Disclaimers This book is in no way affiliated, associated, authorized, endorsed by F5 Networks, Inc. or any of its subsidiaries or its affiliates. The official F5 Networks web site is available at www.f5.com. F5, Traffix, Signaling Delivery Controller, and SDC are trademarks or service marks of F5 Networks, Inc., in the U.S. and other countries. A full list of F5 Networks’ marks can be found at https://f5.com/about-us/policies/trademarks. Trademarks used with permission of F5 Networks, Inc. This book refers to various F5 marks. The use in this book of F5 trademarks and images is strictly for editorial purposes, and no commercial claim to their use, or suggestion of sponsorship or endorsement, is made by the authors or publisher.
Permission Notice The F5 Certified logo used on the front cover of this book is a registered trademark of and is copyright F5 Networks, Inc. F5 Networks, Inc has granted this book’s authors permission to use the logo in this manner.
www.f5books.eu Copyright © 2018 by F5 Books - Philip Jönsson & Steven Iveson All rights reserved. This book or any portion thereof may not be reproduced or used in any manner whatsoever without the express written permission of the authors except for the use of brief quotations in a book review or scholarly journal. First Printing: 2018 ISBN: ISSU_v2 Revision: 2018.v2
2 2
TABLE OF CONTENT Preface
34
About the Authors
34
Dedications
34
Acknowledgements
35
Feedback
36
1. Introduction
37
Who is This Book for?
37
How This Book is Organised
37
F5 Networks the Company
39
F5 Terminology
43
What is BIG-IP?
43
BIG-IP Hardware
43
BIG-IP Software – TMOS
44
TMOS Components in Detail
46
TMOS Planes
48
BIG-IP Hardware Platforms
48
Appliances
49
VIPRION
56
Herculon
59
BIG-IP Virtual Edition (VE)
59
The Different F5 Modules, Products & Services
60
3 3
Overview
60
Access Policy Manager (APM) Module
61
Advanced Firewall Manager (AFM) Module
62
Application Acceleration Manager (AAM) Core Module
62
Application Acceleration Manager (AAM) Full Module
63
Application Security Manager (ASM) Module
63
Application Visibility and Reporting (AVR)
64
BIG-IQ Centralised Management Product
65
BIG-IQ Cloud & Orchestration Product
66
Carrier Grade NAT (CGNAT) Module
66
Edge Gateway Product
67
Enterprise Manager (EM) Product
67
DNS (formerly Global Traffic Manager (GTM)) Module
67
IP Intelligence Service
68
Link Controller Product (& Module)
69
MobileSafe Product & Service
69
Policy Enforcement Manager (PEM) Module
69
Secure Web Gateway (SWG) Module & Websense Cloud-based Service
70
Silverline Cloud-based Service
70
WebSafe Service & Module
70
DDoS Hybrid Defender (Herculon)
71
SSL Orchestrator (Herculon)
71
Free and/or Open Source Products
71
Bigsuds
72
iControl REST Software Development Kit (F5-SDK)
72
Ansible
72
Containers
72
OpenStack
72
Cloud - AWS
73
Cloud - Azure
73
Cloud - GCP
73
The Full Application Proxy
73
The Packet Based FastL4 Proxy
75
4 4
OneConnect
76
2. The TMOS Administrator Exam
78
The F5 Professional Certification Program
78
Why Become Certified?
79
Choosing a Certification
80
Getting Started
80
Taking Exams
81
Additional Resources
81
Practice Exams
81
Additional Study Material
81
AskF5
81
DevCentral
82
F5 University
82
Exam Blueprints
82
BIG-IP LTM Virtual Edition (VE) Trial
82
BIG-IP VE Lab Edition
82
BIG-IP VE on Amazon Web Services (AWS)
83
Other Clouds
83
3. Building Your Own Lab Environment
84
Obtaining the Different Components to Build Your Lab
84
VMware Workstation Playerâ„¢
84
BIG-IP VE Trial Evaluation Key
85
Downloading the BIG-IP VE Machine
85
BIG-IP VE Lab Edition
85
The Lab Architecture
85
Lab Exercises: Setting up Your Lab Environment
87
4. Introduction to LTM - Initial Access and Installation
5 5
107
The BIG-IP LTM Module
107
Initial Setup
107
Configuring the Management Port IP Address
107
Configuration via the LCD Panel
108
Configuring the Management IP address Using the Touch LCD Panel (iSeries platforms)
108
Configuration Using the Config Command
109
Configuration Using TMSH
110
Configuration Using the WebGUI
111
Licensing the BIG-IP System
111
Automatic License Activation
112
Manual License Activation
113
Provisioning
114
The Setup Utility
115
Self-IP Addresses
115
Lab Exercises: Initial Access and Installation
116
Chapter Summary
126
Chapter Review
127
Chapter Review: Answers
128
5. Local Traffic Objects
130
Nodes
130
Pool Members
130
Pools
130
Virtual Servers
131
Wildcard Virtual Servers
132
Local Traffic Objects Dependencies
133
The Different Types of Virtual Servers
136
Standard Virtual Server
137
6 6
Connection Setup with a Standard Virtual Server Using Only a Layer 4 Profile
137
Connection Setup with a Standard Virtual Server Using a Layer 7 Profile
138
Performance Layer 4 Virtual Server Connection Setup with a Performance Layer 4 Virtual Server Performance HTTP Virtual Server
139 139 141
The Fast HTTP Profile
141
Connection Setup with a Performance HTTP Virtual Server
142
Performance HTTP Virtual Server With an Existing Idle Server-Side Connection
142
Forwarding IP Virtual Server Connection Setup with a Forwarding IP Virtual Server Forwarding Layer 2 Virtual Server Connection Setup with a Forwarding Layer 2 Virtual Server
145 145 146 146
Reject Virtual Server
148
DHCP Relay Virtual Server
148
Stateless Virtual Server
149
Internal Virtual Server
149
Message Routing Virtual Server
151
Chapter Summary
151
Chapter Review
152
Chapter Review: Answers
154
6. Load Balancing Methods
156
Member vs. Node
156
Static Load-Balancing
157
Round Robin
158
Ratio
158
Dynamic Load-Balancing
161
Least Connections
7 7
161
Fastest
162
Least Sessions
163
Ratio Sessions
163
Ratio Least Connections
165
Weighted Least Connections
168
Observed
169
Predictive
169
Dynamic Ratio
169
Priority Group Activation
170
FallBack Host
175
Lab Exercises: Load Balancing
175
Chapter Summary
186
Chapter Review
187
Chapter Review: Answers
190
7. Monitors
192
Overview
192
Health Monitors
193
Performance Monitors
193
Intervals & Timeouts
193
Temporarily Failed Monitors
196
Where Can You Apply Health Monitors?
196
Monitoring Methods
200
Simple Monitoring
200
Active Monitoring
200
Passive Monitoring
200
Benefits and Drawbacks With Passive and Active Monitoring
202
Active Monitoring
8 8
202
Passive Monitoring Types of Monitors
203
Application Check Monitors
204
Content Check Monitors
205
Performance Check Monitors
206
Path Check Monitors
206
Service Check Monitors
208 209
Slow Ramp Time
209
Multiple Monitors & the Availability Requirement
209
Manual Resume
210
Monitor Reverse Option
210
Monitor Instances
210
Administrative Partitions
210
Firewalls
210
Testing
211
Monitors - Logging
211
Enable Monitor Logging on Node Level
211
Enable Monitor Logging on Pool Member Level
212
Enabling Monitor Logging for SNMP DCA/DCA Base
212
Disabling Monitor Logging for SNMP DCA/DCA Base
212
Object Status
9
202
Address Check Monitor
Monitors - Advanced Options
9
202
213
The Different Object Status Icons
213
Object State
214
Understanding Object Status Hierarchy
215
When Will the BIG-IP System Send Traffic to a Node/Pool Member?
220
Local Traffic Summary
220
Local Traffic Network Map
221
Filtering Results
221
Verifying Object Status
222
Using the CLI (tmsh) to Verify Object Status
223
Monitor Status Logging
223
Enabling Monitor Status Logging
223
Disabling Monitor Status Logging
224
Monitor Status Changes in the BIG-IP LTM Log
225
Lab Exercises: Monitors
225
Chapter Summary
232
Chapter Review
233
Chapter Review: Answers
235
8. Profiles
237
Why Use Them?
237
Profile Types
237
Protocol Profiles
238
Persistence Profiles
238
SSL Profiles
238
Application (Services) Profiles
238
Remote Server Authentication Profiles
239
Analytics Profile
239
Other Profiles
239
Profile Dependencies
239
Default and Custom Profiles
242
10 10
Creating a Custom Profile
244
Deleting a Custom Profile
244
Assigning Profiles to a Virtual Server
244
Lab Exercises: Profiles
246
Chapter Summary
253
Chapter Review
254
Chapter Review: Answers
256
9. Persistence Concept of Stateless and Stateful Applications
257 257
Sessions
257
Stateful Communication With Load Balancing
257
What is Persistence?
258
Persistence Methods
258
Source Address (aka Simple) Persistence
258
Cookie Persistence
262
Destination Address Persistence
269
Hash Persistence
269
Universal Persistence
270
Other Persistence Profiles
270
Single Node Persistence Configuration Verification
270 275
Primary & Fallback Methods
275
Match Across
276
Match Across Services
276
Match Across Virtual Servers
278
Match Across Pools
278
Persistence Mirroring
279
Lab Exercises: Persistence
279
Chapter Summary
287
11 11
Chapter Review
287
Chapter Review: Answers
290
10. SSL Traffic
293
Terminology of SSL
294
Certificate Authority (CA)
294
Certificate Signing Request (CSR)
294
Personal Information Exchange Syntax #12 (PKCS#12)
295
Managing SSL Certificates for the BIG-IP System Using the WebGUI
295
Procedures
296
Creating a Self-Signed SSL Certificate
296
Creating a Certificate using a CSR
296
Importing an SSL Certificate
298
Importing an SSL Private Key
298
Importing a PKCS#12 File
299
Renewing a SSL Certificate Using a CSR
299
SSL/TLS Offloading
300
The Client SSL Profile
302
Creating a Custom Client SSL Profile
303
SSL Bridging Creating a Custom Server SSL Profile
303 304
SSL Passthrough
305
Certificate Authorities
306
Intermediate CAs and the Certificate Chain
307
Importing Certificates & Constructing the Certificate Chain in the BIG-IP System
308
Importing the CA Certificates
308
Creating the Client SSL Profile With a Certificate Chain
310
Lab Exercises: SSL Traffic
12 12
310
Chapter Summary
316
Chapter Review
317
Chapter Review: Answers
318
11. NAT and SNAT
320
Network Address Translation – NAT
320
Traffic Flow When Using a Virtual Server on Inbound Connections
322
Traffic Flow When Using NAT on Inbound Connections
323
Traffic Flow When Using NAT on Outbound Connections
324
Disadvantages of Using NAT
325
NAT Traffic Statistics
326
Source Network Address Translation – SNAT
13 13
327
Why We Need SNAT
327
Typical Uses of SNAT
329
Pool Member’s Default Gateway is Not the BIG-IP system
329
Both Client and Pool Member Reside on the Same Network
333
Internal Nodes in a Private Subnet Need to Share One External IP Address
336
How to Configure SNATs
337
SNAT Listener
337
SNAT Translation List
337
SNAT With a Virtual Server
338
SNAT Pool
338
SNAT Auto Map
340
How to Enable SNAT Auto Map on a Virtual Server
342
Potential Issues for Server Applications When SNAT Translation is Used
342
Port Exhaustion
342
How to Change the Source Port Preservation for Virtual Servers
343
Socket Pairs
344
Port Exhaustion on a Virtual Server
344
Monitoring Port Exhaustion
345
Lab Exercises: NAT and SNAT
345
Chapter Summary
348
Chapter Review
349
Chapter Review: Answers
350
12. High Availability
352
Configuring a Sync-Failover Pair
353
Device Trust
353
The Different Types of Trust Authorities
353
The Importance of the BIG-IP Device Certificates
354
Device Identity
355
The Device Discovery Process in a Local Trust Domain
355
Important When Configuring a Device Trust
355
Adding a Device to a Local Trust Domain
356
Resetting the Device Trust
356
Device Groups
356
Sync-Only Device Group
357
Sync-Failover Device Group
357
Administrative Folders
357
Floating Self-IP Addresses
357
MAC Masquerading
358
Synchronising the Configuration
358
The CMI Communication Channel in Detail
359
ConfigSync Operation in Detail
360
Determine the State of a System
361
Force to Standby Mode
361
14 14
WebGUI – Method 1
362
WebGUI – Method 2
362
WebGUI – Method 3
362
CLI - tmsh
362
Traffic Groups
362
The Default Traffic Groups on a BIG-IP System
363
Traffic Group Failover Methods
364
Load Aware Failover
364
How to Specify the HA Capacity
365
How to Specify the HA Load Factor
366
Calculation Example
367
HA Order
369
HA Groups
370
Auto-Failback Auto-Failback Feature is Not Compatible With HA Group
371 372
Force to Standby Feature is Not Compatible with HA Group
372
Active-Active Redundancy
372
Failover Options
378
HA Table VLAN Failsafe
378 379
Using the High-Availability Screen
381
Using the VLANs Screen
381
Gateway Failsafe
381
Failover Detection
381
Device Group Communication
381
15 15
Hardware Failover
381
Network Failover
382
Network Communication
382
Stateful Failover
382
Connection Mirroring
383
Persistence Mirroring
383
SNAT Mirroring
383
Considerations Regarding Stateful Failover
384
How to Configure Stateful Failover
384
Specifying an IP Address for Connection Mirroring
384
Enabling Connection Mirroring on a Virtual Server
385
Enabling Connection Mirroring for SNAT Connections
385
Enabling Mirroring of Persistence Records
385
Lab Exercises: High Availability
385
Chapter Summary
406
Chapter Review
407
Chapter Review: Answers
409
13. The Traffic Management Shell (tmsh)
412
Accessing the Traffic Management Shell (tmsh)
412
Understanding the Hierarchical Structure of tmsh
414
The tmsh Prompt
415
Navigating the tmsh Hierarchy
415
Command Completion Feature
416
Perform Wildcard Searches in tmsh
417
Context-Sensitive Help
417
Manual Pages
418
Command History Feature
419
The tmsh Keyboard Map Feature
419
Managing BIG-IP Configuration State and Files
420
16 16
Introduction to BIG-IP Configuration Files and Structure
421
Text Configuration Files
423
Binary Configuration Files
424
Loading and Saving the System Configuration
425
Administrative Partitions
426
How Do Administrative Partitions Work?
427
Referencing Object in Different Partitions
428
Limitations With Administrative Partitions
429
Navigating Between Partition
429
How to Create Administrative Partitions
430
Effect of Load/Save on Administrative Partitions
430
User Roles
430
Creating Local User Accounts
432
Modifying the Properties of a Local User Account
433
Shutting Down and Restarting the BIG-IP System
434
Using Advanced Shell (bash)
434
Viewing the BIG-IP Connection Table in tmsh
435
About the Connection Table
435
Connection Reaping
435
Viewing the Connection Table
435
Filtering Using awk and grep
437
Additional Help Tmsh on DevCentral
437 437
Lab Exercises: tmsh
438
Chapter Summary
442
Chapter Review
443
Chapter Review: Answers
445
17 17
14. File Transfer
447
Linux Client - Sending Files - SCP
447
Linux Client - Retrieving Files - SCP
448
Common SCP Errors
448
Linux Client - Connecting - SFTP
448
Linux Client - Sending Files - SFTP
449
Linux Client - Retrieving Files - SFTP
449
Key Based Authentication
450
Windows Clients
452
15. Selected Topics Always On Management (AOM)
453 453
Accessing AOM Through the Serial Console
453
Accessing AOM Through the HMS Via SSH
453
Directly Connecting to the AOM Via SSH
454
The Command Menu
455
iRules
455
When Should You Use an iRule?
456
When Should You Not Use an iRule?
456
iRule Components
456
Event Declarations
457
Operators
457
Rule Commands
458
iRule Events
458
HTTP Events Data Groups Lists
18 18
459 460
What Are the Benefits of a Data Group?
461
How Do I Use Data Group Lists?
461
Creating Your iRule
462
The iRule Editor
462
Learn more
463
iRule Wiki
463
CodeShare
463
Additional Literature
463
iApps
463
iApps Framework
464
Templates
464
Application Services
464
Strict Updates Disabling Strict Updates What is a Route Domain?
465 465 466
Benefits of Using Route Domains
466
Route Domain IDs
467
Parent ID
467
About VLANs and Tunnels for a Route Domain
468
About Default Route Domains for Administrative Partitions
468
Creating a Route Domain
469
Lab Exercises: iRules
470
Chapter Summary
475
Chapter Review
476
Chapter Review: Answers
478
16. Troubleshooting Hardware
479
Introduction
479
End User Diagnostics (EUD)
479
Obtaining the Latest EUD Software
19 19
479
Installing EUD on the BIG-IP Device
480
Creating an EUD Bootable CD-ROM
480
Creating an EUD Bootable USB Storage Device
480
Launching EUD
480
Running Tests
481
Viewing Output
482
LCD Warning Messages
482
LED Indicators
483
The Power LED Indicator
483
The Status LED Indicator
483
The Activity LED Indicator
483
The Alarm LED Indicator
484
Modifying alert.conf
484
Backing up the Original alert.conf
485
Clearing Alerts
486
Clearing the LCD Warnings and Alarm LED Remotely (Using the CLI)
486
Clearing the LCD Panel
486
Clearing the Alarm LED
487
Log Files
488 Priorities
490
Facilities
490
Perform a Failover
492
Consequences of Performing a Failover
494
How to Perform a Failover
495
WebGUI
495
CLI - tmsh
495
Troubleshooting System Interfaces
20 20
495
The Network Components Hierarchy
495
The System Interfaces
497
Link Layer Discovery Protocol (LLDP)
497
The Interface Properties
498
The Interface Naming Convention
498
Viewing Interface Information
499
Interface State
499
Flow Control
500
VLANs
500 Assigning Interfaces to VLANs
500
Port-based Access Method
501
Tag-based Access Method
501
Creating and Managing VLANs
502
VLAN Groups
502
Transparency Mode
503
Bridge All Traffic
503
Bridge in Standby
503
Creating a VLAN Group
503
Associating a VLAN/VLAN Group With a Self-IP address Creating a Self-IP address Trunks
21
504 504
How Trunks Work
505
Link Aggregation Control Protocol (LACP)
505
Creating a Trunk
506
Troubleshooting Network Issues
21
504
506
Network Statistics
506
Troubleshooting Packet Drops
507
Troubleshooting Interface Packet Drops
507
Troubleshooting TMM Packet Drops
509
Known Issues
511
Chapter Summary
511
Chapter Review
512
Chapter Review: Answers
514
17. Troubleshooting Device Management Connectivity
515
Get to Know Your Environment
515
Verify the Configuration
516
Tools Available for Troubleshooting
516
Ping
516
Traceroute
517
Telnet
517
cURL
518
Verifying the Processes on the BIG-IP device
519
Verifying That the sshd Process is Running Using the WebGUI
519
Verifying That the Web Processes is Running Using SSH
519
Port Lockdown
521
Port Lockdown Exceptions
523
Configuring Port Lockdown
524
Restricting Access to the Management Port
525
Packet Filters
526
Exemptions
529
Creating Packet Filter Rules
530
Reordering Packet Filter Rules
530
Logging of Packet Filter Rules
531
Troubleshooting DNS Settings
22 22
531
Verify the DNS Configuration
531
Tools Available for Troubleshooting DNS
532
nslookup
532 Common Error Messages
dig
533 534
Changing Resource Types
536
Limiting the Output
536
Perform Reverse Lookups
537
Query Another DNS Server
537
Performing Multiple Lookups
537
dig Parameters
537
Remote Authentication Introduction
538
The LDAP Authentication Module
538
The RADIUS Authentication Module
538
The TACACS+ Authentication Module
539
The SSL Client Certificate LDAP Authentication Module
539
The SSL OCSP Authentication Module
539
The CRLDP Authentication Module
540
The Kerberos Delegation Authentication Module
540
The Network Time Protocol (NTP) Configuring an NTP Server Troubleshooting NTP
540 541 541
Verifying the NTP daemon service
541
Verifying the Communication Between the BIG-IP System and the NTP Peer Server
541
Verifying the Network Connectivity to the NTP Peer Server
543
Chapter Summary
543
Chapter Review
543
23 23
Chapter Review: Answers
18. Troubleshooting and Managing Local Traffic Traffic Processing Order
545
547 547
Control Plane Functions
547
Packet Processing Order
547
Listener Processing Order
548
Managing & Troubleshooting Virtual Servers & Pools
550
Managing Virtual Servers
550
What Protocols Does the Application Use?
550
On What VLAN Will the Client Access the Application?
551
How Should the BIG-IP System Handle SSL Connections?
553
SSL Cipher Suites
553
SSL Cipher Mismatch
554
Managing Pool Members Monitoring
555 555
Troubleshooting Virtual Servers
556
DNS record
556
Is the Traffic Reaching the BIG-IP System?
556
Check the Status of the Virtual Server
557
What Error Are You Getting When Accessing the Virtual Server?
557
Troubleshooting Pool Members Impact When Modifying the Configuration
559
Changes Not Taking Effect Immediately
559
Taking a Pool Member/Node Offline
24 24
558
559
Disabled
559
Forced Offline
560
Deleting Existing Connections to a Pool Member
561
Deleting Existing Connections to a Node
561
RST Logging
561
Persistence Issues
562
OneConnect
562
Pool Member Failure
562
Troubleshooting Persistence Issues
562
Chapter Summary
566
Chapter Review
566
Chapter Review: Answers
568
19. Troubleshooting Performance Packet Captures
25
570
Why Should We Capture Packets?
570
When Should We Capture Packets?
570
Where Should We Capture?
570
What Are We Looking For?
571
Expected TCP/IP Behaviours
573
Using tcpdump
25
570
573
Limitations
573
Usage Syntax
574
Specifying an Interface
574
Capturing Additional TMM Information
575
Default Output
575
Writing to a File
576
Restricting the Number of Packets Captured
576
Quick Mode
577
Verbose Mode
577
Capturing Link Level (Layer 2 – Data Link) Headers
577
Capturing Packet Contents – Format
578
Capturing Packet Contents – How Much?
579
Disabling DNS Lookups
579
Also Disabling Service Name Lookups
579
Reading from a File
580
tcpdump Expressions
580
Logical Operators
581
Grouping
582
Single Host
583
Multiple Hosts
583
Single Network
585
Multiple Networks
585
Specific Protocol Port(s) & Direction
587
Address Resolution Protocol (ARP)
588
ICMP
589
Refining That First Example Further
589
A Common Example
590
tcpdump Output
591
Generic TCP
591
Generic UDP
593
Notes on the Protocol Field
594
Notes on Service Ports
595
Protocol Formatting
595
Fragmented Packets
595
Using Wireshark
26 26
596
Opening Capture Files
599
Getting Around
600
The F5 Wireshark Plugin
601
Decodes & Non-standard Ports
605
Display Filters
606
Red Herrings
609
Further Reading
609
Other BIG-IP Tools
609
Monitors
609
The Performance Dashboard
609
Performance Statistics in the GUI
610
Performance Statistics at the CLI
612
AVR
613
iHealth
614
SNMP
614
Chapter Summary
614
Chapter Review
615
Chapter Review: Answers
616
20. Opening a Support Case with F5 Information Required When Opening a Support Case With F5
27 27
618 618
Full Description of the Issue
618
Severity Levels
619
QKview
620
Generating a QKview file
621
Generating a QKview on a High Load BIG-IP System
621
iHealth
622
Log Files
624
Packet Traces (tcpdump)
624
SSL Dump
624
UCS Archives
624
Core Files
625
Assembling an Accurate Problem Description
625
Quantitative Vs. Qualitative Observations
625
Relevant Vs. Irrelevant Information
626
How to Open a Support Case with F5 Support
626
Escalation Methods
628
Chapter Summary
629
Chapter Review
630
Chapter Review: Answers
632
21. Identify and Report Current Device Status
634
The Dashboard
634
Interpreting Log Files
636
Health Monitor Failure
636
High Availability Communication Failure
638
VLAN Failsafe
641
Configuration Sync
641
TMM Core Dump
642
Analytics
643
Analytics Profiles
644
How to Configure Analytics to Collect Data
645
Reviewing and Examining the Application Statistics
646
Investigating Server Latency
648
Investigating Page Load Times
649
Capturing Traffic using Analytics
649
Reviewing Captured Traffic
650
Chapter Summary
652
28 28
Chapter Review
653
Chapter Review: Answers
654
22. Device Maintenance
656
Archive Files
656
The Single Config File (SCF)
656
Example of Data Contained in a SCF file The User Configuration Set (UCS) Archive
657 657
Generating a UCS Archive - WebGUI
658
Loading a UCS Archive – WebGUI
658
Generating a UCS Archive – tmsh
659
Loading a UCS Archive – tmsh
659
Customising What Files Are Included in the UCS Archive
659
The Differences Between UCS and SCF
660
Restoring a BIG-IP System From a UCS Archive
661
Licensing Considerations When Restoring From a UCS Archive
661
Other Considerations When Restoring From a UCS Archive
661
Preventing Synchronisation When Installing a UCS Archive on a BIG-IP DNS (GTM) system
662
Delayed Load on BIG-IP ASM Module
663
vCMP Considerations When Restoring From a UCS Archive
663
Preventing Service Interruptions When Replacing a BIG-IP System in a Redundant Pair
663
Managing Software Images and Upgrades
664
Legacy Version Numbering Schema
664
Major Software Versions
664
Minor Software Versions
664
Maintenance Software Versions
664
Cumulative Hotfixes
664
The Tick Tock Release Cycle
665
29 29
Release Notes
666
Overview of the Disk Management Process
667
The BIG-IP Hard Disk and Boot Locations
667
Software Images
668
How to Install a New Software Image
669
Determine the Software Image to Install
670
Downloading the Software Images/Hotfixes
670
How to Import the Software Images/Hotfixes to the BIG-IP system.
671
Checking the MD5 Checksum of an Image File
671
Re-activate the License Prior to the Upgrade
672
Installing the Software Image
673
Installation Using the WebGUI
673
Installation Using tmsh
674
When Installing a Software Image
674
When Installing a Hotfix
675
Booting the BIG-IP System Into the New Volume
675
Rolling Back to a Previous Version
676
Handling the Configuration Between Volumes
676
Best Practices When Upgrading a BIG-IP System in a HA-pair
678
Potential Problems When Upgrading Your BIG-IP system
679
Enterprise Manager (EM)
681
Performing Basic Device Management
681
Adding Devices to Enterprise Manager
681
The Discovery Process
681
Discovering BIG-IP devices
682
Discovering non-BIG-IP Devices.
683
Performing Basic Tasks on Managed Devices
30 30
684
Verifying and Testing Device Communication
684
Verifying the Enterprise Manager IP Address on a Device
684
Verifying Device Connection to Enterprise Manager
686
Rebooting Managed Devices
686
To Reboot a Device Into a Different Boot Location
686
Managing Licenses Starting a Device Licensing Task
687
Accepting the EULA for Devices
688
Configuring Task Options and Running the Task
688
Collecting Information for F5 Support Starting a Support Information Gathering Task Managing UCS Archives
31
688 689 690
Maintaining Rotating UCS Archives
690
Increasing the Maximum Rotating Archives
690
Changing the Default Archive Options
690
Creating Rotating Archive Schedules
691
Modifying Rotating UCS Archive Schedules
692
Maintaining Specific Configuration Archives
692
Creating a New Pinned Archive
693
Pin an Already Existing Archive
693
Restoring UCS Archives for Managed Devices
693
Performing a UCS Restoration for a Managed Device
693
Deleting UCS archives
694
Comparing Multiple Versions of UCS Archives
694
Creating an Archive Comparison Task
694
Searching for Specific Configuration Elements
695
Managing Software Images
31
687
695
Reviewing Available Software Downloads
696
Adding and Removing Software Images/Hotfixes on the Enterprise Manager
696
Adding an Image/Hotfix to the Software Repository
696
Removing an Image/Hotfix to the Software Repository
696
Copying and Installing Software to Managed Devices
697
Copying Software to Be Installed at a Later Date
697
Installing a Software Image
698
Monitoring and Alerts
699
Managing the Task List
700
Overview of Alerts
700
Setting Alert Default Options
701
Creating Alerts for Enterprise Manager
702
Creating, Modifying, and Deleting Alerts for Devices
702
Creating a Device Alert
702
Modifying a Device Alert
703
Deleting a Device Alert
704
Monitoring Certificates
704
Disabling Certificate Monitoring
704
Enabling Certificate Monitoring
704
Viewing Certificate Information
705
Accessing the Certificate Screen
705
The Certificate Status Flag
706
Creating a Device Certificate Alert
706
BIG-IQ
706
The BIG-IQ Panels
707
The BIG-IQ Device/System Management Panels
707
The BIG-IQ Application Delivery Controller (ADC) Panel
708
32 32
The BIG-IQ Web Application Security Panel
708
The BIG-IQ Network Security Panel
708
The BIG-IQ Access Panel
708
BIG-IQ Device and System Management
709
Installing Required BIG-IQ System Components – Updating the REST Framework
709
Device Discovery
710
License Management
711
BIG-IP System Software Upgrades
712
Uploading Software Images
712
Performing a Managed Device Install
712
Rebooting Managed Devices
714
UCS File Backup and Restoration
714
Creating an Instant Backup
714
Creating Scheduled Backups
715
Restoring a UCS File Backup
716
Monitoring and Alerts
717
Configuring BIG-IQ to Work With SNMP
717
Configuring SNMP Agent for Sending Alerts
718
Configuring SNMP Access for Version 1 and 2C
718
Configuring SNMP Access for Version 3
718
Configuring SNMP Traps
719
SSL Certificate Monitoring
719
Chapter Summary
720
Chapter Review
721
Chapter Review: Answers
722
Index
33 33
724
Preface About the Authors Philip Philip Jönsson was born in Malmö City, Sweden 1988 where he still lives with his family. He gained an interest in technology at an early age. When he was eight years old the family got a home PC, which was the first step in his career. Since Philip had a big interest in technology, choosing his education was easy. His IT studies started at The Nordic Technical Institute (NTI) where he studied the basics of computer technology and eventually focused on network. Later on he studied IT-security at Academedia Masters. Philip’s first job in the IT business was at a home electronics company in Sweden. He worked at the IT department and was responsible for managing and troubleshooting the sales equipment in the stores and managing the IT infrastructure within the organisation. This is where Philip first encountered a BIG-IP controller. Philip eventually started working in a Technical Assistance Center (TAC) department at an IT security company. Now Philip works as a consultant focused on F5 products in a department at one of the largest IT security company in Europe and handles major projects and solves problems for Sweden's most well-known companies. Steve Steven Iveson, the last of four children of the seventies, was born in London and was never too far from a shooting, bombing or riot. He’s now grateful to live in a small town in East Yorkshire in the north east of England with his wife Sam and their four children. He first encountered a BIG-IP Controller in 2004 and has been working with TMOS and LTM since 2005. Steve’s iRules have been featured in four DevCentral articles and he’s made over 3000 posts on the DevCentral forums. He's been awarded F5 DevCentral MVP status four times in 2014, 2016, 2017 and 2018. Steve’s worked in the IT industry for over twenty years in a variety of roles, predominantly in data centre environments. In the last few years he’s widened his skill set to embrace DevOps, Linux, Docker, automation, orchestration and more. He also blogs on subjects including Linux, programming, application delivery and careers at packetpushers; a community of bloggers that contribute technical, work life, and opinion articles from the customer’s perspective.
Dedications Philip I would like to dedicate this book to my wife Helena and my family for their support throughout the writing of this book. Thank you for your patience throughout the making of this book! Steve For Mark. You made it.
34 34
Acknowledgements We would like to thank everyone who participated in the beta program for this book. The great feedback has helped us make this the best book possible. Special thanks to these outstanding contributors (in no particular order): ▪ ▪ ▪
Scott Campbell, Canada Hannes Rapp, Portugal Thomas Domingo Dahlmann, Denmark
Philip First off, I would like to thank Holger Yström for promoting my first book. With his help, the first and original study guide was acknowledged by many F5 representatives and made it all the way to the corporate headquarters in Seattle. Without his help the original Study Guide would not have become this big. A big thanks to my mentor, colleague and great friend Thomas Domingo Dahlmann who has been an invaluable asset throughout the making of this book. Thomas has assisted with proof reading our material and providing swift and great feedback, solely on his spare time. Both me and Steven are forever grateful! During the beta program for this book, I came in contact with Scott Campbell whom I also want to thank. The work you put into the proof reading is just astonishing and seeing that kind of enthusiasm is truly inspiring. You have really helped us with raising the quality of this book and we are truly grateful for that. I would also like to thank my employer SecureLink for giving me the opportunity to widen my knowledge and experience of F5 products. Thanks to my department for the encouragement and support throughout the writing of this book. Thanks to the Designerz who created the cover and the design of the book, you did a great job! Thanks to F5 for making this possible and for all the help we’ve got in making this book. An honourable mention is Kenneth Salchow, Julio Hevia Posada and James Dean. You have all been great to work with and have always provided us with great input and assistance. Finally, I would like to thank Steven Iveson for wanting to participate in this collaboration. Your contribution to this book has truly raised its value and it has been a pleasure working with you. Steve We all stand on ‘the shoulders of giants’. We’ve both put a huge amount of time and effort into this book and every sentence requires research, reading, testing and time to understand and contextualise. None of that would be possible without the incredible information and tools we now have at our disposal. The contributions of countless people and entire generations, programs, movements, ideas and even cultures have all played a part. From the Internet to Ethernet to the road network and back to the Magna Carta; this book wouldn’t have been possible without them.
35 35
Thanks to the many who’ve taken the time to contribute to DevCentral (DC) to inform, educate and assist others, myself included. A special mention to Colin Walker (now with Extrahop) and these F5 staff members and DC contributors: Joe Pruitt (username: Joe) who created DevCentral, Aaron Hooley (username: hoolio) who’s made over twelve thousand posts on DC, Nitass Sutaveephamochanon (username: nitass) and Kevin Stewart. Again, thanks to Philip for making this book happen in the first place.
Feedback If you have any comments, corrections or feedback regarding this book, feel free to send an email to feedback@f5books.eu. Philip You are very welcome to connect on Linkedin. You can find my public profile at: https://www.linkedin.com/pub/philipj%C3%B6nsson/3a/680/810. Steve You can follow me on Twitter: @sjiveson, read my blogs at http://packetpushers.net/author/steven-iveson/ and you’re welcome to connect on Linkedin. You can also follow my work on GitHub: sjiveson and Docker Hub: itsthenetwork. You can also join this book’s Linkedin group by searching Linkedin for: ‘All Things F5’. This is an independent group that is not associated with F5.
36 36
1. Introduction Who is This Book for? This book is designed to provide the reader and student with everything they need to know and understand in order to pass the F5 TMOS Administration 201 exam and become a F5 Certified BIG-IP Administrator. All generic networking, application, protocol and F5 specific topics and elements found in the exam blueprint are covered in full and in detail. No prior knowledge is assumed and the book includes review summaries, over 350 diagrams, over 90 test questions and a number of lab exercises to aid understanding and assist in preparing for the exam. Even those attending official F5 training courses will find this book of benefit as those courses only cover the F5 specific elements of the curriculum.
How This Book is Organised Most readers should read and study this book from start to finish, front to back. As with the official F5 blueprint, things move from the simple and abstract to the more complex and detailed and each topic builds upon the knowledge gained in earlier ones. We’ve ordered the book’s chapters and sections to mostly reflect the order of that exam blueprint, although in a few cases where we’ve felt it’s more appropriate we’ve ignored it. Each chapter starts with a brief overview of the topics that will be covered and many end with a useful review summary as well as some simple questions to test your understanding. The chapters of the book and their contents are as follows; ▪
This chapter, Chapter 1 – Introduction provides the background on F5 Networks the company and its history and overviews of F5 terminology, technologies, hardware and software products.
▪
Chapter 2 – The TMOS Administrator Exam describes the wider technical certification program, the exam and offers a list of useful additional study resources.
▪
Chapter 3 - Building Your Own Lab Environment gives you everything you need in order to set up your own BIG-IP lab environment.
▪
Chapter 4 - Introduction to LTM - Initial Access and Installation introduces you to the BIG-IP system and describes how you perform an initial setup.
▪
Chapter 5 - Local Traffic Objects introduces you to the different local traffic objects such as nodes, pool members, pools and virtual servers. It also describes the different virtual server types.
▪
Chapter 6 - Load Balancing Methods covers all of the different load balancing algorithms and the concept of Member vs. Node.
▪
Chapter 7 - Monitors will in detail, describe all of the different monitors. Along with the many object statuses and states.
▪
Chapter 8 - Profiles covers the profiles which you can assign to the virtual servers. We discuss the different profile types, but we also detail some of the more common ones.
▪
Chapter 9 - Persistence describes what a stateless vs. stateful application is. It also covers all existing profiles and the benefit vs. drawbacks of each.
37 37
▪
Chapter 10 - SSL Traffic introduces you to the different SSL modes that the BIG-IP system support along with some SSL certificate management.
▪
Chapter 11 - NAT and SNAT will discuss how the BIG-IP system handles its adress translation and differences between NAT and SNAT.
▪
Chapter 12 - High Availability describes what is needed to configure your BIG-IP environment in a HighAvailability setup and in detail, explain how the HA communication works.
▪
Chapter 13 - The Traffic Management Shell (tmsh) covers the BIG-IP command line interface and how it is structured.
▪
Chapter 14 - File Transfer teaches you how to transfer files to and from the BIG-IP system.
▪
Chapter 15 - Selected Topics contain random subjects like iRules, AOM and iApps that describes what it is and what it can be used for.
▪
Chapter 16 - Troubleshooting Hardware covers hardware troubleshooting tools such as EUD and log files in depth and explores instigating HA failover.
▪
Chapter 17 – Troubleshooting Device Management Connectivity provides an in-depth review of areas related to remote management covering features and subjects such as DNS, packet filtering, Port Lockdown and many more. The ping and traceroute tools are introduced.
▪
Chapter 18 – Troubleshooting and Managing Local Traffic steps through the process of identifying and resolving issues with local traffic and provides detail on the traffic processing order of operations.
▪
Chapter 19 – Troubleshooting Performance moves on to observing and determining performance related issues and using related tools such as the packet capture program tcpdump.
▪
Chapter 20 – Opening a Support Ticket With F5 explores how to best gather relevant information prior to raising a call, how to provide it to F5, selecting a suitable severity level and escalating cases.
▪
Chapter 21 – Identify and Report Current Device Status covers general operational monitoring through, amongst others, the network map, dashboard, log files and iApps Analytics.
▪
Chapter 22 – Device Maintenance offers information on local configuration backup and restoration, automated remote configuration archiving and dealing with TMOS software image upgrades in a HA environment. It also covers the F5 products BIG-IQ and Enterprise Manager.
The book also contains numerous notifications divided into five categories, as follows: Icon
Text
Description Warning
38 38
You will see this icon and text whenever you should proceed with caution. We'll use this when an instruction might have an impact on the system. Ensure you read this notice before proceeding.
Note
Used whenever additional information is provided to benefit your overall understanding of a topic.
Important
When we need to provide clarity and avoid misunderstanding we'll use this icon and text.
Exam Tip
This icon and text highlight information that is essential or important in order to pass the exam.
Recommendation
Used to indicate a personal recommendation based on our experience managing BIG-IP over many years.
F5 Networks the Company Created as F5 Labs in 1996* by Michael D. Almquist** (aka Mad Bomber and Squish,) a technical entrepreneur and programmer and Jeffrey S. Hussey, an investment banker. F5 released its first HTTP web server load balancing device: the BIG-IP Controller, in 1997. The company, head-quartered in Seattle, Washington since its inception, has grown rapidly to date (barring a lull during the dot.com collapse between 1999 and 2001) and has expanded its product offerings significantly. They now produce a wide range of dedicated hardware and virtualised appliance application delivery controllers (ADCs). As well as load balancing these can provide SSL offload, WAN acceleration, low and high level security functions, application acceleration, firewalling, SSL VPN, remote access and much more. Michael Almquist left the company in May 1998 over a year before the company went public on NASDAQ (symbol: FFIV) in June 1999 and was renamed F5 Networks. By mid-2005, industry analyst firm Gartner reported F5 had captured the highest share of the overall ADC market and by late 2016*** the company earned almost $2 billion in annual revenue and employed over 4,500 people in 59 locations around the world, 1200 in R&D. Refreshingly, they paid tax of $184m for their financial year 2016 in stark contrast to the likes of Google (who have paid £200m on profits (not revenue) of apparently over £7b since 2000 in the UK), Cisco and Starbucks. The company has no long term debt and assets of over $2.3 billion. Services earned just over 52% of revenues compared to products, with the largest sales market being the Americas, followed by EMEA, APAC and Japan. Research and development expenses for the financial year were $334m. According to Netcraft®, in May 2009, 4.26% of all websites and around 3.8% of the top million sites were being served through F5 BIG-IP devices. A look at this Netcraft page: http://uptime.netcraft.com/up/reports/performance/Fortune_100, shows that on 7th February 2014, 20% of the US Fortune 100’s public websites were served through F5 BIP-IP ADCs including those of Bank of America, Dell, Disney, Lehman Brothers, Lockheed Martin, Wachovia and Wells Fargo. The company’s longest servicing President and CEO was John McAdam who held these roles for fifteen years until he was briefly replaced by Manny Rivelo. Manny took the reigns in July 2015 for six months until John McAdam returned on an interim basis. He was finally replaced by François Locoh-Donou in April 2016.
39 39
The company name was inspired by the 1996 movie Twister, in which reference is made to the fastest and most powerful tornado on the Fujita Scale: F5. Significant technical milestones and business events in F5 Networks’ history include; 1895 – Nortel® is founded (as Northern Telecom Limited) 1995 – Brocade® is founded 1996 – F5 is incorporated (February) 1996 – Cisco® launches LocalDirector; technology based on its acquisition of Network Translation Incorporated that same year (the PIX® firewall platform also sprung from this acquisition) 1996 – Foundry Networks® is founded (originally called Perennium Networks and then StarRidge Networks, renamed Foundry in 1997) (later to be acquired by Brocade in 2008) 1996 – Alteon Networks® is founded (later to be acquired by Nortel in 2000) 1997 – F5 Launches its first BIG-IP Controller (July) 1997 – ArrowPoint Communications® is founded by Chin-Cheng Wu (later to be acquired by Cisco in 2000) 1998 – F5 Launches the 3DNS Controller (September) 1998 – Reactivity is founded 1998 – NetScaler is founded 1999 – F5 Goes public on NASDAQ (June) 2000 – Cisco acquires ArrowPoint Communications (at a cost of $5.7b) for their content switching technology which they release as the Content Services Switch (CSS) range the same year but fails to develop the product further 2000 – Redline Networks® is founded (later to be acquired by Juniper in 2005) 2000 – FineGround Networks® founded (later to be acquired by Cisco in 2005) 2000 – MagniFire Websystems® founded (later to be acquired by F5 in 2004) 2000 – Peribit Networks® (WAN optimisation) founded (later to be acquired by Juniper® in 2005) 2000 – Nortel acquire Alteon Networks (at a cost of $6b in stock) (the Alteon application delivery assets later to be acquired by Radware® in 2009) 2001 – The iControl XML-based open API is introduced by F5 with v4 2002 – v4.5 Released and includes the UIE and iRules 2002 – Acopia Networks® founded by Chin-Cheng Wu (who also founded ArrowPoint Communications in 1997) (later to be acquired by F5 in 2007) 2002 – Crescendo Networks® founded (later to have its IP acquired by F5 in 2011) 2003 – F5’s DevCentral Community and technical reference website launched 2003 – F5 Acquires uRoam (at a cost of $25m) for its FirePass technology (SSL VPN, application and user security) 2004 – F5 Acquires MagniFire Websystems (at a cost of $29m) for its web application firewall (WAF) technology TrafficShield, which forms the basis of the ASM product 2004 – F5 releases TMOS v9 and TCL-based iRules 2004 – Zeus Technology® releases Zeus Traffic Manager 2005 – F5 Acquires Swan Labs® (at a cost of $43m) for its WAN optimisation technology (WANJet) 2005 – Juniper Networks purchases Peribit Networks (WAN optimisation) and Redline Networks (ADCs) at a cost of $337m and $132m respectively 2005 – Cisco acquires FineGround Networks (at a cost of $70m) and integrates its technology with the Catalyst switch line to create the ACE product
▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
40 40
2005 – Cisco launch numerous Application-Oriented Networking (AON) products to support the convergence of ‘intelligent networks’ with application infrastructure 2005 – Citrix acquires NetScaler (at a cost of $300m) 2006 – Lori MacVittie joins F5 2007 – Don MacVittie joins F5 2007 – A10 Networks® launches its AX Series family of ADC appliances 2007 – F5 Acquires Acopia Networks (at a cost of $210m) for its file virtualisation technology, which is later rebranded as its ARX range 2007 – Cisco acquires Reactivity (at a cost of $135m) for its XML gateway technology, which they launch as the ACE XML Gateway product the same year 2008 – F5’s VIPRION modular, blade based hardware is released 2008 – Juniper discontinues it’s DX line of load balancers based on the Redline Networks technology acquired in 2005 2008 – LineRate Systems® is founded 2008 – Foundry Networks is acquired by Brocade (at a cost of $2.6b (Brocade originally offered $3b)) 2009 – Nortel ceases operations 2009 – Radware acquire Nortel’s Alteon application delivery assets (at a cost of $18m) 2009 – F5 Releases TMOS and LTM v10 2010 – Cisco ACE XML Gateway sales end 2010 – Cisco Application-Oriented Networking (AON) products sales end 2011 – F5 Releases TMOS and LTM v11 2011 – F5 Acquires Crescendo Networks intellectual property (at a cost of $5.6m) for its application acceleration technology 2011 – Riverbed® acquires Zeus Technology (at a cost of $110m) for its software based ADC product Zeus Traffic Manager and rebrands it as Stingray (rebranded again as SteelApp™ in 2014) 2011 – Cisco CSS sales end 2012 – F5 Acquires Traffix Systems® (at a cost of $140m) for its mobile/cellular 4G/LTE and Diameter signalling protocol switching technology 2012 – Riverbed and Juniper form a partnership in WAN optimisation and application delivery products, with Juniper licensing the Riverbed Stingray (later renamed SteelApp™) software ADC and Riverbed integrating Steelhead Mobile technology into Juniper’s JunOS Pulse client 2012 – Cisco end development of their ACE load balancing products and partner with Citrix to recommend NetScaler as their preferred product 2013 – F5 Acquires LineRate Systems (at a cost of $125m) for its layer seven and application delivery software defined networking technology 2013 – F5 Acquires Versafe® (at an unknown cost) for its mobile and browser security and monitoring products (the TotALL suite) 2013 - The iControl REST open API is introduced by F5 with TMOS v11.4 2013 – F5 Becomes an OpenStack corporate sponsor 2013 – F5 Launches the Synthesis frame work and introduces SDAS: Software-Defined Application Services™ 2013 – F5 Reduces the price of the 10Mb limited Lab Edition of BIG-IP VE (including LTM, GTM, AFM, ASM, AVR, PSM, WAM and WOM) from around $2000 to just $95, in a gutsy move to capture market share 2014 – Riverbed rename Stingray (formerly Zeus Traffic Manager) to SteelApp™
▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
41 41
2014 – F5 Acquire Defense.Net® (at an unknown cost) for its cloud-based DDoS mitigation technology and services 2014 - F5 Launches its Silverline cloud-based security service in the US, powered by it’s earlier Defense.Net acquisition 2015 - F5 Launches the LineRate Point Load Balancer 2015 - F5 Launches Silverline in EMEA 2015 - Manny Rivelo becomes President and CEO as John McAdam steps down after fifteen years 2015 - Manny Rivelo leaves and John McAdam resumes his roles as President and CEO 2016 - François Locoh-Donou becomes President and CEO 2016 - F5 is named a leader in the Gartner Magic Quadrant for application delivery controllers for the 10th year running 2017 - F5 Launches Herculon security appliances and the DDoS Hybrid Defender and SSL Orchestrator products that run upon them. The Silverline WAF Express service and Container Connector are also launched
▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
Having gained a leading market share in the load balancing and local traffic management enterprise market for some time F5 is now targeting and looking for growth in additional markets, supported and evidenced by their ever expanding product range. These markets include; security (AFM, ASM and APM), cloud (AWS etc.), mobile signalling (Traffix) and acceleration, virtualisation and SSL VPN and RAS. *This article suggests it was actually late 1995: http://www.udel.edu/PR/Messenger/98/1/cyber.html although it was indeed early 1996 when the company was incorporated. **You’ll find in many sources that Michael Almquist has effectively been written out of the company’s history. ***Data taken from the company’s September 2016 financial year end 10K annual report found here.
42 42
F5 Terminology Before we get into the exam specifics we think it’s worthwhile exploring the terminology surrounding F5 Networks’ products (again). This isn’t tested on the exam in any way but without an understanding of the terms you’ll find in this book and elsewhere and particularly how they relate to F5’s hardware and software, things will be harder for you than they need to be. To that end, the next three sections will explore the primary marketing term for the overall product range and then move on to the terms used in relation to the hardware and software (some of which are the same!)
What is BIG-IP? So, just what is BIG-IP? It’s confusing; back in the day, BIG-IP was the single name for everything and all you had was the BIG-IP Controller. Now, things are a bit different and you have the application switch hardware, virtual edition, TMOS, TMM, LTM, APM and all the rest. To add to the confusion BIG-IP is quite often used interchangeably with TMOS or even just F5. As specific and well, simply pedantic I can be I still catch myself saying things like “check your F5’s logs…” or “what’s the CPU load on this BIG-IP.” So, back to the question, what is BIG-IP? Well, simply put it’s all of the things I’ve mentioned so far; it’s an allencompassing term for the hardware, the Virtual Edition container, TMOS (the software components), TMM (a component of TMOS), LTM (which runs within TMM), APM and all the other modules.
BIG-IP Hardware When discussing BIG-IP hardware, things become rather more specific but keep in mind that for many hardware components there will be a related software component that runs on top of it, which has the same name. The primary hardware elements and their purpose are as follows; ▪
Traffic Management Microkernel (TMM); traffic processing hardware components as follows; o A L2 switch module (possibly using network processing NICs) o Packet Velocity ASIC(s) (PVAs) or embedded PVA (ePVA) using Field-programmable gate arrays (FPGAs) o FPGAs providing ePVA, SYN check and other functions in hardware o Dedicated SSL encryption or FIPS hardware o Dedicated compression hardware (in some models) o TMM uses all CPUs (although one is shared with the HMS) and almost all system RAM, a small amount being provisioned for the HMS. TurboFlex™; available on iSeries appliances only, provides FPGA driven, user selectable pre-packaged optimisations that tightly integrate with other hardware and software components and free CPU resources for other tasks. Examples of supported optimisation profiles include layer 4 offload, denial-of service (DoS) functions and tunneling encapsulation. Host Management Subsystem (HMS); responsible for system management and administration functions and runs a version of CentOS (Community enterprise Operating System) Linux (which includes the SELinux feature). The HMS uses a single CPU (shared with TMM) and is assigned a dedicated provision of the overall system RAM, the rest being assigned to TMM. Always On Management (AOM); provides additional ‘lights out’ management of the HMS via a dedicated management processor as well as layer 2 switch management and other supporting functions for TMM.
▪
▪
▪
43 43
▪
Baseboard Management Controller (BMC); another subsystem with a dedicated controller that is independent of the primary TMM and HMS components, which provides for out-of-bound (or so called ‘sideband’) management and monitoring. The BMC is the primary constituent of the Intelligent Platform Management Interface (IPMI) computer interface specifications and protocol which we’ll cover in the BIG-IP Software - TMOS section.
BIG-IP Software – TMOS F5 Network’s Traffic Management Operating System (TMOS) is, first and foremost and for the sake of clarity, NOT an individual operating system. It is the software foundation for all of F5’s network or traffic (not data) products; physical or virtual. TMOS almost seems to be a concept rather than a concrete thing when you first try to understand it. I’ve struggled to find a truly definitive definition of TMOS in any manual or on any website. So, what is TMOS? It’s not too tough after all, really; TMOS encompasses a collection of operating systems and firmware, all of which run on BIG-IP hardware appliances or within the BIG-IP Virtual Edition. BIG-IP and TMOS (and even TMM) are often used interchangeably where features, system and feature modules are concerned. This can be confusing; for instance, although LTM is a TMOS system module running within TMM, it’s commonly referred to as BIG-IP LTM. I suspect we have the F5 marketing team to thank for this muddled state of affairs. TMOS and F5’s so-called ‘full application proxy’ architecture was introduced in 2004 with the release of v9.0.
44 44
This is essentially where the BIG-IP software and hardware diverged; previously the hardware and software were simply both referred to as BIG-IP (or BIG-IP Controller). Now, the hardware or ‘platform’ is BIG-IP, and the software TMOS. Anything capable of running TMOS and supporting its full proxy counts as a BIG-IP so the virtualised version of TMOS is called BIG-IP Virtual Edition(VE) rather than TMOS VE. Where the VE editions are concerned, just the TMM and HMS software components of TMOS are present (more details soon). The primary software elements of BIG-IP, collectively known as TMOS, encompass all of these things; ▪
TMM; o
o o o o ▪
HMS; this runs a modified version of the CentOS Linux operating system and provides the various interfaces and tools used to manage the system such as the WebGUI, tmsh CLI, DNS client, SNMP and NTP. The HMS also contains an SSL stack (known as the COMPAT stack): OpenSSL, which can also be used by TMM where necessary.
▪
Local Traffic Manager (LTM); this and other ‘feature’ modules such as APM, ASM and DNS (formerly GTM) expose specific parts of TMM functionality when licensed. They are typically focussed on a particular type of service (load balancing, authentication and so on).
▪
AOM; lights out system management accessible through the management network interface and serial console.
▪
Intelligent Platform Management Interface (IPMI); IPMI is a hardware-level interface specification and protocol supported on BIG-IP iSeries hardware. It allows for out of band monitoring and management of a system independently of (or without) an operating system and when the system is ‘off’. Like AOM, IPMI functions are accessible through the management network interface and serial console.
▪
Maintenance Operating System (MOS); disk management, file system mounting and maintenance.
▪
End User Diagnostics (EUD); performs BIG-IP hardware tests.
45 45
Software in the form of an operating system, system and feature modules (such as LTM), other modules (such as iRules) and multiple network ‘stacks’ and proxies; FastL4, FastHTTP, Fast Application Proxy, TCPExpress, IPv4, IPv6 and SCTP. Software in the form of the interface to and the firmware that operates the dedicated SSL and other cards and hardware. A ‘native’ SSL stack. Interfaces to the HMS. TurboFlex FPGA firmware
TMOS Components in Detail Let’s explore some of the TMOS components in a little more detail. Traffic Management Microkernel (TMM) TMM is the core component of TMOS as it handles all network activities and communicates directly with the network switch hardware (or vNICs for VE). TMM also controls communications to and from the HMS. Local Traffic Manager (LTM) and other modules run within the TMM. TMM is single threaded until TMOS v11.3; on multi-processor or multi-core systems, Clustered Multi-Processing(CMP) is used to run multiple TMM instances/processes, one per core. From v11.3 two TMM processes are run per core, greatly increasing potential performance and throughput. TMM shares hardware resources with the HMS (discussed next) but has access to all CPUs and the majority of RAM.
46 46
Host Management Subsystem (HMS) The Host Management Subsystem runs a modified version of the CentOS Linux operating system and provides the various interfaces and tools used to manage the system such as the WebGUI, Advanced (Bash) Shell, tmsh CLI, DNS client, SNMP and NTP client and/or server. The HMS can be accessed through the dedicated management network interface, TMM switch interfaces or the serial console (either directly or via AOM). The HMS shares hardware resources with TMM but only runs on a single CPU and is assigned a limited amount of RAM. Always On Management (AOM) The AOM (another dedicated hardware subsystem) allows for ‘lights out’ power management of and console access to the HMS via the serial console or using SSH via the management network interface. AOM Is available on nearly all BIG-IP hardware platforms including the Enterprise Manager 4000 product, but not on VIPRION. Note AOM ‘shares’ the management network interface with the HMS. Maintenance Operating System (MOS) MOS is installed in an additional boot location that is automatically created when TMOS version 10 or above is installed. MOS, which runs in RAM, is used for disk and file system maintenance purposes such as drive reformatting, volume mounting, system re-imaging and file retrieval. MOS also supports network access and file transfer. MOS is entered by interrupting the standard boot process via the serial console (by selecting TMOS maintenance at the GRUB boot menu) or booting from USB media. The grub_default -d command can be used to display the MOS version currently installed. Only one copy of MOS is installed on the system (taken from the latest TMOS image file installed) regardless of the number of volumes present. End User Diagnostics (EUD) EUD is a software program used to perform a series of BIG-IP hardware tests – accessible via the serial console only on system boot. EUD is run from the boot menu or via supported USB media.
47 47
TMOS Planes The following diagram provides an overview of the operational planes within TMOS and where each function and element resides;
BIG-IP Hardware Platforms BIG-IP Application switch hardware comes in a wide range of fixed and modular models. Both the physical hardware and the Virtual Edition are considered a form of application delivery platform; in other words, they run TMOS. Hardware provides superior performance and throughput using Field-Programmable Gate Array (FPGA) circuitry, specialised high performance network interfaces and optimised data paths. Further benefits are gained from the inclusion of additional dedicated hardware for SSL processing (all models) and compression processing (higher end models only) which provide much higher performance than commodity processors. Due to this higher performance the number of TMOS modules you can install on an appliance is also typically quite high, which lends itself well to functional consolidation. Clearly more suited to high workloads, hardware appliances are therefore typically placed in a logically central position in the network to maximise their benefits and ensure the maximum amount of traffic is easily processed through them.
48 48
The built-in AOM and BMC subsystems (covered in detail in the earlier F5 Terminology section) are a useful inclusion and vendor support is also simplified as both the hardware and software are supported and designed by the same vendor. Of course, for all these benefits there are some downsides, the primary ones being cost and a lack of flexibility. The hardware is an expensive upfront cost, however, make good use of their high performance and capacity and the cost is low compared to their true value, over time. This is a primary design consideration, the higher the throughput (within suitable limits) the greater the potential return on your investment (ROI). Moving to the second and related drawback, with the exception of VIPRION, hardware appliances in general simply don’t scale well. If you need to do more than your current device has capacity for you have to (rip and) replace it with a larger device (known as vertical scaling). Equally, future (estimated) capacity requirements must be incorporated in the original purchase, which may mean the hardware is not used to anything like its full capacity for a significant time. These issues can be mitigated to some extent through the use of tiered designs, horisontal scaling made possible through device groups and related HA features and/or segmentation and multi-tenancy with vCMP, route domains and the like.
Appliances You don’t need to know this for the exam but its still useful to have an understanding of the physical BIG-IP platforms. They all (with the exception of VIPRION systems detailed in the next section) have a minimum specification of; ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
LCD Panel & Physical Controls (some models now have a colour touch-panel) Intel dual core CPU Dual power supply capable (AC and DC) Gigabit Ethernet copper and fibre interfaces Front mounted LCD panel Dedicated management network interface Serial console interface Failover/HA serial interface Front to back airflow Software HTTP compression Hardware SSL encryption via ‘Cryogen’ card 8GB RAM 500GB HDD Up to 4,000 2K SSL transactions per second 5Gbps Layer four and layer seven throughput 4Gbps Bulk encryption 425,000 Layer seven requests per second 150,000 Layer four connections per second
49 49
Specifications increase up to the following for the higher end models (excluding the VIPRION platforms discussed shortly); ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
Intel 12 core CPUs 40GbE Fibre interfaces Hardware compression (up to 40Gbps) 128GB RAM Dual 10,000RPM 1TB HHDs with RAID (SSDs are an option) Up to 240,000 2K SSL transactions per second (TPS) 84Gbps Layer four throughput 40Gbps Layer seven throughput 40Gbps Bulk encryption 4,000,000 Layer seven requests per second 1,500,000 Layer four connections per second
The only hot swappable components are the power supplies (assuming two are installed), SFP network interfaces and fan tray (in some models only). Hard disks are not hot swappable even on models that support RAID. FIPS Compliant and Turbo SSL versions of some models are also available. Here’s a quick rundown of the models available at the time of publication, from most powerful to least;
12250v L7 Requests Per Second: 4M L4 Connections Per Second: 1.5M Throughput L4/L7: 84/40Gb Bulk Encryption: 40Gb vCMP Capable: Yes TurboFlex: No Hardware Compression: 40Gb Processors/Cores: 1/12 Memory: 128GB Hard Drive(s): 1x 800GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes
50 50
i10800 L7 Requests Per Second: 3.5M L4 Connections Per Second: 1.5M Throughput L4/L7: 160/80Gb Bulk Encryption: 40Gb vCMP Capable: Yes TurboFlex: Yes - Tier 3 Hardware Compression: 40Gb Processors/Cores: 1/8 Memory: 128GB Hard Drive(s): 1x 480GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes
i10600 L7 Requests Per Second: 2.1M L4 Connections Per Second: 1M Throughput L4/L7: 160/80Gb Bulk Encryption: 40Gb vCMP Capable: No TurboFlex: No Hardware Compression: No Processors/Cores: 1/8 Memory: 128GB Hard Drive(s): 1x 480GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes
10350v/-N/-F L7 Requests Per Second: 3M L4 Connections Per Second: 1.2M Throughput L4/L7: 84/40Gb Bulk Encryption: 24Gb FIPS Option: Yes for 10350v-F vCMP Capable: Yes TurboFlex: No Hardware Compression: 24Gb Processors/Cores: 1/10 Memory: 128GB Hard Drive(s): 1x 800GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes
10255v/10250v/10200v-SSL L7 Requests Per Second: 2M L4 Connections Per Second: 1M Throughput L4/L7: 80/40Gb Bulk Encryption: 22Gb/22Gb/33Gb FIPS Option: Yes for 10200v vCMP Capable: Yes TurboFlex: No Hardware Compression: 24Gb Processors/Cores: 1/6 Memory: 48GB Hard Drive(s): 2x 400GB/1x 400GB SSD/2x 1TB 10GB Interfaces: Yes 40Gb Interfaces: Yes
10055s/10050s/10000s L7 Requests Per Second: 1M L4 Connections Per Second: 0.5M Throughput L4/L7: 80/40Gb Bulk Encryption: 22Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/6 Memory: 48GB Hard Drive(s): 2x 400GB/1x 400GB SSD/2x 1TB 10GB Interfaces: Yes 40Gb Interfaces: Yes
51 51
i7800 L7 Requests Per Second: 3M L4 Connections Per Second: 1.1M Throughput L4/L7: 80/40Gb Bulk Encryption: 20Gb vCMP Capable: Yes TurboFlex: Tier 3 Hardware Compression: 20Gb Processors/Cores: 1/6 Memory: 96GB Hard Drive(s): 1x 480GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes
i7600 L7 Requests Per Second: 1.8M L4 Connections Per Second: 750K Throughput L4/L7: 80/40Gb Bulk Encryption: 20Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/6 Memory: 96GB Hard Drive(s): 1x 480GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes
7255v/7250v/7200v-SSL L7 Requests Per Second: 1.6M L4 Connections Per Second: 775K Throughput L4/L7: 40/20Gb Bulk Encryption: 18/18/19Gb FIPS Option: Yes for 7200v vCMP Capable: Yes TurboFlex: No Hardware Compression: 18Gb Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 2x 1TB/1x 400GB SSD/2x 400GB SSD 10GB Interfaces: Yes 40Gb Interfaces: No
7055s/7050s/7000s L7 Requests Per Second: 800K L4 Connections Per Second: 390K Throughput L4/L7: 40/20Gb Bulk Encryption: 18Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 2x 1TB/1x 400GB SSD/2x 400GB SSD 10GB Interfaces: Yes 40Gb Interfaces: No
52 52
i5800 L7 Requests Per Second: 1.8M L4 Connections Per Second: 800K Throughput L4/L7: 60/35Gb Bulk Encryption: 20Gb vCMP Capable: Yes TurboFlex: Tier 3 Hardware Compression: 20Gb Processors/Cores: 1/4 Memory: 48GB Hard Drive(s): 1x 480GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes
i5600 L7 Requests Per Second: 1.1M L4 Connections Per Second: 500K Throughput L4/L7: 60/35Gb Bulk Encryption: 15Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/4 Memory: 48GB Hard Drive(s): 1x 480GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes
5250v/5200v L7 Requests Per Second: 1.5M L4 Connections Per Second: 700K Throughput L4/L7: 30/15Gb Bulk Encryption: 12Gb FIPS Option: Yes for 5250v vCMP Capable: Yes TurboFlex: No Hardware Compression: 12Gb Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 1x 1TB/400GB SSD 10GB Interfaces: Yes 40Gb Interfaces: No
5050s/5000s L7 Requests Per Second: 750K L4 Connections Per Second: 350K Throughput L4/L7: 30/15Gb Bulk Encryption: 12Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 1x 1TB/400GB SSD 10GB Interfaces: Yes 40Gb Interfaces: No
53 53
i4800 L7 Requests Per Second: 1.1M L4 Connections Per Second: 450K Throughput L4/L7: 20/20Gb Bulk Encryption: 15Gb vCMP Capable: No TurboFlex: Tier 2 Hardware Compression: 10Gb Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No
i4600 L7 Requests Per Second: 650K L4 Connections Per Second: 250K Throughput L4/L7: 20/20Gb Bulk Encryption: 10Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No
4200v L7 Requests Per Second: 850K L4 Connections Per Second: 300K Throughput L4/L7: 10/10Gb Bulk Encryption: 8Gb vCMP Capable: No TurboFlex: No Hardware Compression: 8Gb Processors/Cores: 1/4 Memory: 16GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No
4000s L7 Requests Per Second: 425K L4 Connections Per Second: 150K Throughput L4/L7: 10/10Gb Bulk Encryption: 8Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/4 Memory: 16GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No
54 54
i2800 L7 Requests Per Second: 650K L4 Connections Per Second: 250K Throughput L4/L7: 10/10Gb Bulk Encryption: 8Gb vCMP Capable: No TurboFlex: Tier 1 Hardware Compression: 5Gb Processors/Cores: 1/2 Memory: 16GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No
i2600 L7 Requests Per Second: 350K L4 Connections Per Second: 125K Throughput L4/L7: 10/10Gb Bulk Encryption: 5Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/2 Memory: 16GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No
2200s L7 Requests Per Second: 425K L4 Connections Per Second: 150K Throughput L4/L7: 5/5Gb Bulk Encryption: 4Gb vCMP Capable: No TurboFlex: No Hardware Compression: 4Gb Processors/Cores: 1/2 Memory: 8GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No
2000s L7 Requests Per Second: 212K L4 Connections Per Second: 75K Throughput L4/L7: 5/5Gb Bulk Encryption: 4Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/2 Memory: 8GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No
You’ll find further technical details here: https://www.f5.com/pdf/products/big-ip-platforms-datasheet.pdf.
55 55
VIPRION VIPRION is F5 Networks’ high density hardware consolidation platform; the Cisco Catalyst 6500 of the BIG-IP range if you will. The four VIPRION models are modular chassis with capacity for up to eight hot-swappable blade modules, all featuring hardware compression. The larger 16 rack unit (RU) high 4800 can accommodate dual duodecad (12) core CPU full-width blades, the smaller 4RU 2400 holds single quad core CPU half-width blades. The features and benefits of these chassis are similar to those of other modular, expandable network devices; ▪
Hot-swappable blades, multiple power supplies and field replaceable components increase uptime and provide a high level of redundancy Consolidation of multiple devices in a high density form factor reduces and/or fixes hardware, environmental, operational and management costs High interface density and capacity Non-disruptive capacity scaling Easy expansion capabilities (aka vertical scaling or scale up)
▪ ▪ ▪ ▪
You don’t need to know this for the exam but, if you’re interested, the technical highlights of the VIPRION platforms include; ▪ ▪
Load is dynamically shared across all available blades All physical interfaces on all blades are fully meshed using high-speed bridge Field Programmable Gate Arrays (FPGAs) The entire system is managed through a single interface Everything from firmware, software and configuration settings is automatically duplicated from the primary blade to every other blade The SuperVIP feature allows a VIP to span multiple blades Up to 256GB RAM per blade 100Gb Ethernet interfaces Up to 160,000 2K RSA SSL transactions per second (TPS) Up to 140Gbps layer four and seven throughput per second, per blade Up to 80Gbps bulk encryption per blade Up to 5M Layer seven requests per second, per blade Up to 2.9M Layer four connections per second, per blade Up to 80Gb hardware compression per blade
▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
Here’s a quick rundown of the VIPRION chassis and blade models available at the time of publication, from most powerful to least;
56 56
57 57
4800 Chassis Rack Units: 16 Slots: 8 Power Supplies: 4 Fan Trays: 2 Supported Blades: 4450, 4340N & 4300
4480 Chassis
4450 Blade
4340N Blade
L7 Requests Per Second: 5M L4 Connections Per Second: 2.9M Throughput L4/L7: 140/140Gb Bulk Encryption: 80Gb vCMP Capable: Yes Processors/Cores: 2/12 Memory: 256GB Hard Drive(s): 1x 1.2TB SSD 10/40/100GB Interfaces: Yes/Yes/Yes
L7 Requests Per Second: 2M L4 Connections Per Second: 1.1M Throughput L4/L7: 80/40Gb Bulk Encryption: 20Gb vCMP Capable: Yes Processors/Cores: 2/6 Memory: 96GB Hard Drive(s): 1x 600GB 10/40/100GB Interfaces: Yes/Yes/No
Rack Units: 7 Slots: 4 Power Supplies: 4 Fan Trays: 1 Supported Blades: 4450, 4340N & 4300
4300 Blade L7 Requests Per Second: 2.5M L4 Connections Per Second: 1.4M Throughput L4/L7: 80/40Gb Bulk Encryption: 20Gb vCMP Capable: Yes Processors/Cores: 2/6 Memory: 48GB Hard Drive(s): 1x 600GB 10/40/100GB Interfaces: Yes/Yes/No
2400 Chassis
2200 Chassis
Rack Units: 4 Slots: 4 Power Supplies: 2 Fan Trays: 1 Supported Blades: 2250 & 2150
Rack Units: 2 Slots: 2 Power Supplies: 2 Fan Trays: 1 Supported Blades: 2250 & 2150
2250 Blade
2150 Blade
L7 Requests Per Second: 2M L4 Connections Per Second: 1M Throughput L4/L7: 155/80Gb Bulk Encryption: 36Gb vCMP Capable: Yes Processors/Cores: 1/10 Memory: 64GB Hard Drive(s): 1x 800GB SSD 10/40/100GB Interfaces: Yes/Yes/No
L7 Requests Per Second: 1M L4 Connections Per Second: 400K Throughput L4/L7: 40/18Gb Bulk Encryption: 9Gb vCMP Capable: Yes Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 1x 400GB SSD 10/40/100GB Interfaces: Yes/No/No
You’ll find further technical details here: https://www.f5.com/pdf/products/viprion-overview-ds.pdf.
58 58
Herculon The Herculon range was released in 2017 with the DDoS Hybrid Defender and SSL Orchestrator products. Despite being declared purpose-built dedicated security appliance products the hardware platforms at least are the i10800, i5800 and i2800 products. All these appliances support and rely upon TurboFlex for FPGA driven packet processing optimisations focused on the tasks they are designed to handle. The genuinely purpose-built element of these products is the simplified visual user interface and highly focused functionality. They also feature significant integration with dynamic external services such as IP Intelligence, F5’s Security Operations Center (SOC), Platform Security Team, Security Incident Response Team (SIRT) and 24x7 customer support.
BIG-IP Virtual Edition (VE) BIG-IP Virtual Edition (VE) provides a modern and lightweight alternative to purchasing hardware appliances. VE Has been available since TMOS v10.1 and supports all but one feature module, Enterprise Manager, BIG-IQ and Edge Gateway. It is available at lower cost to hardware, with a wide variety of throughput levels (up to 40G now); providing licensing flexibility and the ability to use a ‘pay as you grow’ model. Information on which products are supported on which hypervisors can be found here: https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/vesupported-hypervisor-matrix.html. You also benefit from the various advantages of using virtualisation in general and take advantage of the various methodologies, features and efficiencies of orchestration, cloud services and micro-services. Availability on Amazon Web Services (AWS) and other cloud providers allows for yet more (potential) cost control and flexibility. Of course, you lose the performance of hardware acceleration (particularly for SSL/TLS) but you don’t have to initially over-specify hardware to accommodate future growth or peaks in demand.
Keep in mind VE performance is highly dependent on the host hardware and hypervisor software used.
Potentially poor SSL/TLS performance is slowly being eliminated with recent advances and contemporary features now available with commodity Intel processors. It’s argued that network performance is a bottleneck introduced by most hypervisors and that’s probably true at present but we don’t see this being an issue for too much longer as the vendors focus on it and even now this is only an issue if your traffic profile includes a large number of short lived connections. These hypervisors are supported; ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
Citrix XenServer (v5.6 sp2 and 6.0) Microsoft Hyper-V on Windows® 2008 R2 (Fully supported in TMOS v11.3.0) VMWare vCloud Director v1.5 onwards VMWare ESX/ESXi/vSphere v4.0 onwards Linux KVM (From TMOS v11.3) Community Xen (From TMOS v11.3) OpenStack (From TMOS v12.1.1) Amazon Web Services (AWS) (From TMOS v11.4.1) Microsoft Azure (From TMOS v12.0.0) Google Cloud Platform (From TMOS v13.0.0)
59 59
BIG-IP Features not available in the Virtual Edition include; ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
CMP (until TMOS v11.3) Spanning Tree Protocols (vSwitches don’t run STP) Link Aggregation Control Protocol (LACP) – but Trunking is still available The hard-wired fail-over functionality and interface Federal Information Processing Standards (FIPS) 140-2 compliance (specific hardware is required) Interface mirroring The Serial console interface Always On Management (AOM) Baseboard Management Controller (BMC) and Intelligent Platform Management Interface (IPMI) TurboFlex Use of more than 4GB of memory (until TMOS v11.3) Use of more than 16 vCPUs Throughput of more than 1Gb (until TMOS v11.4) The Link Controller (LC) module Advanced SSL functions Advanced TCP profile settings
A free trial is available here: https://www.f5.com/trial/big-ip-trial.php.
The Different F5 Modules, Products & Services F5 Have an ever increasing and diverse set of products, modules and services. Local Traffic Manager (LTM) remains the ‘core’ product, with many other modules requiring it in order to work. However, F5’s expansion into the security market in particular, means there is now significant diversity in the product line and services unrelated to BIG-IP (such as cloud-based DDoS protection) are now a prominent part of the mix. This section provides a brief overview of nearly all the currently software and services available; we’ve already covered the hardware. You’ll note that LTM is not listed as it is discussed in considerable detail in the BIG-IP Administration chapter.
Overview These are the modules available; ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
Application Acceleration Manager (AAM) - web acceleration and WAN optimisation Access Policy Manager (APM) - access security including VPN, SSO and AAA Advanced Firewall Manager (AFM) - high performance firewall Application Visibility and Reporting (AVR)/Analytics - historical and near time statistics and metrics Application Security Manager (ASM) - web application firewall BIG-IQ - BIG-IP device, license, configuration, cloud and security management and orchestration Carrier Grade NAT (CGNAT) - highly optimised network address translation Edge Gateway - remote access including SSL VPN Enterprise Manager (EM) - BIG-IP device management DDoS Hybrid Defender - dynamic, high performance traffic analysis, DDoS identification and mitigation supported by various F5 services DNS - global server load balancing (GSLB) Link Controller (LC) - management, aggregation and monitoring of multiple internet connections (links)
▪ ▪
60 60
▪
Policy Enforcement Manager (PEM) - mobile network subscriber and traffic reporting, management and control Secure Web Gateway (SWG) - forward proxy and web access gateway used in combination with the WebSense service and APM SSL Orchestrator - high-performance decryption and encryption of outbound SSL/TLS traffic DDoS Hybrid Defender - multi-layered detection of and defense against network and application layer attacks
▪ ▪ ▪
Services ▪
IP Intelligence Service - constantly updated database of IP addresses known to be used for malicious activities MobileSafe - corporate mobile device protection and security Silverline - DoS/DDoS protection and web application firewalling Websafe - website analysis and malicious traffic traffic detection by the F5 security operations centre (SOC) Websense - URL categorisation and internet risk protection used in combination with the SWG module
▪ ▪ ▪ ▪
The following modules and products are end of life (EoL): ▪ ▪ ▪ ▪ ▪ ▪
ARX (file system load balancing) WebAccelerator (WAM) WAN Optimization Manager (WOM) Message Security Manager (MSM) Protocol Security Manager (PSM) Firepass
Access Policy Manager (APM) Module APM offers a unified, centralised access security solution for applications and networks, at typical TMM scale and performance; up to 3000 logins per second and 1m concurrent users. The module provides an increasing number of features and benefits; ▪ ▪ ▪ ▪ ▪ ▪
Dynamic, policy-based, context-aware access control Central control for diverse users and locations (remote, mobile, LAN and WLAN) Centralised, repeatable and consistent policy application Support for the CRLDP and OCSP dynamic certificate revocation protocols SSL VPN Authentication offload with support for RADIUS, LDAP, MS AD Kerberos, HTTP, RSA SecurID, OAM and TACACS+ authentication methods Single Sign On (SSO) features Java applet rewriting SAML support (from v11.3) Multi-vendor VDI support including VMware View, Citrix XenApp & XenDesktop, Microsoft RDP and Java RDP clients Enterprise Manager and BIG-IQ management High speed logging (HSL) Secure Web Gateway (SWG) integration
▪ ▪ ▪ ▪ ▪ ▪ ▪
61 61
Access Policy Manager is available as an LTM or ASM add-on module for physical and Virtual Editions and VIPRION chassis platforms. It is also available as part of the BIG-IP Edge Gateway remote access product. APM (in particular as part of the Edge Gateway product) is the successor to the FirePass product. APM and LTM or ASM are now the successor to the Edge Gateway product itself. APM also supersedes and vastly improves upon the ‘legacy’ Advanced Client Authentication (ACA) Module although it is still available.
Advanced Firewall Manager (AFM) Module Introduced in early 2013 and available with TMOS v11.3 onwards, AFM simplifies and unifies the configuration and management of the Application Delivery Firewall (ADF) related features of TMOS, TMM and LTM. All relevant features are fully integrated into TMM and therefore provide very high performance; the figures are impressive. The ADF is defined as a combination of the AFM and LTM modules. Other common TMOS, TMM and LTM features and benefits apply and are possibly even more relevant in a security context; ▪
Comprehensive DDoS mitigation features as described in the TMM and LTM chapters (and also including those previously available with the PSM) The full proxy architecture Flexible scaling options and ScaleN Full standard HA feature support Very high throughput and performance TCP Optimisations, reducing response times iRules and data and protocol manipulation Application awareness and context Function consolidation and further integration benefits when used with other modules (particularly ASM, APM and GTM) and features (such as IP Intelligence and Geolocation) AVR/Analytics integration ICSA Network Firewall Certification High speed logging (HSL) SSL Termination VPN Termination
▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
This module is available for physical and virtual editions and VIPRION chassis platforms. This LTM add-on Module is dependent on and can only be used in conjunction with LTM.
Application Acceleration Manager (AAM) Core Module The AAM Core module is available for physical and virtual editions and VIPRION chassis platforms and is included with the base LTM license. AAM Core is a subset of the combination of features previously available in the WA and WOM Modules. The Full version, detailed next, provides the full suite of features. Core includes; ▪ ▪ ▪ ▪ ▪
Symmetric Compression Dynamic Compression The SPDY Gateway Feature Bandwidth Controllers HTTP Caching
62 62
▪ ▪ ▪ ▪
HTTP Compression TCP Express OneConnect iSessions
This module is available for physical and virtual editions and VIPRION chassis platforms. This Module is dependent on and can only be used in conjunction with LTM.
Application Acceleration Manager (AAM) Full Module The full AAM module is available for physical and virtual editions and VIPRION chassis platforms. A combination of the previously separately available WA and WOM Modules, AAM provides the full set of features from those products. Features over and above the Core product include; Intelligent Browser Referencing (IBR) – increasing browser cache expiration dates (and other features) to reduce conditional GET requests Image Optimisation – reducing image size to something appropriate to the requesting device Content Reordering – modifying the order of served content to optimise page load times Dynamic caching/deduplication Multi-protocol optimisations (HTTP, FTP, MAPI, UDP) Forward Error Correction (FEC) – provides recovery of lost packets to avoid retransmission and increase throughput on poor networks or links Parking Lot – GET request queuing for expired cache objects MultiConnect – performs client-side link modifications, which, along with additional DNS entries, ‘force’ browsers to open additional connections to a site PDF Dynamic Linearisation A Performance Dashboard Symmetric and Asymmetric deployment options BIG-IP APM, ASM, and AAM layering iApps support Enterprise Manager and BIG-IQ management
▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
This module is available for physical and virtual editions and VIPRION chassis platforms. This Module is dependent on and can only be used in conjunction with LTM.
Application Security Manager (ASM) Module ASM (initially based on technology gained through the 2004 acquisition of MagniFire Websystems) provides advanced web application aware ‘firewall’ (WAF) functionality. Unlike most modules it does not run within TMM but the HMS instead and therefore doesn’t benefit directly from typical TMM performance and scale. It provides protection against a wide range of attacks and attack vectors including;
63 63
▪ ▪
Web scraping (the automatic (mass) extraction of data from a website or sites) SQL Injection (execution of SQL code, ‘injected’ via a website or service’s user input methods (such as a form field), on the database backend used by that site’s web servers) Layer seven (aka Application Layer) DoS and DDoS ((distributed) denial of service attacks aimed at application functions) Cross-site scripting (aka XSS) (malicious browser code injection and trusted site permission hijacking) JSON payload attacks FTP Application attacks SMTP Application attacks XML Application attacks
▪ ▪ ▪ ▪ ▪ ▪
Other features include; ▪ ▪
Vulnerability assessment and mitigation Integration with vulnerability scanners from Cenzic Hailstorm, IBM Rational AppScan, QualysGuard Web Application Scanning and WhiteHat Sentinel Session awareness White and black listing Regulatory compliance reporting (PCI for example) An automatic policy-building engine Enterprise Manager and BIG-IQ management WebSockets support
▪ ▪ ▪ ▪ ▪ ▪
Application Security Manager is available on a selection of BIG-IP application switches, as a Virtual Edition and as an LTM add-on module for physical and virtual editions and VIPRION chassis platforms.
Application Visibility and Reporting (AVR) Commonly referred to as simply Analytics or BIG-IP Analytics, this Module provides detailed historical and near-time HTTP and TCP/IP related statistics for iApps applications, Virtual Servers, Pool Members, URLs and even specific countries, allowing for in-depth traffic analysis. The available metrics and counters include transactions per second, server latency, page load time, request and response throughput, sessions, response codes, user agents, HTTP methods, countries, and IP addresses. Fine grained filters can be used to limit what is recorded, full transaction and data capture is possible and alerts (via SNMP trap, email or syslog) can be configured based on user defined thresholds. Remote logging of statistics data is also supported but unfortunately data cannot be collect via SNMP polling or iControl. IPv6 is fully supported from v11.1. Enterprise Manager can be used as a centralised Analytics reporting tool if required. Analytics is available as an LTM add-on feature for physical and virtual editions and VIPRION chassis platforms and is included with the base LTM license. This wasn’t always the case. This module is dependent on and can only be used in conjunction with LTM and needs to be provisioned as Nominal.
64 64
BIG-IQ Centralised Management Product Planned as the eventual successor to Enterprise Manager, BIG-IQ is a management and orchestration platform with considerable scope. As with any centralised management system, the main goal is to reduce operational costs, reduce administrative overheads and improve scalability. Currently BIG-IQ has four main components each focused on specific functional areas; Access, Devices, Traffic and Security. The following modules and services are supported; ▪ ▪ ▪ ▪ ▪ ▪
AFM APM ASM LTM MobileSafe WebSafe
General features include; ▪ ▪ ▪ ▪ ▪
A comprehensive set of RESTful APIs So-called ‘single pane of glass’ management Centralised audit and control License management of BIG-IP Virtual Editions Role based access control (RBAC)
Here’s a brief overview of each component; Access Management of up to 100 APM devices including; ▪ ▪ ▪
Policy verification, staging, auditing and monitoring Multi-device policy push Extensive reporting
Devices Centralised management of up to 200 physical, virtual or vCMP BIG-IP appliances, including; ▪ ▪ ▪ ▪ ▪ ▪
TMOS Software deployment Remote deployment of appliances hosted within VMware NSX, Cisco APIC, OpenStack or AWS Centralised license management of up to 5000 unmanaged devices for highly flexible provisioning Status and usage reporting including SSL certificate status Device discovery and monitoring Configuration backup and restore
65 65
Traffic Management and real-time monitoring of LTM configurations and objects including; ▪ ▪ ▪ ▪ ▪
RBAC For pool member and virtual server control Centralised logging and audit trails Configuration templating, staging and scheduling Virtual server cloning Health and statistics monitoring
Security Centralised AFM and ASM management including; ▪ ▪ ▪ ▪ ▪ ▪
RBAC For security instances Policy verification, staging, auditing and monitoring Multi-device policy push Rule monitoring, reporting and prioritisation Configuration snapshots Reporting and security alerts, including for WebSafe and MobileSafe
BIG-IQ is available as a standalone appliance and a virtual edition. It supports and can manage all hardware and virtual appliances running TMOS v11.4 and above including VIPRION.
BIG-IQ Cloud & Orchestration Product Orchestration of BIG-IP deployments in public and private clouds, with integration support for; ▪ ▪ ▪ ▪
Cisco APIC Amazon Web Services (AWS) OpenStack VMware environments including NSX
Additional features include; ▪ ▪ ▪ ▪ ▪
Automatic provisioning Dynamic application server ‘bursting’ Tenant awareness and service catalogue provision iApps management, provision and templating Health and performance monitoring
Carrier Grade NAT (CGNAT) Module Introduced with v11.3 this Service Provider focused module provides highly optimised, available and scalable IPv4 and IPv6 Network Address Translation (NAT) and related features such as NAT44, NAT64, DNS64, DS-Lite, endpoint independent mapping, endpoint independent filtering and deterministic NAT. A number of the Module’s features rely on existing TMOS or LTM features such as HA, High-speed Logging (HSL), the full proxy architecture for translating or migrating between IPv4 and IPv6 objects and TCP Express. CGNAT is available as an LTM add-on module for physical and virtual editions and VIPRION chassis platforms.
66 66
Edge Gateway Product Edge Gateway was available as a virtual edition and on a selection of BIG-IP application switches but not on VIPRION chassis platforms. It is a combination of the APM, WA and WOM modules, providing secure remote access (RAS) gateway features such as; ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
ICSA Certified SSL VPN Clientless access End point validation and security and access policy enforcement Single Sign On (SSO) and credential caching Multi-factor authentication Symmetric acceleration (if the client is using the Edge Client software) Wide AAA protocol support Wide remote access protocol support (Citrix, RDP, ActiveSync etc.) IPv6 Support Enterprise Manager Management
Enterprise Manager (EM) Product I have to admit that large scale management and monitoring bore me rigid; I blame this on the incumbent vendors happy to milk the cash cow rather than innovate and please their customers. I’ve actually used Enterprise Manager (v2.x) and whilst I’m unlikely to describe it as exciting it’s certainly an improvement over other so-called solutions I’ve seen and it is very focused. Enterprise Manager has numerous features and benefits; ▪ ▪
Aids with scaling up Improves device, application and service visibility and therefore troubleshooting capabilities and capacity planning and forecasting accuracy, as with other centralised management solutions Reduces cost and complexity Automates common tasks including device configuration backups, ASM policy deployments and reporting Custom Alerts and thresholds Manages and eases; o Device inventory tasks o Service contract monitoring o SSL TPS monitoring and certificate management Centralised configuration management including comprehensive search Allows for the use of configuration templates Granular (distributed) configuration management Uses a local or remote MySQL database allowing enterprise integration and high compatibility with various DB management and reporting tools Physical and virtual edition support for LTM, GTM, ASM, LC, AAM, APM and Edge Gateway
▪ ▪ ▪ ▪
▪ ▪ ▪ ▪ ▪
EM is available as a standalone appliance and a virtual edition. It supports and can manage all hardware appliances including VIPRION and Virtual Editions.
EM is very likely to be phased out and replaced by the BIG-IQ Device product.
DNS (formerly Global Traffic Manager (GTM)) Module Global Traffic Manager is a TMOS Module and is part of the core, long standing F5 product set. GTM primarily provides DNS based ‘global’ server load balancing (GSLB) for IPv4 and IPv6 (inter-Data Centre) rather than LTM’s
67 67
intended intra-Data Centre operation). In order to make this Module a more attractive proposition, its feature set has been significantly expanded since 2012 it now runs in TMM natively, rather than within the HMS. The considerable list of features and benefits include; ▪ ▪
Global server load balancing (using DNS to direct traffic between multiple DCs) Dynamic ratio load balancing (load balancing based on weights derived from Node metrics such as CPU and memory usage) Wide area persistence (DNS response persistence, a same client will get the same response and load balancing will be ignored unless/until a timeout is reached) Geographic load balancing (load balancing a client to its geographically closest DC) Advanced health monitoring QoS Awareness DNS Security Extensions (DNSSEC) support (including rate limiting and centralised key management) Up to 10 million DNS responses per second using the VIPRION platform DNS Caching DNS Server consolidation and offload DNS DDoS and Local DNS (LDNS) cache poisoning protection DNS server load balancing (similar to LTM server load balancing) Not BIND based and therefore not subject to BIND security vulnerabilities Protocol inspection and validation DNS record type ACLs IP Anycast support IPv6 support
▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
GTM is available as a standalone appliance, a virtual edition and an LTM add-on module for physical and Virtual Editions and on VIPRION chassis platforms. DNS Services are also available as an LTM add-on Feature Set.
IP Intelligence Service This subscription-based service is designed to be used in conjunction with ASM or LTM to block malicious traffic at the very edge of your network, thus increasing efficiency by avoiding processing overheads further within your infrastructure. The service provides a constantly updated database of IP addresses known to be used in relation to activities such as; ▪ ▪ ▪ ▪ ▪
Phishing sites and other fraudulent activity DoS, DDoS, SYN flood and other anomalous traffic attacks Botnet command and control servers and infected zombie machines Proxy and anonymisation services Probes, host scans, domain scans and password brute force attacks
This database can then be referenced by iRules to allow for automated blocking, allowing for context aware policy decisions.
68 68
Link Controller Product (& Module) LC Provides features to manage, aggregate and monitor multiple ISP internet connections (links) and controls the traffic flow across them, based on multiple dynamic factors and user specified criteria. Traffic optimisation and prioritisation features are also available to improve application performance. TCPExpress, IPv6, iRules and SNAT are fully supported and there is an optional compression feature. BIG-IP Link Controller is available as a standalone version and as a LTM add-on module for BIG-IP application switches.
MobileSafe Product & Service This enterprise level product aims to protect and secure corporate mobile devices from various threats and ensure the company, it’s networks and its data are protected. The software is available for iOS and Android devices, with management achieved through a web portal run by the F5 Security Operations Center (SOC). Features include; ▪
Mitigates against various mobile device threats including; application tampering, unpatched operating systems, keyloggers, certificate forging and DNS spoofing Strong validation of SSL certificates Application-level encryption Malware detection Rooted and jail-broken device detection
▪ ▪ ▪ ▪
Policy Enforcement Manager (PEM) Module Available from TMOS v11.3, PEM provides mobile network subscriber and traffic reporting, management and control. The module provides a host of features and benefits, presumably based on the assets of the Traffix Systems acquisition; ▪ ▪
Comprehensive analytics including per session and per application statistics L7 Intelligent traffic steering (to appropriate caches, CDNs, proxies) and bandwidth control to reduce network congestion and increase performance Traffic classification (p2p, VoIP, Web, streaming) Deep packet inspection Rate limiting, QoS, CoS and fair usage policy enforcement Charging system integration (PCRF, OCS) 3GPP standards based Subscriber awareness (IP address, IMSI, RADIUS data, Gx and/or mobile tower) and application context Function consolidation and further integration benefits when used with other modules (particularly CGNAT and AFM) Very high throughput and performance TCP Optimisations, reducing response times iRules and data and protocol manipulation Flexible scaling options and ScaleN Full standard HA feature support High speed logging (HSL)
▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
Policy Enforcement Manager is available only as a standalone appliance on high-end physical appliance a virtual edition and VIPRION chassis platforms.
69 69
Secure Web Gateway (SWG) Module & Websense Cloud-based Service SWG Provides control, security and management of inbound and outbound user driven web traffic; it’s effectively a secure internet proxy, or web access gateway as F5 like to call it. The module itself provides integration between Access Policy Manager and Cloud-based Websense security services and updates. Combined, these components offer; URL categorisation and filtering ▪ ▪ ▪ ▪ ▪ ▪ ▪
User tracking Malware protection Endpoint integrity checking Policy-based blocking Real-time threat intelligence Detailed logging Splunk reporting
Silverline Cloud-based Service The Silverline service (Software as a Service or SaaS) delivers two core internet related security functions; DDoS protection and web application firewalling. Rather than implement these yourself on-site, you can simply transparently route your inbound traffic through the F5 SOC and let them do the hard work for you. The services are as follows; ▪
F5 Silverline DDoS Protection - typical TMOS supported DDoS protection and features, along with the resources and bandwidth required to sustain a high volume attack.
▪
F5 Silverline Web Application Firewall - ASM features (see the earlier section), along with the processing resources and bandwidth required to mitigate attacks.
WebSafe Service & Module The WebSafe service provides protection for the users and customers using your website properties, as well as the sites themselves. Traffic is transparently passed through the F5 SOC where it is analyzed and malicious traffic dropped before it reaches your site. Additionally, the BIG-IP module component of this service, the Fraud Protection Service (FPS) provides additional features and protections at the local, Virtual Server level. This is fully integrated into the GUI from TMOS v11.6. The protection and features provided by this combination include; ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
Malware prevention Phishing and pharming attack mitigation Fraud detection and prevention Application-level encryption Transaction monitoring, analysis and integrity checking Device and behavior analysis Integration with MobileSafe Incident reporting Real-time alerts dashboard
70 70
DDoS Hybrid Defender (Herculon) A sophisticated, high performance and throughput security appliance, software and service bundle designed to defend against multi-vector network and application attacks. Only available in physical form on i10800, i5800 and i2800 appliances which provide TurboFlex FPGA driven performance enhancements and acceleration. Herculon products have a unique, simplified interface and configuration requirements. Features include; Backed by F5’s Security Operations Center (SOC), Platform Security Team, Security Incident Response Team (SIRT) and 24x7 customer support Full SSL decryption Anti-bot capabilities Advanced detection methods Line rate capabilities Cloud-based volumetric attack prevention Traffic baselining and automatic configuration Multiple attack mitigation mechanisms Threat intelligence Granular reporting and visibility
▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
SSL Orchestrator (Herculon) A security appliance, designed to provide security devices with visibility of SSL/TLS traffic. Since more organisations and companies are transitioning over to SSL/TLS, this will render existing security devices (such as IPS, Anti-Virus etc.) useless if they cannot decrypt and review the payload of the packets. If you install the SSL Orchestrator in front of your existing security devices, you can decrypt the traffic, create policy-based flows and steer unencrypted traffic to your security devices making them useful again. Only available in physical form on i10800, i5800 and i2800 appliances which provide TurboFlex FPGA driven performance enhancements and acceleration resulting in very high performance and throughput. Herculon products have a unique, simplified interface and configuration requirements. Features include; Backed by F5’s Security Operations Center (SOC), Platform Security Team, Security Incident Response Team (SIRT) and 24x7 customer support Inline layer 3, inline layer 2, ICAP services and receive only modes Reverse and forward proxy operation Dynamic service chaining, monitoring and load balancing Context and identification services including geo-location, IP reputation and URL categorisation
▪ ▪ ▪ ▪ ▪
Free and/or Open Source Products F5 publish and maintain a number of open source software packages and resources to help their customers manage their appliances (virtual or physical), modules and application services and integrate them into their wider environment as well as automate their deployment and administration. For anything involving source code you’ll probably find a repository for it on the main F5 GitHub company page here: https://github.com/F5Networks, or, for more informal work on the DevCentral Github page here: https://github.com/f5devcentral. Here’s a quick overview of the most popular or significant projects you’ll find there and also what’s available elsewhere.
71 71
Bigsuds Bigsuds is a Python library designed to make it easy to create programs and automate operations on F5 devices utilising the ‘legacy’ iControl SOAP API. https://github.com/F5Networks/bigsuds.
iControl REST Software Development Kit (F5-SDK) This is the equivalent Python library designed to make it easy to create programs and automate operations on F5 devices utilising the more recent iControl REST API. https://github.com/F5Networks/f5-common-python
Ansible Ansible is a popular and simple Python-based IT automation engine. Over 20 LTM and GTM related modules are available to support automated configuration of device settings, from NTP to SNAT Pools. You can find out more here: https://www.ansible.com/ansible-f5 and the latest list of stable modules (for download if required) is here: https://github.com/ansible/ansible/tree/devel/lib/ansible/modules/network/f5. Most of the modules required either the F5-SDK or bigsuds to be installed on the host running Ansible.
Containers F5 have released a number of container based applications to allow for BIG-IP product integration with container orchestration systems. These include the F5 BIG-IP Controller for Kubernetes, Cloud Foundry and Marathon. F5 have also developed the container-based Application Services Proxy (ASP) which acts as a proxy and load balancer for distributed applications running in containerised environments. You’ll find all of these container images on Docker Hub here: https://hub.docker.com/u/f5networks/ and can find out more about the ASP here: http://clouddocs.f5.com/products/asp/v1.0/.
OpenStack OpenStack is a set of free and open-source software tools that provide a (cloud) computing platform typically deployed as infrastructure-as-a-service (IaaS). It is used to build, operate and manage pools of compute, storage, and networking resources upon which applications and services are run. F5 provide a fair number of drivers, plugins and agents to allow for BIG-IP product integration with various OpenStack components and to enable orchestration abilities.
72 72
Cloud - AWS F5 offer supported and experimental CloudFormation templates to ease deployment of Virtual Edition EC2 instances AWS in a declarative and repeatable manner. CloudFormation is AWS proprietary and specific, unlike Terraform which is detailed next. You can find the templates here: https://github.com/F5Networks/f5-aws-cloudformation. Terraform provides the same services as CloudFormation but can be used with the top three cloud platforms and many other platforms, known as providers. You can find configurations for AWS, Azure and Google Cloud Platform (GCP) providers and additional resources here: https://github.com/f5devcentral/f5-terraform.
Cloud - Azure You can find F5 formulated Azure ARM templates here: https://github.com/F5Networks/f5-azure-arm-templates. You’ll find Terraform Azure provider configurations and many others as well as additional resources here: https://github.com/f5devcentral/f5-terraform.
Cloud - GCP You can find F5 formulated GCP GDM templates here: https://github.com/F5Networks/f5-google-gdm-templates. You’ll find Terraform GCP provider configurations and many others as well as additional resources here: https://github.com/f5devcentral/f5-terraform.
The Full Application Proxy The first release of TMOS, v9 in 2005 introduced the Full Application Proxy; providing a significant improvement in functionality over the prior Packet Based Proxy architecture used in previous products. The Packet Based Proxy is still available and can still be the most desirable, high performance solution where only L2-L4 functions are required. The Full Application Proxy architecture is just that; it functions as a proxy that fully and completely separates the client and server sides of a connection. There are in fact two connections; the client side connection is terminated on the proxy (the load balancer) and a new, separate connection is established to the server. The proxy acts in the role of server to the client and client to the real server. There are two related connection table entries too; one for client side, one for server side. Each can have independent parameters applied, such as idle timeouts, buffers, MTU, window size and so on. The Application Delivery Controller offers many different functions including: ▪
Host Monitoring - The BIG-IP system is constantly monitoring the status of each ‘real’ server host. In the upcoming diagram, the offline server (server 2) will not be used or considered in a load balancing decision seeing its monitor is failing.
▪
Load Balancing - The BIG-IP system will load balance the traffic and make a decision on which real server will receive each request. In our upcoming diagram we are using Round Robin as the load balancing algorithm.
The following diagram demonstrates this full proxy functionality in respect to the TCP/IP connections;
73 73
1. 2. 3.
4.
The client establishes a TCP connection to a virtual IP address hosted on the BIG-IP system and sends a HTTP GET request. The client TCP connection is terminated on the BIG-IP system. Once the client connection has been established, the BIG-IP system will make a load balancing decision and choose one of the three servers. Seeing that Server 2 is currently being marked as offline, it will choose between Server 1 and Server 3. When it has chosen a ‘real’ server, the BIG-IP system will establish a new TCP connection and send the HTTP GET request to the ‘real’ server. The BIG-IP system’s TCP connections will be terminated on the ‘real’ server and each of the client’s GET requests will be processed and responded to.
This happens for each new connection being sent to the BIG-IP system when using the Full Proxy architecture and it allows for a huge number of features and functions to be dynamically applied to each connection separately, as well as the inspection, manipulation and modification of application layer data. This architecture provides the foundation for many of the advanced features described in this book (as well as many, many more that are not) such as; iRules (working above OSI Model layer four), advanced Persistence methods, SSL offload, TCP Optimisations and HTTP Compression, Caching and Pipelining.
74 74
If you don’t actually require any of these features or the benefits of two independent connections, then using the Packet Based Proxy is probably preferable as it is simpler and will provide even higher performance. Note in some documentation and other materials published by F5 the Full Application Proxy is sometimes referred to as the Fast Application Proxy.
The Packet Based FastL4 Proxy A Packet Based Proxy architecture is what was employed in the first generation of load balancers and generally only operates up to OSI Model layer four, the transport layer. Sometimes referred to as a Half Proxy, there is only a single connection which the load balancer modifies the TCP/IP parameters of, without the client or server being aware. The half proxy does not act as either a client or server from a TCP/IP perspective. The actual connection state and flow of packets is generally not controlled in any way. The following diagram demonstrates this half proxy functionality in respect to the TCP/IP connection;
75 75
1. 2. 3.
Client establishes a TCP connection to a virtual IP address (VIP) hosted on the Application Delivery Controller (ADC) and sends a HTTP GET request. The client TCP connection are NOT terminated on the ADC. Only the destination IP address and TCP/IP parameters. The client TCP connections is terminated by the relevant real server and each client GET request is processed and responded to.
Unlike with the Full Application Proxy, the advanced features described in this book (as well as many, many more that are not) such as; iRules (working above OSI Model layer four), advanced Persistence methods, SSL offload, TCP Optimisations and HTTP Compression, Caching and Pipelining are not available with the Packet Based Proxy. Even though a Packet Based Proxy operates up to layer four, the Full Application Proxy still provides some advantages over it even at this layer, due to its use of separate client and server-side connections and the resulting ability to modify and control separate parameters for each.
The lines between the half and full proxy can sometimes get rather blurry as one obviously evolved from the other resulting in features that can be common to both. In the most simplistic terms, the half proxy does not act as a TCP/IP client or server; it operates transparently with the single connection established between the real client and server. The full proxy acts as a TCP/IP server to the client and client to the real server; it terminates the first and initiates the second and thus there are two independent connections.
OneConnect Also known as Connection Pooling, the OneConnect feature minimises the number of server-side connections by reusing previously established connections for subsequent client requests. Rather than closing an idle connection to a real server (Pool Member) and reopening a new one for the next client request that gets load balanced to that server, the connection is maintained and re-used, within user configurable limits. This is demonstrated in the following diagram.
76 76
1. 2. 3.
77 77
Client 1 establishes a TCP connection to a virtual IP address hosted on the BIG-IP system and sends a HTTP GET request. The BIG-IP system establishes a new TCP connection to the end server and sends the HTTP GET request. When a new request arrive at the BIG-IP from for instance Client 3 or Client 4, it will load balance the request to an end-server. Once the load balancing algorithm has chosen an end-server, the BIG-IP will review its own connection table to see if it contains any stale TCP session to the end-server which is currently not being used by a client. If it finds one, it will use that TCP session and directly send the GET request to the end-server.
2. The TMOS Administrator Exam The TMOS Administrator exam is the second within the F5 Professional Certification Program and is based on TMOS v11.4. Passing this exam is a prerequisite for all further certifications and exams. Passing the Application Delivery Fundamentals 101 exam is a prerequisite to taking this one. In this chapter we’ll discuss the wider Professional Certification Program and detail additional resources that you might find useful as you work through this guide and plan for the exam.
The F5 Professional Certification Program The F5 Professional Certification Program (F5-PCP), as it is now known, has been undergoing radical transformation since the second half of 2012. Prior to this transformation, there were a limited set of exam subjects at two certification levels. With the new program there are now three levels of certification and four levels of exams or labs (there’s a difference as the first level exam does not result in any certification or credential award.) All four of the exam levels (three certification levels) are shown in the following table; Exam Level 101
Exam Name Application Delivery Fundamentals
Certification Level None
201
TMOS Administration
C1: F5 Certified BIG-IP Administrator (F5-CA)
301a
LTM Specialist: Architect, Set-up & Deploy
None
301b 302
LTM Specialist: Maintain & Troubleshoot BIG-IP DNS Specialist
C2: F5 Certified Technology Specialist (F5-CTS) LTM C2: F5 Certified Technology Specialist (F5-CTS) BIG-IP DNS
303
ASM Specialist
C2: F5 Certified Technology Specialist (F5-CTS) ASM
304
APM Specialist
C2: F5 Certified Technology Specialist (F5-CTS) APM
78 78
Skillset ▪ Basic network, protocol ▪ ADC concepts and operation ▪ TMOS architecture and modules ▪ Basic troubleshooting ▪ Day to day maintenance and management of devices and configuration objects ▪ Architect ▪ Setup ▪ Deploy ▪ Maintain ▪ Troubleshoot ▪ DNS administration ▪ GSLB, ▪ Multiple data centres ▪ Configuration and administration ▪ Web application security and operation ▪ Configuration ▪ Administration ▪ RAS, AAA & SSL VPN configuration ▪ Administration
401
Security Solution Expert
C3: F5 Certified Solution Expert (F5-CSE, Security)
402
Cloud Solution Expert
C3: F5 Certified Solution Expert (F5-CSE, Cloud)
▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
LTM GTM ASM APM AFM BIG-IQ modules IP Intelligence (IPI), WebSafe and MobileSafe LTM GTM BIG-IP Cloud Edition Automation Cloud Platforms OpenStack RedHat® OpenShift Kubernetes© F5 Container Connector F5 Application Connector RestAPI
In order to achieve the certification F5 Certified Technology Specialist (F5-CTS) LTM you will need to pass both the 301a and 301b. As you’ll know, the first exam doesn’t result in a certification; this is designed to encourage greater candidate commitment and deter ‘casual’ candidates who might normally take an ‘easy’ entry level exam simply to bulk out their CV. This, along with the wider network, protocol and application knowledge requirements increase the value and quality of the program and hopefully reduce the likelihood of accelerated training programs being formulated. Further information on the PCP can be found here: https://f5.com/certification.
Why Become Certified? Before embarking on any certification path, this is a worthwhile question to ask of yourself. There are many benefits to certification (and debate on the entire subject) but most of them must be qualified based on factors such as; which vendor, the program’s reputation, the employment market, employer attitudes, certification relevance and more. Remember that most vendors will make money from a certification program regardless of its benefits or value to you. Also keep in mind that a certification doesn’t prove you are competent. Here is our view on the typical benefits; ▪
Certification involves study, learning and the acquisition of knowledge – these are all good things but remember you’ll learn and benefit more if you go for something that isn’t an everyday part of your job. It’s still of benefit to certify in skills you already possess, and this will help fill any gaps in your knowledge, but studying something outside of your everyday will be more rewarding and hopefully open more avenues of opportunity in the future, especially if you chose something in demand or likely to be soon.
▪
Certification will improve your understanding, knowledge and self-confidence.
79 79
▪
Certification proves to others you can study, read, take notes, work alone, follow through, do research and organise yourself in general – assuming it hasn’t taken too long to achieve and isn’t considered an easy certification.
▪
Certification can help you keep your job, gain a pay rise or a promotion although what you choose, and its perceived value will be critical here.
▪
Certification gives you an advantage over other candidates without it although, again, what you choose, and its perceived value will be critical.
Choosing a Certification All of the benefits detailed previously will vary in ‘weight’ depending on the certification program (or programs) you chose to embark on. When deciding, you should consider the following; ▪
Forget the vendor; will you learn something useful about technology, skills that you can use even if the vendor went out of business? Does the certification carry any weight in the market, how is it perceived by employers/hirers? Do too many people have it? Is this certification alone good enough to achieve your goals? Is there demand for the certified skills? What benefits of certification does the vendor provide, if any?
▪ ▪ ▪ ▪ ▪
Getting Started If you’ve passed the Application Delivery Fundamentals 101 exam, which is a prerequisite to this one, you should already know this but in case you need a reminder, we’ll repeat it here. You should take a quick look at the certification pages on the F5 website that can be found here: https://f5.com/certification. A getting started page can be found here: K93611383: F5 certification | Introduction and very useful program policies can be found here: K90101564: F5 certification | Policies and program details. Along with the overview provided at the start of this chapter this should tell you all you need to know about the certification program. You should already have one but if not, register for an F5.com account here: https://login.f5.com/resource/registerEmail.jsp which will give you access to a number of resources exclusive to registered users. Equally, a DevCentral account will also be very useful and provides access to F5’s community support and documentation site. Register here: https://devcentral.f5.com/register. You can also follow @F5Certified on Twitter and join the very active LinkedIn group here: http://www.linkedin.com/groups?home=&gid=85832.
80 80
Taking Exams As you should know, you must register with the F5 PCP here: http://certification.f5.com/ in order to be eligible to take this or any other exam and book it through Pearson VUE. The number of questions, time allowed, and passing score are provided when you book the exam. You can also find the passing score here: K29900360: F5 certification | Exams and study materials. Exams are typically $135 USD in the Americas, $145 USD in EMEA, and $155 USD in APAC and normally last at least 90 minutes. You must wait at least 15 days before you can retake a failed exam the first time, 30 days the second time, 45 days the third time and finally a full year the fourth time. You have to wait a full year before you can attempt an exam for the fifth time to decrease the possibility of cheating and question recording. The extended delay ensures you face a rewritten exam as exams are updated every two years. Certifications expire after two years; re-certifying your highest certification achieved recertifies all lower level certifications, as is the norm for most certification programs. Note that F5 Training courses only cover the F5-specific elements of each exam as you are expected to already have (or gain) knowledge and experience of general networking and network and application protocols. Don’t worry, this book, of course, covers everything.
Additional Resources The following will be of particular interest to students studying for this exam;
Practice Exams F5 now offer official practice exams to help you accurately predict your likely performance on the live, production exams. The practice exams are designed to mimic the real tests which means you will receive 80 questions to answer within 90 minutes. As of this book’s writing the exams cost $25 for a single test which needs to be attempted within 30 days or $40 for two tests that need to be attempted within 90 days. To take a practice test visit https://portal-v5.examstudio.com/Default.aspx?id=20882 and log on using your candidate credentials.
Additional Study Material Official study guides and exam descriptions can be found in this AskF5 article: K29900360: F5 certification | Exams and study materials.
AskF5 Available at: https://support.f5.com/ (previously https://ask.f5.com/ which still works too) AskF5 is the F5 Networks technical knowledge base and self-service online support site – no account is required. AskF5 provides knowledge base articles related to; support, known issues, solutions, best practises and security advisories. You can also obtain release notes, manuals and guides.
81 81
DevCentral F5 DevCentral (DC), available here: https://devcentral.f5.com/ is a community website featuring forums, blogs, tech tips, wikis, code sharing for iRules, iControl, iApps templates, tutorials and more. An account is required to access some content or contribute. Created as CodeShare in 2003 by Joe Pruitt, the architect of iControl (Joe is still with the company) DevCentral now has over 250,000 members in 191 countries. Membership grew over 25% in 2012 alone.
F5 University Free, self-paced web-based training related to basic technologies and concepts, changes in new software versions and basic LTM configuration are available via the F5 University available here: https://university.f5.com/. An F5 support account is required to access the site. You can also gain lab access to an F5 running TMOS v11.4.0 (plus two Linux hosts) for two hours at a time; an invaluable tool for those without access to their own device.
Exam Blueprints These can be found on the F5.com website and in the Downloads section of the CMS and provide a comprehensive list of the exam objectives and the skills and knowledge required to pass the exam. The blueprint for this exam can be found here: http://www.f5.com/pdf/certification/exams/F5_blueprinttemplate_TMOS_v2.pdf.
BIG-IP LTM Virtual Edition (VE) Trial An LTM VE 90 Day Trial can be obtained from here: https://www.f5.com/trial/big-ip-trial.php - you’ll need an F5.com account to obtain it. You’ve probably already got one right and if not, it’ll be useful going forward. Unfortunately, the trial is for TMOS v12.1 which is slightly ahead of the TMOS version the exam is based upon.
BIG-IP VE Lab Edition You can now purchase the latest BIG-IP VE Lab Edition for the very, very cheap price of $95 (it used to be around $2000). It’s limited to 10Mb total throughput but includes LTM, GTM (DNS), AAM, AFM, APM (10 user limit), ASM. It’s an incredibly cost effective tool for getting hands on experience using F5’s products, lab testing and building an understanding of how things work and interact. Unlike with the 101 exam, this one does require some practical knowledge of actually using or configuring BIG-IP. You can request a license here: https://www.f5.com/trial/.
82 82
BIG-IP VE on Amazon Web Services (AWS) It takes more time, effort and research to get started but I can highly recommend AWS as an alternative to the VE Trial and Lab Editions, especially if you don’t have a lab server or powerful PC/laptop with the right software. As an added benefit you also get to learn about and gain practical experience with AWS (and the cloud) itself. The recently introduced Free Usage Tier (details here: http://aws.amazon.com/free/) makes building a small, private lab environment very cheap. You can create a Virtual Private Cloud (VPC) and a number of EC2 Linux server ‘micro instances’ for purposes such as running a web server or other services, all for free. Then you just need to add an LTM VE EC2 instance. It isn’t free, but you can create and run one, charged hourly, with any of the Good, Better or Best license bundles, at a very low cost. Those costs are constantly changing and depend on a number of factors (including taxes) but to give you an example, I can run a VE with the Good license for around $0.50 an hour. You only need to run your instances (and thus only get charged) as and when you need to. Of course, there is a steep learning curve to overcome but this is a very worthwhile option if your budget is limited and you have no other way to gain access to a device.
Other Clouds BIG-IP VE is also now available on Microsoft® Azure™ and Google© Cloud Platform™. All the benefits detailed above for AWS generally apply although it could be debated that as AWS is the most prevalent and popular cloud provider, any cloud related skills you gain are potentially more valuable.
83 83
3. Building Your Own Lab Environment A practical understanding of TMOS and LTM is an essential ingredient in any exam-passing formula. Whilst most readers of this book will hopefully have practical experience of F5 administration in a live, production environment, it’s rare any form of experimentation is possible. To that end, a so-called ‘lab’ that allows for this and more, without risk, is a must.
Fel! Bok There are a multitude of services and products that a useful lab can be created with and obviously we can’t cover them mär all. In this book we’ll only cover one that is free for non-commercial use and does not require any aditional expensive ket equipment. The lab environment should have no problem running on your PC or laptop as long as the following requirements are fulfilled: är inte CPU: ▪ The host system must have a 64-bit x86 CPU with 1.3 GHz or faster core speed. Multiprocessor systems are defi supported. nier ▪ An AMD CPU that has AMD-V support ▪ An Intel CPU that has VT-x support at. Memory: ▪ To run all of the machines for the lab you will need 4GB of memory. Disk: ▪
To run all of the machines for the lab you will need 30GB worth of diskspace.
The virtual machines are configured with more than 30GB but they are thin provisioned and will only occupy more diskspace when the virtual machines needs it.
Obtaining the Different Components to Build Your Lab In order to make this easier for you as the reader to build your own lab environment, we have created a webpage that contains mirrors, instructions and links to each component necessary to build your lab environment. This web page is located at: https://www.f5books.eu/building-your-own-lab/. Please visit this site to download all necessary components before you start building your own lab environment.
VMware Workstation Player™ The Hypervisor used in these lab exercises is VMware Workstation Player. The reason we have used this hypervisor instead of other open-source alternatives is simply because the F5 Virtual Machine is not fully compliant with some of the open-source hypervisors currently available. To obtain your VMware Workstation Player go to http://www.vmware.com/products/player/playerpro-evaluation.html This hypervisor is free of charge for non-commercial use and will work natively with the BIG-IP VE.
84 84
BIG-IP VE Trial Evaluation Key First you will have to obtain a BIG-IP VE 90 Day Trial Evaluation Key by filling out a trial evaluation form located at: https://downloads.f5.com/trial/secure/generate-eval-key.php?product=ltmve. We also keep an updated instruction and set of links on: https://www.f5books.eu/building-your-own-lab/. In order to fill out the form you will first have to register for a free F5 account. If you already have one, you simply have to log in and follow the instructions. When done, you should receive an email with the Base Registration Keys, therefore, verify that the email address assigned to your account is correct. The email will also contain links to download the ESXi image but ignore this as we require a specific version for our lab exercises.
Downloading the BIG-IP VE Machine After you have received your base registration key, download your BIG-IP® Virtual Edition (VE) from F5. In order to give you the correct user experience, we require you to download BIG-IP version 12.1.2. For instructions on how to download this version, please visit https://www.f5books.eu/building-your-own-lab/.
BIG-IP VE Lab Edition You can now purchase the latest BIG-IP VE Lab Edition for the very, very cheap price of $95 (it used to be around $2000). It’s limited to 10Mb total throughput but includes LTM, DNS (formerly GTM), APM (10 user limit) AFM, ASM, AVR, PSM and AAM. It’s an incredibly cost effective tool for getting hands-on experience using F5 products, testing and building an understanding of how things work and interact.
The Lab Architecture So, what are we building? It’s pretty simple yet covers all our needs, where the 201 syllabus is concerned at least. These are the computing components; ▪
A Linux client running Lubuntu, allowing the use of CLI and GUI based tools and software such as ping, PuTTY (SSH), Filezilla (FTP) and a web browser.
▪
A BIG-IP VE running version 12.1.2
▪
A Linux server running the Tomcat Apache web server, configured with five virtual hosts, listening on different IP addresses and TCP ports.
We’ll be using these networks; ▪
Management - used for configuring the BIG-IP.
▪
External - the client-side network connecting the Linux client and BIG-IP; this will be a private (internal) network.
▪
Internal - the server-side network connecting the BIG-IP and Linux server; this will be another private (internal) network
85 85
Here’s a diagram to help you visualise the end state:
In the end of this chapter you will find the instructions for how to configure your lab environment.
86 86
Lab Exercises: Setting up Your Lab Environment Exercise 1.1 – Installing VMware Workstation Player Exercise Summary In this exercise, we’ll install VMware Workstation Player that will act as our hypervisor to build up our lab environment. Simply put, a hypervisor is a platform which creates and runs virtual machines. VMware Workstation Player is free for non-commercial, personal and home use which perfectly suits our purpose as a personal lab environment.
Exercise Prerequisites Before you start this lab exercise make sure you have the following: The installation file for VMware Workstation Player. The version we’ll use in this exercise is v12.5. A machine which meets the system requirements detailed earlier running either Windows or Linux.
▪ ▪
Running the installation file 1.
Run the installation file VMware Workstation Player. This will start the installation wizard. Click Next to proceed to the next page.
2.
On the End-User License Agreement page, after reading the terms (should you wish to), check the I accept the terms in the License Agreement box and click Next to proceed to the next page.
87 87
3.
On the Custom Setup page, if you need to change the installation path for VMware Workstation Player click Change. If not then click Next to proceed to the next page.
4.
On the User Experience Settings page you will have the options to choose if the program should automatically look for updates each startup and send anonymous system data and statistical information to VMware. These settings are completely optional and will not affect the lab. You may choose on how you would like to proceed.
88 88
5.
On the Shortcuts page you will have the options to add shortcuts on the Desktop and/or the Start Menu Programs Folder. As with the previous step, this is entirely optional and will not affect the lab. You may choose on how you would like to proceed.
6.
On the Ready to install VMware Workstation 12 Player page, click Install to start the installation of program.
89 89
7.
90 90
Once the installation is finished you will be presented with the Completed the VMware Workstation 12 Player Setup Wizard. On this page, click Finished to end the setup wizard.
Exercise 1.2 – Importing the Virtual Machines into VMware Workstation Player Exercise Summary In this exercise we’ll proceed with importing the virtual machines necessary for the lab environment. The virtual machines are in an *.ova format which means that you can simply import them and with very little adjustments have a functioning lab environment.
Exercise Prerequisites Before you start this lab exercise make sure you have the following: ▪
Successfully installed VMware Workstation Player
Obtaining a BIG-IP VE Trial Evaluation Key At the time of writing, F5 offers a 90-day free trial edition of the BIG-IP VE. To access this trial edition, you will have to create an F5 account. This is free of charge and anyone can register for an account. 1. 2.
3. 4.
To get started with the BIG-IP VE Free Trial, go to the following web page: a. https://downloads.f5.com/trial/secure/generate-eval-key.php?product=ltmve On our website we make sure that all links are working and are up to date. Therefore, if the previous link does not work, please go to: a. https://www.f5books.eu/building-your-own-lab/ Fill out the trial evaluation form and click on Request License Key. Please verify that the email address assigned to your account is correct as the Base Registration Key will be sent to this address. In the email you will also receive a link to where you can download the BIG-IP VE machine. Ignore this as we require a specific version for our lab exercises.
Downloading the BIG-IP VE Virtual Machine For our lab exercises we require you to run version/build 12.1.2.0.0.249. 1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
To download your BIG-IP VE virtual machine, visit https://downloads.f5.com. Click on Find a Download. Choose the Product Line BIG-IP v12.x / Virtual Edition. In the drop-down menu choose 12.1.2. Click on Virtual-Edition. If necessary, accept the Software Terms and Conditions. Click on BIGIP-12.1.2.0.0.249.ALL-scsi.ova. Select the download mirror appropriate for your location. When clicking on one of the links a download pop-up will appear. Save the BIGIP-12.1.2.0.0.249.ALL-scsi at a convenient location. we’ll be using this later in this exercise. If the previous instruction does not work, please visit https://www.f5books.eu/building-your-own-lab/. On this website we keep updated instructions and links to the lab components necessary for the lab exercises.
91 91
Downloading the Client Virtual Machine 1. 2. 3.
To download the Client Virtual Machine, go to the following web page: https://www.f5books.eu/building-yourown-lab/ Go to the Client Virtual Machine section and select one of the download mirrors available on the webpage. Save the virtual machine image at a convenient location. we’ll be using this later in this exercise.
Downloading the Apache Server Virtual Machine 1. 2. 3.
To download the Apache Server Virtual Machine, go to the following web page: https://www.f5books.eu/building-your-own-lab/ Go to the Apache Server Virtual Machine section and select one of the download mirrors available on the webpage. Save the virtual machine image at a convenient location. we’ll be using this later in this exercise.
Importing the F5 BIG-IP Virtual Machine into VMware Workstation Player 1. 2.
Start VMware Workstation Player. You should be presented with a licensing screen. Simply select Non-Commercial use only and you will arrive at the Welcome to VMware Workstation 12 Player screen.
3.
Once you are at the welcome screen, click on the Player tab and select File > Open.
92 92
4. 5.
Navigate to the location where you saved the OVA files and select BIGIP-12.1.2.0.0.249.ALL-scsi This will launch the Import Virtual Machine wizard. Here you can rename the Virtual Machine and select where you want to store it. Make sure that the location you choose to store it has enough disk space. Once you are done, click Import.
6. 7.
Next you will receive the License Agreement for the Virtual Machine. Click Accept to continue. Now the Virtual Machine is being imported into VMware Workstation Player. This might take a while depending on what hardware you are using. Once the import is complete, the virtual machine should end up in the library list.
8.
93 93
Importing the Client Virtual Machine into VMware Workstation Player 1. 2. 3. 4. 5.
94 94
Start VMware Workstation Player. You should be presented with the library screen. Click on the Player tab and select File > Open. Navigate to the location where you saved the OVA files and select F5_Lab_Client_vX.ova. Where X represents the current version of the OVA build. This will launch the Import Virtual Machine wizard. Here you can rename the Virtual Machine and select where you want to store it. Make sure that the location you choose to store it has enough disk space. Once you are done, click Import.
6. 7.
Now the Virtual Machine is being imported into VMware Workstation Player. This might take a while depending on what hardware you are using. Once the import is complete, the virtual machine should end up in the library list.
Importing the Apache Server Virtual Machine into VMware Workstation Player 1. 2. 3. 4. 5.
95 95
Start VMware Workstation Player. You should be presented with the library screen. Click on the Player tab and select File > Open. Navigate to the location where you saved the OVA files and select F5_Lab_ApacheServer_vX.ova. Where X represents the current version of the OVA build. This will launch the Import Virtual Machine wizard. Here you can rename the Virtual Machine and select where you want to store it. Make sure that the location you choose to store it has enough disk space. Once you are done, click Import.
6. 7.
Now the Virtual Machine is being imported into VMware Workstation Player. This might take a while depending on what hardware you are using. Once the import is complete, the virtual machine should end up in the library list.
Exercise 1.3 – Editing the Virtual Machine settings Exercise Summary In this exercise, we’ll continue to set up our lab environment. You should now have all three machines imported into VMware Workstation Player. Next, we need to configure the network interfaces on each machine so that they reside on the correct network. In our lab we’ll use what is known as a LAN Segment. A LAN Segment is a private network that can be shared with other virtual machines.
96 96
Exercise Prerequisites Before you start this lab exercise make sure you have the following: â–Ş â–Ş
Successfully installed VMware Workstation Player Successfully imported the machines F5_Lab_ApacheServer, F5_Lab_Client and BIGIP-12.1.2.0.0.249.ALLscsi.
Editing the Virtual Machine Settings for the F5 BIG-IP Virtual Machine 1. 2. 3. 4. 5.
Start VMware Workstation Player. You should be presented with the library screen. Click on the virtual machine named BIGIP-12.1.2.0.0.249.ALL-scsi. Click on Edit virtual machine settings. Click on the network adapter in the top of the list.
6.
Click on LAN Segments. This will launch a separate window where you can create LAN Segments.
97 97
7. 8.
Create the first LAN Segment called MGMT by clicking Add and writing the name MGMT. Create the next two LAN Segments using the same method. Name the them, Internal and External. When you are done, it should look like this:
9. Click OK twice to save the configuration. 10. Reopen the Virtual Machine settings by click Edit virtual machine settings. 11. Now for the first Network Adapter, assign it the LAN Segment called MGMT.
98 98
12. For the second Network Adapter, assign it the LAN Segment called External.
99 99
13. For the third Network Adapter, assign it the LAN Segment called Internal.
14. Click OK to save the configuration for the virtual machine.
Editing the Virtual Machine Settings for the Client Virtual Machine 1. 2. 3.
Click on the virtual machine named F5_Lab_Client_vX Click on Edit virtual machine settings. Now for the first Network Adapter, assign it the LAN Segment called MGMT.
100 100
4.
For the second Network Adapter, assign it the LAN Segment called External.
5.
Click OK to save the configuration for the virtual machine.
Editing the Virtual Machine Settings for the Apache Server Virtual Machine 1. 2. 3.
Click on the virtual machine named F5_Lab_ApacheServer_vX Click on Edit virtual machine settings. This virtual machine only has one Network Adapter, assign it the LAN Segment called Internal.
101 101
4.
Click OK to save the configuration for the virtual machine.
Exercise 1.4 – Starting Up the Virtual Machines Exercise Summary In this exercise, we’ll start all of our virtual machines and perform some final tweaking. We’ll also make sure you can access the management interface of the BIG-IP system.
Exercise Prerequisites Before you start this lab exercise make sure you have the following: ▪ ▪
Successfully installed VMware Workstation Player Successfully imported the machines F5_Lab_ApacheServer, F5_Lab_Client and BIGIP-12.1.2.0.0.249.ALLscsi. Successfully created all of the LAN Segments and assigned to the correct interfaces.
▪
Starting the F5 BIG-IP Virtual Machine 1. 2. 3. 4. 5. 6.
Start VMware Workstation Player. You should be presented with the library screen. Click on the virtual machine named BIGIP-12.1.2.0.0.249.ALL-scsi. Click on Play virtual machine. This will start the virtual machine. The screen will turn black and prompt the message: GRUB Loading Stage 2.. The startup of the BIG-IP might take up to 10 minutes. Simply let it be and it will eventually give you the following screen:
102 102
Starting the Apache Server Virtual Machine 1.
2. 3. 4. 5. 6.
Start another instance VMware Workstation Player. VMWare Workstation Player only has support for one machine at a time. Therefore, in order to launch more than one, simply start VMware Workstation Player again. Once you have started VMware Workstation Player you should be presented with the library screen. Click on the virtual machine named F5_Lab_ApacheServer_vX. Click on Play virtual machine. This will start the virtual machine. The screen will turn black and text from the bootup will be printed out. After a few minutes the operating system should be fully loaded and you should be presented with the following screen:
103 103
Starting the Client Virtual Machine 1. 2. 3. 4. 5. 6.
Start another instance VMware Workstation Player. Once you have started VMware Workstation Player you should be presented with the library screen. Click on the virtual machine named F5_Lab_Client_vX. Click on Play virtual machine. This will start the virtual machine. The screen will turn black and text from the bootup will be printed out. After a few minutes the operating system should be fully loaded and you should be presented with the desktop:
Changing the Keyboard Layout for the Client Virtual Machine The default keyboard layout of this Linux machine is English (US). This may not be the preferred keyboard layout and if you need to change it please perform the following steps: 1.
In the bottom right corner there is an icon of the American flag.
2. 3.
Right Click on this Icon in order to launch a menu. Click on the item named “Keyboard Layout Handler� Settings.
104 104
4.
In this window, uncheck the setting named Keep system layouts:
5. 6.
This will unlock the possibility to add/remove keyboard layouts. Click on Add and in the list of available keyboard layouts, select the layout you wish to use and simply press OK. The new keyboard layout should now be added to the list of keyboard layouts.
7.
105 105
8.
In order to eliminate the risk of the linux host changing the keyboard layout, remove the US keyboard layout by selecting it and clicking Remove. When you are done the final results should look like this:
9.
Save your settings by clicking Close.
106 106
4. Introduction to LTM - Initial Access and Installation Before we can get started load balancing traffic to our servers, we need to perform the initial installation of the BIG-IP device. This chapter will take you through each step and the options available to you.
The BIG-IP LTM Module Local Traffic Manager (LTM) is a core feature module for the Traffic Management Operating System (TMOS) that runs on BIG-IP platforms, physical or virtual. LTM is today’s version of the original product that F5 the company was created to provide. Most other modules rely upon LTM to provide their own functions. The LTM’s purpose is to manage and load balance various types of traffic, services and applications. These can be web, file, proxy, DNS or email servers, caches, voice services and even IP routers. The LTM module is highly configurable and offers a multitude of features that solve many of the challenges that service providers and enterprise companies face today. Traffic management functions relate to the many things beyond mere load balancing that LTM is capable of, including contextual traffic routing, programmatic traffic manipulation, security, monitoring and much more.
Initial Setup There are three steps you need to perform in order to get any BIG-IP system up and running: 1. 2. 3.
Configure an IP address, mask and, if required, default gateway for the dedicated Management (mgmt) interface. License the system. Use the Setup Utility in the Configuration Utility WebGUI to specify basic device configuration settings including: the root and administrator passwords, module provisioning, interfaces, VLANs and self IP addresses. If the default management interface IP addressing configuration is appropriate for your environment, then you will not have to change its values.
Configuring the Management Port IP Address The default management port IP address of the BIG-IP system is 192.168.1.245/24. There are, however, some scenarios where DHCP will try to obtain an IP address from a DHCP server and if successful, this will be assigned to the management port instead. Here are all the possible scenarios: ▪ ▪ ▪
Where DHCP is not enabled, and in the absence of any prior static configuration, the device’s management port will be assigned the address: 192.168.1.245/24. No default route is created, as no default gateway is assigned. When DHCP is enabled, but there is no DHCP server available, or DHCP fails for any reason, the 192.168.1.245/24 address is again assigned. If DHCP is enabled and works successfully, the assigned IP address (and possibly default gateway) can be observed using the LCD panel or the CLI via the serial port (using command ip address show eth0).
Physical devices are (by default) not configured to use DHCP on the management port. However, Virtual Edition virtual machine images are configured, with the exception of .iso image files.
107 107
The management interface IP address can be set or modified using any of these methods: 1. 2. 3. 4.
The LCD panel on the appliance. The config command in the CLI. tmsh (traffic management shell). The Web GUI, but only if an address is already configured.
Configuration via the LCD Panel If you have physical access to a device, you can configure the management interface IP address using the LCD panel, as follows: 1. 2.
Use the red X button to put the LCD into menu mode. Use the navigation arrows to navigate to the System menu and use the Check mark (green tick) button to select it. 3. Select Management and press the Check button. 4. Select Mgmt IP and press the Check button. 5. Enter the IP address you want to use and press the Check button. 6. Enter the relevant netmask and then press the Check button. 7. Use the navigation arrows and select Mgmt Gateway and press the Check button. 8. Enter the default gateway you would like to use and press the Check button. 9. Use the navigation arrows and select Commit and then press the Check button. 10. Select OK and then press the Check button. Here’s an image of the LCD panel:
Configuring the Management IP address Using the Touch LCD Panel (iSeries platforms) On the new iSeries platform, the LCD panel has become a touch display. In order to configure the management IP address using the touch LCD panel, use the following instructions: 1. 2. 3. 4. 5. 6. 7. 8. 9. 10.
Touch the screen to activate Menu mode for the LCD. Tap Setup. Tap Management. For the Type setting, tap to select IPv4 or IPv6. Tap IP Address. Use the arrows on the screen to configure the management IP address and the prefix length. Tap Commit to save your changes. Scroll down and tap Gateway. Use the arrows on the screen to configure the default management route. If you do not have a default route, enter 0.0.0.0.
108 108
11. Tap Commit to save your changes.
Configuration Using the Config Command You’ll need to establish a serial console connection to the device in order to use this method. For a physical device, connect to the console port using a suitable cable and a terminal application. For a virtual machine, you’ll use a hypervisor console. If the device already has an IP address assigned, you can, of course, also use SSH. When using a physical serial console port, set the baud rate in your terminal application to 19200 as this is the default.
By default, the admin user account cannot login to the CLI.
1.
Launch a terminal client such as PuTTY and use one of the following methods: a. SSH to xxx.xxx.xxx.xxx. Where xxx.xxx.xxx.xxx is the management IP address. b. Connect using the Serial Console Port. Select the COM port that is connected to the BIG-IP system. 2. Log in using the default user account root and the password default. 3. Type the following command to launch the application: config 4. On the introduction screen (shown below), press [Enter] to confirm OK. 5. On the Configure IP Address screen, you will be asked if you would like to Use Automatic Configuration of IP Address. The default value is No. Confirm this setting by pressing [Enter]. 6. On the Configure IP Address screen, enter the IP address you would like to use. When done, use [Tab] to navigate to the OK selection and press [Enter] to move forward to the next screen. 7. On the Configure Netmask screen, enter the associated netmask. Use [Tab] to navigate to the OK and press [Enter] to move forward to the next screen. 8. On the next screen, you configure the Management Route. This is the default gateway that the HMS (Host Management System) operating system uses. If you have a default gateway for the management port, select Yes. If not, then select No. 9. If you selected Yes, enter the IP address of a suitable default gateway. 10. If you selected No or after you’ve entered a default gateway on the Confirm Configuration screen, select Yes to save the configuration.
109 109
Configuration Using TMSH You’ll need to establish a serial console connection to the device in order to use this method. For a physical device, connect to the console port using a suitable cable and a terminal application. For a virtual machine, you’ll use a hypervisor console. If the device already has an IP address assigned, you can, of course, also use SSH. When using a physical serial console port, set the baud rate in your terminal application to 19200 as this is the default. By default, the admin user account cannot login to the CLI. Once you’re connected and logged in, follow these steps: 1.
2. 3.
4.
Launch a terminal client such as PuTTY and use one of the following methods: a. SSH to xxx.xxx.xxx.xxx. Where xxx.xxx.xxx.xxx is the management IP address. b. Connect using the Serial Console Port. Select the COM port that is connected to the BIG-IP system. Log in using the default user account root and the password default. You will either be at a Linux host shell prompt or directly in the tmsh. This is indicated by the prompt in the terminal program.; a. Linux Host: config # b. TMSH: (/Common)(tmos)# The Linux host shell prompt is the default for the root user. In order to enter tmsh type the following command:
tmsh 5.
In order to set the management IP address, type the following command: create /sys management-ip
[ip address/netmask] 6.
To optionally configure the management route, type the following command: create /sys management-
route default gateway [gateway ip address] 7.
In order to to save the configuration, type the following command: save /sys config partitions all
110 110
The configuration changes you make in tmsh are only saved to the running configuration. If the BIG-IP device is rebooted the settings will be lost. Therefore, you must save the running configuration to the startup configuration by utilising the command save /sys config.
Configuration Using the WebGUI This method requires the device to already have an IP address and default gateway configured. The Configuration Utility, usually called the WebGUI, is a browser-based interface that gives you secure access to your BIG-IP device for real-time configuration. An Apache OpenSSL web server runs on the BIG-IP device in the HMS to provide this interface. To access the Web GUI, browse to the management IP address of the device ensuring you use https://. You may also be able to use a self IP address of the device if configured and permitted. When accessing the BIG-IP system for the first time using the WebGUI you will be prompted to run the Setup Utility which is a setup wizard created to assist the BIG-IP administrator to perform initial configuration of the system. Using this wizard, you will have the opportunity to change the management port address. The following instructions presume that this has already been run.
To modify the management interface address, follow these steps; 1.
2. 3. 4. 5. 6. 7.
Open up a browser session to https://xxx.xxx.xxx.xxx. Where xxx.xxx.xxx.xxx is the management IP address. On the first log-on attempt for that particular browser you will be prompted with a certificate error, but this is normal. The BIG-IP system is shipped with a self-signed certificate which will not be validated by the web browser. Accept the certificate and when the webpage has been retrieved it should load up the logon screen. Log in to the BIG-IP system using the default user name admin and the password admin. Navigate to System > Platform. Under General Properties change the Management Port Configuration to Manual. Enter the required management IP address and netmask. Optionally, enter a management route (a default gateway). Save your configuration by clicking Update. The HMS runs RedHat Linux operating system and provides the various interfaces and tools used to manage the system such as the WebGUI, tmsh CLI, DNS client, SNMP and NTP.
Licensing the BIG-IP System Once the device has a management IP address, it needs to be licensed using the Web GUI. This requires a base registration key; a 27-character long string stored in the /config/RegKey.license file, which uniquely identifies the device. This is used by the F5 license server to associate the device with the licensed modules you’ve paid for and thus enable their use on the device.
111 111
Not all systems are shipped with the base registration key (for instance the Virtual Editions), in which case, it must be manually entered. The registration key is presented in the following format: AAAAA-BBBBB-CCCCC-DDDDD-EEEEEEE Make a note of the base registration key and keep it in a safe place because it uniquely identifies the device. In some scenarios, such as an upgrade, the RegKey.license file may be deleted. Subsequently, when you need to update the license of the system you won’t be able to. In order to retrieve the Base Registration Key you will have to open up a ticket with F5 Support and this might delay the process, causing a long outage of your system.
The BIG-IP system uses the base registration key to generate what is known as a dossier, which is what is actually passed to the F5’s license server. The dossier contains numerous encrypted characters that uniquely identify your system. Multiple options are stored in the dossier including registration key and the system time. To make sure nothing goes wrong when generating the dossier, verify that the system time is correct. On physical appliances the base registration key is already present on the box. If you are using a virtual edition you will most likely need to enter the registration key manually.
Automatic License Activation In order to use automatic license activation, the BIG-IP device needs Internet access to reach the F5 licensing servers. Therefore, you will need to make sure a device is configured with a suitable IP address, default route and DNS server(s). These can be configured either manually or through DHCP. We have already covered configuration of the management interface IP address, mask and default gateway (and consequently default route), but we haven’t covered manual DNS configuration. Prior to the system being licensed, the only available method to manually configure DNS servers is via the CLI, using this command: $ [tmsh] modify sys dns name-servers add { 10.11.12.99 } With the Automatic method, the BIG-IP device generates a dossier and automatically sends it to the F5 license server. The F5 license server matches the dossier against its database, generates the license and sends it back to the device. The license is then installed on the BIG-IP device. The steps required to perform automatic license activation are as follows: 1.
2. 3. 4. 5.
Open up a browser session to https://xxx.xxx.xxx.xxx. Where xxx.xxx.xxx.xxx is the management IP address. On first logon for that particular browser, you will be prompted with a certificate error, but this is normal. The BIG-IP system is shipped with a self-signed certificate which will not be validated by the web browser. Accept the certificate and when the webpage has been retrieved it should load up the logon screen. Log in to the BIG-IP system using the default user name admin and the password admin. You will be presented with the Welcome screen, click Next to launch the Setup Utility. At the License page, click Activate. If the Base Registration Key value is not present, enter it.
112 112
6. 7. 8. 9. 10.
Select Activation Method: Automatic For the Outbound Interface setting, select the mgmt interface. Click Next to activate your BIG-IP device. On the next page, press Accept to accept the EULA. Wait while the BIG-IP device communicates with the F5 licensing servers, uploads the dossier, installs the License, and verifies its configuration. 11. Click Continue to load the Resource Provision page (we’ll cover Provisioning shortly).
Once the license has been installed, it is stored in the /config/bigip.license file.
Manual License Activation This method is used when the BIG-IP device does not have direct access to the Internet. It can also be necessary if the owner of the BIG-IP device wants to keep all the dossiers that the BIG-IP device generates. This activation method is, as you’d imagine, more involved than automatic activation. The dossier must be generated and then downloaded or copied to the connecting client’s clipboard using the WebGUI. A host must then submit the dossier to the F5 licensing server via a web page and obtain the generated license. The license is then transferred back to the BIG-IP device; again, either uploaded as a file or pasted from the clipboard, where it gets activated. In most scenarios, the device that you are using to access the BIG-IP device will have Internet access, so you can do it all using the same web browser that you use to manage the BIG-IP device. The steps required to perform manual license activation are as follows: 1.
2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14.
Open up a browser session to https://xxx.xxx.xxx.xxx. Where xxx.xxx.xxx.xxx is the management IP address. On first logon for that particular browser, you will be prompted with a certificate error, but this is normal. The BIG-IP system is shipped with a self-signed certificate which will not be validated by the web browser. Accept the certificate and when the webpage has been retrieved it should load up the logon screen. Log in to the BIG-IP system using the default user name admin and the password admin. You will be presented with the Welcome screen, click Next to launch the Setup Utility. At the License, page click Activate. If the Base Registration Key value is not present, enter it. Select Activation Method: Manual and click Next On the next page the dossier has been generated. Copy the dossier to the clipboard and either click the link “Click here to access F5 Licensing Server” or open up a new web browser (tab) and browse to: http://activate.f5.com. In the text box Enter your dossier, paste in the dossier that the BIG-IP device generated and click Next. On the Accept User Legal Agreement, check the box “I have read and agree to the terms of this license” and click Next Copy the license that was generated to your clipboard. Head back to the BIG-IP device and paste the license into the License box and click Next. Wait whilst the BIG-IP device installs the License and verifies its configuration. Click Continue to load the Resource Provision page.
113 113
When performing a license reactivation, the BIG-IP system may reload the configuration which will temporarily interrupt traffic processing.
Once the license has been installed it is stored in the /config/bigip.license file.
Provisioning Before you can start working with the modules that you plan on running on your BIG-IP system, you will first need to provision them. Provisioning can be done under System > Resource Provisioning. In this list you will be able to see all modules that currently exist, but note that even though they exist in this table they are not necessarily provisioned. You see, the license will state which modules you have the right to provision by reviewing the License State. Even if the module is set to Licensed it will still not be provisioned unless you click in the box named None and select one out of five different levels.
114 114
Keep in mind that provisioning will only give you some control over how much CPU, RAM and disk resources each module uses, you cannot specify an exact value. The resources it receives will be determined by the provisioning level that you have selected. You will be able to choose between the following levels: ▪
Dedicated – You will use this if you only run one module on your BIG-IP device.
▪
Nominal – This will give the module the minimum resources available in order to run the module, and if there are resources to spare, this will also be available for the module. It will give a majority of the system resources to the module.
▪
Minimum – This will give the module the minimum resources available in order to function and if there are resources to spare this may be distributed to other modules.
▪
None – None is the same as having a module turned off. Meaning that the module is not provisioned.
▪
Lite – This is used for selected modules that grant limited features for trial purposes.
When you provision multiple modules, you choose between Nominal and Minimum (Dedicated is only used for one module and None is the same as the module being turned off). This is very limiting, as you cannot specifically configure a set amount of memory or define how many CPU cores the modules should have.
The Setup Utility The Setup Utility is a quick and easy way to get started with your BIG-IP device once it is licensed and provisioned. It helps you configure the passwords of the system, networking, HA and other management settings. Here are some examples of what is configured during the Setup Utility process: ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪
Device certificates Host name Time zone Passwords for the root (used for CLI) and the admin (used for the Web GUI) account SSH access Self-IP addresses HA VLANs NTP DNS ConfigSync Failover Mirroring
Self-IP Addresses During the Setup Utility, you will configure what is known as self-IP addresses. A self-IP address is an IP address on the BIG-IP system which you associate with a VLAN. The BIG-IP will use this IP address to communicate with hosts in that particular VLAN, whether it is monitoring or application traffic.
115 115
When the BIG-IP system is configured in a High-Availability setup, you will also configure a floating self-IP address. This is the same as a regular self-IP address, but the ownership of this address will change depending on which BIG-IP system is active. In the following lab exercises, you will configure both a self-IP address and a floating self-IP address. This is part of the Setup Utility which you will run during the lab exercise. You can configure both, even though you do not configure the BIG-IP system in a high-availability setup. In case you add another BIG-IP system later on, there will already be a floating self-IP address configured.
Lab Exercises: Initial Access and Installation Exercise 2.1 – License, Provision and Initial Setup Exercise Summary In this exercise, we’ll go through the Licensing, Provisioning and the Initial Setup of your BIG-IP system. These are the actions necessary to get your BIG-IP system up and running and you will learn the following: ▪ ▪ ▪ ▪
How to access your BIG-IP system using the WebGUI. How to license your BIG-IP system. How to provision your BIG-IP system. How to create a baseline configuration using the Setup Utility.
Exercise Prerequisites Before you start this lab exercise, make sure you have the following: Network access to the BIG-IP system’s management port. Obtained a BIG-IP system’s base registration key. Obtained through lab exercise Exercise 1.2. Access to the Internet.
▪ ▪ ▪
Access the WebGUI via the Management Port 1.
2. 3. 4.
Open up a browser session to https://192.168.1.245. You will be prompted with a certificate error, but this is normal. The BIG-IP system is shipped with a self-signed certificate which will not be validated by the web browser. Accept the certificate, this will load up the logon screen. Log in to the BIG-IP system using the default username admin and the password admin. When logging on to the BIG-IP system for the first time you should be presented with the Setup Utility. Click Next in order to start the Setup Utility. When the Setup Utility starts, it will immediately go to the License page. Click Activate button in order to start the licensing process.
116 116
License your BIG-IP system 1.
Use the Base Registration Key in order to generate a dossier. If the base registration is already prepopulated, then follow the instruction present in 1a. If the base registration key is not prepopulated, then follow the instruction present in 1b. a.
If your Base Registration Key is already prepopulated, select activation method Manual and click Next.
Setup Utility Setup Utility > License General Properties Activation Method When done, click b.
Manual Next
If your Base Registration Key is not already prepopulated, enter the following values:
Setup Utility Setup Utility > License General Properties Base Registration Key Add-On Registration Key List Activation Method When done, click Next 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14.
Make sure that Manual Method is set to Download/Upload File In the Step 1: Dossier area click Click Here to Download Dossier File. Save the dossier.do file on your client computer. In the Step 2: Licensing Server area, click Click here to access F5 Licensing Server. This will launch a new web browser session to the F5 Licensing Server. When you are at the Activate F5 Product web page under Select Your Dossier File, click on browse. Browse to the dossier.do file you just downloaded. When done, click Next. On the Accept User Legal Agreement page, check the I have read and agree to the terms of this license. When done, click Next. On the next page, click Download license. Save the license.txt file on your client computer. Go back to your web browser session that is connected to the BIG-IP system’s WebGUI. In the Step 3: License area, click Browse and browse to the license.txt file. Select the license.txt file and click Open. When done, click Next. You will be prompted with a white box stating, “BIG-IP system configuration has changed”. Once it is done, click Continue and you will be presented with the Resource Provisioning page.
117 117
Enter the base registration key you obtained in Exercise 1.2. Leave blank Manual
Provisioning Your BIG-IP System 1.
On the Resource Provisioning page, provision your BIG-IP system using the following settings:
Setup Utility Setup Utility > Resource Provisioning Module Management (MGMT) Small Local Traffic (LTM) Nominal When done, click Next Your BIG-IP system may produce a warning message stating that certain system daemons may restart, or the system may reboot causing your web browser session to wait up to several minutes. This is normal when modifying the resource provisioning of the BIG-IP system.
Configuring the Device Certificates 1.
Next, you will be presented with the Device Certificates page. Keep the default values and move on to the next page by clicking Next.
Configuring the Platform Settings 1.
On the Platform page, configure your BIG-IP system using the following settings:
Setup Utility Setup Utility > Platform General Properties Management Port Configuration Management Port
Host Name Host IP Address Time Zone User Administration Root Account
Password: f5training Confirm: f5training Password: f5training Confirm: f5training Enabled * All Addresses
Admin Account SSH Access SSH IP Allow When done, click
Manual IP Address [/prefix]: 192.168.1.245 Network Mask: 255.255.255.0 Management Route: Leave Blank bigip1.f5lab.com Leave default Select the time zone appropriate for your location
Next
You will be prompted with a notice that you have changed the password and will therefore have to re-login to the device again.
118 118
2.
Log back into the BIG-IP system using the admin account with the password f5training. Once logged in, you will be redirected to the Setup Utility > Network page.
Performing the Standard Network Configuration 1. 2.
On the Setup Utility > Network page, under the Standard Network Configuration, click Next. On the Setup Utility > Redundancy page, ensure that it contains the following settings:
Setup Utility Setup Utility > Redundancy Redundant Device Wizard Options Config Sync High Availability When done, click 3.
Check the box Display configuration synchronization options Check the box Display failover and mirroring options Select Network for the Failover Method Next
Next, we’ll configure the VLANs and start with the Internal Network configuration. Here we’ll assign the VLANs. This includes the self-IP address, netmask and network interface. On the Setup Utility > VLANs page, enter the following settings:
Setup Utility Setup Utility > VLANs Internal Network Configuration Self IP
Floating IP Internal VLAN Configuration VLAN Name VLAN Tag ID Select the following VLAN Interface and Tagging.
IP Address [/prefix]: 172.16.1.31 Network Mask: 255.255.0.0 Port Lockdown: Allow Default Address: 172.16.1.33 Port Lockdown: Allow Default internal auto VLAN Interfaces: 1.2 Tagging: Untagged
When done, click Add This should result in the following configuration: Interfaces 1.2 (untagged) When done, click Next
Move the Interface 1.2 to Untagged by selecting it and pressing the arrow key.
119 119
4.
Next, we’ll configure the VLAN for the External Network configuration. On this page, enter the following settings:
Setup Utility Setup Utility > VLANs External Network Configuration Self IP
Default Gateway Floating IP External VLAN Configuration VLAN Name VLAN Tag ID Select the following VLAN Interface and Tagging.
IP Address [/prefix]: 10.10.1.31 Network Mask: 255.255.0.0 Port Lockdown: Allow None Leave Blank Address: 10.10.1.33 Port Lockdown: Allow None external auto VLAN Interfaces: 1.1 Tagging: Untagged
When done, click Add This should result in the following configuration: Interfaces 1.1 (untagged) When done, click Next 5.
Next, we’ll configure the High Availability Network Configuration. Even though we’ll not configure our BIG-IP system in a high-availability setup we can still add the configuration to prepare it. For the High Availability communication, we’ll use the existing internal VLAN which we created earlier in the Setup Utility. On the Setup Utility > VLANs page enter the following settings:
Setup Utility Setup Utility > VLANs High Availability Network Configuration High Availability VLAN Click the Select existing VLAN button Select VLAN internal When done, click Next 6. 7. 8.
On the next page, we’ll be asked to configure NTP. This is not necessary for the lab exercises. Skip to the next page by clicking, Next. On the next page, we’ll be asked to configure DNS. This is not necessary for the lab exercises. Skip to the next page by clicking, Next. Next, we’ll configure the local address of the ConfigSync. On the Setup Utility > ConfigSync page enter the following settings:
120 120
Setup Utility Setup Utility > ConfigSync ConfigSync Configuration Local Address When done, click 9.
172.16.1.31 (internal) Next
On the next page, we’ll configure the failover configuration. On the Setup Utility > Failover page, use the default settings specified in the following table:
Setup Utility Setup Utility > Failover Failover Unicast Configuration Local Address | Port | VLAN Failover Multicast Configuration Use Failover Multicast Address When done, click
172.16.1.31 192.168.1.245
1026 1026
internal Management Address
Unchecked (Disabled) Next
10. Next, we’ll configure the mirroring configuration. On the Setup Utility > Mirroring page, use the default settings specified in the following table:
Setup Utility Setup Utility > Mirroring Mirroring Configuration Primary Local Mirror Address Secondary Local Mirror Address When done, click
172.16.1.31 None Next
11. Now we’ll finish the Setup Utility as we’ll not configure the BIG-IP system in a redundant high availability pair. On the Setup Utility > Active/Standby Pair page, under Advanced Device Management Configuration click Finished.
121 121
Once you are done with the Setup Utility you be redirected to the Statistics page and at the top of the browser you will be presented with the message Setup Utility Complete. This is presented with the following message:
12. Log out from the BIG-IP WebGUI by clicking the Log out button and close down your web browser.
Exercise 2.2 – Verifying Administrative Access Exercise Summary In this exercise, we’ll verify the access to the BIG-IP system and that everything is working as it should be after the Initial Setup and also change the Port Lockdown settings. In this lab, we’ll perform the following: ▪ ▪
Test and verify the access to the BIG-IP system. Change the Port Lockdown settings.
Exercise Prerequisites Before you start this lab exercise, make sure you have the following: Network access to the BIG-IP system’s management port. A web browser and a terminal client such as PuTTY.
▪ ▪
Verify HTTPS Access to the Management Port 1. 2.
Open up a browser session to https://192.168.1.245 Log on to the WebGUI using the account admin and the password f5training.
Were you able to connect and log in? You should be able to do this. If you cannot connect and login, you will have to verify your configuration. 3.
Log out from the BIG-IP WebGUI system by clicking the Log out button
Verify HTTPS Access to the External Port 1.
Open up a browser session to https://10.10.1.31 Were you able to connect? You should not be able to. This is because the current Port Lockdown setting of the External VLAN is set to Allow None. We configured this during the Setup Utility. This is good practice and you should never allow external access to your BIG-IP system if you do not have a specific requirement to do so. To solve this, proceed with the next step of this exercise.
2. 3. 4.
Open up a browser session to https://192.168.1.245 and login using the admin credentials. Navigate to Network > Self IPs and click on the address 10.10.1.31. This will open up the configuration for that self IP address. On the Network > Self IPs > 10.10.1.31 page, change the following configuration:
122 122
Network > Self IPs > 10.10.1.31 Configuration Port Lockdown Custom List When done, click
Select Allow Custom Check the TCP and the Port. Enter the port 443 and press Add. Update
The results should look like the following diagram:
5. 6. 7.
8.
Log out from the BIG-IP WebGUI system by clicking the Log out button. Try to access the WebGUI once again using a new browser session to https://10.10.1.31. Since we have modified the Port Lockdown setting, you should now be able to access the WebGUI on the external Interface. You will be prompted with a certificate error, but this is normal. The BIG-IP system is shipped with a selfsigned certificate which will not be validated by the web browser. Accept the certificate, this will load up the logon screen. Log in to the WebGUI using the admin credentials.
123 123
9.
Now try to access the WebGUI on the external floating self-IP address. Open up a browser session to https://10.10.1.33. Did you succeed? You should not be able to access the WebGUI on the floating self-IP address. This is again caused by the Port Lockdown setting as this is configured on a per self-IP basis. If you would like to access the WebGUI on the floating self-IP address, then use the same configuration as in the previous scenario but instead use the floating self-IP address. 10. Log out from the BIG-IP WebGUI system by clicking the Log out button.
Verify SSH Access to the Management Port 1. 2. 3.
Launch a terminal client such as PuTTY and SSH to 192.168.1.245 on port 22. You will be presented with a security alert because the BIG-IP system is presenting a certificate that is not cached on the desktop. Simply click Accept and it will continue to the log in prompt. Log on using the account root and the password f5training.
Were you able to connect and log in? You should be able to do this. If you cannot connect and login you will have to verify your configuration. 4.
Close down the SSH session by typing:
[root@bigip1:Active:Standalone] config # exit Verify SSH Access to the External Port 1.
Launch a terminal client such as PuTTY and SSH to 10.10.1.31 on port 22. Are you able to connect?
You should not be able to connect with SSH to the external port. But why? What is causing this problem? Like we mentioned in the earlier exercise, Port Lockdown prohibits access to the external port and in the earlier exercise we only allowed access for HTTPS and not SSH. In order to allow access, perform the same configuration changes but instead add TCP and Port 22.
Verify SSH Access for the Admin Account to the Management Port 1. 2.
Launch a terminal client such as PuTTY and SSH to 192.168.1.245 on port 22. Log on using the account admin and the password f5training.
What happens? Does the connection fail? By default, the admin account does not have any access to the command line, so the result should be that the SSH connection would be immediately terminated. However, this can be changed. To change this setting, continue to the next step of this exercise. 3. 4. 5.
Open a browser session to https://192.168.1.245 and login using the admin credentials. Navigate to System > Users > User List and click on the admin account. This will open the configuration of the admin account. On the System > Users > User List > admin page, change the following configuration:
System > Users > User List > admin Account Properties Terminal Access When done, click 6.
Log out from the BIG-IP WebGUI system by clicking the Log out button.
124 124
tmsh Update
7. 8. 9.
Try again to launch a terminal client and SSH to 192.168.1.245 on port 22. Log on using the admin credentials. This time you should be able to log on but you will immediately log on, to tmsh as this is the Terminal Access we specified under the admin account configuration. Close down the SSH session by typing:
admin@(bigip1)(cfg-sync Standalone)(Active)(/Common)(tmos) # quit Verify Root Access to the WebGUI 1.
Open a browser session to https://192.168.1.245 and login using the root credentials. Were you able to log in? The root account does not have access to the WebGUI therefore this attempt should fail. This behaviour is default and cannot be changed.
Exercise 2.3 – Backing up the Configuration Exercise Summary In this exercise, we’ll save the current configuration of the BIG-IP system to store a baseline configuration of the system which we can revert to when needed. It will also be used for backup purposes. In this lab, we’ll perform the following: ▪
Create a UCS archive of the BIG-IP system configuration. We’ll cover backups and UCS archives in greater detail in the Maintain Configuration chapter but to give you a short description, UCS is a compressed archive that contains a snapshot of the BIG-IP system. It contains all the configuration files, the BIG-IP license, User Accounts and their passwords. It will also contain the SSL certificates that you have uploaded to the device (including private keys if not selectively excluded).
Exercise Prerequisites Before you start this lab exercise, make sure you have the following: Network access to the BIG-IP system’s management port. Storage on your client computer where you can store the backup.
▪ ▪
Creating a UCS Archive of the BIG-IP Configuration 1. 2. 3. 4. 5. 6. 7.
Open up a browser session to https://192.168.1.245 and login using the admin credentials. Navigate to System > Archives and in the upper right corner, click Create. Under File Name enter baseline.ucs and click Finished. This will generate the UCS archive and it can take up to a couple of minutes before it is finished. Once it is finished, it will prompt a message stating: /var/local/ucs/baseline.ucs is saved. Click OK in order to get redirected back to the Archives page. On the Archives page, click on baseline.ucs. This will open up the properties of the baseline.ucs archive. Under Archive File, click the Download: baseline.ucs. This will download the UCS archive. Browse to a convenient location and save the file. Now you have a backup of the Initial Setup that you have verified.
125 125
Chapter Summary ▪
The management interface IP address can be set or modified using the LCD panel on the appliance, the CLI (bash), tmsh (traffic management shell) or the Web GUI.
▪
When using a physical serial console port, set the baud rate in your terminal application to 19200 as this is the default.
▪
The default account for the CLI access is root with the password default.
▪
The BIG-IP system uses the base registration key to generate what is known as a dossier, which is what is actually passed to the F5’s license server. The dossier contains numerous encrypted characters that uniquely identify your system.
▪
The BIG-IP system can be licensed using the Automatic or Manual Licensing Method.
▪
Before you can start working with the modules that you plan on running on your BIG-IP device, you need to provision them. Provisioning gives you some control over how much CPU, RAM and disk resources each module uses.
▪
The Setup Utility is a quick and easy way to get started with your BIG-IP device once it is licensed and provisioned. It helps you configure the passwords of the system, networking, HA and other management settings.
126 126
Chapter Review 1. What is the default Management Port IP Address? a. b. c. d.
192.168.1.1/24 172.16.1.245/16 192.168.1.254/24 192.168.1.245/24
2. What command is used to change the Management Port IP address from CLI (bash)? a. b. c. d.
configure edit config ipedit
3. You have established a terminal connection to your BIG-IP system using PuTTY. You are using the admin account but are unable to log in. What is the problem? a. b. c. d.
The admin account is by default not able to log into the CLI. This needs to be configured on the admin account. You have not yet run the Setup Utility. During the Setup Utility you provide the admin access to the CLI. The BIG-IP system does not have CLI access by default, this needs to configured using the WebGUI. You have configured the wrong baud rate.
4. When using the Automatic License Activation Method, what requirements do you need to fulfil? a. b. c. d.
Configure an NTP server. Provide the BIG-IP system with Internet access. Run the Setup Utility prior to running Automatic License Activation Method. Register the device with F5 support.
5. What provision level will give the module the minimum resources available to run the module and if there are resources to spare it will receive this as well? a. b. c. d.
Dedicated Lite Minimum Nominal
127 127
Chapter Review: Answers 1. What is the default Management Port IP Address? a. b. c. d.
192.168.1.1/24 172.16.1.245/16 192.168.1.254/24 192.168.1.245/24
The correct answer is: d Where DHCP is not enabled, and in the absence of any prior static configuration, the device’s management port will be assigned address: 192.168.1.245/24. No default route is created as no default gateway is assigned. 2. What command is used to change the Management Port IP address from CLI (bash)? a. b. c. d.
configure edit config ipedit
The correct answer is: c The management interface IP address can be set or modified in CLI (bash) using the following command: config 3. You have established a terminal connection to your BIG-IP system using PuTTY. You are using the admin account but are unable to log in. What is the problem? a. b. c. d.
The admin account is by default not able to log into the CLI. This needs to be configured on the admin account. You have not yet run the Setup Utility. During the Setup Utility you provide the admin access to the CLI. The BIG-IP system does not have CLI access by default, this needs to configured using the WebGUI. You have configured the wrong baud rate.
The correct answer is: a 4. When using the Automatic License Activation Method, what requirements do you need to fulfil? a. b. c. d.
Configure an NTP server. Provide the BIG-IP system with Internet access. Run the Setup Utility prior to running Automatic License Activation Method. Register the device with F5 support.
The correct answer is: b To use automatic license activation, the BIG-IP device needs Internet access to reach the F5 licensing servers. Therefore, you will need to make sure a device is configured with a suitable IP address, default route and DNS server(s). These can be configured either manually or through DHCP.
128 128
5. What provision level will give the module the minimum resources available in order to run the module and if there are resources to spare it will receive this as well? a. b. c. d.
Dedicated Lite Minimum Nominal
Nominal will give the module the minimum resources available in order to run the module, and if there is are resources to spare, this will also be available for the module. It will give a majority of the system resources to the module.
129 129
5. Local Traffic Objects The BIG-IP Local Traffic Manager (LTM) is only one of many modules that can be run on the BIG-IP system and is the one we’ll be focusing on the most throughout the chapters of this book. As we covered in the 101 Application Delivery Fundamentals Study Guide, the main purpose of LTM is to assist organisations and companies with their application delivery by load balancing traffic between servers, offloading server services such as SSL processing, monitoring applications and ensuring traffic is not sent to a faulty or offline server and adding TCP optimisation techniques. The BIG-IP system is a default deny device, meaning that it will only accept traffic if it is configured to do so. In order for the BIG-IP system to process traffic it needs to be configured with listeners. Virtual Servers are one type of listener and in order for the BIG-IP LTM to process and load balance traffic, it needs to have certain Local Traffic Objects in place. These are Nodes, Pool Members, Pools and Virtual Servers and we’ll cover them all in this chapter.
Nodes Nodes are objects which represent the real servers or other hosts on your network. Nodes are only represented by an IP address and this is important to remember. A node is uniquely identified by its IP address and therefore two nodes cannot have the same IP address (unless they are in different route domains). A node is assigned a service (port) and then added to a Pool. In this moment the node becomes a Pool Member. A single node can be added to multiple pools (or even the same pool but with a different port) and thus logically represent multiple pool members. With a node, you can configure the host’s IP address, Node Name, Health Monitor, Ratio (used with some load balancing methods) and Connection Limit. You do not need to manually create nodes as they will be automatically created when you assign Members to a Pool. However, when assigning members to a pool you cannot specify any non-default configuration options including the name.
Pool Members Pool members are, conceptually, the actual application service that you load balance traffic to. Pool members are nodes and an associated service port (TCP or UDP listening port) that are added to a pool and have traffic load balanced across them. In other words, you can say that a pool member is the server-side listener. A pool member is uniquely identified by its IP address, service port and pool name. The members of a pool can also be members of other pools using the same or a different service port.
Pools A Pool is very similar to a server farm or cluster. It is a logical object that contains one or more pool members that traffic is load balanced across. With very few exceptions, all of the members contained in a pool serve the same content. Pools have many configuration options including Health Monitors and the Load Balancing Method itself. Whenever traffic has been received by a virtual server and it is ready to pass traffic on to the pool member, the BIG-IP system will send the traffic to the pool and this is where the actual load balancing takes place. The pool will choose the best available member based on health monitors and the configured load balancing algorithm.
130 130
When adding pool members to a pool, you can either manually add them or choose from a list of previously configured nodes, but the service port must be specified in all cases. A pool is assigned to a virtual server as the Default Pool unless it will be used as a Clone or Last Hop Pool. You should note that a virtual server isn’t required to have a default pool configured. Also, a pool can still be used even if it is not assigned to a Virtual Server, as it can be referenced using an iRule or a Local Traffic Policy. The Local Traffic Policies feature was introduced in version 11.4 and is an upgraded version of HTTP Class. It has similar features to that of an iRule where you can manipulate traffic based upon certain match conditions such as HTTP header, HTTP URI, HTTP host and perform actions when matched. You can for instance enable or disable compression, forward traffic to a specific pool/node or perform redirects. The huge benefit of using Local Traffic Policies is that they evaluate conditions in parallel, making them faster than iRules. They are also considered to be built-in functions making them preferred over iRules.
Virtual Servers As we previously mentioned, the BIG-IP system is a default deny device. In order for it to take in and process traffic you have to configure a listener. A virtual server is one type of listener. Virtual servers are made up of a virtual IP address and a service port that the BIG-IP systems listens to and receives traffic on. A virtual server configured with a specific IP address is referred as a host virtual server. However, a virtual server can also be configured to listen on a network address, referred to as a network virtual server. How you configure your virtual server to listen really depends on how your application is running and what requirements you have. For a standard virtual server setup listening on a specific port using the TCP protocol, the traffic usually flows in the following manner: 1. 2. 3. 4. 5. 6.
A client wishing to access the application establishes a connection to the virtual server IP address (typically provided via DNS resolution). If the incoming request (a SYN packet) matches the IP address and service (port) of a virtual server then it permits the packet and processes it. Since the BIG-IP system is utilising a full proxy architecture it completes the three-way handshake and establishes a TCP connection with the client. Once the TCP connection is established and the client has sent an application request, the virtual server will load balance it to a particular pool member, decided by the configured load balancing algorithm. Again, since the BIG-IP system is utilising a full proxy architecture, a new TCP connection will be established between the BIG-IP and the pool member on the service (port) that the pool member is listening on. Once established, the BIG-IP system will create its own application request containing the same payload as the client’s and sent it to the pool member. This is because the client-side and server-side connection are completely separate.
It is very important to remember that the BIG-IP system utilises a full proxy architecture and that traffic is actually being listened to on the client-side and server-side of the connection. On the client-side the BIG-IP system is listening for traffic using the virtual server and its associated service (port). On the server-side the pool member is listening for traffic on its associated service (port).
131 131