Professional Documents
Culture Documents
Articles
Contact
Tools
Us
HAProxy Reporting
Get live and historic reports for
the haproxy load balancer.
Home Articles Loadbalancers F5 BIG-IP BigIP F5 LTM - High Availability / DSC (v11.x)
pdfcrowd.com
ARTICLE INFO
VENDOR
BigIP
F5
PLATFORM LTM
VERSION
11.x
HAProxy
Reporting
Get live and historic reports
for the haproxy load
balancer.
SCOPE
Within this article we will explain the key components to DSC, the
con guration steps and also the main commands used to troubleshoot
problems.
COMPONENTS
open in browser PRO version
pdfcrowd.com
pdfcrowd.com
SYNCHRONIZATION
Unlike v10.x and below, TMOS v11 now uses rsync internally to perform
open in browser PRO version
pdfcrowd.com
synchronization between devices. Also unlike v10 which used tcp/443 for
synchronizing data, v11 uses tcp/4353.
The available options and also the ways in which you can issue a
synchronization.
OPTIONS
The various options for synchronization can be found under 'Device
Groups' and 'Devices'.
DEVICE GROUPS
Automatic Sync (via Properties Panel) - Automatically synchronize
objects between devices based on the modi ed time. The most
recently modi ed object is synchronized to the other device. Because
the modi ed time is used as the trigger NTP (i.e time synchronization)
must be con gured.
Full Sync (via Properties Panel) - Rather then only synchronizing the
con guration objects that have been modi ed, the whole
con guration is synchronized.
Network Failover (via Failover Panel) - Determines whether a network
probe is sent between the devices to ensure neighbor status. This is
instead of uses cable based failover*.
* As cable based failover mandates only 1 device can ever be active cable
based failover doesn't support an Active-Active based setup (i.e more then
open in browser PRO version
pdfcrowd.com
based failover doesn't support an Active-Active based setup (i.e more then
2 tra c groups).
DEVICES
Con g Sync (via Device Connectivity) - De nes which interface is used
for synchronization. Its recommended by F5 that this is a dedicated
link.
Failover (via Device Connectivity) - De nes which port is used for the
network failover probes.
Mirroring (via Device Connectivity) - De nes which interfaces are used
for mirroring. It is recommended that a secondary address is also
con gured to provide redundancy should the primary fail.
ISSUING A SYNC
Manual DSC synchronization can be performed via either the command
line or the WebUI. To perform a manual synchronization within the WebUI
go to 'Device Management / Overview'. From this screen you will be
presented with an overview of the synchronization state across your
devices and device groups.
The will also see the following options,
Sync Device to Group - Synchronizes any objects that have been
recently modi ed to the other devices within the device group.
Sync Group to Device - Synchronizes any objects that have been
open in browser PRO version
pdfcrowd.com
DEPLOYMENT MODES
There are 2 main types of deployment modes with DSC, Active-Standby
and Active-Active.
ACTIVE-STANDBY
With an Active-Standby based deployment tra c is only processed by a
single device. This is achieved via single tra c group, which all failover
objects (virtual servers, self-ips etc) reside within. This tra c group is then
active on one of the nodes. Should this node fail its HA checks the tra c
group will be marked as standby and the tra c group on the other node
promoted to active.
pdfcrowd.com
ACTIVE-ACTIVE
With an Active-Active based deployment tra c is processed by both
devices. This is achieved via 2 Tra c Groups, (based on the example below)
one Tra c Group is placed as active on Node 1 and the other as active on
Node 2. Your failover objects are then assigned to either of the tra c
groups, i.e Virtual Server A in tra c group 1 and then Virtual Server B in
Tra c Group 2.
This results in Node 1 processing tra c for Virtual Server A, and Node 2
processing tra c for Virtual Server B.
Note : It is important to ensure that both nodes are running under 50%
capacity. This ensures if either of the devices fail then at the point all tra c
is processed by the single node that the devices capacity is not reached.
open in browser PRO version
pdfcrowd.com
CONFIGURATION
The rst step in con guring DSC is to con gure a Trust Domain. Then we
con gure the tra c groups for either a active-active or active-standby
open in browser PRO version
pdfcrowd.com
deployment.
DEVICE TRUST
1.
2.
3.
4.
DEVICE GROUP
1. Goto 'Device Management' / 'Device Groups'.
2. Click 'Create'.
3. Enter name, select 'Sync-Failover' as the 'Group Type', and then add all
devices to the 'Included' members list.
4. Enable 'Network Failover'.
SYNCHRONIZE
1.
2.
3.
4.
Note : To con gure the IP used for Con gSync and Mirroring, along with
the the IP, VLAN and Port for Network Failover go to 'Device Management'
open in browser PRO version
pdfcrowd.com
ACTIVE-STANDBY
Once the trust domain is con gured the oating IP for each VLAN needs to
be con gured.
ASSIGN TRAFFIC GROUP 1
1. Goto 'Network' / 'Self IPs'.
2. Create a oating Self IP for each VLAN (i.e Internal and External).
3. For each self IP created con gure the 'Tra c Group' as 'tra c-group1oating'.
In this example we will only be using a single Tra c Group, because of this
any virtual servers that are created will be placed into the default (single
tra c group).
Note : Should you require MAC Masquerading, a single tra c group can
still be used. However this will result in the same MAC address being
advertised for all Self-IPs within the tra c group which may complicate
future troubleshooting.
ACTIVE-ACTIVE
Once the trust domain is con gured the oating IP for each VLAN needs to
be con gured. Once done an additional tra c group is also created.
open in browser PRO version
pdfcrowd.com
pdfcrowd.com
Virtual Server. Within the tra c group section select 'tra c-group-2'.
ENABLE SNAT
1. Under 'Source Address Translation' select Automap*.
Once complete the default tra c-group will be active on one node and
tra c-group-2 will be active on the node.
*As the SelfIP is assigned to tra c-group-1 without Automap the tra c
would be sent through the wrong device.
VE ISSUES
When con guring DSC on Virtual LTMs (when using the steps above) you
may nd that both sides show as disconnected. I have only found this in the
lab for VE devices on both v11.4 and v11.5.
To resolve this you will need to change each of the devices certi cates to a
self-signed certi cate and also perform the steps in a slighty di erent
order.
STEPS
Below provides a summary of the required steps.
1. Generate new self signed cert for each device - Goto Device
open in browser PRO version
pdfcrowd.com
2.
3.
4.
5.
6.
7.
8.
TROUBLESHOOTING
CHECKS
If your are facing issues with your HA setup, the following should be
checked,
Verify NTP is working correctly.
Check connectivity between peer addresses.
Check Self IPs used as peer addresses reside in route domain 0.
open in browser PRO version
pdfcrowd.com
COMMANDS
tmsh
tmsh
tmsh
tmsh
tmsh
run
run
run
run
run
/cm
/cm
/cm
/cm
/cm
sniff-updates
config-sync
watch-devicegroup-device
watch-sys-device
watch-trafficgroup-device
REFERENCES
http://support.f5.com/kb/enus/solutions/public/13000/900/sol13946.html
Comments Community
open in browser PRO version
pdfcrowd.com
Recommend
guest1234
12 days ago
Hello,
What if the peer VLAN has gone down and both f5 boxes are in standby mode
feature that when the pool is not reachable for both devices, not to make the 2
Reply Share
guest123
22 days ago
Reply Share
22 days ago
Yep as long the software versions are the same your be fine
Reply Share
thank you for your reply.. can i use any BigIP Virtual edition with
cnoyes72
open in browser PRO version
Reply Share
3 months ago
pdfcrowd.com
I get "This device is not found" when trying to add the peer unit's management
ping it so I'm not sure what the problem could be.
Reply Share
Vijay
3 months ago
stfu
Reply Share
3 months ago
Early in the article the port for syncing data is not correct - should be 4353.
Reply Share
3 months ago
Reply Share
pdfcrowd.com
Subscribe
Privacy
pdfcrowd.com
back to
top
pdfcrowd.com
LATEST ARTICLES
POPULAR ARTICLES
IPSO - Commands
What is Auto-Scaling?
pdfcrowd.com
About
Sitemap
Partners
Login
pdfcrowd.com