Forum Discussion
Vip is always up even if the servers behind service port are down
Vip is always up even if the servers behind service port are down
14 Replies
- IheartF5_45022
Nacreous
Do you mean that the VIP is UP or that it always accepts a 3-way handshake?
- nitass
Employee
are you using pool command in the irule?
if yes, can you try to remove the irule just for testing?
- sinu1_149558
Nimbostratus
@ IheartF5 yes we can telnet to the vip and vip is green and active up @ nitass no irule associated to this vip
- nitass
Employee
@ nitass no irule associated to this vip
rules SNAT2VIP
- IheartF5_45022
Nacreous
So that says to me that your "tcp half open" monitor is not right - if the monitor passes then the F5 will think the pool/virtual is UP. If you think the servers are actually DOWN and want the F5 to think so too, then adjust your check - like use an http-based check.
- BinaryCanary_19Historic F5 Account
Standard VIP always accepts 3-way handshake.
- sinu1_149558
Nimbostratus
Is there any way to avoid that @ aFanen01 as per my requirement need to down the vip also when the servers behind service port are down
- BinaryCanary_19Historic F5 Account
No. You will have to use an extended monitor. Example, HTTP, or full TCP monitor that sends some data and looks for something in the output returned by the server.
A standard VIP will only terminate a connection after it receives data, and then does not find a pool member to send it to.
Alternatively, a Performance-L4 VIP will fail on the first SYN if there is no pool member, but you lose all the layer 7 capabilities of a standard VIP.
- nag_54823
Cirrostratus
b pool remotepc.com_p_9010 shows pool members are down ? Also this one is an L7 VIP which is having http-xff with tcp profile. It will also respond for telnet
- nitass
Employee
if you do not want 3-way handshake when pool is down, you need to disable virtual server or turn off virtual address arp.
Toggle Virtual Address ARP
https://devcentral.f5.com/wiki/tmsh.ToggleVirtualAddressARP.ashxMark the status of a virtual server down
https://devcentral.f5.com/questions/mark-the-status-of-a-virtual-server-down- BinaryCanary_19Historic F5 AccountMy advise is to just use an extended content verification monitor. Doing things like this to your box is liable to cause you more pain than gain.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com