For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

igorzhuk's avatar
igorzhuk
Icon for Altostratus rankAltostratus
Mar 13, 2019

Sync Configuration without Traffic Group

Hi all, I have 2 BIGIP that have each of them have a VLAN_groupe that do only SSL chippers change between client and internal Bigip's each of them is a standalone but both of them have the same configuration because of one of them in DR I will need to design sync between to standalone device VS POOL NOOD CERTS AND PROFILES I found that article: https://deviousnetworks.blogspot.com/2017/03/big-ip-folders.html?m=1 but it not works for me in VS

 

We also have a BIGIQ but BIGIQ can't import configuration because of the VLAN-group

 

1 Reply

  • Hi Igorzhuk,

     

    you may look into the SCF (Single Configuration File) feature.

     

    Using SCF allows you to export the configuration to a flat configuration file and import the configuration (after cleaning any unnessesary objects or chaning them as needed) back to a different unit.

     

    K13408: Overview of single configuration files (11.x - 14.x)

     

    https://support.f5.com/csp/article/K13408

     

    K81271448: Merging BIG-IP configuration objects into the running configuration using tmsh

     

    https://support.f5.com/csp/article/K81271448

     

    Wrap the SCF approach into a shell script which save the config on unit A, does some text parsings, file transfers and imports the SCP to unit B and you will get a tailordered Config-Sync for all the configuration objects you need...

     

    Yeah, I know its not the stuff you where looking for, but at least it does what your asking for... ;-)

     

    Cheers, Kai