Forum Discussion

jan_de_wachter_'s avatar
jan_de_wachter_
Icon for Nimbostratus rankNimbostratus
Mar 27, 2014

LTM: Local Traffic log problems

We have two BigIps working in active/standby mode - no automatic sync.

 

We are new to F5 and are starting to use it. We noticed some strange things in our logging and statistics.

 

How can we set the local hour for our logging. The hour specified on our F5's is correct, but the log do not show the same hour.

 

Why are both logs not identical - in most cases we have to go to the standby F5 to see the current log messages (coming from irules - log local ).

 

We have the same problem with the statistics - active stays 0, on standby side we see the statistics.

 

We also have strange messages in our log: address conflict detected for 10.249.13.219 (00:23:e9:99:f6:1e) on vlan 113 . Do we have to worry?

 

Thanks.

 

9 Replies

  • Do you have an NTP server configured to use on both of your BIG-IPs? If not, I recommend doing this first.

     

    Regarding the address conflict, what is the IP address it is alarming on? Is that a self IP on the BIG-IP?

     

  • A) Logs are different between active and standby because one is passing traffic the other isn't.

     

    B) Via what mechanism are you identifying which device is Active and which device is Standby? It sounds like the box you are referring to as standby is the one that is actually passing traffic. (Active)

     

    C) Address conflict detected for 10.249.13.219 means just what it says. You have an IP conflict on your network. Did you accidentally put the same self-ip on both boxes? Are you stepping on the IP space of another device in your network? Look at ARP-tables on your upstream switch, see if you can identify the conflicting MAC's.

     

  • We are using VCMP with partitions.

     

    We have NTP server active, and synced. I think the warning messages are for the floating IPs.

     

    We use the LTM panels who show acive or standby state. cluster: enabled on both slot1: active and slot1: standby. In sync on both.

     

  • Ensure that the self IP address (floating and non-floating) don't conflict with something already up on your network.

     

    Regarding the logs being different, are you referring to /var/log/ltm or some custom log (local or remote)?

     

  • I will check all the self-ips. The log is the local log used in irules with "log local0'.

     

    • Cory_50405's avatar
      Cory_50405
      Icon for Noctilucent rankNoctilucent
      As safeinst mentioned above, the difference in logging is expected between your active and standby units due to one appliance handling production traffic and the other one being idle.
  • I think (hope) I found the reason. Before creating our VCMP we had 'normal' definitions. Creating our VCMP all old definitions were deleted on our active system BUT were still active on our standby system - using the same reused IPs.

     

    Thanks for helping me - I hope all problems will be solved with this.

     

    • Cory_50405's avatar
      Cory_50405
      Icon for Noctilucent rankNoctilucent
      Sounds promising. Please let us know if this resolved your issue.
  • In anyway now I see statistics on my active side. The logging is showing normal hours (the old definition didn't have connection with time server) and for the moment no IP messages in the log.