Forum Discussion

Paula_Schiaffin's avatar
Paula_Schiaffin
Icon for Nimbostratus rankNimbostratus
Nov 20, 2014

ACE migration to F5

Hi there, I am working on a migration of an ACE failover pair to two F5 F5-BIG-LTM-2000S. The ACE are now configures with the ADMIN context which has a management network and the heartbeat vlan, and a customer context with 2 service vlans. At this moment the ADMIN and the customer contexts are managed separated, that is, each of them have a different set of snmp, radius, syslog servers. I would like to move to F5 in the same way. I have a totally separated OOB network, so I configured the F5 management ip in the OOB and added the HA-vlan using the IP I have now configured as heartbeat in the ACE. Those are used for the HA in the F5. Then I thought in configuring the F5 cluster with two route domains, having rd 0 as the ADMIN in the ACE and rd 10 as the customer context. RD 0 would have only the management IP I have now in the ACE and the RD10 will have two vlans. I hope this is correct. However, when I want to configure the snmp traps, remote logging and radius, I am not able to configure many differentiating them by RD. Is there any way to do this? Thanks in advance for your help! Regards, Paula

 

2 Replies

  • We use to have a dedicated admin plane, through the out off band management port. which is not "partitionable/RDizable". if you just want to have out off band for management that is build in with the correct cabling.

     

    otherwise you should be able, if you add the correct routing information in the tmm, to send auth, radius and log through the RD0.

     

  • Hi Arnaud. thanks for your reply. I do have a separate OOB network with dedicated switches and there is where I plugged the Management port cable. There are other set of switches which are the production ones where I plan to plug of the service interfaces and where I need to have both RD0 for management and RD10 for the customer. I guess there will be now issues to have send auth, radius and log through RD0. But can I also hava another set of auth, radius and log servers going through RD10? Thanks and regards,