application delivery
40188 TopicsDisastser Recovery
Hello everyone, need to implement a Disaster recovery solution for a customer. I read the solution K39543431 but there are some points that are not clear for me. In order to build it, I need to configure the same vlans that are present on active/stand-by to disaster recovery devices, so that I needs to configure, for each vlan, only self ip. To sum up: the disaster and recovery device needs to reach all vlan configurated on the active/stand by device . it needs to be add as peer and configured as part of traffic group - in this way is possible to sync everything. Is it correct ? Someone knows if there is a guide or tutorial that is possible to download for having major information about how to do it ? Many thanks everyone for your time and consideration. Awaiting news. Rgds,23Views0likes1CommentF5 breaking Exchange authentication
We have Exchange 2016 going through our F5 BigIP. It works nicely. When we add our new Exchange 2019 server, clients are unable to authenticate using the desktop version of Outlook. Auth works fine without the F5 in the loop. Thanks in advance for any thoughts you might offer as our team as well as F5 support are stumped.24Views0likes1CommentFailed to execute iptable cmd: ," CMD="iptables -A SSH_ALLOW_RULES error
Hi Mates, After upgrading rseries F5 OS to 1.5.4, I observed the below error and I am unable to do SSH for my F5 OS machine version 1.5.4 from the network: 10.54.7.0/24. Rest all the networks are working fine and we are able to do SSH to the same F5 OS machine. Is it something that device was unable to update this entry into iptables. Do we have to manually re-configure this rule? ys-host-config[11678]: priority="Err" version=1.0 msgid=0x7001000000000062 msg="Failed to execute iptable cmd: ," CMD="iptables -A SSH_ALLOW_RULES -s 10.54.7.0/24 -p tcp -m state --state NEW --dport 22 -j ACCEPT -w &>/dev/null" ERR="EXITINFO: 4".29Views0likes0CommentsIdentify which virtual servers are using a specific SSL certificate
We use a wildcard SSL certificate for our QA sites. There are many of them. I am renewing the SSL cert but have no idea which Virtuals are using it. Is there an easy way to determine this other than checking each and every virtual, listing the Client-ssl profile and then looking up the profile to see what certificate is being used?9.9KViews1like4CommentsUsers account sessions mixed up..
Hi < I have been asked to look into a very strange issue. And not sure from where to start. I dont think it is happening due to Big IP. But could someone please provide a insight. Only persistence cookie is sent by big ip. Session and auth cookie is sent by back end servers. Although Big IP just add 'secure' parameter into all those cookies. Summary of the issue is below. We need your help on this critical matter. A user has reported that for some reason, her sessions got mixed up. That is, she logged under Username JFSM first and went to My Billing page to perform a function. Then she logged as JSMIREZ and was going to the My Billing Page for the new account. Instead, of getting to right page, she was directed to the previous log-in’s Account Summary page. Now, she confirmed she was only using one browser session. Is there any chance that sessions can get mixed up from the big ip for the same browser? That is, somehow a prior page request can be re-sent to the current session? I know am grasping at straws here but I am not sure what are the possibilities. I do have to note that the way the site has been working is that when I open up a browser and log-in to a User Account, let’s call Account A. Then on the same browser, I open up a new window and try to log-in as Account B; I would still get the information for Account A. The reason being, that this is considered as the same session/browser and considers Account A as still active for this session and not Account B even if the requests were made from different windows/tabs. One thing for sure though, if there are multiple users hitting the servers from different browsers, is there any chance at all where their requests can get mixed up? That is, you can have Users A, B, and C all hitting the website at the same time. And each of them are using separate browsers from different ip addresses. Is there any chance that the load balancer would ever mix up their sessions where User A’s page requests will be returned to User C and User C’s requests are returned to User B enabling them to see someone else’s account?574Views0likes2CommentsSFP Port LEDs Blinking Yellow
Hi I upgraded the F5 OS to version 1.8 and the tenant software to 17.5.1.3. The upgrade went smoothly and both the Active and Standby devices successfully handled traffic after the upgrade. However I have noticed that the SFP port LEDs on both the Primary and Secondary devices are blinking yellow. Both devices appear to be operating normally but I would like to confirm whether this is expected behavior Could the yellow blinking indicate a speed mismatch or should the LEDs be green under normal conditionsSolved59Views0likes2CommentsXC -Web Application Firewall - Exclude FQDN but log security events
Hello all, I have LB with many FQDNs. LB is with block waf policy. I want to add new application with another FQDN to same LB. During application onboarding I want to first review security events and then enforce policy to avoid false positives. I have two options: I will add application to the LB and then define rule to skip WAF processing for application. But in this case I will not see security events. Can I enable logs for such configuration for purpose of the configuration of the WAF exclusion rules? I will create new LB and configure application there and after that I will move application to prod LB. I prefer point 1 as in point two I will have to trigger Jenkins job to apply new Terraform config what will destroy resources and after that I will execute another job to recreate resources on productive LB. This will lead to the short outage. But due to this outage I have to follow up process what I would like to avoid. Thank you.Solved87Views0likes7Comments"A valid service contract is required" after upgrade to 17.5.1.3
Hi, I upgraded our virtual Big-IP from 16.1.2 to 16.1.6 reactivating the license first without issue. Right after, I upgraded to 17.5.1.3 and then I get the message "A valid service contract is required is required to complete the installation" and the system is offline. Following the https://my.f5.com/manage/s/article/K000150276 I booted back from the 16.1.6. Re-licensed the appliance and installed the configuration during the boot from the 17.5.1.3 again. However, I still getting this message. What I'missing? In the "licensed date" I see 17th of October 2025 in the GUI, and this is the date I get from CLI: [root@f5:INOPERATIVE:] config # grep "Service check date" /config/bigip.license Service check date : 20240511 ThanksSolved204Views0likes5Commentsdf -h /shared file missing
Hello during install os slot 1 still waiting for image because 17.1.3 does not exist and df -h show this file missing on slot 1, is it possible to create disk file manual or should i reboot this slot i tried import image used scp but failed /dev/mapper/vg--db--sda-dat.share.166Views0likes2Comments