Jul 19, 2011

ssh and iQuery via non-management interfaces?

Is it possible to have iQuery (and the SSH sessions where keys/certs are exchange for it) to happen over non-management interfaces? For a variety of reasons, I'd rather have the LTMs and GTMs talking amongst themselves via the regular interfaces, but it looks like the LTMs are ignoring ssh connections to their non-management interfaces as a tcpdump shows a series of SYNs without answers.



The documentation on iQuery and bigip_add etc doesn't specify what interfaces can and cannot be used for this.



Suggestions? Pointers to more info?







    You can... but



    A. I don't recommend it.


    B. You need to enable services on the self-ip addresses involved... (I set all my port-lockdowns to Allow None. You can set ALl, default or custom as well)



  • Our professional services installation from F5 specifically stated that the iquery between GTMS & LTMs will not occur over the mgmt interfaces. We specifically use self-ips on the RFC1918 networks with only those ports allowed to do synchronization. We were told that it was the F5 best practices. Correct me if I'm wrong though.



    If memory serves, trying to iquery to the mgmt interface consistently failed when doing the initial setup.