F5 is upgrading its customer support chat feature on My.F5.com. Chat support will be unavailable from 6am-10am PST on 1/20/26. Refer to K000159584 for details.

Forum Discussion

Tracy_150973's avatar
Tracy_150973
Icon for Nimbostratus rankNimbostratus
Dec 28, 2014

Two Active Big IP's in HA mode

I have Two Big IP's that are supposed to be Active / Passive but they are both Active. What is the best way to fix this?

 

5 Replies

  • is unicast-address on device configured correctly? is network-failover enabled on device-group? is there any useful message in /var/log/ltm?

    e.g.

    root@(ve11a)(cfg-sync In Sync)(Active)(/Common)(tmos) list cm device ve11a.acme.local unicast-address
    cm device ve11a.acme.local {
        unicast-address {
            {
                effective-ip 200.200.200.11
                effective-port 1026
                ip 200.200.200.11
                port 1026
            }
        }
    }
    
    root@(ve11a)(cfg-sync In Sync)(Active)(/Common)(tmos) list cm device-group dg network-failover
    cm device-group dg {
        network-failover enabled
    }
    
  • unicast addresses are ok. We had a network problem that caused it. network failover is enabled. No log messages that I can tell but I don't really know what to look for.

     

  • I don't really know what to look for.

    what about grepping sod?

     grep sod /var/log/ltm
    
  • are you sure your network failover is ok? have you checked if the port 1026 (i believe) packets are send correctly with tcpdump?

     

  • shaggy's avatar
    shaggy
    Icon for Nimbostratus rankNimbostratus

    Network failover can be made more robust by directly connecting your LTM's to each other using a straight-through cable, creating a 'peernet' vlan and /30 self-IP addresses (ex. 192.168.255.0/30 = 192.168.255.1 for Unit 1 and 192.168.255.2 for Unit 2), and then using configuring network failover with the peernet self-IP addresses and your management IP addresses. HA groups or VLAN failsafe can then be applied to the production (non-peernet) trunks/vlans to ensure failover occurs when active unit loses connectivity to the rest of the network