Forum Discussion

aalkhuja_160331's avatar
Feb 23, 2015

F5-LTM Best practice for Datacenters

Hi,

 

I have a new Data Center (Active-DR/Passive), I want to know the best practice for deploying LTM. can we go for the VE, or it is not recommended. My considerations for the VE are:

 

  • Scalability.
  • High Availability.
  • Deploying both the FE and BE servers over the same F5 device.

considering the above three points, can I implement the VE, or it is risky and i have to go for the H/W equipment( 2K, 4K series?

 

Thank you

 

BR Ammar

 

9 Replies

  • Hi Ammar,

     

    VE and BIGIP have the same functionalities. Except for SSL performances. There is no SSL card on ESX.

     

    What performances are you expecting ? CPS, RPS for instance ???

     

  • Hi Matthieu,

     

    The issue is till now, i don't have a clear picture how much requests or connection they expect. but i can say that the expected services are: their customized ERP system, Emails, and some minor web services. As an entry point, i want to know whether to go with the VE, or to the Big IP appliance. This is my 1st decision step.

     

  • The only way to know if you choose a VE or BIGIP is the performances needed. You need to know how many people, connection, services ...

     

  • Hi allkhuja,

     

    from my perspective using VE is fine. Actually I´m using it in a client´s environment (TMOS v11.5.1; keeping HF level up-to-date) and have no stability issues at all.

     

    Running frontend and backend services on the same system can be done by using routing domains.

     

    Routing domains separate the contexts and do not allow crosscommunication by default.

     

    Another aspect to think about is redundancy.

     

    As a virtual machine can quickly be restored it depends on your client´s availability requirements to run non-redundant per site which saves a lot of costs.

     

    The VE licenses scale up to multi gigabit now. So you will be able to either just increase the license to increase the avaible bandwidth if required.

     

    But most times I would expect adding CPU cores to the virtual machine will help to meet requirements of cpu intensive iRule processing tasks and SSL en-/decryption.

     

    Thanks, Stephan

     

  • Hi Stephan, Thank you for your explanation. but for the availability, I think there is a 8 or 10 G traffic limitation when we consider the VE. also do you experience any kind of service distribution, because I have some concerns about the Hypervisor and the HA issues.

     

    Thank you again.

     

    Ammar

     

    • StephanManthey's avatar
      StephanManthey
      Icon for MVP rankMVP
      Hi Ammar, yes. VE is limited in throughput. By now I did not notice any stability issues with the hypervisor (VMware ESX in my case). Thanks, Stephan
  • As a Summary, can we compare the VE to the H/W appliance in medium, or large scale DCs? because till now, i simply want to know the drawbacks and cons if i go with the VE instead of the H/W appliance.

     

  • As a Summary, can we compare the VE to the H/W appliance in medium, or large scale DCs? because till now, i simply want to know the drawbacks and cons if i go with the VE instead of the H/W appliance.