# Big-IP sending Health Check to not-used Node-IP

**URL:** <https://community.f5.com/t/big-ip-sending-health-check-to-not-used-node-ip/76112>\
**Category:** Technical Forums\
**Tags:** bug, node, monitor, pool\
**Created:** [May 20, 2025, 12:24pm UTC](https://community.f5.com/t/big-ip-sending-health-check-to-not-used-node-ip/76112 "2025-05-20T12:24:45Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![nickLa248](https://avatars.discourse-cdn.com/v4/letter/n/5f8ce5/32.png) [@nickLa248](https://community.f5.com/u/nickLa248)\
**Post date:** [May 20, 2025, 12:24pm UTC](https://community.f5.com/t/big-ip-sending-health-check-to-not-used-node-ip/76112/1 "2025-05-20T12:24:45Z")

</div>

Hello everyone,

my customer recently noticed while checking traffic on his firewall that healt checks are send from the Big-IPs internal self-ip to an IP that fits into the address range of the nodes in use on the f5.

This node ip is not known to the customer, and by searching the node table or looking in /var/log/ltm we were unable to find this ip-address. So either this node was used a while ago and the node object was deleted or the Big-IP send tries talking to this ip via 443 for some other reason.

Pings & curls send from the Big-IP fail.

Has anyone noticed something like this before? Or is there another way to see where health checks are sent?

Thanks and regards

---

<div class="post-metadata">

**Author:** ![WillRobbins](https://avatars.discourse-cdn.com/v4/letter/w/bb73d2/32.png) [@WillRobbins](https://community.f5.com/u/WillRobbins)\
**Post date:** [May 20, 2025, 5:55pm UTC](https://community.f5.com/t/big-ip-sending-health-check-to-not-used-node-ip/76112/2 "2025-05-20T17:55:44Z")

</div>

Have you checked iRules Or Traffic Polices ? Sometimes a node could be part of an iRule or Traffic Policy.

---

<div class="post-metadata">

**Author:** ![MubaiwaCharles26](https://avatars.discourse-cdn.com/v4/letter/m/b9e5f3/32.png) [@MubaiwaCharles26](https://community.f5.com/u/MubaiwaCharles26)\
**Post date:** [May 21, 2025, 9:49am UTC](https://community.f5.com/t/big-ip-sending-health-check-to-not-used-node-ip/76112/3 "2025-05-21T09:49:32Z")

</div>

The node in question could have been created in a different partition on your client’s BIG-IP device. Does the device have other partitions, other than the default “common” partition.

---

<div class="post-metadata">

**Author:** ![Mayur\_Sutare](https://d1p9zq3aats0t8.cloudfront.net/user_avatar/community.f5.com/mayur_sutare/32/5035_2.png) [@Mayur\_Sutare](https://community.f5.com/u/Mayur_Sutare)\
**Post date:** [May 21, 2025, 2:10pm UTC](https://community.f5.com/t/big-ip-sending-health-check-to-not-used-node-ip/76112/4 "2025-05-21T14:10:00Z")

</div>

Did you tried to take packet captures?

---

<div class="post-metadata">

**Author:** ![MubaiwaCharles26](https://avatars.discourse-cdn.com/v4/letter/m/b9e5f3/32.png) [@MubaiwaCharles26](https://community.f5.com/u/MubaiwaCharles26)\
**Post date:** [May 21, 2025, 2:18pm UTC](https://community.f5.com/t/big-ip-sending-health-check-to-not-used-node-ip/76112/5 "2025-05-21T14:18:40Z")

</div>

How many partitions are on the customer’s BIG-IP device?

---

<div class="post-metadata">

**Author:** ![nickLa248](https://avatars.discourse-cdn.com/v4/letter/n/5f8ce5/32.png) [@nickLa248](https://community.f5.com/u/nickLa248)\
**Post date:** [May 22, 2025, 6:20am UTC](https://community.f5.com/t/big-ip-sending-health-check-to-not-used-node-ip/76112/6 "2025-05-22T06:20:31Z")

</div>

no, we are only using the common partition on these devices.

---

<div class="post-metadata">

**Author:** ![nickLa248](https://avatars.discourse-cdn.com/v4/letter/n/5f8ce5/32.png) [@nickLa248](https://community.f5.com/u/nickLa248)\
**Post date:** [May 22, 2025, 6:49am UTC](https://community.f5.com/t/big-ip-sending-health-check-to-not-used-node-ip/76112/7 "2025-05-22T06:49:00Z")

</div>

thanks, sounded like a good idea, but i just checked all iRules & Traffic Policies but i couldnt find anything in regards to this ip

---

<div class="post-metadata">

**Author:** ![nickLa248](https://avatars.discourse-cdn.com/v4/letter/n/5f8ce5/32.png) [@nickLa248](https://community.f5.com/u/nickLa248)\
**Post date:** [May 28, 2025, 12:15pm UTC](https://community.f5.com/t/big-ip-sending-health-check-to-not-used-node-ip/76112/8 "2025-05-28T12:15:20Z")

</div>

im not sure what it would help me. the customer provided me the logs from the firewall showing the traffic from the self ip to this node, which would fit it beeing a health check.

is there a way to view logs of monitors? Or self ip logs?

i know of the /var/logs/monitors but this is empty

---

<div class="post-metadata">

**Author:** ![nickLa248](https://avatars.discourse-cdn.com/v4/letter/n/5f8ce5/32.png) [@nickLa248](https://community.f5.com/u/nickLa248)\
**Post date:** [May 28, 2025, 12:19pm UTC](https://community.f5.com/t/big-ip-sending-health-check-to-not-used-node-ip/76112/9 "2025-05-28T12:19:28Z")

</div>

only the common partition

---

<div class="post-metadata">

**Author:** ![MubaiwaCharles26](https://avatars.discourse-cdn.com/v4/letter/m/b9e5f3/32.png) [@MubaiwaCharles26](https://community.f5.com/u/MubaiwaCharles26)\
**Post date:** [May 28, 2025, 12:38pm UTC](https://community.f5.com/t/big-ip-sending-health-check-to-not-used-node-ip/76112/10 "2025-05-28T12:38:14Z")

</div>

A packet capture will prove concretely if the connections being logged on the firewall and being attributed to being sourced from the F5 are indeed coming the current f5 device or another old f5 device still on the network and sending health check probes to the node ip address in question.
