Forum Discussion
8 Replies
restjavad restnoded are not critical processes related to F5 REST-API so it shouldn't cause big impact but still do this in a maintainance window:
https://support.f5.com/csp/article/K48615077
Also read the bug articles as they specify to run the commands first on the active then sandby
https://cdn.f5.com/product/bugtracker/ID860245.html
- kgaiglCirrocumulus
thank you, but my concern is, that if the device-trust is reset, then for a (very short) time both units are active and so there would be IP Adress Conflict when the same VIP's on both units are active.
I think about the commands restcurl -X DELETE...
I will try after Office Hours
If you are worrying about split brain you can make the standby in offline mode this way it will not take over as active even when the trust is broken between the HA pair.
- kgaiglCirrocumulus
oh, didn't think about this, thank you
Hello,
After the upgrade please share if everything is ok and if you saw any issues so we can close the question.
- kgaiglCirrocumulus
I'm in contact with the support, they told me to change in Ressource Provisioning the Management from Small to Large, now:
[root@ldb-ara31-brz-00:Standby:In Sync] ~ # restcurl shared/gossip |egrep '\"status\"|\"gossipPeerGroup\"' "status": "ACTIVE", "gossipPeerGroup": "tm-shared-all-big-ips",
in the overview of the Security Policies the Policies are present and attached to the VS, but under Guided Configuration, the Policies are still not present.
It looks like a displaying Error.
tried to export/import the Policies, get an Error, Policy already exists
tried to create a new Policy, this will also not displayed on the standby
- kgaiglCirrocumulus
after running the described actions, it's still the same on the standby-unit:
[root@ldb-ara31-brz-00:Standby:In Sync] ~ # restcurl shared/gossip |egrep '\"status\"|\"gossipPeerGroup\"' "status": "UNPAIRED", "gossipPeerGroup": "tm-shared-all-big-ips",
- kgaiglCirrocumulus
Solution:
F5-Support provided me a Script "ha-sync" and after run
/var/tmp/ha-sync --force -H 192.168.97.2 -D device-group-failover-21b78xxxx
everything's ok now