Forum Discussion
Two Active Big IP's in HA mode
I have Two Big IP's that are supposed to be Active / Passive but they are both Active. What is the best way to fix this?
5 Replies
- nitass
Employee
is unicast-address on device configured correctly? is network-failover enabled on device-group? is there any useful message in /var/log/ltm?
e.g.
root@(ve11a)(cfg-sync In Sync)(Active)(/Common)(tmos) list cm device ve11a.acme.local unicast-address cm device ve11a.acme.local { unicast-address { { effective-ip 200.200.200.11 effective-port 1026 ip 200.200.200.11 port 1026 } } } root@(ve11a)(cfg-sync In Sync)(Active)(/Common)(tmos) list cm device-group dg network-failover cm device-group dg { network-failover enabled } - Tracy_150973
Nimbostratus
unicast addresses are ok. We had a network problem that caused it. network failover is enabled. No log messages that I can tell but I don't really know what to look for.
- nitass
Employee
I don't really know what to look for.
what about grepping sod?
grep sod /var/log/ltm are you sure your network failover is ok? have you checked if the port 1026 (i believe) packets are send correctly with tcpdump?
- shaggy
Nimbostratus
Network failover can be made more robust by directly connecting your LTM's to each other using a straight-through cable, creating a 'peernet' vlan and /30 self-IP addresses (ex. 192.168.255.0/30 = 192.168.255.1 for Unit 1 and 192.168.255.2 for Unit 2), and then using configuring network failover with the peernet self-IP addresses and your management IP addresses. HA groups or VLAN failsafe can then be applied to the production (non-peernet) trunks/vlans to ensure failover occurs when active unit loses connectivity to the rest of the network
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com