Beruflich Dokumente
Kultur Dokumente
Jack Fenimore
FSE, Central and Southern Ohio
http://xkcd.com/979/
Where am I starting from?
What are we troubleshooting?
Did this work before?
Does the traffic go through the F5?
Is it reproducible?
Is there a log server?
Did the timing of the issue coincide with any other changes?
Before beginning determine what devices are involved
Obtain or create a network diagram from the client to the F5 to the pool
members
Network Map
Module Statistics
Statistics -> Performance
iHealth
What does BIG-IP iHealth do?
• Displays a snapshot of the BIG-IP system configuration
in a user-friendly format
• Evaluates the configuration against a database of
known issues, common errors, and published F5 best
practices
• Provides tailored feedback about configuration issues,
a description of the issue, recommendations for
resolution, and a link to additional information in the
AskF5 Knowledge Base
Displays System Configuration Snapshot
• Self IPs
• SNATs
• NATs
• Virtual Servers 10.2.2.1
External VLAN
10.2.2.100:80 10.2.2.50
NAT to 192.168.4.8
Packet Processing Priority
HTTP response
DST: 3.3.3.3 HTTP request
SRC:1.1.1.1:8080 DST: 1.1.1.1:8080
SRC: 3.3.3.3
RAM
iRules
Cache
Load balancing
iRules HTTP HTTP iRules
algorithms
TCP TCP
iRules Express Express
iRules
VS listener
Forward Request
TCP
VS listener iRules
UDP
• Check routes
• Tracepath utility
• Reject: Use "Reject" when you want LTM to explicitly close both
sides of the connection when the server goes DOWN
“The configuration has not yet loaded. If this message persists, it may
indicate a configuration problem.”
4 TRANSPORT
• Dynamic Reaping
3 NETWORK
• Continually monitors existing TCP connections to ensure
the integrity of the connection table 2 DATA LINK
• Removes the oldest idle connections if it needs to clear 1 PHYSICAL
up more memory
• Protects the BIG-IP against SYN attacks from non-
spoofed IP addresses that fully negotiate a connection
• Avoid changing default values without Support
assistance
* The article http://cr.yp.to/syncookies.html provides an elaborate explanation
of SYN cookies
Tips on General Configuration
• Set DNS and NTP
• Nagles algorithm