Forum Discussion
Why does SSLO not support ACTIVE-ACTIVE mode deployments?
I think it is because iApps LX generates the configurations and iApps LX synchronizes them from Active to Standby via REST API.
I am guessing that this behavior is the reason why Active-Active is not supported.
Starting with v16.1.0-9.0, the configuration synchronization behavior has been changed to use the TMOS native MCP/CMI HA sync method.
F5 SSL Orchestrator Release Notes version 16.1.0-9.0
https://techdocs.f5.com/kb/en-us/products/ssl-orchestrator/releasenotes/product/relnote-ssl-orchestrator-16-1-0-iapp-9-0.html
> SSO Control Plane re-architecture
> SSL Orchestrator 9.0 includes the following significant improvements to the control plane:
> The source-of-truth for the SSL Orchestrator configuration is now stored in the iFile objects. This allows the SSL Orchestrator to utilize native MCP/CMI HA sync functions and support automatic and incremental sync.
> The iApp strictness lock icon has been removed from several objects, excluding network and access objects allowing you to make out-of-band changes freely.
> The SSLO architecture now no longer uses the Gossip sync function to sync SSLO REST configuration.
thanks ,I plan to divide the ipv4 and ipv6 service traffic by two traffic-groups to be carried on two devices. I plan to reduce the pressure on a single device.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com