Solved

bigip 4.2 active/standby configuration

Posted on 2006-06-15
21
1,545 Views
Last Modified: 2012-08-13
I have run into a wall trying to configure bigip 4.2 redundancy on two F5 boxes.  The problem is when i sync my configuration onto the second F5 box i get the redundant pair in a active/active  configuration.  Even when i try to force one down with configuration utility, it will come back to active after a couple of seconds.  I've tried changed the UnitId's around too, like 1-1, 1-2, 2-2 ,2-1.  The documents i have from F5 talk more about active/active than active/standby.  Does anyone have any ideas or more documentation.  thanks
0
Comment
Question by:ligmania
  • 9
  • 8
  • 4
21 Comments
 
LVL 12

Expert Comment

by:Scotty_cisco
Comment Utility
Have you looked at the licencing ?  There is a licence file in them that allows the Redundancey I am assuming you are talking the HA units?  The redundancy is setup initially through the ./configure command from the command prompt.

Thanks
Scott
0
 

Author Comment

by:ligmania
Comment Utility
Scott,

After looking at each license each has the product code HA so i assume this is the correct license for redundancy. Maybe the steps i doing are incorrect.  Basically, first i use the config utility to create vlans, ip's, the failover address and unitId #.Then on the second unit i create the same way after i'm done i sync from the first box to the second one.  Would this work to create a active/standby configuration ?
0
 
LVL 12

Expert Comment

by:Scotty_cisco
Comment Utility
you are running version 4.2??? I have the older version 4.2.7 and it is done via command line on the console in the initail setup can you console in and run the configure command?

Thanks
scott
0
 

Author Comment

by:ligmania
Comment Utility
Should their be a unitId configured on both boxes before the sync takes place or will the sync assign the unitID ?
0
 
LVL 12

Expert Comment

by:Scotty_cisco
Comment Utility
the initial config asks which one is primary and for the IP of the secondary so it gets assigned automatically
0
 

Author Comment

by:ligmania
Comment Utility
How can i clear the configuration on a bigip unit?  I want to start from a clean slate.
0
 
LVL 12

Expert Comment

by:Scotty_cisco
Comment Utility
you have access through the console?  cd /config/

there should be a file called bigip.conf or something like that.

Thanks
0
 

Author Comment

by:ligmania
Comment Utility
I deleted the bigip.conf and someother default files and rebooted.  The box still shows active for unitids 1 and 2.  All i need to do now is to get this box to stop being active.  I'm puzzled why after I run the config utility and say it is not a redundant system, the box still shows active for unitid's 1 and 2.  What am i doing wrong here ?
0
 
LVL 9

Expert Comment

by:CLoz
Comment Utility
This might be a stupid question but do you have the serial failover cable connected between the two units?  If not, did you configure the two boxes to use network failover?  The BigIP by default is configured to use hardware failover and if the failover cable is not present both boxes will go active unless you have manually configured it for network failover.  
In the case of network failover it will take about 15 - 30 seconds for the hartbeats to go through the network and the election of active/standby to happen, during this short period both boxes will be active/active.
0
 

Author Comment

by:ligmania
Comment Utility
Cloz,

I realized i did not have the serial cable connected, thus both my units stayed in active mode.  After attaching the serial cable they became active/standby, but I did configure network failover.  From what i understand from BIG-IP docs is that you can use both hard-wired serial cable failover and network failover.  From testing i noticied that when the failover cable is attached network failover doesn't work, by that i mean if i take out the ethernet cable from the active unit the standby unit doesn't because active.  I would rather use network failover but my problem is that i can only keep the units in active/standby mode by attaching the failover cable and by doing so network failover doesn't work because the failover isn't detected by the standby unit.  How can i keep the two units in active/standby mode without use of the failover cable?
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 
LVL 12

Expert Comment

by:Scotty_cisco
Comment Utility
I have discovered VIA F5 this is a licence issue ... AAARGGGGHHH as I have the same thing going on to an extent luckily I have support so I will upgrade the code and hope it fixes the issue.

Thanks
scott
0
 

Author Comment

by:ligmania
Comment Utility
Scotty_cisco,

Very curious about the license issue!  What particular license do you need ?  I have the HA license's for both machines .
0
 
LVL 12

Expert Comment

by:Scotty_cisco
Comment Utility
The HA if you have that then not a problem .... I had to get the correct licence on one of my boxes to get either to work is what I was eluding to. What platform is this on the LTM or GTM I am going to be running 9.1.2 when I am done I have found not many people at F5 know the older 4.x product very well.

thanks
Scott
0
 

Author Comment

by:ligmania
Comment Utility
Scotty,

We are running on older 4.2.x, what are the support costs ?
0
 
LVL 12

Expert Comment

by:Scotty_cisco
Comment Utility
are they currently not under support? if so how long have they been out of support?

If they are not supported currently and have been out of support for anytime at all forget it buy new!!! they are cheaper to use another vendor.

F5 is the only company with network gear that requires a recertification fee that I was aware of... each unit to have it recertified is over 5K the support is like 2500 after that we support 2 3DNS boxes because our BIGIP's were EOL and they cost us 15k to cover for 1 year.  Then we purchased 3 new BIGIP LTM 1500's because the old BIGIP HA units we had could no longer be supported.

I would seriously look at coyotepoint as a replacement they seem to do everything the F5's do and are a hell of a lot less expensive.  F5 for loadbalancing used to be the only one in the game but not so now. When it comes time to replace the ones we have just purchased I will strongly recomend that they look at other vendors.  See the link below for coyote point.

http://www.coyotepoint.com/

Thanks
Scott
0
 

Author Comment

by:ligmania
Comment Utility
Thx Scotty I will look at the coyotepoint when and if we replace the F5's.
0
 
LVL 9

Accepted Solution

by:
CLoz earned 500 total points
Comment Utility
ligmania,

You can do active/standby without the serial cable but when the units first come up they will go active/active, after about 15 - 20 seconds they should go to active/standby. If it’s taking longer check that the timeout hasn’t been adjusted for a longer period. Make sure that both boxes can communicate with each other over the failover VLAN. Network Failover uses TCP port 1028, so make sure it’s not being blocked.  Also make sure both systems have been configured for network failover and that they have been synchronized after the network failover is enabled.

Serial failover is still the preferred method because it has the best response time.  If you’re worried about a primary unit staying up even though its network has gone down you can do VLAN Arm Failsafe.  What this option does is test the VLAN on the BigIP and if it is down it will trigger a failover to the standby unit.  To turn this option on go to Network and choose the VLAN you want to test for failover.  Click the Arm Failsafe checkbox and Apply.  Do it on both boxes.  

I wouldn't go with coyotepoint , we evaluated them, we ran into big issues in a redundant pair config and they don't have half the functionality of today’s load balancers from F5 or Cisco.  If you can afford it upgrade to the new BigIP LTM 1500's or try Cisco's CSM.  Both the F5 and Cisco offer standard hardware SSL acceleration and dedicated switching fabric.  SSL offload and switching are still software based on the coyotepoint.

Let me know how it goes,
Cloz
0
 
LVL 12

Expert Comment

by:Scotty_cisco
Comment Utility
I have to admit that I have not worked directly with the coyotepoint but I can tell you value for the dollar is not on the F5 side.  I can cover any cisco product without having to do a recertification BS and support is going to be better on the cisco side too as well as documentation.  

Sorry just not really impressed with F5 at all... been working with them now for awhile and I would much rather work with the cisco in bridge mode's and not deal with the problems with an OS based system.  Try doing a password recovery sometime on an F5 box and see how that goes... I had to rebuild my 3dns box completely because I could not recover the password.

Thanks
Scott
0
 

Author Comment

by:ligmania
Comment Utility
Thanks guys for your feedback, it was very helpful.  The feature that does what i need is the "arm Failsafe".  I tested it today and it works well.    Thanks again everyone.
0
 
LVL 9

Expert Comment

by:CLoz
Comment Utility
We haven't had to deal with recertification b/c none of our boxes have ever lapsed in support coverage and were brought directly from dealers, but recertification is not unique to F5. Many equipment manufactures that deal with OEMs will require a recertification on products that were purchased from none authorized dealers.

I don’t see how running a Cisco in bridge mode would be a solution for load balancing.  As for OS base systems, almost all load balancers on the market today are OS base including Cisco’s own CSS, CSM and ACE (These do not run IOS).  If I can easily circumvent a password on an appliance then I don’t want it in my shop…IMHO  

As with most appliances on the market re-imaging an F5 to recover it takes about 20 minutes.  PXE Boot or CD Boot, then console in and selected the options of where you want to load the new image, wait about 10 minutes while it loads. Finally restore the backups and the box is good to go.

Cheers,
CLoz
0
 
LVL 9

Expert Comment

by:CLoz
Comment Utility
ligmania,

Glad to hear things worked out.

Good Luck.
CLoz
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
TEST APC Smart UPS 13 69
Inventory Management - Free Tool 1 28
Question on UPS Battery Backup for our equipment 8 57
Lifters 4 36
Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now