vip
38 TopicsGSLB not marking local VS as down
Hi all, I currently have 2 BIG-IP nodes with their own separate LTM pool. When all pool members on 1 BIG-IP node are down, I would have expected the VIP to be marked down in the GSLB VIP pool as well, but this does not seem to be the case for local VIPs. So in my situation, I shut down all pool members on BIG-IP node B. BIG-IP node A sees only its own VIP as available and online, and marks the remote VIP as offline. However, on BIG-IP node B, both VIPs are marked as green. This is a problem, because users are being routed to a VIP that has no active pool members. Its worth mentioning that the VS correctly marks itself down (available - the children pool members might be disabled) on BIG-IP node B, but this is not reflected in the GSLB VIP pool. I have no health monitor in the VIP pool, my GSLB > Servers are using the bigip health monitor (I believe this is default for BIG-ip System) and the virtual servers are using a HTTPS health monitor. Any help here would be greatly appreciated, please let me know if I can provide any additional information123Views0likes3CommentsIs a Dedicated Interface, VLAN, and Self IP Required for a VIP in an F5 Configuration?
Hi All, We have a Red Hat Satellite server (repository), and the client servers need to connect to it via the VIP. The pool members are the Satellite Capsule servers. The Capsule servers communicate directly with the Satellite server, but the clients should only connect to the Capsule servers through the VIP. Current Configuration: Two Capsule servers (pool members) are in one subnet, while the other two are in a different subnet. The VIP is in a different subnet than both the Self IPs and the pool members. Questions: Is it correct that we need two Self IPs because the pool members are split across two different subnets? Does the VIP require its own dedicated interface, VLAN, and Self IP? The pool members, Self IP, and VIP cannot be in the same subnet as the management interface, correct?150Views0likes3CommentsNot able to change virtual server traffic group from traffic-group-local-only to traffic-group-1
We have two LTM device in which i observe one virtual server is missing in secondary device. I checked the virtual server configuration in primary that virtual server configure in traffic group from traffic-group-local-only now i am changing the traffic group but it is not changing. Is there any way to change it?Solved218Views0likes1Commentpool members can't connect to another Virtual Server
Hello, for sure this is a problem already addressed but I have an issue with a client that is part of a pool behind a Vip. If from this client I attempt a connection to another Vip I get no response while the connection works in case I make the connection to my Vip. My client route to the Vip network is the F5 interface. Is there something wrong? I am attaching a diagram that is maybe better than a thousand words....Solved840Views0likes3CommentsRedirect on user browser inactivity on LTM VIP
We have a type Standard F5 LTM VIP (no APM, no ASM, just LTM) with a pool of application servers. Only SSL, TCP and HTTP profiles are applied to that VIP. Connection is made by browser to URL https://www.mysite.com/mypage and web page content displayed. All good at this point. Then a user is idle for 20 minutes doing nothing. We want in this case of inactivity to send http redirect from F5 to a user browser to redirect to https://www.mysite.com Again this is a very basic VIP; beside TCP profile idle timeout I don't see any other posisble timeouts and TCP idle timeout is totally different from what we want to do... Any suggestion how our goal can be achieved? Thanlk yuo in advance!500Views0likes3CommentsVIP not reachable
Hi, I have following simple virtual server on a 11.5.1 system; ltm virtual /ITSS/live-fisheye-temp-vs { destination /ITSS/2.170.236.64:8060 ip-protocol tcp mask 255.255.255.255 partition ITSS profiles { http { } tcp { } } rules { _sys_https_redirect } source 0.0.0.0/0 source-address-translation { type automap } vlans { EXT-WIN-11 } vlans-enabled vs-index 592 } ` ` And the VIP: ``ltm virtual-address /ITSS/2.170.236.64 { address 2.170.236.64 mask 255.255.255.255 partition ITSS traffic-group traffic-group-2 unit 2 } ping works, but a telnet 2.170.236.64 8060 keeps stuck at 'Trying 2.170.236.64...' I tried re-enabling the VIP and ARP status, but to no avail. I can reach other addresses in that range and on that traffic group. A telnet 2.170.236.64 8060 on the bigip works. I see no response back to my computer or to the gateway using telnet. The gateway has the correct VLAN mac address for the listener. Ideas?473Views0likes2CommentsVS Precedence
Hi I have a question relating to VS precedence and which VS would process the packet in the following example: Packet - destination IP > 10.10.10.10 destination port > TCP/80 VIP-A 10.10.10.0:80 protocol tcp mask 255.255.255.0 VIP-B 10.10.10.10:80 protocol udp mask 255.255.255.255 My understanding having read https://support.f5.com/kb/en-us/solutions/public/6000/400/sol6459.html is that there is a higher emphasis on the VS with the longest subnet match. However, in the in above example, this would be VIP-B - but the protocol for this VS is UDP. Would VIP-B process the request and subsequently drop traffic - or is the BigIP intelligent enough to match on a VS with a lower precedence, but one that has the correct protocol configured? Many thanks Lee295Views0likes2CommentsVS Precedence
Hi I have a question relating to VS precedence and which VS would process the packet in the following example: Packet - destination IP > 10.10.10.10 destination port > TCP/80 VIP-A 10.10.10.0:80 protocol tcp mask 255.255.255.0 VIP-B 10.10.10.10:80 protocol udp mask 255.255.255.255 My understanding having read https://support.f5.com/kb/en-us/solutions/public/6000/400/sol6459.html is that there is a higher emphasis on the VS with the longest subnet match. However, in the in above example, this would be VIP-B - but the protocol for this VS is UDP. Would VIP-B process the request and subsequently drop traffic - or is the BigIP intelligent enough to match on a VS with a lower precedence, but one that has the correct protocol configured? Many thanks Lee194Views0likes0CommentsExport VIP, Cert CN and Cert expiration date
Hi all, Client has requested the following information; VIP NAME, VIP IP, Cert CN + Cert Duration. I have a script that exports VIP and Pool, was hoping to collate all the information into this if possible. virtuallist=$(tmsh list ltm virtual | grep virtual | cut -d' ' -f3 | tr "\n" " " ); for v in $virtuallist ; do DEST=""; POOL=""; MEMB=""; DEST=$(tmsh list ltm virtual $v | grep destination | cut -d' ' -f6) POOL=$(tmsh list ltm virtual $v | grep pool | cut -d' ' -f6) MEMB=$(tmsh list ltm pool $POOL | egrep 'address '| sed '$!N;s/\n/ /') if [ "$POOL" != "" ]; then echo ""; echo " Virtual: $v - $DEST"; echo " Pool: $POOL"; echo "$MEMB"; else echo ""; echo "!! Virtual $v $DEST has no pool assigned"; echo ""; fi done :wq Cert expiry can be listed from - tmsh list sys file ssl-cert expiration-string Have noticed CN can be pulled using regex - regexp {CN=([^,]+)} [mcget {session.ssl.cert.subject} ] CNFull CNValue; return $CNValue Would there be a way to compilate this all into one script? I am very new to F5 and scripting, any help would be appreciated.490Views0likes1Comment