Sunday, May 3, 2020

F5 one-arm HA config

Hi,

Firstly , I have been using one-arm configuration on F5 BIG-IP. Because of that , I have SNAT (Automap) for symetrical routing. I am using multiple VLANs for 2 x 10 Gb .(VLAN Trunking) Also I have active-standby environment.

Active F5 LB IP Config :

I have 2 x 10Gb interface such as INT-TRUNK-A (2.1 10Gb) and INT-TRUNK-B(2.2 10Gb)

HA IP : 10.0.0.1 VLAN999 Internal-ip  172.16.10.11/24  Internal 10  Allow Default  non-floationg Internal-fip  172.16.10.254/24  Internal 10  Allow Default  floationg Internal-ip2  172.16.20.11/24  Internal20 20  Allow Default  non-floationg Internal-fip2  172.16.20.254/24  Internal20 20  Allow Default  floationg 

Secondary F5 LB IP Config

HA IP : 10.0.0.2 VLAN999 Internal-ip  172.16.10.12/24  Internal 10  Allow Default  non-floationg Internal-fip  172.16.10.254/24  Internal 10  Allow Default  floationg Internal-ip2  172.16.20.12/24  Internal20 20  Allow Default  non-floationg Internal-fip2  172.16.20.254/24  Internal20 20  Allow Default  floationg 

Management IP :192.168.248.2 and .3 VLAN248 (no default gateway) 

then , I have some questions.

1 - I choose HA IP both LB Config Sync.

2- In the Failover Unicast Configuration , I have added HA IP. --> is it required to add Management IP address too?

3- Management > Device Trust > Peer List , I have added HA IP. OR is it required to add Management IP address instead of HA IP ?

4- Config Mirroring , Primary : HA IP, What require we do for Secondary IP?



No comments:

Post a Comment