did that change after referring the F5 website. Still no luck. The status is red under Virtual Servers with message "The children pool members are down". The node status is green after that change. Also the real_server and snmp_dca are the only monitors working for this node. The node has IIS installed and configured. I have an connection broker software (Symantec Workspace Corporate) installed on it. The node is running on a VMWare ESX 3.5 Server 2003 EE SP2 VM.
Regards,
Bala - hoolio
Cirrostratus
Hi Bala,
I'd try troubleshooting why the pool members are being marked down by the monitors before testing the load balancing. For some tips on troubleshooting monitors, you can check this wiki page:
http://devcentral.f5.com/Wiki/default.aspx/AdvDesignConfig/TroubleshootingLtmMonitors.html
Aaron - Ashish_Ram_Tak1
Nimbostratus
can any one tell me how can i check management port ip address via putty also please share the command to assign management port ip,
i am using VMware on my desktop
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects