Forum Discussion

N_67263's avatar
N_67263
Icon for Nimbostratus rankNimbostratus
Jan 05, 2014

F5 failover related suggestions/best practices.

Folks,

 

I came across a setup with 2 core switches and F5 boxes connected to each of these core switch in a active/standby mode. i.e. Active F5 connected to Core-01 and Standby F5 connected to Core-02.

 

Recently this setup came across an outage where Core-01 switch went down and this was hosting the active F5 box.

 

The standby F5 did not take over during this scenario. I seen that in this setup the Active and Standby F5 were connected to each other with and HA link directly connected and this could be the reason. Is my understanding correct?

 

If yes, is there any best practice document or some design guidelines which can help prevent such an outage in future? I can think of is connect the HA pair over the switched infrastructure.

 

Regards, Nik

 

6 Replies

  • It depends on your HA configuration and the Code version. In V11 the blue HA cable between the devices is no longer used. If your using V11 I can share the configuration I use that works.

     

  • Recently this setup came across an outage where Core-01 switch went down and this was hosting the active F5 box.

     

    The standby F5 did not take over during this scenario. I seen that in this setup the Active and Standby F5 were connected to each other with and HA link directly connected and this could be the reason. Is my understanding correct?

     

    if you want f5 to failover when interface is down or vlan has no traffic, you have to configure ha group or vlan failsafe.

     

    ha group

     

    http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/tmos-concepts-11-1-0/tmos_high_avail.html

     

    sol13297: Overview of VLAN failsafe (10.x - 11.x)

     

    http://support.f5.com/kb/en-us/solutions/public/13000/200/sol13297.html

     

    • N_67263's avatar
      N_67263
      Icon for Nimbostratus rankNimbostratus
      Hi Nitass, one of my F5 pair has this option configured but it still did not failover. This is interesting, is there any reason we can think of? Regards, Nik
  • Recently this setup came across an outage where Core-01 switch went down and this was hosting the active F5 box.

     

    The standby F5 did not take over during this scenario. I seen that in this setup the Active and Standby F5 were connected to each other with and HA link directly connected and this could be the reason. Is my understanding correct?

     

    if you want f5 to failover when interface is down or vlan has no traffic, you have to configure ha group or vlan failsafe.

     

    ha group

     

    http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/tmos-concepts-11-1-0/tmos_high_avail.html

     

    sol13297: Overview of VLAN failsafe (10.x - 11.x)

     

    http://support.f5.com/kb/en-us/solutions/public/13000/200/sol13297.html

     

    • N_67263's avatar
      N_67263
      Icon for Nimbostratus rankNimbostratus
      Hi Nitass, one of my F5 pair has this option configured but it still did not failover. This is interesting, is there any reason we can think of? Regards, Nik
  • one of my F5 pair has this option configured but it still did not failover.

     

    for vlan failsafe, you may run tcpdump on the vlan to see if there is any traffic.

     

    for ha group, was device score changed correctly?