ha
43 TopicsNSX-T and F5 HA using BGP
Hi All, I am working on a lab to get F5 LTM VE high availability pair working with NSX-T T0 router using BGP The routing domain all works find, I am able to establish the BGP neighborship and I see the T0 routes, and the T0 sees my routes. What I am trying to find information on, is on what the best practice is for the Active/Standby F5 HA pair to be BGP paired to the Active/active T0. As is, the NSX-T T0 router sees routes being advertised from both F5, even the standby unit. I ran into a problem where the Standby unit was receiving traffic as it was a valid route in the table of the NSX-T0 and to resolve the issue I created a BGP Floating self ip and configured it as the next-hop ip address for the NSX-T0. This way the active F5 always processes the traffic. I am wondering if this is the intended way to do such a design or if there is a better way to do this, a standardize way to do this. Here is an ASCII representation of the design: +-------------------------------+ | | | CAMPUS NETWORK | | | +-----+---------------------+---+ | | eBGP eBGP | | +-----+---------------------+---+ | Active Active | | +-----+ +-----+ | | |EDGE1| NSX-T |EDGE2| | | +-+---+ T0 +---+-+ | | |.1 .2| | +----+----------------------+---+ | | | | | | eBGP eBGP | | | NEXT-HOP | | FLOAT-IP | |.3 .5 .4| +-+--+ +---+-+ |F5-1+------HA-------+F5-2 | +----+ +-----+ Active PassiveSolved3.1KViews0likes8CommentsBig-IQ HA logs
Hi, We have a BIG-IQ HA setup with 4 servers. Two DCD and two mains. One as active and the other standby. When a failover happens for whatever reason i'm assuming there is some information about that written to a log file. Does anyone know where that info is logged? Is it on the mains servers? Or would it be on the dcd's? And which file? Thanks in advanceSolved1.8KViews0likes8CommentsConfigure HA on trial environment
Hello everyone, I have to two 30 day trial SN. and i am using some instructor to perform ha sync between them but the sync doesn't work. the same instruction help me to set up sync in a production environment. is it possible that HA not supported on trial version ? I'm using BIG-IP VE Version 17.0.0.1.7KViews0likes17CommentsHA pair in VMware v7 update 3 - Should "power on connect" be enabled, or disabled for vlans/network?
Late last year we migrated the vcmp guests off of our 7200 chassis into VMware. Up until now, "Connect at power On" has been diabled for the vlans/networks. The question is whether that should be enabled. The question sent by the Server tech is below... We have noticed that the F5 VMs networks are not checked for “Connect at power On”, should this be the case in our HA F5? We ask this is because we noticed the other HA pair don’t have their network adapter connected and is not connected. Should both HA pairs have their network adapter be checked for “Connect at power On” so they can connect at power on? Thanks!Solved1.6KViews0likes2CommentsChanging Management-ip in an HA pair setup
Hello, I've read this Article:https://support.f5.com/csp/article/K62249587 but I've a question: if the management IP is not involved in Failover Network ot Config Sync, do I need to delete the Device Trust? I thought about these steps: force the standby unit offline change Management IP of the standby unit change Management IP of the active unit release standby unit from offline would there be traffic interruption? Does the Management IP define the Device Trust? As I've described, Failover Networks are HA and Inside Interface Thanks for Answers KarlSolved1.6KViews0likes3CommentsBIG-IP VE VMWare Cluster HA triggering configuration
Hi, this is my first step into BIG-IP VE deployments (always viprion so far). I have all my test clusters up & running in a VMWare environment: Active/Stanby using dedicated vNIC&VLAN. 4 vNIC per device, 2 cluster members, each one running at different ESXi. But I would like to ccountercheck which would be the best option to trigger HA. At PHY deployments we deploy HA Group based on trunks. Now this does not work for all cases. Would a failsafe condition based on VLAN be the best solution? E.g. with failover to the sdby BIG-IP in case no ARP was received from client_VLAN gateway? any comment wellcome! Regards.Solved1.4KViews0likes2CommentsIssues with incremental config sync cache || Unable to do incremental sync, reverting to full load for device group
I received an error similar to below : notice mcpd[2789]: 0107168e:5: Unable to do incremental sync, reverting to full load for device group /Common/syncgroup1device%cmi-mcpd peer-/Common/ltm1.example.comfrom commit id { 4 6390393316259868817 /Common/ltm1.example.com}to commit id { 3 6391877370007482801 /Common/ltm2.exmample.com}. Here, changes pertaining to commit id 3 got executed on the peer device. Undesired change like disabled pool member was enabled which caused impact to the business. The recommended action says to reduce the size and frequency of the configuration changes made to the BIG-IP system. You may also be able to mitigate this issue by increasing the size of the incremental ConfigSync cache. While I see the explanation below saying if incremental sync cache size exceeds 1024, the BIG-IP performs a full sync which is not happening in my case. In theMaximum Incremental Sync Size (KB)field, retain the default value of1024, or type a different value.This value specifies the total size of configuration changes that can reside in the incremental sync cache. If the total size of the configuration changes in the cache exceeds the specified value, the BIG-IP system performs a full sync whenever the next config sync operation occurs. Can anyone help me understand the below concerns. Q. Why the full sync doesn't happen if the incremental sync cache size goes beyond 1024. Also it caused an impact to the traffic by configuring changes specific to commit-id 3. Also I checked below command, show cm device-group <sync_group> incremental-config-sync-cache It shows multiple commit id and related configuration, Q. Is there a procedure to only keep the recent commit-id and flush the old ones so the cache doesn't go beyond default 1024KB. Q. Can the modify the cache value to the suggested 2048 and will there be any impact of it ? And will it require increasing it in future if say again the cache fills up ? modify cm device-group <sync_group> incremental-config-sync-size-max ? Specifies the maximum size (in KB) to devote to incremental config sync cached transactions. Range: 128-10240. Default:1024. Q. Is there a way we can monitor this proactively (leaving aside the preventive measures of reducing size and frequency of config changes). Hope I will get answers to the above concerns. thank DevCentral Community in advance !!!1.1KViews0likes0CommentsWhy is an Active-Active configuration not recommended by F5?
I was considering configuring our F5 LTMs in an Active/Active state within Cisco ACI but I read here that this type of configuration is not recommended without having at least one F5 in standby mode. "F5 does not recommend deploying BIP-IP systems in an Active-Active configuration without a standby device in the cluster, due to potential loss of high availability." Why is this? With two F5s in Active/Active mode, they should still fail over to each other if one happens to go down. Would it take longer for one device to fail over to another who is active rather than being truly standby?999Views0likes5CommentsBIG-IP Device-group synchronization
We normally deploy Big IP host devices as standalone, how come the guest devices sync with eachother when underlying host devices are not connected, I am coming from Palo alto world where they have HA cables connected and do the high availibilty syncing. How it happens in f5 over standalone hosts?769Views0likes3Commentsone-arm scenario, external network?
I just installed two virtual big-ip LTM VMs, and I'm ran “Run Config Sync/HA Utility”. I see I need to configure external network as part of HA utility. I've planned to use one-arm scenario. I'm planning to use SNAT. Is there a need to configure external network? Could you please let me know what is the best practice in such case?Solved705Views0likes2Comments