Pages

Friday, April 8, 2016

F5 BigIP LTM v11.5.3 Virtual Appliance HA Configuration - Part 2

This post is second part for configuring F5 BigIP LTM v11.5.3  High Availability. You can find other related posts in this blog:
1. Topology:

Logical Topology:





Four Networks:
  • Management Network - Network Adapter 1 in F5 VE - 192.168.2.26/24 and 192.168.2.27/24
  • Internal Network - Network Adapter 2 in F5 VE - 10.1.1.1/24 and 10.1.1.2/24
  • External Network - Network Adapter 3 in F5 VE - 172.17.3.1/24 and 172.17.3.2/24
  • HA Network - Network Adapter 4 in F5 VE - 192.168.1.1/24 and 192.168.1.2/24

Networking Configuration in my Virtual Lab Environment:



2. Mgmt Interface Configuration:

Log in with username root and password default.

There are two different ways to do F5 VE management port settings. One is from part 1 using tmsh commands. Or we could use config wizard as show below.

After logged in, use config wizard to change your Mgmt Interface IP address and default route.

Last login: Sat Apr  2 10:15:55 2016
[root@localhost:NO LICENSE:Standalone] config # config


 


 





 


 


 



3. Activate Trial License for both VE

You can get your 90 day free trial license from https://www.f5.com/trial/big-ip-ltm-virtual-edition.php


After entered the registration key into your VE license page, you will get a dossier to generate license from F5 license activation page - https://activate.f5.com/license/dossier.jsp

admin/admin is the default Web GUI account. Here is how your VE looks like after activated license.



4. Create VLANs

Interface 1.1 -> Internal Vlan -> 10.1.1.1 and 10.1.1.2, floating IP is 10.1.1.3
Interface 1.2 -> External Vlan -> 172.17.3.1 and 172.17.3.2, floating IP is 172.17.3.3
Interface 1.3 -> SYNC HA Vlan -> 192.168.1.1 and 192.168.1.2

4.1 Using Wizard


 



 



 



 







 



 


 




 


4.2 Manually

 


 




 


 
 


You can verify self ip addresses by logging in F5 VE and pinging each other.

Last login: Sat Apr  2 20:09:33 2016
[root@ltm-1:Active] config # ping 10.1.1.3
PING 10.1.1.3 (10.1.1.3) 56(84) bytes of data.
64 bytes from 10.1.1.3: icmp_seq=1 ttl=255 time=2.71 ms
64 bytes from 10.1.1.3: icmp_seq=2 ttl=255 time=1.04 ms
^C
--- 10.1.1.3 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1001ms
rtt min/avg/max/mdev = 1.047/1.883/2.719/0.836 ms

[root@ltm-1:Active] config # ping 172.17.3.1
PING 172.17.3.1 (172.17.3.1) 56(84) bytes of data.
64 bytes from 172.17.3.1: icmp_seq=1 ttl=64 time=0.026 ms
^C
--- 172.17.3.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.026/0.026/0.026/0.000 ms
[root@ltm-1:Active] config # ping 172.17.3.2
PING 172.17.3.2 (172.17.3.2) 56(84) bytes of data.
64 bytes from 172.17.3.2: icmp_seq=1 ttl=255 time=62.4 ms
^C
--- 172.17.3.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 62.459/62.459/62.459/0.000 ms
[root@ltm-1:Active] config # ping 192.168.1.2
PING 192.168.1.2 (192.168.1.2) 56(84) bytes of data.
64 bytes from 192.168.1.2: icmp_seq=1 ttl=255 time=35.0 ms
^C
--- 192.168.1.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 35.005/35.005/35.005/0.000 ms
[root@ltm-1:Active] config # 

5. Device Group



 
 





 



Notes:

Fix the F5 sync state disconnected issue:
  1. Device Groups >(device group previously setup) put both boxes back to available.
  2. Delete the existing device group.
  3. Reset Device Trust. Choose Generate New Self-Signed Authority.
  4. REBOOT THE VE!!!!!!
  5. Device Trust>Peer list. Establish peering. (It is able to see peer no problem.)
  6. Create device groups. "test-sync-failover". Put both devices in "includes". and check Network Failover.
  7. Confirm both devices are in the Device List area.
  8. Overview>(click self device)>choose "Sync Device to Group">Choose "Overwrite Configuration">Sync

6. iApp
Getting Started with the iApp for HTTP applications
To begin the HTTP iApp Template, use the following procedure.
6.1. Log on to the BIG-IP system.
6.2. On the Main tab, expand iApp, and then click Application Services.
6.3. Click Create. The Template Selection page opens.
6.4. In the Name box, type a name. In our example, we use HTTP-app_.
6.5. From the Template list, select f5.http.
The HTTP template opens.



 


 




 
after I changed the string at 'What HTTP request should be sent to check the health of each HTTP server?' from default value 'GET /r/n' to 'GET /HTTP/1.0/\r\n\r\n', the virtual server's availability becomes green.




 
 


Reference:







Sunday, April 3, 2016

Check Point R80 Public Released to Download - SK108623

Check Point R80 Security Management Server is released on March 31 2016 in SK108623.





R80 Upgrade Verification ServiceCheck Point Community Exchange PointUpgrade/Download Wizard

R80 Downloads

SmartConsole

GUI client

Clean Install / Advanced Upgrade for Gaia OS

Complete Management (SmartConsole+Server) installation including all features

Demo version 

Fully working demo version,
with all management components
Available soon





From Check Point upgrade wizard page, the package will be available from Smart-1 205 model and up for new installation.

From download link, we will find Check_Point_R80_Install_and_Advanced_Upgrade_T103.Gaia.iso is a 2880.21MB file. The published date is March 31, 2016.
You will be able to check from upgrade wizard site if you device is able to upgrade or install to this new R80 version.
From what I checked, open server is not updated yet.
 
 
 
 
Smart-1 205 and up model will have this option.  
 
 
Downloading it and will give it try soon.





Saturday, April 2, 2016

F5 BigIP LTM v11.5.3 Virtual Appliance HA Configuration - Part 1

BIG-IP Virtual Edition (VE) is a version of the BIG-IP system that runs as a virtual machine. Supported modules include Local Traffic Manager, BIG-IP DNS (formerly Global Traffic Manager), Application Security Manager, Access Policy Manager, Application Acceleration Manager, Policy Enforcement Manager, Application Firewall Manager, and Analytics. BIG-IP VE includes all features of device-based BIG-IP modules running on standard BIG-IP TMOS, except as noted in release notes and product documentation. BIG-IP VE includes all features of device-based BIG-IP modules running on standard BIG-IP TMOS, except as noted in release notes and product documentation.
Note: The BIG-IP VE product license determines the maximum allowed throughput rate. To view this rate limit, you can display the licensing page within the BIG-IP Configuration utility.


There are some related posts in this site regarding F5 BigIP LTM configuration:
1. Download VE:

1.1 In a browser, open the F5 Support page (https://support.f5.com) or Downloads page (https://downloads.f5.com).



If you have not already logged in, you must log in with your F5 support id, not F5 id, before proceeding to next step.



1.2 On the Downloads Overview page, select Find a Download.The Select a Product line screen opens.


1.3 Under Product Line, select BIG-IP v12.x/Virtual Edition.The Select a Product Version and Container for BIG-IP V12.X/VIRTUAL EDITION screen opens. From the version list at the top of the screen, select the version number that you want to install. 

The screen lists the product containers for BIG-IP VE version you selected.
Under Name, select Virtual-Edition.

 

1.4 The first time you select an option, the Software Terms and Conditions screen opens. Otherwise, the Select a Download screen opens. If the End User Software License is displayed, read through it and then click I Accept
The Select a Download screen opens.
Download the BIG-IP VE file package ending with scsi.ova for Vmware ESXi environment or ide.ova for Citrix Xen environment.

  



 


2. Deploy VE

Check Virtual Edition and Supported Hypervisors Matrix before deployment.

2.1 Import into Vmware ESXi

Follow the screenshots to import OVA file into my lab environment Vmware ESXi 5.5. This lab are using default settings for CPU, Memory and Hard drive.
 



 


 





Note: If Memory of VE is  4 GB or less

The following guidelines apply to VE guests provisioned with 4 GB or less of memory.
  • No more than two modules may be configured together.
  • AAM should not be provisioned, except as Dedicated.
 





Network Settings are most critical parts for your VM environment.
Network adapter 1 - > F5's Management NIC  - > ESXi's VM Internet network.
Network adapter 2 - > F5's Internal NIC          - > ESXi's VM DMZ network
Network adapter 3 - > F5's External NIC         - > ESXi's VM Internal network
Network adapter 4 - > F5's HA NIC                 - > ESXi's VM LAN1

You will find topology with IP address details in next post:
 
 


2.2  Import into Citrix Xen
Similar steps in Citrix Xen server environment. Here are some screenshots from Citrix Xen Center:

 



 






  



2.3 Start Virtual Appliance:

 
Note: If your VM is stuck at "grub loading stage 2" , you may need to add a serial port on your VM configuration. 
 



3. Management Configuration

Log in as root with default as password for cli:


login as: root
Using keyboard-interactive authentication.
Password:default
Last login: Fri Apr  1 07:47:22 2016
[root@localhost:NO LICENSE:Standalone] config #
[root@localhost:NO LICENSE:Standalone] config # tmsh
root@(localhost)(cfg-sync Standalone)(NO LICENSE)(/Common)(tmos)# show sys version

Sys::Version
Main Package
  Product  BIG-IP
  Version  11.5.3
  Build    2.10.196
  Edition  Engineering Hotfix HF2
  Date     Thu Sep 24 12:44:06 PDT 2015

Hotfix List
ID515139-4   ID516075-5   ID527649-1   ID534630-3   ID491771-1  ID497564-5
ID495702-3   ID454086-4   ID526419-2   ID525595-1   ID512383-4  ID517872-2
...


Change Management IP from default 192.168.1.245/24 to your management zone ip


root@(localhost)(cfg-sync Standalone)(NO LICENSE)(/)(tmos.sys)# delete /sys management-ip 192.168.1.245/24

root@(localhost)(cfg-sync Standalone)(NO LICENSE)(/)(tmos.sys)# create /sys management-ip 10.94.12.26/24

root@(localhost)(cfg-sync Standalone)(NO LICENSE)(/Common)(tmos)# list /sys management-ip
sys management-ip 10.94.12.26/24 { }
root@(localhost)(cfg-sync Standalone)(NO LICENSE)(/Common)(tmos)# list /sys management-route
sys management-route default {
    gateway 10.94.12.1
    network default
}


Create a default route for management interface to 10.94.12.1



Log in Web GUI using admin/admin as username and password:



Reference: