Sly_85819
Dec 28, 2009Nimbostratus
inet port exhaustion - urgent help needed
We recently had two outages which involved single system sending lot of DNS queries to LTM causing it to slow down and ultimately resulting in performance degradation for all the apps configured on LTM. F5 support suggested that the ephemeral ports were full and we should configure additional self ip to mitigate the situation. A single host on the network causing LTM to slow down is serious cause of concern. I would like to know if there are any ways to proactively take care of this situation. We have configured SNMP traps which helped in getting notification and reduce the outage time when it happened second time.
Here is the messages that we received - 01010201:2: Inet port exhaustion on 10.1.10.61 to 172.24.8.103:53 (proto 17)
10.10.1.61 is the host sending DNS requests. 172.24.8.103 is the pool member of DNS VS. DNS VS is 172.24.4.252. The name server VS is "standard" VS which I believe I need to configure it as "Perf L4" to forward traffic directly instead of doing full proxy. The message is however confusing as the client is hitting server directly??? We have one more VS which allows direct access to the servers behind LTM using a VS - Forwarding (IP). I believe forwarding IP forward traffic directly using route table. I am wondering how the ephemeral ports gets utilized? Is the message actually for the VS?
Thanks in advance.