Forum Discussion

a_basharat_2591's avatar
a_basharat_2591
Icon for Nimbostratus rankNimbostratus
Feb 01, 2017

IPs leaking out from the F5 in Disabled mode.

Hi,

 

We have a new F5 5050 model using LTM and connected to the Production Network. We are configuring the new Virtual Servers on it on disable mode to migrate the old F5 to this new: There is an field when you are configuring a new VS that is 'State', which by default is Enabled but we change it to Disabled, and then finish the configuration of the VS.

 

Even so, we have noticed that the VS IP Address advertises on the Network, so the Firewall ARP table shows it [but the VS has never been Enabled (green)].

 

What is then the point on configuring a VS on Disabled mode then? or Does that mean a different thing? we want to avoid the IPs leaking out from the F5 before the migration.

 

All suggestion appreciated.

 

Thanks.

 

4 Replies

  • VS in disabled state won't accept any new connections. However, the IP is still owned by that VS. When doing hardware migration, I would recommend keeping all the interfaces except management interface shutdown. You can copy the configuration over via mgmt. interface. During maintenance, shut the interfaces for the old F5 and enable interfaces for the new F5.

     

  • Hi,

     

    Apart from disabling the interfaces involved, there is another way of doing it safely without disabling interfaces, so It is like:

     

    • When creating the Virtual Server or SNAT/NAT IPs on disable status -> associate them to a VLAN [dummy VLAN that doesn't propagate to the Network]: Configuration[Advanced]>>VLAN and Tunnel Traffic>>Enabled on>>Select VLAN. And afterward, disable ARP advertising and ICMP echo responses as per the link mentioned above by Jana Bollineni.

    Hope that does help, it did to us.