Skip to main content

F5 Networks TMOS Administration Study Guide

Page 1

Disclaimers This book is in no way affiliated, associated, authorized, endorsed by F5 Networks, Inc. or any of its subsidiaries or its affiliates. The official F5 Networks web site is available at www.f5.com. F5, Traffix, Signaling Delivery Controller, and SDC are trademarks or service marks of F5 Networks, Inc., in the U.S. and other countries. A full list of F5 Networks’ marks can be found at https://f5.com/about-us/policies/trademarks. Trademarks used with permission of F5 Networks, Inc. This book refers to various F5 marks. The use in this book of F5 trademarks and images is strictly for editorial purposes, and no commercial claim to their use, or suggestion of sponsorship or endorsement, is made by the authors or publisher.

Permission Notice The F5 Certified logo used on the front cover of this book is a registered trademark of and is copyright F5 Networks, Inc. F5 Networks, Inc has granted this book’s authors permission to use the logo in this manner.

www.f5books.eu Copyright © 2018 by F5 Books - Philip Jönsson & Steven Iveson All rights reserved. This book or any portion thereof may not be reproduced or used in any manner whatsoever without the express written permission of the authors except for the use of brief quotations in a book review or scholarly journal. First Printing: 2018 ISBN: ISSU_v2 Revision: 2018.v2

2 2


TABLE OF CONTENT Preface

34

About the Authors

34

Dedications

34

Acknowledgements

35

Feedback

36

1. Introduction

37

Who is This Book for?

37

How This Book is Organised

37

F5 Networks the Company

39

F5 Terminology

43

What is BIG-IP?

43

BIG-IP Hardware

43

BIG-IP Software – TMOS

44

TMOS Components in Detail

46

TMOS Planes

48

BIG-IP Hardware Platforms

48

Appliances

49

VIPRION

56

Herculon

59

BIG-IP Virtual Edition (VE)

59

The Different F5 Modules, Products & Services

60

3 3

Overview

60

Access Policy Manager (APM) Module

61

Advanced Firewall Manager (AFM) Module

62

Application Acceleration Manager (AAM) Core Module

62

Application Acceleration Manager (AAM) Full Module

63

Application Security Manager (ASM) Module

63


Application Visibility and Reporting (AVR)

64

BIG-IQ Centralised Management Product

65

BIG-IQ Cloud & Orchestration Product

66

Carrier Grade NAT (CGNAT) Module

66

Edge Gateway Product

67

Enterprise Manager (EM) Product

67

DNS (formerly Global Traffic Manager (GTM)) Module

67

IP Intelligence Service

68

Link Controller Product (& Module)

69

MobileSafe Product & Service

69

Policy Enforcement Manager (PEM) Module

69

Secure Web Gateway (SWG) Module & Websense Cloud-based Service

70

Silverline Cloud-based Service

70

WebSafe Service & Module

70

DDoS Hybrid Defender (Herculon)

71

SSL Orchestrator (Herculon)

71

Free and/or Open Source Products

71

Bigsuds

72

iControl REST Software Development Kit (F5-SDK)

72

Ansible

72

Containers

72

OpenStack

72

Cloud - AWS

73

Cloud - Azure

73

Cloud - GCP

73

The Full Application Proxy

73

The Packet Based FastL4 Proxy

75

4 4


OneConnect

76

2. The TMOS Administrator Exam

78

The F5 Professional Certification Program

78

Why Become Certified?

79

Choosing a Certification

80

Getting Started

80

Taking Exams

81

Additional Resources

81

Practice Exams

81

Additional Study Material

81

AskF5

81

DevCentral

82

F5 University

82

Exam Blueprints

82

BIG-IP LTM Virtual Edition (VE) Trial

82

BIG-IP VE Lab Edition

82

BIG-IP VE on Amazon Web Services (AWS)

83

Other Clouds

83

3. Building Your Own Lab Environment

84

Obtaining the Different Components to Build Your Lab

84

VMware Workstation Playerâ„¢

84

BIG-IP VE Trial Evaluation Key

85

Downloading the BIG-IP VE Machine

85

BIG-IP VE Lab Edition

85

The Lab Architecture

85

Lab Exercises: Setting up Your Lab Environment

87

4. Introduction to LTM - Initial Access and Installation

5 5

107


The BIG-IP LTM Module

107

Initial Setup

107

Configuring the Management Port IP Address

107

Configuration via the LCD Panel

108

Configuring the Management IP address Using the Touch LCD Panel (iSeries platforms)

108

Configuration Using the Config Command

109

Configuration Using TMSH

110

Configuration Using the WebGUI

111

Licensing the BIG-IP System

111

Automatic License Activation

112

Manual License Activation

113

Provisioning

114

The Setup Utility

115

Self-IP Addresses

115

Lab Exercises: Initial Access and Installation

116

Chapter Summary

126

Chapter Review

127

Chapter Review: Answers

128

5. Local Traffic Objects

130

Nodes

130

Pool Members

130

Pools

130

Virtual Servers

131

Wildcard Virtual Servers

132

Local Traffic Objects Dependencies

133

The Different Types of Virtual Servers

136

Standard Virtual Server

137

6 6


Connection Setup with a Standard Virtual Server Using Only a Layer 4 Profile

137

Connection Setup with a Standard Virtual Server Using a Layer 7 Profile

138

Performance Layer 4 Virtual Server Connection Setup with a Performance Layer 4 Virtual Server Performance HTTP Virtual Server

139 139 141

The Fast HTTP Profile

141

Connection Setup with a Performance HTTP Virtual Server

142

Performance HTTP Virtual Server With an Existing Idle Server-Side Connection

142

Forwarding IP Virtual Server Connection Setup with a Forwarding IP Virtual Server Forwarding Layer 2 Virtual Server Connection Setup with a Forwarding Layer 2 Virtual Server

145 145 146 146

Reject Virtual Server

148

DHCP Relay Virtual Server

148

Stateless Virtual Server

149

Internal Virtual Server

149

Message Routing Virtual Server

151

Chapter Summary

151

Chapter Review

152

Chapter Review: Answers

154

6. Load Balancing Methods

156

Member vs. Node

156

Static Load-Balancing

157

Round Robin

158

Ratio

158

Dynamic Load-Balancing

161

Least Connections

7 7

161


Fastest

162

Least Sessions

163

Ratio Sessions

163

Ratio Least Connections

165

Weighted Least Connections

168

Observed

169

Predictive

169

Dynamic Ratio

169

Priority Group Activation

170

FallBack Host

175

Lab Exercises: Load Balancing

175

Chapter Summary

186

Chapter Review

187

Chapter Review: Answers

190

7. Monitors

192

Overview

192

Health Monitors

193

Performance Monitors

193

Intervals & Timeouts

193

Temporarily Failed Monitors

196

Where Can You Apply Health Monitors?

196

Monitoring Methods

200

Simple Monitoring

200

Active Monitoring

200

Passive Monitoring

200

Benefits and Drawbacks With Passive and Active Monitoring

202

Active Monitoring

8 8

202


Passive Monitoring Types of Monitors

203

Application Check Monitors

204

Content Check Monitors

205

Performance Check Monitors

206

Path Check Monitors

206

Service Check Monitors

208 209

Slow Ramp Time

209

Multiple Monitors & the Availability Requirement

209

Manual Resume

210

Monitor Reverse Option

210

Monitor Instances

210

Administrative Partitions

210

Firewalls

210

Testing

211

Monitors - Logging

211

Enable Monitor Logging on Node Level

211

Enable Monitor Logging on Pool Member Level

212

Enabling Monitor Logging for SNMP DCA/DCA Base

212

Disabling Monitor Logging for SNMP DCA/DCA Base

212

Object Status

9

202

Address Check Monitor

Monitors - Advanced Options

9

202

213

The Different Object Status Icons

213

Object State

214

Understanding Object Status Hierarchy

215

When Will the BIG-IP System Send Traffic to a Node/Pool Member?

220


Local Traffic Summary

220

Local Traffic Network Map

221

Filtering Results

221

Verifying Object Status

222

Using the CLI (tmsh) to Verify Object Status

223

Monitor Status Logging

223

Enabling Monitor Status Logging

223

Disabling Monitor Status Logging

224

Monitor Status Changes in the BIG-IP LTM Log

225

Lab Exercises: Monitors

225

Chapter Summary

232

Chapter Review

233

Chapter Review: Answers

235

8. Profiles

237

Why Use Them?

237

Profile Types

237

Protocol Profiles

238

Persistence Profiles

238

SSL Profiles

238

Application (Services) Profiles

238

Remote Server Authentication Profiles

239

Analytics Profile

239

Other Profiles

239

Profile Dependencies

239

Default and Custom Profiles

242

10 10

Creating a Custom Profile

244

Deleting a Custom Profile

244


Assigning Profiles to a Virtual Server

244

Lab Exercises: Profiles

246

Chapter Summary

253

Chapter Review

254

Chapter Review: Answers

256

9. Persistence Concept of Stateless and Stateful Applications

257 257

Sessions

257

Stateful Communication With Load Balancing

257

What is Persistence?

258

Persistence Methods

258

Source Address (aka Simple) Persistence

258

Cookie Persistence

262

Destination Address Persistence

269

Hash Persistence

269

Universal Persistence

270

Other Persistence Profiles

270

Single Node Persistence Configuration Verification

270 275

Primary & Fallback Methods

275

Match Across

276

Match Across Services

276

Match Across Virtual Servers

278

Match Across Pools

278

Persistence Mirroring

279

Lab Exercises: Persistence

279

Chapter Summary

287

11 11


Chapter Review

287

Chapter Review: Answers

290

10. SSL Traffic

293

Terminology of SSL

294

Certificate Authority (CA)

294

Certificate Signing Request (CSR)

294

Personal Information Exchange Syntax #12 (PKCS#12)

295

Managing SSL Certificates for the BIG-IP System Using the WebGUI

295

Procedures

296

Creating a Self-Signed SSL Certificate

296

Creating a Certificate using a CSR

296

Importing an SSL Certificate

298

Importing an SSL Private Key

298

Importing a PKCS#12 File

299

Renewing a SSL Certificate Using a CSR

299

SSL/TLS Offloading

300

The Client SSL Profile

302

Creating a Custom Client SSL Profile

303

SSL Bridging Creating a Custom Server SSL Profile

303 304

SSL Passthrough

305

Certificate Authorities

306

Intermediate CAs and the Certificate Chain

307

Importing Certificates & Constructing the Certificate Chain in the BIG-IP System

308

Importing the CA Certificates

308

Creating the Client SSL Profile With a Certificate Chain

310

Lab Exercises: SSL Traffic

12 12

310


Chapter Summary

316

Chapter Review

317

Chapter Review: Answers

318

11. NAT and SNAT

320

Network Address Translation – NAT

320

Traffic Flow When Using a Virtual Server on Inbound Connections

322

Traffic Flow When Using NAT on Inbound Connections

323

Traffic Flow When Using NAT on Outbound Connections

324

Disadvantages of Using NAT

325

NAT Traffic Statistics

326

Source Network Address Translation – SNAT

13 13

327

Why We Need SNAT

327

Typical Uses of SNAT

329

Pool Member’s Default Gateway is Not the BIG-IP system

329

Both Client and Pool Member Reside on the Same Network

333

Internal Nodes in a Private Subnet Need to Share One External IP Address

336

How to Configure SNATs

337

SNAT Listener

337

SNAT Translation List

337

SNAT With a Virtual Server

338

SNAT Pool

338

SNAT Auto Map

340

How to Enable SNAT Auto Map on a Virtual Server

342

Potential Issues for Server Applications When SNAT Translation is Used

342

Port Exhaustion

342

How to Change the Source Port Preservation for Virtual Servers

343

Socket Pairs

344


Port Exhaustion on a Virtual Server

344

Monitoring Port Exhaustion

345

Lab Exercises: NAT and SNAT

345

Chapter Summary

348

Chapter Review

349

Chapter Review: Answers

350

12. High Availability

352

Configuring a Sync-Failover Pair

353

Device Trust

353

The Different Types of Trust Authorities

353

The Importance of the BIG-IP Device Certificates

354

Device Identity

355

The Device Discovery Process in a Local Trust Domain

355

Important When Configuring a Device Trust

355

Adding a Device to a Local Trust Domain

356

Resetting the Device Trust

356

Device Groups

356

Sync-Only Device Group

357

Sync-Failover Device Group

357

Administrative Folders

357

Floating Self-IP Addresses

357

MAC Masquerading

358

Synchronising the Configuration

358

The CMI Communication Channel in Detail

359

ConfigSync Operation in Detail

360

Determine the State of a System

361

Force to Standby Mode

361

14 14


WebGUI – Method 1

362

WebGUI – Method 2

362

WebGUI – Method 3

362

CLI - tmsh

362

Traffic Groups

362

The Default Traffic Groups on a BIG-IP System

363

Traffic Group Failover Methods

364

Load Aware Failover

364

How to Specify the HA Capacity

365

How to Specify the HA Load Factor

366

Calculation Example

367

HA Order

369

HA Groups

370

Auto-Failback Auto-Failback Feature is Not Compatible With HA Group

371 372

Force to Standby Feature is Not Compatible with HA Group

372

Active-Active Redundancy

372

Failover Options

378

HA Table VLAN Failsafe

378 379

Using the High-Availability Screen

381

Using the VLANs Screen

381

Gateway Failsafe

381

Failover Detection

381

Device Group Communication

381

15 15

Hardware Failover

381

Network Failover

382


Network Communication

382

Stateful Failover

382

Connection Mirroring

383

Persistence Mirroring

383

SNAT Mirroring

383

Considerations Regarding Stateful Failover

384

How to Configure Stateful Failover

384

Specifying an IP Address for Connection Mirroring

384

Enabling Connection Mirroring on a Virtual Server

385

Enabling Connection Mirroring for SNAT Connections

385

Enabling Mirroring of Persistence Records

385

Lab Exercises: High Availability

385

Chapter Summary

406

Chapter Review

407

Chapter Review: Answers

409

13. The Traffic Management Shell (tmsh)

412

Accessing the Traffic Management Shell (tmsh)

412

Understanding the Hierarchical Structure of tmsh

414

The tmsh Prompt

415

Navigating the tmsh Hierarchy

415

Command Completion Feature

416

Perform Wildcard Searches in tmsh

417

Context-Sensitive Help

417

Manual Pages

418

Command History Feature

419

The tmsh Keyboard Map Feature

419

Managing BIG-IP Configuration State and Files

420

16 16


Introduction to BIG-IP Configuration Files and Structure

421

Text Configuration Files

423

Binary Configuration Files

424

Loading and Saving the System Configuration

425

Administrative Partitions

426

How Do Administrative Partitions Work?

427

Referencing Object in Different Partitions

428

Limitations With Administrative Partitions

429

Navigating Between Partition

429

How to Create Administrative Partitions

430

Effect of Load/Save on Administrative Partitions

430

User Roles

430

Creating Local User Accounts

432

Modifying the Properties of a Local User Account

433

Shutting Down and Restarting the BIG-IP System

434

Using Advanced Shell (bash)

434

Viewing the BIG-IP Connection Table in tmsh

435

About the Connection Table

435

Connection Reaping

435

Viewing the Connection Table

435

Filtering Using awk and grep

437

Additional Help Tmsh on DevCentral

437 437

Lab Exercises: tmsh

438

Chapter Summary

442

Chapter Review

443

Chapter Review: Answers

445

17 17


14. File Transfer

447

Linux Client - Sending Files - SCP

447

Linux Client - Retrieving Files - SCP

448

Common SCP Errors

448

Linux Client - Connecting - SFTP

448

Linux Client - Sending Files - SFTP

449

Linux Client - Retrieving Files - SFTP

449

Key Based Authentication

450

Windows Clients

452

15. Selected Topics Always On Management (AOM)

453 453

Accessing AOM Through the Serial Console

453

Accessing AOM Through the HMS Via SSH

453

Directly Connecting to the AOM Via SSH

454

The Command Menu

455

iRules

455

When Should You Use an iRule?

456

When Should You Not Use an iRule?

456

iRule Components

456

Event Declarations

457

Operators

457

Rule Commands

458

iRule Events

458

HTTP Events Data Groups Lists

18 18

459 460

What Are the Benefits of a Data Group?

461

How Do I Use Data Group Lists?

461


Creating Your iRule

462

The iRule Editor

462

Learn more

463

iRule Wiki

463

CodeShare

463

Additional Literature

463

iApps

463

iApps Framework

464

Templates

464

Application Services

464

Strict Updates Disabling Strict Updates What is a Route Domain?

465 465 466

Benefits of Using Route Domains

466

Route Domain IDs

467

Parent ID

467

About VLANs and Tunnels for a Route Domain

468

About Default Route Domains for Administrative Partitions

468

Creating a Route Domain

469

Lab Exercises: iRules

470

Chapter Summary

475

Chapter Review

476

Chapter Review: Answers

478

16. Troubleshooting Hardware

479

Introduction

479

End User Diagnostics (EUD)

479

Obtaining the Latest EUD Software

19 19

479


Installing EUD on the BIG-IP Device

480

Creating an EUD Bootable CD-ROM

480

Creating an EUD Bootable USB Storage Device

480

Launching EUD

480

Running Tests

481

Viewing Output

482

LCD Warning Messages

482

LED Indicators

483

The Power LED Indicator

483

The Status LED Indicator

483

The Activity LED Indicator

483

The Alarm LED Indicator

484

Modifying alert.conf

484

Backing up the Original alert.conf

485

Clearing Alerts

486

Clearing the LCD Warnings and Alarm LED Remotely (Using the CLI)

486

Clearing the LCD Panel

486

Clearing the Alarm LED

487

Log Files

488 Priorities

490

Facilities

490

Perform a Failover

492

Consequences of Performing a Failover

494

How to Perform a Failover

495

WebGUI

495

CLI - tmsh

495

Troubleshooting System Interfaces

20 20

495


The Network Components Hierarchy

495

The System Interfaces

497

Link Layer Discovery Protocol (LLDP)

497

The Interface Properties

498

The Interface Naming Convention

498

Viewing Interface Information

499

Interface State

499

Flow Control

500

VLANs

500 Assigning Interfaces to VLANs

500

Port-based Access Method

501

Tag-based Access Method

501

Creating and Managing VLANs

502

VLAN Groups

502

Transparency Mode

503

Bridge All Traffic

503

Bridge in Standby

503

Creating a VLAN Group

503

Associating a VLAN/VLAN Group With a Self-IP address Creating a Self-IP address Trunks

21

504 504

How Trunks Work

505

Link Aggregation Control Protocol (LACP)

505

Creating a Trunk

506

Troubleshooting Network Issues

21

504

506

Network Statistics

506

Troubleshooting Packet Drops

507


Troubleshooting Interface Packet Drops

507

Troubleshooting TMM Packet Drops

509

Known Issues

511

Chapter Summary

511

Chapter Review

512

Chapter Review: Answers

514

17. Troubleshooting Device Management Connectivity

515

Get to Know Your Environment

515

Verify the Configuration

516

Tools Available for Troubleshooting

516

Ping

516

Traceroute

517

Telnet

517

cURL

518

Verifying the Processes on the BIG-IP device

519

Verifying That the sshd Process is Running Using the WebGUI

519

Verifying That the Web Processes is Running Using SSH

519

Port Lockdown

521

Port Lockdown Exceptions

523

Configuring Port Lockdown

524

Restricting Access to the Management Port

525

Packet Filters

526

Exemptions

529

Creating Packet Filter Rules

530

Reordering Packet Filter Rules

530

Logging of Packet Filter Rules

531

Troubleshooting DNS Settings

22 22

531


Verify the DNS Configuration

531

Tools Available for Troubleshooting DNS

532

nslookup

532 Common Error Messages

dig

533 534

Changing Resource Types

536

Limiting the Output

536

Perform Reverse Lookups

537

Query Another DNS Server

537

Performing Multiple Lookups

537

dig Parameters

537

Remote Authentication Introduction

538

The LDAP Authentication Module

538

The RADIUS Authentication Module

538

The TACACS+ Authentication Module

539

The SSL Client Certificate LDAP Authentication Module

539

The SSL OCSP Authentication Module

539

The CRLDP Authentication Module

540

The Kerberos Delegation Authentication Module

540

The Network Time Protocol (NTP) Configuring an NTP Server Troubleshooting NTP

540 541 541

Verifying the NTP daemon service

541

Verifying the Communication Between the BIG-IP System and the NTP Peer Server

541

Verifying the Network Connectivity to the NTP Peer Server

543

Chapter Summary

543

Chapter Review

543

23 23


Chapter Review: Answers

18. Troubleshooting and Managing Local Traffic Traffic Processing Order

545

547 547

Control Plane Functions

547

Packet Processing Order

547

Listener Processing Order

548

Managing & Troubleshooting Virtual Servers & Pools

550

Managing Virtual Servers

550

What Protocols Does the Application Use?

550

On What VLAN Will the Client Access the Application?

551

How Should the BIG-IP System Handle SSL Connections?

553

SSL Cipher Suites

553

SSL Cipher Mismatch

554

Managing Pool Members Monitoring

555 555

Troubleshooting Virtual Servers

556

DNS record

556

Is the Traffic Reaching the BIG-IP System?

556

Check the Status of the Virtual Server

557

What Error Are You Getting When Accessing the Virtual Server?

557

Troubleshooting Pool Members Impact When Modifying the Configuration

559

Changes Not Taking Effect Immediately

559

Taking a Pool Member/Node Offline

24 24

558

559

Disabled

559

Forced Offline

560

Deleting Existing Connections to a Pool Member

561


Deleting Existing Connections to a Node

561

RST Logging

561

Persistence Issues

562

OneConnect

562

Pool Member Failure

562

Troubleshooting Persistence Issues

562

Chapter Summary

566

Chapter Review

566

Chapter Review: Answers

568

19. Troubleshooting Performance Packet Captures

25

570

Why Should We Capture Packets?

570

When Should We Capture Packets?

570

Where Should We Capture?

570

What Are We Looking For?

571

Expected TCP/IP Behaviours

573

Using tcpdump

25

570

573

Limitations

573

Usage Syntax

574

Specifying an Interface

574

Capturing Additional TMM Information

575

Default Output

575

Writing to a File

576

Restricting the Number of Packets Captured

576

Quick Mode

577

Verbose Mode

577

Capturing Link Level (Layer 2 – Data Link) Headers

577


Capturing Packet Contents – Format

578

Capturing Packet Contents – How Much?

579

Disabling DNS Lookups

579

Also Disabling Service Name Lookups

579

Reading from a File

580

tcpdump Expressions

580

Logical Operators

581

Grouping

582

Single Host

583

Multiple Hosts

583

Single Network

585

Multiple Networks

585

Specific Protocol Port(s) & Direction

587

Address Resolution Protocol (ARP)

588

ICMP

589

Refining That First Example Further

589

A Common Example

590

tcpdump Output

591

Generic TCP

591

Generic UDP

593

Notes on the Protocol Field

594

Notes on Service Ports

595

Protocol Formatting

595

Fragmented Packets

595

Using Wireshark

26 26

596

Opening Capture Files

599

Getting Around

600


The F5 Wireshark Plugin

601

Decodes & Non-standard Ports

605

Display Filters

606

Red Herrings

609

Further Reading

609

Other BIG-IP Tools

609

Monitors

609

The Performance Dashboard

609

Performance Statistics in the GUI

610

Performance Statistics at the CLI

612

AVR

613

iHealth

614

SNMP

614

Chapter Summary

614

Chapter Review

615

Chapter Review: Answers

616

20. Opening a Support Case with F5 Information Required When Opening a Support Case With F5

27 27

618 618

Full Description of the Issue

618

Severity Levels

619

QKview

620

Generating a QKview file

621

Generating a QKview on a High Load BIG-IP System

621

iHealth

622

Log Files

624

Packet Traces (tcpdump)

624

SSL Dump

624


UCS Archives

624

Core Files

625

Assembling an Accurate Problem Description

625

Quantitative Vs. Qualitative Observations

625

Relevant Vs. Irrelevant Information

626

How to Open a Support Case with F5 Support

626

Escalation Methods

628

Chapter Summary

629

Chapter Review

630

Chapter Review: Answers

632

21. Identify and Report Current Device Status

634

The Dashboard

634

Interpreting Log Files

636

Health Monitor Failure

636

High Availability Communication Failure

638

VLAN Failsafe

641

Configuration Sync

641

TMM Core Dump

642

Analytics

643

Analytics Profiles

644

How to Configure Analytics to Collect Data

645

Reviewing and Examining the Application Statistics

646

Investigating Server Latency

648

Investigating Page Load Times

649

Capturing Traffic using Analytics

649

Reviewing Captured Traffic

650

Chapter Summary

652

28 28


Chapter Review

653

Chapter Review: Answers

654

22. Device Maintenance

656

Archive Files

656

The Single Config File (SCF)

656

Example of Data Contained in a SCF file The User Configuration Set (UCS) Archive

657 657

Generating a UCS Archive - WebGUI

658

Loading a UCS Archive – WebGUI

658

Generating a UCS Archive – tmsh

659

Loading a UCS Archive – tmsh

659

Customising What Files Are Included in the UCS Archive

659

The Differences Between UCS and SCF

660

Restoring a BIG-IP System From a UCS Archive

661

Licensing Considerations When Restoring From a UCS Archive

661

Other Considerations When Restoring From a UCS Archive

661

Preventing Synchronisation When Installing a UCS Archive on a BIG-IP DNS (GTM) system

662

Delayed Load on BIG-IP ASM Module

663

vCMP Considerations When Restoring From a UCS Archive

663

Preventing Service Interruptions When Replacing a BIG-IP System in a Redundant Pair

663

Managing Software Images and Upgrades

664

Legacy Version Numbering Schema

664

Major Software Versions

664

Minor Software Versions

664

Maintenance Software Versions

664

Cumulative Hotfixes

664

The Tick Tock Release Cycle

665

29 29


Release Notes

666

Overview of the Disk Management Process

667

The BIG-IP Hard Disk and Boot Locations

667

Software Images

668

How to Install a New Software Image

669

Determine the Software Image to Install

670

Downloading the Software Images/Hotfixes

670

How to Import the Software Images/Hotfixes to the BIG-IP system.

671

Checking the MD5 Checksum of an Image File

671

Re-activate the License Prior to the Upgrade

672

Installing the Software Image

673

Installation Using the WebGUI

673

Installation Using tmsh

674

When Installing a Software Image

674

When Installing a Hotfix

675

Booting the BIG-IP System Into the New Volume

675

Rolling Back to a Previous Version

676

Handling the Configuration Between Volumes

676

Best Practices When Upgrading a BIG-IP System in a HA-pair

678

Potential Problems When Upgrading Your BIG-IP system

679

Enterprise Manager (EM)

681

Performing Basic Device Management

681

Adding Devices to Enterprise Manager

681

The Discovery Process

681

Discovering BIG-IP devices

682

Discovering non-BIG-IP Devices.

683

Performing Basic Tasks on Managed Devices

30 30

684


Verifying and Testing Device Communication

684

Verifying the Enterprise Manager IP Address on a Device

684

Verifying Device Connection to Enterprise Manager

686

Rebooting Managed Devices

686

To Reboot a Device Into a Different Boot Location

686

Managing Licenses Starting a Device Licensing Task

687

Accepting the EULA for Devices

688

Configuring Task Options and Running the Task

688

Collecting Information for F5 Support Starting a Support Information Gathering Task Managing UCS Archives

31

688 689 690

Maintaining Rotating UCS Archives

690

Increasing the Maximum Rotating Archives

690

Changing the Default Archive Options

690

Creating Rotating Archive Schedules

691

Modifying Rotating UCS Archive Schedules

692

Maintaining Specific Configuration Archives

692

Creating a New Pinned Archive

693

Pin an Already Existing Archive

693

Restoring UCS Archives for Managed Devices

693

Performing a UCS Restoration for a Managed Device

693

Deleting UCS archives

694

Comparing Multiple Versions of UCS Archives

694

Creating an Archive Comparison Task

694

Searching for Specific Configuration Elements

695

Managing Software Images

31

687

695


Reviewing Available Software Downloads

696

Adding and Removing Software Images/Hotfixes on the Enterprise Manager

696

Adding an Image/Hotfix to the Software Repository

696

Removing an Image/Hotfix to the Software Repository

696

Copying and Installing Software to Managed Devices

697

Copying Software to Be Installed at a Later Date

697

Installing a Software Image

698

Monitoring and Alerts

699

Managing the Task List

700

Overview of Alerts

700

Setting Alert Default Options

701

Creating Alerts for Enterprise Manager

702

Creating, Modifying, and Deleting Alerts for Devices

702

Creating a Device Alert

702

Modifying a Device Alert

703

Deleting a Device Alert

704

Monitoring Certificates

704

Disabling Certificate Monitoring

704

Enabling Certificate Monitoring

704

Viewing Certificate Information

705

Accessing the Certificate Screen

705

The Certificate Status Flag

706

Creating a Device Certificate Alert

706

BIG-IQ

706

The BIG-IQ Panels

707

The BIG-IQ Device/System Management Panels

707

The BIG-IQ Application Delivery Controller (ADC) Panel

708

32 32


The BIG-IQ Web Application Security Panel

708

The BIG-IQ Network Security Panel

708

The BIG-IQ Access Panel

708

BIG-IQ Device and System Management

709

Installing Required BIG-IQ System Components – Updating the REST Framework

709

Device Discovery

710

License Management

711

BIG-IP System Software Upgrades

712

Uploading Software Images

712

Performing a Managed Device Install

712

Rebooting Managed Devices

714

UCS File Backup and Restoration

714

Creating an Instant Backup

714

Creating Scheduled Backups

715

Restoring a UCS File Backup

716

Monitoring and Alerts

717

Configuring BIG-IQ to Work With SNMP

717

Configuring SNMP Agent for Sending Alerts

718

Configuring SNMP Access for Version 1 and 2C

718

Configuring SNMP Access for Version 3

718

Configuring SNMP Traps

719

SSL Certificate Monitoring

719

Chapter Summary

720

Chapter Review

721

Chapter Review: Answers

722

Index

33 33

724


Preface About the Authors Philip Philip Jönsson was born in Malmö City, Sweden 1988 where he still lives with his family. He gained an interest in technology at an early age. When he was eight years old the family got a home PC, which was the first step in his career. Since Philip had a big interest in technology, choosing his education was easy. His IT studies started at The Nordic Technical Institute (NTI) where he studied the basics of computer technology and eventually focused on network. Later on he studied IT-security at Academedia Masters. Philip’s first job in the IT business was at a home electronics company in Sweden. He worked at the IT department and was responsible for managing and troubleshooting the sales equipment in the stores and managing the IT infrastructure within the organisation. This is where Philip first encountered a BIG-IP controller. Philip eventually started working in a Technical Assistance Center (TAC) department at an IT security company. Now Philip works as a consultant focused on F5 products in a department at one of the largest IT security company in Europe and handles major projects and solves problems for Sweden's most well-known companies. Steve Steven Iveson, the last of four children of the seventies, was born in London and was never too far from a shooting, bombing or riot. He’s now grateful to live in a small town in East Yorkshire in the north east of England with his wife Sam and their four children. He first encountered a BIG-IP Controller in 2004 and has been working with TMOS and LTM since 2005. Steve’s iRules have been featured in four DevCentral articles and he’s made over 3000 posts on the DevCentral forums. He's been awarded F5 DevCentral MVP status four times in 2014, 2016, 2017 and 2018. Steve’s worked in the IT industry for over twenty years in a variety of roles, predominantly in data centre environments. In the last few years he’s widened his skill set to embrace DevOps, Linux, Docker, automation, orchestration and more. He also blogs on subjects including Linux, programming, application delivery and careers at packetpushers; a community of bloggers that contribute technical, work life, and opinion articles from the customer’s perspective.

Dedications Philip I would like to dedicate this book to my wife Helena and my family for their support throughout the writing of this book. Thank you for your patience throughout the making of this book! Steve For Mark. You made it.

34 34


Acknowledgements We would like to thank everyone who participated in the beta program for this book. The great feedback has helped us make this the best book possible. Special thanks to these outstanding contributors (in no particular order): ▪ ▪ ▪

Scott Campbell, Canada Hannes Rapp, Portugal Thomas Domingo Dahlmann, Denmark

Philip First off, I would like to thank Holger Yström for promoting my first book. With his help, the first and original study guide was acknowledged by many F5 representatives and made it all the way to the corporate headquarters in Seattle. Without his help the original Study Guide would not have become this big. A big thanks to my mentor, colleague and great friend Thomas Domingo Dahlmann who has been an invaluable asset throughout the making of this book. Thomas has assisted with proof reading our material and providing swift and great feedback, solely on his spare time. Both me and Steven are forever grateful! During the beta program for this book, I came in contact with Scott Campbell whom I also want to thank. The work you put into the proof reading is just astonishing and seeing that kind of enthusiasm is truly inspiring. You have really helped us with raising the quality of this book and we are truly grateful for that. I would also like to thank my employer SecureLink for giving me the opportunity to widen my knowledge and experience of F5 products. Thanks to my department for the encouragement and support throughout the writing of this book. Thanks to the Designerz who created the cover and the design of the book, you did a great job! Thanks to F5 for making this possible and for all the help we’ve got in making this book. An honourable mention is Kenneth Salchow, Julio Hevia Posada and James Dean. You have all been great to work with and have always provided us with great input and assistance. Finally, I would like to thank Steven Iveson for wanting to participate in this collaboration. Your contribution to this book has truly raised its value and it has been a pleasure working with you. Steve We all stand on ‘the shoulders of giants’. We’ve both put a huge amount of time and effort into this book and every sentence requires research, reading, testing and time to understand and contextualise. None of that would be possible without the incredible information and tools we now have at our disposal. The contributions of countless people and entire generations, programs, movements, ideas and even cultures have all played a part. From the Internet to Ethernet to the road network and back to the Magna Carta; this book wouldn’t have been possible without them.

35 35


Thanks to the many who’ve taken the time to contribute to DevCentral (DC) to inform, educate and assist others, myself included. A special mention to Colin Walker (now with Extrahop) and these F5 staff members and DC contributors: Joe Pruitt (username: Joe) who created DevCentral, Aaron Hooley (username: hoolio) who’s made over twelve thousand posts on DC, Nitass Sutaveephamochanon (username: nitass) and Kevin Stewart. Again, thanks to Philip for making this book happen in the first place.

Feedback If you have any comments, corrections or feedback regarding this book, feel free to send an email to feedback@f5books.eu. Philip You are very welcome to connect on Linkedin. You can find my public profile at: https://www.linkedin.com/pub/philipj%C3%B6nsson/3a/680/810. Steve You can follow me on Twitter: @sjiveson, read my blogs at http://packetpushers.net/author/steven-iveson/ and you’re welcome to connect on Linkedin. You can also follow my work on GitHub: sjiveson and Docker Hub: itsthenetwork. You can also join this book’s Linkedin group by searching Linkedin for: ‘All Things F5’. This is an independent group that is not associated with F5.

36 36


1. Introduction Who is This Book for? This book is designed to provide the reader and student with everything they need to know and understand in order to pass the F5 TMOS Administration 201 exam and become a F5 Certified BIG-IP Administrator. All generic networking, application, protocol and F5 specific topics and elements found in the exam blueprint are covered in full and in detail. No prior knowledge is assumed and the book includes review summaries, over 350 diagrams, over 90 test questions and a number of lab exercises to aid understanding and assist in preparing for the exam. Even those attending official F5 training courses will find this book of benefit as those courses only cover the F5 specific elements of the curriculum.

How This Book is Organised Most readers should read and study this book from start to finish, front to back. As with the official F5 blueprint, things move from the simple and abstract to the more complex and detailed and each topic builds upon the knowledge gained in earlier ones. We’ve ordered the book’s chapters and sections to mostly reflect the order of that exam blueprint, although in a few cases where we’ve felt it’s more appropriate we’ve ignored it. Each chapter starts with a brief overview of the topics that will be covered and many end with a useful review summary as well as some simple questions to test your understanding. The chapters of the book and their contents are as follows; ▪

This chapter, Chapter 1 – Introduction provides the background on F5 Networks the company and its history and overviews of F5 terminology, technologies, hardware and software products.

Chapter 2 – The TMOS Administrator Exam describes the wider technical certification program, the exam and offers a list of useful additional study resources.

Chapter 3 - Building Your Own Lab Environment gives you everything you need in order to set up your own BIG-IP lab environment.

Chapter 4 - Introduction to LTM - Initial Access and Installation introduces you to the BIG-IP system and describes how you perform an initial setup.

Chapter 5 - Local Traffic Objects introduces you to the different local traffic objects such as nodes, pool members, pools and virtual servers. It also describes the different virtual server types.

Chapter 6 - Load Balancing Methods covers all of the different load balancing algorithms and the concept of Member vs. Node.

Chapter 7 - Monitors will in detail, describe all of the different monitors. Along with the many object statuses and states.

Chapter 8 - Profiles covers the profiles which you can assign to the virtual servers. We discuss the different profile types, but we also detail some of the more common ones.

Chapter 9 - Persistence describes what a stateless vs. stateful application is. It also covers all existing profiles and the benefit vs. drawbacks of each.

37 37


Chapter 10 - SSL Traffic introduces you to the different SSL modes that the BIG-IP system support along with some SSL certificate management.

Chapter 11 - NAT and SNAT will discuss how the BIG-IP system handles its adress translation and differences between NAT and SNAT.

Chapter 12 - High Availability describes what is needed to configure your BIG-IP environment in a HighAvailability setup and in detail, explain how the HA communication works.

Chapter 13 - The Traffic Management Shell (tmsh) covers the BIG-IP command line interface and how it is structured.

Chapter 14 - File Transfer teaches you how to transfer files to and from the BIG-IP system.

Chapter 15 - Selected Topics contain random subjects like iRules, AOM and iApps that describes what it is and what it can be used for.

Chapter 16 - Troubleshooting Hardware covers hardware troubleshooting tools such as EUD and log files in depth and explores instigating HA failover.

Chapter 17 – Troubleshooting Device Management Connectivity provides an in-depth review of areas related to remote management covering features and subjects such as DNS, packet filtering, Port Lockdown and many more. The ping and traceroute tools are introduced.

Chapter 18 – Troubleshooting and Managing Local Traffic steps through the process of identifying and resolving issues with local traffic and provides detail on the traffic processing order of operations.

Chapter 19 – Troubleshooting Performance moves on to observing and determining performance related issues and using related tools such as the packet capture program tcpdump.

Chapter 20 – Opening a Support Ticket With F5 explores how to best gather relevant information prior to raising a call, how to provide it to F5, selecting a suitable severity level and escalating cases.

Chapter 21 – Identify and Report Current Device Status covers general operational monitoring through, amongst others, the network map, dashboard, log files and iApps Analytics.

Chapter 22 – Device Maintenance offers information on local configuration backup and restoration, automated remote configuration archiving and dealing with TMOS software image upgrades in a HA environment. It also covers the F5 products BIG-IQ and Enterprise Manager.

The book also contains numerous notifications divided into five categories, as follows: Icon

Text

Description Warning

38 38

You will see this icon and text whenever you should proceed with caution. We'll use this when an instruction might have an impact on the system. Ensure you read this notice before proceeding.


Note

Used whenever additional information is provided to benefit your overall understanding of a topic.

Important

When we need to provide clarity and avoid misunderstanding we'll use this icon and text.

Exam Tip

This icon and text highlight information that is essential or important in order to pass the exam.

Recommendation

Used to indicate a personal recommendation based on our experience managing BIG-IP over many years.

F5 Networks the Company Created as F5 Labs in 1996* by Michael D. Almquist** (aka Mad Bomber and Squish,) a technical entrepreneur and programmer and Jeffrey S. Hussey, an investment banker. F5 released its first HTTP web server load balancing device: the BIG-IP Controller, in 1997. The company, head-quartered in Seattle, Washington since its inception, has grown rapidly to date (barring a lull during the dot.com collapse between 1999 and 2001) and has expanded its product offerings significantly. They now produce a wide range of dedicated hardware and virtualised appliance application delivery controllers (ADCs). As well as load balancing these can provide SSL offload, WAN acceleration, low and high level security functions, application acceleration, firewalling, SSL VPN, remote access and much more. Michael Almquist left the company in May 1998 over a year before the company went public on NASDAQ (symbol: FFIV) in June 1999 and was renamed F5 Networks. By mid-2005, industry analyst firm Gartner reported F5 had captured the highest share of the overall ADC market and by late 2016*** the company earned almost $2 billion in annual revenue and employed over 4,500 people in 59 locations around the world, 1200 in R&D. Refreshingly, they paid tax of $184m for their financial year 2016 in stark contrast to the likes of Google (who have paid £200m on profits (not revenue) of apparently over £7b since 2000 in the UK), Cisco and Starbucks. The company has no long term debt and assets of over $2.3 billion. Services earned just over 52% of revenues compared to products, with the largest sales market being the Americas, followed by EMEA, APAC and Japan. Research and development expenses for the financial year were $334m. According to Netcraft®, in May 2009, 4.26% of all websites and around 3.8% of the top million sites were being served through F5 BIG-IP devices. A look at this Netcraft page: http://uptime.netcraft.com/up/reports/performance/Fortune_100, shows that on 7th February 2014, 20% of the US Fortune 100’s public websites were served through F5 BIP-IP ADCs including those of Bank of America, Dell, Disney, Lehman Brothers, Lockheed Martin, Wachovia and Wells Fargo. The company’s longest servicing President and CEO was John McAdam who held these roles for fifteen years until he was briefly replaced by Manny Rivelo. Manny took the reigns in July 2015 for six months until John McAdam returned on an interim basis. He was finally replaced by François Locoh-Donou in April 2016.

39 39


The company name was inspired by the 1996 movie Twister, in which reference is made to the fastest and most powerful tornado on the Fujita Scale: F5. Significant technical milestones and business events in F5 Networks’ history include; 1895 – Nortel® is founded (as Northern Telecom Limited) 1995 – Brocade® is founded 1996 – F5 is incorporated (February) 1996 – Cisco® launches LocalDirector; technology based on its acquisition of Network Translation Incorporated that same year (the PIX® firewall platform also sprung from this acquisition) 1996 – Foundry Networks® is founded (originally called Perennium Networks and then StarRidge Networks, renamed Foundry in 1997) (later to be acquired by Brocade in 2008) 1996 – Alteon Networks® is founded (later to be acquired by Nortel in 2000) 1997 – F5 Launches its first BIG-IP Controller (July) 1997 – ArrowPoint Communications® is founded by Chin-Cheng Wu (later to be acquired by Cisco in 2000) 1998 – F5 Launches the 3DNS Controller (September) 1998 – Reactivity is founded 1998 – NetScaler is founded 1999 – F5 Goes public on NASDAQ (June) 2000 – Cisco acquires ArrowPoint Communications (at a cost of $5.7b) for their content switching technology which they release as the Content Services Switch (CSS) range the same year but fails to develop the product further 2000 – Redline Networks® is founded (later to be acquired by Juniper in 2005) 2000 – FineGround Networks® founded (later to be acquired by Cisco in 2005) 2000 – MagniFire Websystems® founded (later to be acquired by F5 in 2004) 2000 – Peribit Networks® (WAN optimisation) founded (later to be acquired by Juniper® in 2005) 2000 – Nortel acquire Alteon Networks (at a cost of $6b in stock) (the Alteon application delivery assets later to be acquired by Radware® in 2009) 2001 – The iControl XML-based open API is introduced by F5 with v4 2002 – v4.5 Released and includes the UIE and iRules 2002 – Acopia Networks® founded by Chin-Cheng Wu (who also founded ArrowPoint Communications in 1997) (later to be acquired by F5 in 2007) 2002 – Crescendo Networks® founded (later to have its IP acquired by F5 in 2011) 2003 – F5’s DevCentral Community and technical reference website launched 2003 – F5 Acquires uRoam (at a cost of $25m) for its FirePass technology (SSL VPN, application and user security) 2004 – F5 Acquires MagniFire Websystems (at a cost of $29m) for its web application firewall (WAF) technology TrafficShield, which forms the basis of the ASM product 2004 – F5 releases TMOS v9 and TCL-based iRules 2004 – Zeus Technology® releases Zeus Traffic Manager 2005 – F5 Acquires Swan Labs® (at a cost of $43m) for its WAN optimisation technology (WANJet) 2005 – Juniper Networks purchases Peribit Networks (WAN optimisation) and Redline Networks (ADCs) at a cost of $337m and $132m respectively 2005 – Cisco acquires FineGround Networks (at a cost of $70m) and integrates its technology with the Catalyst switch line to create the ACE product

▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

40 40


2005 – Cisco launch numerous Application-Oriented Networking (AON) products to support the convergence of ‘intelligent networks’ with application infrastructure 2005 – Citrix acquires NetScaler (at a cost of $300m) 2006 – Lori MacVittie joins F5 2007 – Don MacVittie joins F5 2007 – A10 Networks® launches its AX Series family of ADC appliances 2007 – F5 Acquires Acopia Networks (at a cost of $210m) for its file virtualisation technology, which is later rebranded as its ARX range 2007 – Cisco acquires Reactivity (at a cost of $135m) for its XML gateway technology, which they launch as the ACE XML Gateway product the same year 2008 – F5’s VIPRION modular, blade based hardware is released 2008 – Juniper discontinues it’s DX line of load balancers based on the Redline Networks technology acquired in 2005 2008 – LineRate Systems® is founded 2008 – Foundry Networks is acquired by Brocade (at a cost of $2.6b (Brocade originally offered $3b)) 2009 – Nortel ceases operations 2009 – Radware acquire Nortel’s Alteon application delivery assets (at a cost of $18m) 2009 – F5 Releases TMOS and LTM v10 2010 – Cisco ACE XML Gateway sales end 2010 – Cisco Application-Oriented Networking (AON) products sales end 2011 – F5 Releases TMOS and LTM v11 2011 – F5 Acquires Crescendo Networks intellectual property (at a cost of $5.6m) for its application acceleration technology 2011 – Riverbed® acquires Zeus Technology (at a cost of $110m) for its software based ADC product Zeus Traffic Manager and rebrands it as Stingray (rebranded again as SteelApp™ in 2014) 2011 – Cisco CSS sales end 2012 – F5 Acquires Traffix Systems® (at a cost of $140m) for its mobile/cellular 4G/LTE and Diameter signalling protocol switching technology 2012 – Riverbed and Juniper form a partnership in WAN optimisation and application delivery products, with Juniper licensing the Riverbed Stingray (later renamed SteelApp™) software ADC and Riverbed integrating Steelhead Mobile technology into Juniper’s JunOS Pulse client 2012 – Cisco end development of their ACE load balancing products and partner with Citrix to recommend NetScaler as their preferred product 2013 – F5 Acquires LineRate Systems (at a cost of $125m) for its layer seven and application delivery software defined networking technology 2013 – F5 Acquires Versafe® (at an unknown cost) for its mobile and browser security and monitoring products (the TotALL suite) 2013 - The iControl REST open API is introduced by F5 with TMOS v11.4 2013 – F5 Becomes an OpenStack corporate sponsor 2013 – F5 Launches the Synthesis frame work and introduces SDAS: Software-Defined Application Services™ 2013 – F5 Reduces the price of the 10Mb limited Lab Edition of BIG-IP VE (including LTM, GTM, AFM, ASM, AVR, PSM, WAM and WOM) from around $2000 to just $95, in a gutsy move to capture market share 2014 – Riverbed rename Stingray (formerly Zeus Traffic Manager) to SteelApp™

▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

41 41


2014 – F5 Acquire Defense.Net® (at an unknown cost) for its cloud-based DDoS mitigation technology and services 2014 - F5 Launches its Silverline cloud-based security service in the US, powered by it’s earlier Defense.Net acquisition 2015 - F5 Launches the LineRate Point Load Balancer 2015 - F5 Launches Silverline in EMEA 2015 - Manny Rivelo becomes President and CEO as John McAdam steps down after fifteen years 2015 - Manny Rivelo leaves and John McAdam resumes his roles as President and CEO 2016 - François Locoh-Donou becomes President and CEO 2016 - F5 is named a leader in the Gartner Magic Quadrant for application delivery controllers for the 10th year running 2017 - F5 Launches Herculon security appliances and the DDoS Hybrid Defender and SSL Orchestrator products that run upon them. The Silverline WAF Express service and Container Connector are also launched

▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

Having gained a leading market share in the load balancing and local traffic management enterprise market for some time F5 is now targeting and looking for growth in additional markets, supported and evidenced by their ever expanding product range. These markets include; security (AFM, ASM and APM), cloud (AWS etc.), mobile signalling (Traffix) and acceleration, virtualisation and SSL VPN and RAS. *This article suggests it was actually late 1995: http://www.udel.edu/PR/Messenger/98/1/cyber.html although it was indeed early 1996 when the company was incorporated. **You’ll find in many sources that Michael Almquist has effectively been written out of the company’s history. ***Data taken from the company’s September 2016 financial year end 10K annual report found here.

42 42


F5 Terminology Before we get into the exam specifics we think it’s worthwhile exploring the terminology surrounding F5 Networks’ products (again). This isn’t tested on the exam in any way but without an understanding of the terms you’ll find in this book and elsewhere and particularly how they relate to F5’s hardware and software, things will be harder for you than they need to be. To that end, the next three sections will explore the primary marketing term for the overall product range and then move on to the terms used in relation to the hardware and software (some of which are the same!)

What is BIG-IP? So, just what is BIG-IP? It’s confusing; back in the day, BIG-IP was the single name for everything and all you had was the BIG-IP Controller. Now, things are a bit different and you have the application switch hardware, virtual edition, TMOS, TMM, LTM, APM and all the rest. To add to the confusion BIG-IP is quite often used interchangeably with TMOS or even just F5. As specific and well, simply pedantic I can be I still catch myself saying things like “check your F5’s logs…” or “what’s the CPU load on this BIG-IP.” So, back to the question, what is BIG-IP? Well, simply put it’s all of the things I’ve mentioned so far; it’s an allencompassing term for the hardware, the Virtual Edition container, TMOS (the software components), TMM (a component of TMOS), LTM (which runs within TMM), APM and all the other modules.

BIG-IP Hardware When discussing BIG-IP hardware, things become rather more specific but keep in mind that for many hardware components there will be a related software component that runs on top of it, which has the same name. The primary hardware elements and their purpose are as follows; ▪

Traffic Management Microkernel (TMM); traffic processing hardware components as follows; o A L2 switch module (possibly using network processing NICs) o Packet Velocity ASIC(s) (PVAs) or embedded PVA (ePVA) using Field-programmable gate arrays (FPGAs) o FPGAs providing ePVA, SYN check and other functions in hardware o Dedicated SSL encryption or FIPS hardware o Dedicated compression hardware (in some models) o TMM uses all CPUs (although one is shared with the HMS) and almost all system RAM, a small amount being provisioned for the HMS. TurboFlex™; available on iSeries appliances only, provides FPGA driven, user selectable pre-packaged optimisations that tightly integrate with other hardware and software components and free CPU resources for other tasks. Examples of supported optimisation profiles include layer 4 offload, denial-of service (DoS) functions and tunneling encapsulation. Host Management Subsystem (HMS); responsible for system management and administration functions and runs a version of CentOS (Community enterprise Operating System) Linux (which includes the SELinux feature). The HMS uses a single CPU (shared with TMM) and is assigned a dedicated provision of the overall system RAM, the rest being assigned to TMM. Always On Management (AOM); provides additional ‘lights out’ management of the HMS via a dedicated management processor as well as layer 2 switch management and other supporting functions for TMM.

43 43


Baseboard Management Controller (BMC); another subsystem with a dedicated controller that is independent of the primary TMM and HMS components, which provides for out-of-bound (or so called ‘sideband’) management and monitoring. The BMC is the primary constituent of the Intelligent Platform Management Interface (IPMI) computer interface specifications and protocol which we’ll cover in the BIG-IP Software - TMOS section.

BIG-IP Software – TMOS F5 Network’s Traffic Management Operating System (TMOS) is, first and foremost and for the sake of clarity, NOT an individual operating system. It is the software foundation for all of F5’s network or traffic (not data) products; physical or virtual. TMOS almost seems to be a concept rather than a concrete thing when you first try to understand it. I’ve struggled to find a truly definitive definition of TMOS in any manual or on any website. So, what is TMOS? It’s not too tough after all, really; TMOS encompasses a collection of operating systems and firmware, all of which run on BIG-IP hardware appliances or within the BIG-IP Virtual Edition. BIG-IP and TMOS (and even TMM) are often used interchangeably where features, system and feature modules are concerned. This can be confusing; for instance, although LTM is a TMOS system module running within TMM, it’s commonly referred to as BIG-IP LTM. I suspect we have the F5 marketing team to thank for this muddled state of affairs. TMOS and F5’s so-called ‘full application proxy’ architecture was introduced in 2004 with the release of v9.0.

44 44


This is essentially where the BIG-IP software and hardware diverged; previously the hardware and software were simply both referred to as BIG-IP (or BIG-IP Controller). Now, the hardware or ‘platform’ is BIG-IP, and the software TMOS. Anything capable of running TMOS and supporting its full proxy counts as a BIG-IP so the virtualised version of TMOS is called BIG-IP Virtual Edition(VE) rather than TMOS VE. Where the VE editions are concerned, just the TMM and HMS software components of TMOS are present (more details soon). The primary software elements of BIG-IP, collectively known as TMOS, encompass all of these things; ▪

TMM; o

o o o o ▪

HMS; this runs a modified version of the CentOS Linux operating system and provides the various interfaces and tools used to manage the system such as the WebGUI, tmsh CLI, DNS client, SNMP and NTP. The HMS also contains an SSL stack (known as the COMPAT stack): OpenSSL, which can also be used by TMM where necessary.

Local Traffic Manager (LTM); this and other ‘feature’ modules such as APM, ASM and DNS (formerly GTM) expose specific parts of TMM functionality when licensed. They are typically focussed on a particular type of service (load balancing, authentication and so on).

AOM; lights out system management accessible through the management network interface and serial console.

Intelligent Platform Management Interface (IPMI); IPMI is a hardware-level interface specification and protocol supported on BIG-IP iSeries hardware. It allows for out of band monitoring and management of a system independently of (or without) an operating system and when the system is ‘off’. Like AOM, IPMI functions are accessible through the management network interface and serial console.

Maintenance Operating System (MOS); disk management, file system mounting and maintenance.

End User Diagnostics (EUD); performs BIG-IP hardware tests.

45 45

Software in the form of an operating system, system and feature modules (such as LTM), other modules (such as iRules) and multiple network ‘stacks’ and proxies; FastL4, FastHTTP, Fast Application Proxy, TCPExpress, IPv4, IPv6 and SCTP. Software in the form of the interface to and the firmware that operates the dedicated SSL and other cards and hardware. A ‘native’ SSL stack. Interfaces to the HMS. TurboFlex FPGA firmware


TMOS Components in Detail Let’s explore some of the TMOS components in a little more detail. Traffic Management Microkernel (TMM) TMM is the core component of TMOS as it handles all network activities and communicates directly with the network switch hardware (or vNICs for VE). TMM also controls communications to and from the HMS. Local Traffic Manager (LTM) and other modules run within the TMM. TMM is single threaded until TMOS v11.3; on multi-processor or multi-core systems, Clustered Multi-Processing(CMP) is used to run multiple TMM instances/processes, one per core. From v11.3 two TMM processes are run per core, greatly increasing potential performance and throughput. TMM shares hardware resources with the HMS (discussed next) but has access to all CPUs and the majority of RAM.

46 46


Host Management Subsystem (HMS) The Host Management Subsystem runs a modified version of the CentOS Linux operating system and provides the various interfaces and tools used to manage the system such as the WebGUI, Advanced (Bash) Shell, tmsh CLI, DNS client, SNMP and NTP client and/or server. The HMS can be accessed through the dedicated management network interface, TMM switch interfaces or the serial console (either directly or via AOM). The HMS shares hardware resources with TMM but only runs on a single CPU and is assigned a limited amount of RAM. Always On Management (AOM) The AOM (another dedicated hardware subsystem) allows for ‘lights out’ power management of and console access to the HMS via the serial console or using SSH via the management network interface. AOM Is available on nearly all BIG-IP hardware platforms including the Enterprise Manager 4000 product, but not on VIPRION. Note AOM ‘shares’ the management network interface with the HMS. Maintenance Operating System (MOS) MOS is installed in an additional boot location that is automatically created when TMOS version 10 or above is installed. MOS, which runs in RAM, is used for disk and file system maintenance purposes such as drive reformatting, volume mounting, system re-imaging and file retrieval. MOS also supports network access and file transfer. MOS is entered by interrupting the standard boot process via the serial console (by selecting TMOS maintenance at the GRUB boot menu) or booting from USB media. The grub_default -d command can be used to display the MOS version currently installed. Only one copy of MOS is installed on the system (taken from the latest TMOS image file installed) regardless of the number of volumes present. End User Diagnostics (EUD) EUD is a software program used to perform a series of BIG-IP hardware tests – accessible via the serial console only on system boot. EUD is run from the boot menu or via supported USB media.

47 47


TMOS Planes The following diagram provides an overview of the operational planes within TMOS and where each function and element resides;

BIG-IP Hardware Platforms BIG-IP Application switch hardware comes in a wide range of fixed and modular models. Both the physical hardware and the Virtual Edition are considered a form of application delivery platform; in other words, they run TMOS. Hardware provides superior performance and throughput using Field-Programmable Gate Array (FPGA) circuitry, specialised high performance network interfaces and optimised data paths. Further benefits are gained from the inclusion of additional dedicated hardware for SSL processing (all models) and compression processing (higher end models only) which provide much higher performance than commodity processors. Due to this higher performance the number of TMOS modules you can install on an appliance is also typically quite high, which lends itself well to functional consolidation. Clearly more suited to high workloads, hardware appliances are therefore typically placed in a logically central position in the network to maximise their benefits and ensure the maximum amount of traffic is easily processed through them.

48 48


The built-in AOM and BMC subsystems (covered in detail in the earlier F5 Terminology section) are a useful inclusion and vendor support is also simplified as both the hardware and software are supported and designed by the same vendor. Of course, for all these benefits there are some downsides, the primary ones being cost and a lack of flexibility. The hardware is an expensive upfront cost, however, make good use of their high performance and capacity and the cost is low compared to their true value, over time. This is a primary design consideration, the higher the throughput (within suitable limits) the greater the potential return on your investment (ROI). Moving to the second and related drawback, with the exception of VIPRION, hardware appliances in general simply don’t scale well. If you need to do more than your current device has capacity for you have to (rip and) replace it with a larger device (known as vertical scaling). Equally, future (estimated) capacity requirements must be incorporated in the original purchase, which may mean the hardware is not used to anything like its full capacity for a significant time. These issues can be mitigated to some extent through the use of tiered designs, horisontal scaling made possible through device groups and related HA features and/or segmentation and multi-tenancy with vCMP, route domains and the like.

Appliances You don’t need to know this for the exam but its still useful to have an understanding of the physical BIG-IP platforms. They all (with the exception of VIPRION systems detailed in the next section) have a minimum specification of; ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

LCD Panel & Physical Controls (some models now have a colour touch-panel) Intel dual core CPU Dual power supply capable (AC and DC) Gigabit Ethernet copper and fibre interfaces Front mounted LCD panel Dedicated management network interface Serial console interface Failover/HA serial interface Front to back airflow Software HTTP compression Hardware SSL encryption via ‘Cryogen’ card 8GB RAM 500GB HDD Up to 4,000 2K SSL transactions per second 5Gbps Layer four and layer seven throughput 4Gbps Bulk encryption 425,000 Layer seven requests per second 150,000 Layer four connections per second

49 49


Specifications increase up to the following for the higher end models (excluding the VIPRION platforms discussed shortly); ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

Intel 12 core CPUs 40GbE Fibre interfaces Hardware compression (up to 40Gbps) 128GB RAM Dual 10,000RPM 1TB HHDs with RAID (SSDs are an option) Up to 240,000 2K SSL transactions per second (TPS) 84Gbps Layer four throughput 40Gbps Layer seven throughput 40Gbps Bulk encryption 4,000,000 Layer seven requests per second 1,500,000 Layer four connections per second

The only hot swappable components are the power supplies (assuming two are installed), SFP network interfaces and fan tray (in some models only). Hard disks are not hot swappable even on models that support RAID. FIPS Compliant and Turbo SSL versions of some models are also available. Here’s a quick rundown of the models available at the time of publication, from most powerful to least;

12250v L7 Requests Per Second: 4M L4 Connections Per Second: 1.5M Throughput L4/L7: 84/40Gb Bulk Encryption: 40Gb vCMP Capable: Yes TurboFlex: No Hardware Compression: 40Gb Processors/Cores: 1/12 Memory: 128GB Hard Drive(s): 1x 800GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes

50 50

i10800 L7 Requests Per Second: 3.5M L4 Connections Per Second: 1.5M Throughput L4/L7: 160/80Gb Bulk Encryption: 40Gb vCMP Capable: Yes TurboFlex: Yes - Tier 3 Hardware Compression: 40Gb Processors/Cores: 1/8 Memory: 128GB Hard Drive(s): 1x 480GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes


i10600 L7 Requests Per Second: 2.1M L4 Connections Per Second: 1M Throughput L4/L7: 160/80Gb Bulk Encryption: 40Gb vCMP Capable: No TurboFlex: No Hardware Compression: No Processors/Cores: 1/8 Memory: 128GB Hard Drive(s): 1x 480GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes

10350v/-N/-F L7 Requests Per Second: 3M L4 Connections Per Second: 1.2M Throughput L4/L7: 84/40Gb Bulk Encryption: 24Gb FIPS Option: Yes for 10350v-F vCMP Capable: Yes TurboFlex: No Hardware Compression: 24Gb Processors/Cores: 1/10 Memory: 128GB Hard Drive(s): 1x 800GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes

10255v/10250v/10200v-SSL L7 Requests Per Second: 2M L4 Connections Per Second: 1M Throughput L4/L7: 80/40Gb Bulk Encryption: 22Gb/22Gb/33Gb FIPS Option: Yes for 10200v vCMP Capable: Yes TurboFlex: No Hardware Compression: 24Gb Processors/Cores: 1/6 Memory: 48GB Hard Drive(s): 2x 400GB/1x 400GB SSD/2x 1TB 10GB Interfaces: Yes 40Gb Interfaces: Yes

10055s/10050s/10000s L7 Requests Per Second: 1M L4 Connections Per Second: 0.5M Throughput L4/L7: 80/40Gb Bulk Encryption: 22Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/6 Memory: 48GB Hard Drive(s): 2x 400GB/1x 400GB SSD/2x 1TB 10GB Interfaces: Yes 40Gb Interfaces: Yes

51 51


i7800 L7 Requests Per Second: 3M L4 Connections Per Second: 1.1M Throughput L4/L7: 80/40Gb Bulk Encryption: 20Gb vCMP Capable: Yes TurboFlex: Tier 3 Hardware Compression: 20Gb Processors/Cores: 1/6 Memory: 96GB Hard Drive(s): 1x 480GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes

i7600 L7 Requests Per Second: 1.8M L4 Connections Per Second: 750K Throughput L4/L7: 80/40Gb Bulk Encryption: 20Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/6 Memory: 96GB Hard Drive(s): 1x 480GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes

7255v/7250v/7200v-SSL L7 Requests Per Second: 1.6M L4 Connections Per Second: 775K Throughput L4/L7: 40/20Gb Bulk Encryption: 18/18/19Gb FIPS Option: Yes for 7200v vCMP Capable: Yes TurboFlex: No Hardware Compression: 18Gb Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 2x 1TB/1x 400GB SSD/2x 400GB SSD 10GB Interfaces: Yes 40Gb Interfaces: No

7055s/7050s/7000s L7 Requests Per Second: 800K L4 Connections Per Second: 390K Throughput L4/L7: 40/20Gb Bulk Encryption: 18Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 2x 1TB/1x 400GB SSD/2x 400GB SSD 10GB Interfaces: Yes 40Gb Interfaces: No

52 52


i5800 L7 Requests Per Second: 1.8M L4 Connections Per Second: 800K Throughput L4/L7: 60/35Gb Bulk Encryption: 20Gb vCMP Capable: Yes TurboFlex: Tier 3 Hardware Compression: 20Gb Processors/Cores: 1/4 Memory: 48GB Hard Drive(s): 1x 480GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes

i5600 L7 Requests Per Second: 1.1M L4 Connections Per Second: 500K Throughput L4/L7: 60/35Gb Bulk Encryption: 15Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/4 Memory: 48GB Hard Drive(s): 1x 480GB SSD 10GB Interfaces: Yes 40Gb Interfaces: Yes

5250v/5200v L7 Requests Per Second: 1.5M L4 Connections Per Second: 700K Throughput L4/L7: 30/15Gb Bulk Encryption: 12Gb FIPS Option: Yes for 5250v vCMP Capable: Yes TurboFlex: No Hardware Compression: 12Gb Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 1x 1TB/400GB SSD 10GB Interfaces: Yes 40Gb Interfaces: No

5050s/5000s L7 Requests Per Second: 750K L4 Connections Per Second: 350K Throughput L4/L7: 30/15Gb Bulk Encryption: 12Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 1x 1TB/400GB SSD 10GB Interfaces: Yes 40Gb Interfaces: No

53 53


i4800 L7 Requests Per Second: 1.1M L4 Connections Per Second: 450K Throughput L4/L7: 20/20Gb Bulk Encryption: 15Gb vCMP Capable: No TurboFlex: Tier 2 Hardware Compression: 10Gb Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No

i4600 L7 Requests Per Second: 650K L4 Connections Per Second: 250K Throughput L4/L7: 20/20Gb Bulk Encryption: 10Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No

4200v L7 Requests Per Second: 850K L4 Connections Per Second: 300K Throughput L4/L7: 10/10Gb Bulk Encryption: 8Gb vCMP Capable: No TurboFlex: No Hardware Compression: 8Gb Processors/Cores: 1/4 Memory: 16GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No

4000s L7 Requests Per Second: 425K L4 Connections Per Second: 150K Throughput L4/L7: 10/10Gb Bulk Encryption: 8Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/4 Memory: 16GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No

54 54


i2800 L7 Requests Per Second: 650K L4 Connections Per Second: 250K Throughput L4/L7: 10/10Gb Bulk Encryption: 8Gb vCMP Capable: No TurboFlex: Tier 1 Hardware Compression: 5Gb Processors/Cores: 1/2 Memory: 16GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No

i2600 L7 Requests Per Second: 350K L4 Connections Per Second: 125K Throughput L4/L7: 10/10Gb Bulk Encryption: 5Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/2 Memory: 16GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No

2200s L7 Requests Per Second: 425K L4 Connections Per Second: 150K Throughput L4/L7: 5/5Gb Bulk Encryption: 4Gb vCMP Capable: No TurboFlex: No Hardware Compression: 4Gb Processors/Cores: 1/2 Memory: 8GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No

2000s L7 Requests Per Second: 212K L4 Connections Per Second: 75K Throughput L4/L7: 5/5Gb Bulk Encryption: 4Gb vCMP Capable: No TurboFlex: No Processors/Cores: 1/2 Memory: 8GB Hard Drive(s): 1x 500GB 10GB Interfaces: Yes 40Gb Interfaces: No

You’ll find further technical details here: https://www.f5.com/pdf/products/big-ip-platforms-datasheet.pdf.

55 55


VIPRION VIPRION is F5 Networks’ high density hardware consolidation platform; the Cisco Catalyst 6500 of the BIG-IP range if you will. The four VIPRION models are modular chassis with capacity for up to eight hot-swappable blade modules, all featuring hardware compression. The larger 16 rack unit (RU) high 4800 can accommodate dual duodecad (12) core CPU full-width blades, the smaller 4RU 2400 holds single quad core CPU half-width blades. The features and benefits of these chassis are similar to those of other modular, expandable network devices; ▪

Hot-swappable blades, multiple power supplies and field replaceable components increase uptime and provide a high level of redundancy Consolidation of multiple devices in a high density form factor reduces and/or fixes hardware, environmental, operational and management costs High interface density and capacity Non-disruptive capacity scaling Easy expansion capabilities (aka vertical scaling or scale up)

▪ ▪ ▪ ▪

You don’t need to know this for the exam but, if you’re interested, the technical highlights of the VIPRION platforms include; ▪ ▪

Load is dynamically shared across all available blades All physical interfaces on all blades are fully meshed using high-speed bridge Field Programmable Gate Arrays (FPGAs) The entire system is managed through a single interface Everything from firmware, software and configuration settings is automatically duplicated from the primary blade to every other blade The SuperVIP feature allows a VIP to span multiple blades Up to 256GB RAM per blade 100Gb Ethernet interfaces Up to 160,000 2K RSA SSL transactions per second (TPS) Up to 140Gbps layer four and seven throughput per second, per blade Up to 80Gbps bulk encryption per blade Up to 5M Layer seven requests per second, per blade Up to 2.9M Layer four connections per second, per blade Up to 80Gb hardware compression per blade

▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

Here’s a quick rundown of the VIPRION chassis and blade models available at the time of publication, from most powerful to least;

56 56


57 57

4800 Chassis Rack Units: 16 Slots: 8 Power Supplies: 4 Fan Trays: 2 Supported Blades: 4450, 4340N & 4300

4480 Chassis

4450 Blade

4340N Blade

L7 Requests Per Second: 5M L4 Connections Per Second: 2.9M Throughput L4/L7: 140/140Gb Bulk Encryption: 80Gb vCMP Capable: Yes Processors/Cores: 2/12 Memory: 256GB Hard Drive(s): 1x 1.2TB SSD 10/40/100GB Interfaces: Yes/Yes/Yes

L7 Requests Per Second: 2M L4 Connections Per Second: 1.1M Throughput L4/L7: 80/40Gb Bulk Encryption: 20Gb vCMP Capable: Yes Processors/Cores: 2/6 Memory: 96GB Hard Drive(s): 1x 600GB 10/40/100GB Interfaces: Yes/Yes/No

Rack Units: 7 Slots: 4 Power Supplies: 4 Fan Trays: 1 Supported Blades: 4450, 4340N & 4300


4300 Blade L7 Requests Per Second: 2.5M L4 Connections Per Second: 1.4M Throughput L4/L7: 80/40Gb Bulk Encryption: 20Gb vCMP Capable: Yes Processors/Cores: 2/6 Memory: 48GB Hard Drive(s): 1x 600GB 10/40/100GB Interfaces: Yes/Yes/No

2400 Chassis

2200 Chassis

Rack Units: 4 Slots: 4 Power Supplies: 2 Fan Trays: 1 Supported Blades: 2250 & 2150

Rack Units: 2 Slots: 2 Power Supplies: 2 Fan Trays: 1 Supported Blades: 2250 & 2150

2250 Blade

2150 Blade

L7 Requests Per Second: 2M L4 Connections Per Second: 1M Throughput L4/L7: 155/80Gb Bulk Encryption: 36Gb vCMP Capable: Yes Processors/Cores: 1/10 Memory: 64GB Hard Drive(s): 1x 800GB SSD 10/40/100GB Interfaces: Yes/Yes/No

L7 Requests Per Second: 1M L4 Connections Per Second: 400K Throughput L4/L7: 40/18Gb Bulk Encryption: 9Gb vCMP Capable: Yes Processors/Cores: 1/4 Memory: 32GB Hard Drive(s): 1x 400GB SSD 10/40/100GB Interfaces: Yes/No/No

You’ll find further technical details here: https://www.f5.com/pdf/products/viprion-overview-ds.pdf.

58 58


Herculon The Herculon range was released in 2017 with the DDoS Hybrid Defender and SSL Orchestrator products. Despite being declared purpose-built dedicated security appliance products the hardware platforms at least are the i10800, i5800 and i2800 products. All these appliances support and rely upon TurboFlex for FPGA driven packet processing optimisations focused on the tasks they are designed to handle. The genuinely purpose-built element of these products is the simplified visual user interface and highly focused functionality. They also feature significant integration with dynamic external services such as IP Intelligence, F5’s Security Operations Center (SOC), Platform Security Team, Security Incident Response Team (SIRT) and 24x7 customer support.

BIG-IP Virtual Edition (VE) BIG-IP Virtual Edition (VE) provides a modern and lightweight alternative to purchasing hardware appliances. VE Has been available since TMOS v10.1 and supports all but one feature module, Enterprise Manager, BIG-IQ and Edge Gateway. It is available at lower cost to hardware, with a wide variety of throughput levels (up to 40G now); providing licensing flexibility and the ability to use a ‘pay as you grow’ model. Information on which products are supported on which hypervisors can be found here: https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/vesupported-hypervisor-matrix.html. You also benefit from the various advantages of using virtualisation in general and take advantage of the various methodologies, features and efficiencies of orchestration, cloud services and micro-services. Availability on Amazon Web Services (AWS) and other cloud providers allows for yet more (potential) cost control and flexibility. Of course, you lose the performance of hardware acceleration (particularly for SSL/TLS) but you don’t have to initially over-specify hardware to accommodate future growth or peaks in demand.

Keep in mind VE performance is highly dependent on the host hardware and hypervisor software used.

Potentially poor SSL/TLS performance is slowly being eliminated with recent advances and contemporary features now available with commodity Intel processors. It’s argued that network performance is a bottleneck introduced by most hypervisors and that’s probably true at present but we don’t see this being an issue for too much longer as the vendors focus on it and even now this is only an issue if your traffic profile includes a large number of short lived connections. These hypervisors are supported; ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

Citrix XenServer (v5.6 sp2 and 6.0) Microsoft Hyper-V on Windows® 2008 R2 (Fully supported in TMOS v11.3.0) VMWare vCloud Director v1.5 onwards VMWare ESX/ESXi/vSphere v4.0 onwards Linux KVM (From TMOS v11.3) Community Xen (From TMOS v11.3) OpenStack (From TMOS v12.1.1) Amazon Web Services (AWS) (From TMOS v11.4.1) Microsoft Azure (From TMOS v12.0.0) Google Cloud Platform (From TMOS v13.0.0)

59 59


BIG-IP Features not available in the Virtual Edition include; ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

CMP (until TMOS v11.3) Spanning Tree Protocols (vSwitches don’t run STP) Link Aggregation Control Protocol (LACP) – but Trunking is still available The hard-wired fail-over functionality and interface Federal Information Processing Standards (FIPS) 140-2 compliance (specific hardware is required) Interface mirroring The Serial console interface Always On Management (AOM) Baseboard Management Controller (BMC) and Intelligent Platform Management Interface (IPMI) TurboFlex Use of more than 4GB of memory (until TMOS v11.3) Use of more than 16 vCPUs Throughput of more than 1Gb (until TMOS v11.4) The Link Controller (LC) module Advanced SSL functions Advanced TCP profile settings

A free trial is available here: https://www.f5.com/trial/big-ip-trial.php.

The Different F5 Modules, Products & Services F5 Have an ever increasing and diverse set of products, modules and services. Local Traffic Manager (LTM) remains the ‘core’ product, with many other modules requiring it in order to work. However, F5’s expansion into the security market in particular, means there is now significant diversity in the product line and services unrelated to BIG-IP (such as cloud-based DDoS protection) are now a prominent part of the mix. This section provides a brief overview of nearly all the currently software and services available; we’ve already covered the hardware. You’ll note that LTM is not listed as it is discussed in considerable detail in the BIG-IP Administration chapter.

Overview These are the modules available; ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

Application Acceleration Manager (AAM) - web acceleration and WAN optimisation Access Policy Manager (APM) - access security including VPN, SSO and AAA Advanced Firewall Manager (AFM) - high performance firewall Application Visibility and Reporting (AVR)/Analytics - historical and near time statistics and metrics Application Security Manager (ASM) - web application firewall BIG-IQ - BIG-IP device, license, configuration, cloud and security management and orchestration Carrier Grade NAT (CGNAT) - highly optimised network address translation Edge Gateway - remote access including SSL VPN Enterprise Manager (EM) - BIG-IP device management DDoS Hybrid Defender - dynamic, high performance traffic analysis, DDoS identification and mitigation supported by various F5 services DNS - global server load balancing (GSLB) Link Controller (LC) - management, aggregation and monitoring of multiple internet connections (links)

▪ ▪

60 60


Policy Enforcement Manager (PEM) - mobile network subscriber and traffic reporting, management and control Secure Web Gateway (SWG) - forward proxy and web access gateway used in combination with the WebSense service and APM SSL Orchestrator - high-performance decryption and encryption of outbound SSL/TLS traffic DDoS Hybrid Defender - multi-layered detection of and defense against network and application layer attacks

▪ ▪ ▪

Services ▪

IP Intelligence Service - constantly updated database of IP addresses known to be used for malicious activities MobileSafe - corporate mobile device protection and security Silverline - DoS/DDoS protection and web application firewalling Websafe - website analysis and malicious traffic traffic detection by the F5 security operations centre (SOC) Websense - URL categorisation and internet risk protection used in combination with the SWG module

▪ ▪ ▪ ▪

The following modules and products are end of life (EoL): ▪ ▪ ▪ ▪ ▪ ▪

ARX (file system load balancing) WebAccelerator (WAM) WAN Optimization Manager (WOM) Message Security Manager (MSM) Protocol Security Manager (PSM) Firepass

Access Policy Manager (APM) Module APM offers a unified, centralised access security solution for applications and networks, at typical TMM scale and performance; up to 3000 logins per second and 1m concurrent users. The module provides an increasing number of features and benefits; ▪ ▪ ▪ ▪ ▪ ▪

Dynamic, policy-based, context-aware access control Central control for diverse users and locations (remote, mobile, LAN and WLAN) Centralised, repeatable and consistent policy application Support for the CRLDP and OCSP dynamic certificate revocation protocols SSL VPN Authentication offload with support for RADIUS, LDAP, MS AD Kerberos, HTTP, RSA SecurID, OAM and TACACS+ authentication methods Single Sign On (SSO) features Java applet rewriting SAML support (from v11.3) Multi-vendor VDI support including VMware View, Citrix XenApp & XenDesktop, Microsoft RDP and Java RDP clients Enterprise Manager and BIG-IQ management High speed logging (HSL) Secure Web Gateway (SWG) integration

▪ ▪ ▪ ▪ ▪ ▪ ▪

61 61


Access Policy Manager is available as an LTM or ASM add-on module for physical and Virtual Editions and VIPRION chassis platforms. It is also available as part of the BIG-IP Edge Gateway remote access product. APM (in particular as part of the Edge Gateway product) is the successor to the FirePass product. APM and LTM or ASM are now the successor to the Edge Gateway product itself. APM also supersedes and vastly improves upon the ‘legacy’ Advanced Client Authentication (ACA) Module although it is still available.

Advanced Firewall Manager (AFM) Module Introduced in early 2013 and available with TMOS v11.3 onwards, AFM simplifies and unifies the configuration and management of the Application Delivery Firewall (ADF) related features of TMOS, TMM and LTM. All relevant features are fully integrated into TMM and therefore provide very high performance; the figures are impressive. The ADF is defined as a combination of the AFM and LTM modules. Other common TMOS, TMM and LTM features and benefits apply and are possibly even more relevant in a security context; ▪

Comprehensive DDoS mitigation features as described in the TMM and LTM chapters (and also including those previously available with the PSM) The full proxy architecture Flexible scaling options and ScaleN Full standard HA feature support Very high throughput and performance TCP Optimisations, reducing response times iRules and data and protocol manipulation Application awareness and context Function consolidation and further integration benefits when used with other modules (particularly ASM, APM and GTM) and features (such as IP Intelligence and Geolocation) AVR/Analytics integration ICSA Network Firewall Certification High speed logging (HSL) SSL Termination VPN Termination

▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

This module is available for physical and virtual editions and VIPRION chassis platforms. This LTM add-on Module is dependent on and can only be used in conjunction with LTM.

Application Acceleration Manager (AAM) Core Module The AAM Core module is available for physical and virtual editions and VIPRION chassis platforms and is included with the base LTM license. AAM Core is a subset of the combination of features previously available in the WA and WOM Modules. The Full version, detailed next, provides the full suite of features. Core includes; ▪ ▪ ▪ ▪ ▪

Symmetric Compression Dynamic Compression The SPDY Gateway Feature Bandwidth Controllers HTTP Caching

62 62


▪ ▪ ▪ ▪

HTTP Compression TCP Express OneConnect iSessions

This module is available for physical and virtual editions and VIPRION chassis platforms. This Module is dependent on and can only be used in conjunction with LTM.

Application Acceleration Manager (AAM) Full Module The full AAM module is available for physical and virtual editions and VIPRION chassis platforms. A combination of the previously separately available WA and WOM Modules, AAM provides the full set of features from those products. Features over and above the Core product include; Intelligent Browser Referencing (IBR) – increasing browser cache expiration dates (and other features) to reduce conditional GET requests Image Optimisation – reducing image size to something appropriate to the requesting device Content Reordering – modifying the order of served content to optimise page load times Dynamic caching/deduplication Multi-protocol optimisations (HTTP, FTP, MAPI, UDP) Forward Error Correction (FEC) – provides recovery of lost packets to avoid retransmission and increase throughput on poor networks or links Parking Lot – GET request queuing for expired cache objects MultiConnect – performs client-side link modifications, which, along with additional DNS entries, ‘force’ browsers to open additional connections to a site PDF Dynamic Linearisation A Performance Dashboard Symmetric and Asymmetric deployment options BIG-IP APM, ASM, and AAM layering iApps support Enterprise Manager and BIG-IQ management

▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

This module is available for physical and virtual editions and VIPRION chassis platforms. This Module is dependent on and can only be used in conjunction with LTM.

Application Security Manager (ASM) Module ASM (initially based on technology gained through the 2004 acquisition of MagniFire Websystems) provides advanced web application aware ‘firewall’ (WAF) functionality. Unlike most modules it does not run within TMM but the HMS instead and therefore doesn’t benefit directly from typical TMM performance and scale. It provides protection against a wide range of attacks and attack vectors including;

63 63


▪ ▪

Web scraping (the automatic (mass) extraction of data from a website or sites) SQL Injection (execution of SQL code, ‘injected’ via a website or service’s user input methods (such as a form field), on the database backend used by that site’s web servers) Layer seven (aka Application Layer) DoS and DDoS ((distributed) denial of service attacks aimed at application functions) Cross-site scripting (aka XSS) (malicious browser code injection and trusted site permission hijacking) JSON payload attacks FTP Application attacks SMTP Application attacks XML Application attacks

▪ ▪ ▪ ▪ ▪ ▪

Other features include; ▪ ▪

Vulnerability assessment and mitigation Integration with vulnerability scanners from Cenzic Hailstorm, IBM Rational AppScan, QualysGuard Web Application Scanning and WhiteHat Sentinel Session awareness White and black listing Regulatory compliance reporting (PCI for example) An automatic policy-building engine Enterprise Manager and BIG-IQ management WebSockets support

▪ ▪ ▪ ▪ ▪ ▪

Application Security Manager is available on a selection of BIG-IP application switches, as a Virtual Edition and as an LTM add-on module for physical and virtual editions and VIPRION chassis platforms.

Application Visibility and Reporting (AVR) Commonly referred to as simply Analytics or BIG-IP Analytics, this Module provides detailed historical and near-time HTTP and TCP/IP related statistics for iApps applications, Virtual Servers, Pool Members, URLs and even specific countries, allowing for in-depth traffic analysis. The available metrics and counters include transactions per second, server latency, page load time, request and response throughput, sessions, response codes, user agents, HTTP methods, countries, and IP addresses. Fine grained filters can be used to limit what is recorded, full transaction and data capture is possible and alerts (via SNMP trap, email or syslog) can be configured based on user defined thresholds. Remote logging of statistics data is also supported but unfortunately data cannot be collect via SNMP polling or iControl. IPv6 is fully supported from v11.1. Enterprise Manager can be used as a centralised Analytics reporting tool if required. Analytics is available as an LTM add-on feature for physical and virtual editions and VIPRION chassis platforms and is included with the base LTM license. This wasn’t always the case. This module is dependent on and can only be used in conjunction with LTM and needs to be provisioned as Nominal.

64 64


BIG-IQ Centralised Management Product Planned as the eventual successor to Enterprise Manager, BIG-IQ is a management and orchestration platform with considerable scope. As with any centralised management system, the main goal is to reduce operational costs, reduce administrative overheads and improve scalability. Currently BIG-IQ has four main components each focused on specific functional areas; Access, Devices, Traffic and Security. The following modules and services are supported; ▪ ▪ ▪ ▪ ▪ ▪

AFM APM ASM LTM MobileSafe WebSafe

General features include; ▪ ▪ ▪ ▪ ▪

A comprehensive set of RESTful APIs So-called ‘single pane of glass’ management Centralised audit and control License management of BIG-IP Virtual Editions Role based access control (RBAC)

Here’s a brief overview of each component; Access Management of up to 100 APM devices including; ▪ ▪ ▪

Policy verification, staging, auditing and monitoring Multi-device policy push Extensive reporting

Devices Centralised management of up to 200 physical, virtual or vCMP BIG-IP appliances, including; ▪ ▪ ▪ ▪ ▪ ▪

TMOS Software deployment Remote deployment of appliances hosted within VMware NSX, Cisco APIC, OpenStack or AWS Centralised license management of up to 5000 unmanaged devices for highly flexible provisioning Status and usage reporting including SSL certificate status Device discovery and monitoring Configuration backup and restore

65 65


Traffic Management and real-time monitoring of LTM configurations and objects including; ▪ ▪ ▪ ▪ ▪

RBAC For pool member and virtual server control Centralised logging and audit trails Configuration templating, staging and scheduling Virtual server cloning Health and statistics monitoring

Security Centralised AFM and ASM management including; ▪ ▪ ▪ ▪ ▪ ▪

RBAC For security instances Policy verification, staging, auditing and monitoring Multi-device policy push Rule monitoring, reporting and prioritisation Configuration snapshots Reporting and security alerts, including for WebSafe and MobileSafe

BIG-IQ is available as a standalone appliance and a virtual edition. It supports and can manage all hardware and virtual appliances running TMOS v11.4 and above including VIPRION.

BIG-IQ Cloud & Orchestration Product Orchestration of BIG-IP deployments in public and private clouds, with integration support for; ▪ ▪ ▪ ▪

Cisco APIC Amazon Web Services (AWS) OpenStack VMware environments including NSX

Additional features include; ▪ ▪ ▪ ▪ ▪

Automatic provisioning Dynamic application server ‘bursting’ Tenant awareness and service catalogue provision iApps management, provision and templating Health and performance monitoring

Carrier Grade NAT (CGNAT) Module Introduced with v11.3 this Service Provider focused module provides highly optimised, available and scalable IPv4 and IPv6 Network Address Translation (NAT) and related features such as NAT44, NAT64, DNS64, DS-Lite, endpoint independent mapping, endpoint independent filtering and deterministic NAT. A number of the Module’s features rely on existing TMOS or LTM features such as HA, High-speed Logging (HSL), the full proxy architecture for translating or migrating between IPv4 and IPv6 objects and TCP Express. CGNAT is available as an LTM add-on module for physical and virtual editions and VIPRION chassis platforms.

66 66


Edge Gateway Product Edge Gateway was available as a virtual edition and on a selection of BIG-IP application switches but not on VIPRION chassis platforms. It is a combination of the APM, WA and WOM modules, providing secure remote access (RAS) gateway features such as; ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

ICSA Certified SSL VPN Clientless access End point validation and security and access policy enforcement Single Sign On (SSO) and credential caching Multi-factor authentication Symmetric acceleration (if the client is using the Edge Client software) Wide AAA protocol support Wide remote access protocol support (Citrix, RDP, ActiveSync etc.) IPv6 Support Enterprise Manager Management

Enterprise Manager (EM) Product I have to admit that large scale management and monitoring bore me rigid; I blame this on the incumbent vendors happy to milk the cash cow rather than innovate and please their customers. I’ve actually used Enterprise Manager (v2.x) and whilst I’m unlikely to describe it as exciting it’s certainly an improvement over other so-called solutions I’ve seen and it is very focused. Enterprise Manager has numerous features and benefits; ▪ ▪

Aids with scaling up Improves device, application and service visibility and therefore troubleshooting capabilities and capacity planning and forecasting accuracy, as with other centralised management solutions Reduces cost and complexity Automates common tasks including device configuration backups, ASM policy deployments and reporting Custom Alerts and thresholds Manages and eases; o Device inventory tasks o Service contract monitoring o SSL TPS monitoring and certificate management Centralised configuration management including comprehensive search Allows for the use of configuration templates Granular (distributed) configuration management Uses a local or remote MySQL database allowing enterprise integration and high compatibility with various DB management and reporting tools Physical and virtual edition support for LTM, GTM, ASM, LC, AAM, APM and Edge Gateway

▪ ▪ ▪ ▪

▪ ▪ ▪ ▪ ▪

EM is available as a standalone appliance and a virtual edition. It supports and can manage all hardware appliances including VIPRION and Virtual Editions.

EM is very likely to be phased out and replaced by the BIG-IQ Device product.

DNS (formerly Global Traffic Manager (GTM)) Module Global Traffic Manager is a TMOS Module and is part of the core, long standing F5 product set. GTM primarily provides DNS based ‘global’ server load balancing (GSLB) for IPv4 and IPv6 (inter-Data Centre) rather than LTM’s

67 67


intended intra-Data Centre operation). In order to make this Module a more attractive proposition, its feature set has been significantly expanded since 2012 it now runs in TMM natively, rather than within the HMS. The considerable list of features and benefits include; ▪ ▪

Global server load balancing (using DNS to direct traffic between multiple DCs) Dynamic ratio load balancing (load balancing based on weights derived from Node metrics such as CPU and memory usage) Wide area persistence (DNS response persistence, a same client will get the same response and load balancing will be ignored unless/until a timeout is reached) Geographic load balancing (load balancing a client to its geographically closest DC) Advanced health monitoring QoS Awareness DNS Security Extensions (DNSSEC) support (including rate limiting and centralised key management) Up to 10 million DNS responses per second using the VIPRION platform DNS Caching DNS Server consolidation and offload DNS DDoS and Local DNS (LDNS) cache poisoning protection DNS server load balancing (similar to LTM server load balancing) Not BIND based and therefore not subject to BIND security vulnerabilities Protocol inspection and validation DNS record type ACLs IP Anycast support IPv6 support

▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

GTM is available as a standalone appliance, a virtual edition and an LTM add-on module for physical and Virtual Editions and on VIPRION chassis platforms. DNS Services are also available as an LTM add-on Feature Set.

IP Intelligence Service This subscription-based service is designed to be used in conjunction with ASM or LTM to block malicious traffic at the very edge of your network, thus increasing efficiency by avoiding processing overheads further within your infrastructure. The service provides a constantly updated database of IP addresses known to be used in relation to activities such as; ▪ ▪ ▪ ▪ ▪

Phishing sites and other fraudulent activity DoS, DDoS, SYN flood and other anomalous traffic attacks Botnet command and control servers and infected zombie machines Proxy and anonymisation services Probes, host scans, domain scans and password brute force attacks

This database can then be referenced by iRules to allow for automated blocking, allowing for context aware policy decisions.

68 68


Link Controller Product (& Module) LC Provides features to manage, aggregate and monitor multiple ISP internet connections (links) and controls the traffic flow across them, based on multiple dynamic factors and user specified criteria. Traffic optimisation and prioritisation features are also available to improve application performance. TCPExpress, IPv6, iRules and SNAT are fully supported and there is an optional compression feature. BIG-IP Link Controller is available as a standalone version and as a LTM add-on module for BIG-IP application switches.

MobileSafe Product & Service This enterprise level product aims to protect and secure corporate mobile devices from various threats and ensure the company, it’s networks and its data are protected. The software is available for iOS and Android devices, with management achieved through a web portal run by the F5 Security Operations Center (SOC). Features include; ▪

Mitigates against various mobile device threats including; application tampering, unpatched operating systems, keyloggers, certificate forging and DNS spoofing Strong validation of SSL certificates Application-level encryption Malware detection Rooted and jail-broken device detection

▪ ▪ ▪ ▪

Policy Enforcement Manager (PEM) Module Available from TMOS v11.3, PEM provides mobile network subscriber and traffic reporting, management and control. The module provides a host of features and benefits, presumably based on the assets of the Traffix Systems acquisition; ▪ ▪

Comprehensive analytics including per session and per application statistics L7 Intelligent traffic steering (to appropriate caches, CDNs, proxies) and bandwidth control to reduce network congestion and increase performance Traffic classification (p2p, VoIP, Web, streaming) Deep packet inspection Rate limiting, QoS, CoS and fair usage policy enforcement Charging system integration (PCRF, OCS) 3GPP standards based Subscriber awareness (IP address, IMSI, RADIUS data, Gx and/or mobile tower) and application context Function consolidation and further integration benefits when used with other modules (particularly CGNAT and AFM) Very high throughput and performance TCP Optimisations, reducing response times iRules and data and protocol manipulation Flexible scaling options and ScaleN Full standard HA feature support High speed logging (HSL)

▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

Policy Enforcement Manager is available only as a standalone appliance on high-end physical appliance a virtual edition and VIPRION chassis platforms.

69 69


Secure Web Gateway (SWG) Module & Websense Cloud-based Service SWG Provides control, security and management of inbound and outbound user driven web traffic; it’s effectively a secure internet proxy, or web access gateway as F5 like to call it. The module itself provides integration between Access Policy Manager and Cloud-based Websense security services and updates. Combined, these components offer; URL categorisation and filtering ▪ ▪ ▪ ▪ ▪ ▪ ▪

User tracking Malware protection Endpoint integrity checking Policy-based blocking Real-time threat intelligence Detailed logging Splunk reporting

Silverline Cloud-based Service The Silverline service (Software as a Service or SaaS) delivers two core internet related security functions; DDoS protection and web application firewalling. Rather than implement these yourself on-site, you can simply transparently route your inbound traffic through the F5 SOC and let them do the hard work for you. The services are as follows; ▪

F5 Silverline DDoS Protection - typical TMOS supported DDoS protection and features, along with the resources and bandwidth required to sustain a high volume attack.

F5 Silverline Web Application Firewall - ASM features (see the earlier section), along with the processing resources and bandwidth required to mitigate attacks.

WebSafe Service & Module The WebSafe service provides protection for the users and customers using your website properties, as well as the sites themselves. Traffic is transparently passed through the F5 SOC where it is analyzed and malicious traffic dropped before it reaches your site. Additionally, the BIG-IP module component of this service, the Fraud Protection Service (FPS) provides additional features and protections at the local, Virtual Server level. This is fully integrated into the GUI from TMOS v11.6. The protection and features provided by this combination include; ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

Malware prevention Phishing and pharming attack mitigation Fraud detection and prevention Application-level encryption Transaction monitoring, analysis and integrity checking Device and behavior analysis Integration with MobileSafe Incident reporting Real-time alerts dashboard

70 70


DDoS Hybrid Defender (Herculon) A sophisticated, high performance and throughput security appliance, software and service bundle designed to defend against multi-vector network and application attacks. Only available in physical form on i10800, i5800 and i2800 appliances which provide TurboFlex FPGA driven performance enhancements and acceleration. Herculon products have a unique, simplified interface and configuration requirements. Features include; Backed by F5’s Security Operations Center (SOC), Platform Security Team, Security Incident Response Team (SIRT) and 24x7 customer support Full SSL decryption Anti-bot capabilities Advanced detection methods Line rate capabilities Cloud-based volumetric attack prevention Traffic baselining and automatic configuration Multiple attack mitigation mechanisms Threat intelligence Granular reporting and visibility

▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

SSL Orchestrator (Herculon) A security appliance, designed to provide security devices with visibility of SSL/TLS traffic. Since more organisations and companies are transitioning over to SSL/TLS, this will render existing security devices (such as IPS, Anti-Virus etc.) useless if they cannot decrypt and review the payload of the packets. If you install the SSL Orchestrator in front of your existing security devices, you can decrypt the traffic, create policy-based flows and steer unencrypted traffic to your security devices making them useful again. Only available in physical form on i10800, i5800 and i2800 appliances which provide TurboFlex FPGA driven performance enhancements and acceleration resulting in very high performance and throughput. Herculon products have a unique, simplified interface and configuration requirements. Features include; Backed by F5’s Security Operations Center (SOC), Platform Security Team, Security Incident Response Team (SIRT) and 24x7 customer support Inline layer 3, inline layer 2, ICAP services and receive only modes Reverse and forward proxy operation Dynamic service chaining, monitoring and load balancing Context and identification services including geo-location, IP reputation and URL categorisation

▪ ▪ ▪ ▪ ▪

Free and/or Open Source Products F5 publish and maintain a number of open source software packages and resources to help their customers manage their appliances (virtual or physical), modules and application services and integrate them into their wider environment as well as automate their deployment and administration. For anything involving source code you’ll probably find a repository for it on the main F5 GitHub company page here: https://github.com/F5Networks, or, for more informal work on the DevCentral Github page here: https://github.com/f5devcentral. Here’s a quick overview of the most popular or significant projects you’ll find there and also what’s available elsewhere.

71 71


Bigsuds Bigsuds is a Python library designed to make it easy to create programs and automate operations on F5 devices utilising the ‘legacy’ iControl SOAP API. https://github.com/F5Networks/bigsuds.

iControl REST Software Development Kit (F5-SDK) This is the equivalent Python library designed to make it easy to create programs and automate operations on F5 devices utilising the more recent iControl REST API. https://github.com/F5Networks/f5-common-python

Ansible Ansible is a popular and simple Python-based IT automation engine. Over 20 LTM and GTM related modules are available to support automated configuration of device settings, from NTP to SNAT Pools. You can find out more here: https://www.ansible.com/ansible-f5 and the latest list of stable modules (for download if required) is here: https://github.com/ansible/ansible/tree/devel/lib/ansible/modules/network/f5. Most of the modules required either the F5-SDK or bigsuds to be installed on the host running Ansible.

Containers F5 have released a number of container based applications to allow for BIG-IP product integration with container orchestration systems. These include the F5 BIG-IP Controller for Kubernetes, Cloud Foundry and Marathon. F5 have also developed the container-based Application Services Proxy (ASP) which acts as a proxy and load balancer for distributed applications running in containerised environments. You’ll find all of these container images on Docker Hub here: https://hub.docker.com/u/f5networks/ and can find out more about the ASP here: http://clouddocs.f5.com/products/asp/v1.0/.

OpenStack OpenStack is a set of free and open-source software tools that provide a (cloud) computing platform typically deployed as infrastructure-as-a-service (IaaS). It is used to build, operate and manage pools of compute, storage, and networking resources upon which applications and services are run. F5 provide a fair number of drivers, plugins and agents to allow for BIG-IP product integration with various OpenStack components and to enable orchestration abilities.

72 72


Cloud - AWS F5 offer supported and experimental CloudFormation templates to ease deployment of Virtual Edition EC2 instances AWS in a declarative and repeatable manner. CloudFormation is AWS proprietary and specific, unlike Terraform which is detailed next. You can find the templates here: https://github.com/F5Networks/f5-aws-cloudformation. Terraform provides the same services as CloudFormation but can be used with the top three cloud platforms and many other platforms, known as providers. You can find configurations for AWS, Azure and Google Cloud Platform (GCP) providers and additional resources here: https://github.com/f5devcentral/f5-terraform.

Cloud - Azure You can find F5 formulated Azure ARM templates here: https://github.com/F5Networks/f5-azure-arm-templates. You’ll find Terraform Azure provider configurations and many others as well as additional resources here: https://github.com/f5devcentral/f5-terraform.

Cloud - GCP You can find F5 formulated GCP GDM templates here: https://github.com/F5Networks/f5-google-gdm-templates. You’ll find Terraform GCP provider configurations and many others as well as additional resources here: https://github.com/f5devcentral/f5-terraform.

The Full Application Proxy The first release of TMOS, v9 in 2005 introduced the Full Application Proxy; providing a significant improvement in functionality over the prior Packet Based Proxy architecture used in previous products. The Packet Based Proxy is still available and can still be the most desirable, high performance solution where only L2-L4 functions are required. The Full Application Proxy architecture is just that; it functions as a proxy that fully and completely separates the client and server sides of a connection. There are in fact two connections; the client side connection is terminated on the proxy (the load balancer) and a new, separate connection is established to the server. The proxy acts in the role of server to the client and client to the real server. There are two related connection table entries too; one for client side, one for server side. Each can have independent parameters applied, such as idle timeouts, buffers, MTU, window size and so on. The Application Delivery Controller offers many different functions including: ▪

Host Monitoring - The BIG-IP system is constantly monitoring the status of each ‘real’ server host. In the upcoming diagram, the offline server (server 2) will not be used or considered in a load balancing decision seeing its monitor is failing.

Load Balancing - The BIG-IP system will load balance the traffic and make a decision on which real server will receive each request. In our upcoming diagram we are using Round Robin as the load balancing algorithm.

The following diagram demonstrates this full proxy functionality in respect to the TCP/IP connections;

73 73


1. 2. 3.

4.

The client establishes a TCP connection to a virtual IP address hosted on the BIG-IP system and sends a HTTP GET request. The client TCP connection is terminated on the BIG-IP system. Once the client connection has been established, the BIG-IP system will make a load balancing decision and choose one of the three servers. Seeing that Server 2 is currently being marked as offline, it will choose between Server 1 and Server 3. When it has chosen a ‘real’ server, the BIG-IP system will establish a new TCP connection and send the HTTP GET request to the ‘real’ server. The BIG-IP system’s TCP connections will be terminated on the ‘real’ server and each of the client’s GET requests will be processed and responded to.

This happens for each new connection being sent to the BIG-IP system when using the Full Proxy architecture and it allows for a huge number of features and functions to be dynamically applied to each connection separately, as well as the inspection, manipulation and modification of application layer data. This architecture provides the foundation for many of the advanced features described in this book (as well as many, many more that are not) such as; iRules (working above OSI Model layer four), advanced Persistence methods, SSL offload, TCP Optimisations and HTTP Compression, Caching and Pipelining.

74 74


If you don’t actually require any of these features or the benefits of two independent connections, then using the Packet Based Proxy is probably preferable as it is simpler and will provide even higher performance. Note in some documentation and other materials published by F5 the Full Application Proxy is sometimes referred to as the Fast Application Proxy.

The Packet Based FastL4 Proxy A Packet Based Proxy architecture is what was employed in the first generation of load balancers and generally only operates up to OSI Model layer four, the transport layer. Sometimes referred to as a Half Proxy, there is only a single connection which the load balancer modifies the TCP/IP parameters of, without the client or server being aware. The half proxy does not act as either a client or server from a TCP/IP perspective. The actual connection state and flow of packets is generally not controlled in any way. The following diagram demonstrates this half proxy functionality in respect to the TCP/IP connection;

75 75


1. 2. 3.

Client establishes a TCP connection to a virtual IP address (VIP) hosted on the Application Delivery Controller (ADC) and sends a HTTP GET request. The client TCP connection are NOT terminated on the ADC. Only the destination IP address and TCP/IP parameters. The client TCP connections is terminated by the relevant real server and each client GET request is processed and responded to.

Unlike with the Full Application Proxy, the advanced features described in this book (as well as many, many more that are not) such as; iRules (working above OSI Model layer four), advanced Persistence methods, SSL offload, TCP Optimisations and HTTP Compression, Caching and Pipelining are not available with the Packet Based Proxy. Even though a Packet Based Proxy operates up to layer four, the Full Application Proxy still provides some advantages over it even at this layer, due to its use of separate client and server-side connections and the resulting ability to modify and control separate parameters for each.

The lines between the half and full proxy can sometimes get rather blurry as one obviously evolved from the other resulting in features that can be common to both. In the most simplistic terms, the half proxy does not act as a TCP/IP client or server; it operates transparently with the single connection established between the real client and server. The full proxy acts as a TCP/IP server to the client and client to the real server; it terminates the first and initiates the second and thus there are two independent connections.

OneConnect Also known as Connection Pooling, the OneConnect feature minimises the number of server-side connections by reusing previously established connections for subsequent client requests. Rather than closing an idle connection to a real server (Pool Member) and reopening a new one for the next client request that gets load balanced to that server, the connection is maintained and re-used, within user configurable limits. This is demonstrated in the following diagram.

76 76


1. 2. 3.

77 77

Client 1 establishes a TCP connection to a virtual IP address hosted on the BIG-IP system and sends a HTTP GET request. The BIG-IP system establishes a new TCP connection to the end server and sends the HTTP GET request. When a new request arrive at the BIG-IP from for instance Client 3 or Client 4, it will load balance the request to an end-server. Once the load balancing algorithm has chosen an end-server, the BIG-IP will review its own connection table to see if it contains any stale TCP session to the end-server which is currently not being used by a client. If it finds one, it will use that TCP session and directly send the GET request to the end-server.


2. The TMOS Administrator Exam The TMOS Administrator exam is the second within the F5 Professional Certification Program and is based on TMOS v11.4. Passing this exam is a prerequisite for all further certifications and exams. Passing the Application Delivery Fundamentals 101 exam is a prerequisite to taking this one. In this chapter we’ll discuss the wider Professional Certification Program and detail additional resources that you might find useful as you work through this guide and plan for the exam.

The F5 Professional Certification Program The F5 Professional Certification Program (F5-PCP), as it is now known, has been undergoing radical transformation since the second half of 2012. Prior to this transformation, there were a limited set of exam subjects at two certification levels. With the new program there are now three levels of certification and four levels of exams or labs (there’s a difference as the first level exam does not result in any certification or credential award.) All four of the exam levels (three certification levels) are shown in the following table; Exam Level 101

Exam Name Application Delivery Fundamentals

Certification Level None

201

TMOS Administration

C1: F5 Certified BIG-IP Administrator (F5-CA)

301a

LTM Specialist: Architect, Set-up & Deploy

None

301b 302

LTM Specialist: Maintain & Troubleshoot BIG-IP DNS Specialist

C2: F5 Certified Technology Specialist (F5-CTS) LTM C2: F5 Certified Technology Specialist (F5-CTS) BIG-IP DNS

303

ASM Specialist

C2: F5 Certified Technology Specialist (F5-CTS) ASM

304

APM Specialist

C2: F5 Certified Technology Specialist (F5-CTS) APM

78 78

Skillset ▪ Basic network, protocol ▪ ADC concepts and operation ▪ TMOS architecture and modules ▪ Basic troubleshooting ▪ Day to day maintenance and management of devices and configuration objects ▪ Architect ▪ Setup ▪ Deploy ▪ Maintain ▪ Troubleshoot ▪ DNS administration ▪ GSLB, ▪ Multiple data centres ▪ Configuration and administration ▪ Web application security and operation ▪ Configuration ▪ Administration ▪ RAS, AAA & SSL VPN configuration ▪ Administration


401

Security Solution Expert

C3: F5 Certified Solution Expert (F5-CSE, Security)

402

Cloud Solution Expert

C3: F5 Certified Solution Expert (F5-CSE, Cloud)

▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

LTM GTM ASM APM AFM BIG-IQ modules IP Intelligence (IPI), WebSafe and MobileSafe LTM GTM BIG-IP Cloud Edition Automation Cloud Platforms OpenStack RedHat® OpenShift Kubernetes© F5 Container Connector F5 Application Connector RestAPI

In order to achieve the certification F5 Certified Technology Specialist (F5-CTS) LTM you will need to pass both the 301a and 301b. As you’ll know, the first exam doesn’t result in a certification; this is designed to encourage greater candidate commitment and deter ‘casual’ candidates who might normally take an ‘easy’ entry level exam simply to bulk out their CV. This, along with the wider network, protocol and application knowledge requirements increase the value and quality of the program and hopefully reduce the likelihood of accelerated training programs being formulated. Further information on the PCP can be found here: https://f5.com/certification.

Why Become Certified? Before embarking on any certification path, this is a worthwhile question to ask of yourself. There are many benefits to certification (and debate on the entire subject) but most of them must be qualified based on factors such as; which vendor, the program’s reputation, the employment market, employer attitudes, certification relevance and more. Remember that most vendors will make money from a certification program regardless of its benefits or value to you. Also keep in mind that a certification doesn’t prove you are competent. Here is our view on the typical benefits; ▪

Certification involves study, learning and the acquisition of knowledge – these are all good things but remember you’ll learn and benefit more if you go for something that isn’t an everyday part of your job. It’s still of benefit to certify in skills you already possess, and this will help fill any gaps in your knowledge, but studying something outside of your everyday will be more rewarding and hopefully open more avenues of opportunity in the future, especially if you chose something in demand or likely to be soon.

Certification will improve your understanding, knowledge and self-confidence.

79 79


Certification proves to others you can study, read, take notes, work alone, follow through, do research and organise yourself in general – assuming it hasn’t taken too long to achieve and isn’t considered an easy certification.

Certification can help you keep your job, gain a pay rise or a promotion although what you choose, and its perceived value will be critical here.

Certification gives you an advantage over other candidates without it although, again, what you choose, and its perceived value will be critical.

Choosing a Certification All of the benefits detailed previously will vary in ‘weight’ depending on the certification program (or programs) you chose to embark on. When deciding, you should consider the following; ▪

Forget the vendor; will you learn something useful about technology, skills that you can use even if the vendor went out of business? Does the certification carry any weight in the market, how is it perceived by employers/hirers? Do too many people have it? Is this certification alone good enough to achieve your goals? Is there demand for the certified skills? What benefits of certification does the vendor provide, if any?

▪ ▪ ▪ ▪ ▪

Getting Started If you’ve passed the Application Delivery Fundamentals 101 exam, which is a prerequisite to this one, you should already know this but in case you need a reminder, we’ll repeat it here. You should take a quick look at the certification pages on the F5 website that can be found here: https://f5.com/certification. A getting started page can be found here: K93611383: F5 certification | Introduction and very useful program policies can be found here: K90101564: F5 certification | Policies and program details. Along with the overview provided at the start of this chapter this should tell you all you need to know about the certification program. You should already have one but if not, register for an F5.com account here: https://login.f5.com/resource/registerEmail.jsp which will give you access to a number of resources exclusive to registered users. Equally, a DevCentral account will also be very useful and provides access to F5’s community support and documentation site. Register here: https://devcentral.f5.com/register. You can also follow @F5Certified on Twitter and join the very active LinkedIn group here: http://www.linkedin.com/groups?home=&gid=85832.

80 80


Taking Exams As you should know, you must register with the F5 PCP here: http://certification.f5.com/ in order to be eligible to take this or any other exam and book it through Pearson VUE. The number of questions, time allowed, and passing score are provided when you book the exam. You can also find the passing score here: K29900360: F5 certification | Exams and study materials. Exams are typically $135 USD in the Americas, $145 USD in EMEA, and $155 USD in APAC and normally last at least 90 minutes. You must wait at least 15 days before you can retake a failed exam the first time, 30 days the second time, 45 days the third time and finally a full year the fourth time. You have to wait a full year before you can attempt an exam for the fifth time to decrease the possibility of cheating and question recording. The extended delay ensures you face a rewritten exam as exams are updated every two years. Certifications expire after two years; re-certifying your highest certification achieved recertifies all lower level certifications, as is the norm for most certification programs. Note that F5 Training courses only cover the F5-specific elements of each exam as you are expected to already have (or gain) knowledge and experience of general networking and network and application protocols. Don’t worry, this book, of course, covers everything.

Additional Resources The following will be of particular interest to students studying for this exam;

Practice Exams F5 now offer official practice exams to help you accurately predict your likely performance on the live, production exams. The practice exams are designed to mimic the real tests which means you will receive 80 questions to answer within 90 minutes. As of this book’s writing the exams cost $25 for a single test which needs to be attempted within 30 days or $40 for two tests that need to be attempted within 90 days. To take a practice test visit https://portal-v5.examstudio.com/Default.aspx?id=20882 and log on using your candidate credentials.

Additional Study Material Official study guides and exam descriptions can be found in this AskF5 article: K29900360: F5 certification | Exams and study materials.

AskF5 Available at: https://support.f5.com/ (previously https://ask.f5.com/ which still works too) AskF5 is the F5 Networks technical knowledge base and self-service online support site – no account is required. AskF5 provides knowledge base articles related to; support, known issues, solutions, best practises and security advisories. You can also obtain release notes, manuals and guides.

81 81


DevCentral F5 DevCentral (DC), available here: https://devcentral.f5.com/ is a community website featuring forums, blogs, tech tips, wikis, code sharing for iRules, iControl, iApps templates, tutorials and more. An account is required to access some content or contribute. Created as CodeShare in 2003 by Joe Pruitt, the architect of iControl (Joe is still with the company) DevCentral now has over 250,000 members in 191 countries. Membership grew over 25% in 2012 alone.

F5 University Free, self-paced web-based training related to basic technologies and concepts, changes in new software versions and basic LTM configuration are available via the F5 University available here: https://university.f5.com/. An F5 support account is required to access the site. You can also gain lab access to an F5 running TMOS v11.4.0 (plus two Linux hosts) for two hours at a time; an invaluable tool for those without access to their own device.

Exam Blueprints These can be found on the F5.com website and in the Downloads section of the CMS and provide a comprehensive list of the exam objectives and the skills and knowledge required to pass the exam. The blueprint for this exam can be found here: http://www.f5.com/pdf/certification/exams/F5_blueprinttemplate_TMOS_v2.pdf.

BIG-IP LTM Virtual Edition (VE) Trial An LTM VE 90 Day Trial can be obtained from here: https://www.f5.com/trial/big-ip-trial.php - you’ll need an F5.com account to obtain it. You’ve probably already got one right and if not, it’ll be useful going forward. Unfortunately, the trial is for TMOS v12.1 which is slightly ahead of the TMOS version the exam is based upon.

BIG-IP VE Lab Edition You can now purchase the latest BIG-IP VE Lab Edition for the very, very cheap price of $95 (it used to be around $2000). It’s limited to 10Mb total throughput but includes LTM, GTM (DNS), AAM, AFM, APM (10 user limit), ASM. It’s an incredibly cost effective tool for getting hands on experience using F5’s products, lab testing and building an understanding of how things work and interact. Unlike with the 101 exam, this one does require some practical knowledge of actually using or configuring BIG-IP. You can request a license here: https://www.f5.com/trial/.

82 82


BIG-IP VE on Amazon Web Services (AWS) It takes more time, effort and research to get started but I can highly recommend AWS as an alternative to the VE Trial and Lab Editions, especially if you don’t have a lab server or powerful PC/laptop with the right software. As an added benefit you also get to learn about and gain practical experience with AWS (and the cloud) itself. The recently introduced Free Usage Tier (details here: http://aws.amazon.com/free/) makes building a small, private lab environment very cheap. You can create a Virtual Private Cloud (VPC) and a number of EC2 Linux server ‘micro instances’ for purposes such as running a web server or other services, all for free. Then you just need to add an LTM VE EC2 instance. It isn’t free, but you can create and run one, charged hourly, with any of the Good, Better or Best license bundles, at a very low cost. Those costs are constantly changing and depend on a number of factors (including taxes) but to give you an example, I can run a VE with the Good license for around $0.50 an hour. You only need to run your instances (and thus only get charged) as and when you need to. Of course, there is a steep learning curve to overcome but this is a very worthwhile option if your budget is limited and you have no other way to gain access to a device.

Other Clouds BIG-IP VE is also now available on Microsoft® Azure™ and Google© Cloud Platform™. All the benefits detailed above for AWS generally apply although it could be debated that as AWS is the most prevalent and popular cloud provider, any cloud related skills you gain are potentially more valuable.

83 83


3. Building Your Own Lab Environment A practical understanding of TMOS and LTM is an essential ingredient in any exam-passing formula. Whilst most readers of this book will hopefully have practical experience of F5 administration in a live, production environment, it’s rare any form of experimentation is possible. To that end, a so-called ‘lab’ that allows for this and more, without risk, is a must.

Fel! Bok There are a multitude of services and products that a useful lab can be created with and obviously we can’t cover them mär all. In this book we’ll only cover one that is free for non-commercial use and does not require any aditional expensive ket equipment. The lab environment should have no problem running on your PC or laptop as long as the following requirements are fulfilled: är inte CPU: ▪ The host system must have a 64-bit x86 CPU with 1.3 GHz or faster core speed. Multiprocessor systems are defi supported. nier ▪ An AMD CPU that has AMD-V support ▪ An Intel CPU that has VT-x support at. Memory: ▪ To run all of the machines for the lab you will need 4GB of memory. Disk: ▪

To run all of the machines for the lab you will need 30GB worth of diskspace.

The virtual machines are configured with more than 30GB but they are thin provisioned and will only occupy more diskspace when the virtual machines needs it.

Obtaining the Different Components to Build Your Lab In order to make this easier for you as the reader to build your own lab environment, we have created a webpage that contains mirrors, instructions and links to each component necessary to build your lab environment. This web page is located at: https://www.f5books.eu/building-your-own-lab/. Please visit this site to download all necessary components before you start building your own lab environment.

VMware Workstation Player™ The Hypervisor used in these lab exercises is VMware Workstation Player. The reason we have used this hypervisor instead of other open-source alternatives is simply because the F5 Virtual Machine is not fully compliant with some of the open-source hypervisors currently available. To obtain your VMware Workstation Player go to http://www.vmware.com/products/player/playerpro-evaluation.html This hypervisor is free of charge for non-commercial use and will work natively with the BIG-IP VE.

84 84


BIG-IP VE Trial Evaluation Key First you will have to obtain a BIG-IP VE 90 Day Trial Evaluation Key by filling out a trial evaluation form located at: https://downloads.f5.com/trial/secure/generate-eval-key.php?product=ltmve. We also keep an updated instruction and set of links on: https://www.f5books.eu/building-your-own-lab/. In order to fill out the form you will first have to register for a free F5 account. If you already have one, you simply have to log in and follow the instructions. When done, you should receive an email with the Base Registration Keys, therefore, verify that the email address assigned to your account is correct. The email will also contain links to download the ESXi image but ignore this as we require a specific version for our lab exercises.

Downloading the BIG-IP VE Machine After you have received your base registration key, download your BIG-IP® Virtual Edition (VE) from F5. In order to give you the correct user experience, we require you to download BIG-IP version 12.1.2. For instructions on how to download this version, please visit https://www.f5books.eu/building-your-own-lab/.

BIG-IP VE Lab Edition You can now purchase the latest BIG-IP VE Lab Edition for the very, very cheap price of $95 (it used to be around $2000). It’s limited to 10Mb total throughput but includes LTM, DNS (formerly GTM), APM (10 user limit) AFM, ASM, AVR, PSM and AAM. It’s an incredibly cost effective tool for getting hands-on experience using F5 products, testing and building an understanding of how things work and interact.

The Lab Architecture So, what are we building? It’s pretty simple yet covers all our needs, where the 201 syllabus is concerned at least. These are the computing components; ▪

A Linux client running Lubuntu, allowing the use of CLI and GUI based tools and software such as ping, PuTTY (SSH), Filezilla (FTP) and a web browser.

A BIG-IP VE running version 12.1.2

A Linux server running the Tomcat Apache web server, configured with five virtual hosts, listening on different IP addresses and TCP ports.

We’ll be using these networks; ▪

Management - used for configuring the BIG-IP.

External - the client-side network connecting the Linux client and BIG-IP; this will be a private (internal) network.

Internal - the server-side network connecting the BIG-IP and Linux server; this will be another private (internal) network

85 85


Here’s a diagram to help you visualise the end state:

In the end of this chapter you will find the instructions for how to configure your lab environment.

86 86


Lab Exercises: Setting up Your Lab Environment Exercise 1.1 – Installing VMware Workstation Player Exercise Summary In this exercise, we’ll install VMware Workstation Player that will act as our hypervisor to build up our lab environment. Simply put, a hypervisor is a platform which creates and runs virtual machines. VMware Workstation Player is free for non-commercial, personal and home use which perfectly suits our purpose as a personal lab environment.

Exercise Prerequisites Before you start this lab exercise make sure you have the following: The installation file for VMware Workstation Player. The version we’ll use in this exercise is v12.5. A machine which meets the system requirements detailed earlier running either Windows or Linux.

▪ ▪

Running the installation file 1.

Run the installation file VMware Workstation Player. This will start the installation wizard. Click Next to proceed to the next page.

2.

On the End-User License Agreement page, after reading the terms (should you wish to), check the I accept the terms in the License Agreement box and click Next to proceed to the next page.

87 87


3.

On the Custom Setup page, if you need to change the installation path for VMware Workstation Player click Change. If not then click Next to proceed to the next page.

4.

On the User Experience Settings page you will have the options to choose if the program should automatically look for updates each startup and send anonymous system data and statistical information to VMware. These settings are completely optional and will not affect the lab. You may choose on how you would like to proceed.

88 88


5.

On the Shortcuts page you will have the options to add shortcuts on the Desktop and/or the Start Menu Programs Folder. As with the previous step, this is entirely optional and will not affect the lab. You may choose on how you would like to proceed.

6.

On the Ready to install VMware Workstation 12 Player page, click Install to start the installation of program.

89 89


7.

90 90

Once the installation is finished you will be presented with the Completed the VMware Workstation 12 Player Setup Wizard. On this page, click Finished to end the setup wizard.


Exercise 1.2 – Importing the Virtual Machines into VMware Workstation Player Exercise Summary In this exercise we’ll proceed with importing the virtual machines necessary for the lab environment. The virtual machines are in an *.ova format which means that you can simply import them and with very little adjustments have a functioning lab environment.

Exercise Prerequisites Before you start this lab exercise make sure you have the following: ▪

Successfully installed VMware Workstation Player

Obtaining a BIG-IP VE Trial Evaluation Key At the time of writing, F5 offers a 90-day free trial edition of the BIG-IP VE. To access this trial edition, you will have to create an F5 account. This is free of charge and anyone can register for an account. 1. 2.

3. 4.

To get started with the BIG-IP VE Free Trial, go to the following web page: a. https://downloads.f5.com/trial/secure/generate-eval-key.php?product=ltmve On our website we make sure that all links are working and are up to date. Therefore, if the previous link does not work, please go to: a. https://www.f5books.eu/building-your-own-lab/ Fill out the trial evaluation form and click on Request License Key. Please verify that the email address assigned to your account is correct as the Base Registration Key will be sent to this address. In the email you will also receive a link to where you can download the BIG-IP VE machine. Ignore this as we require a specific version for our lab exercises.

Downloading the BIG-IP VE Virtual Machine For our lab exercises we require you to run version/build 12.1.2.0.0.249. 1. 2. 3. 4. 5. 6. 7. 8. 9. 10.

To download your BIG-IP VE virtual machine, visit https://downloads.f5.com. Click on Find a Download. Choose the Product Line BIG-IP v12.x / Virtual Edition. In the drop-down menu choose 12.1.2. Click on Virtual-Edition. If necessary, accept the Software Terms and Conditions. Click on BIGIP-12.1.2.0.0.249.ALL-scsi.ova. Select the download mirror appropriate for your location. When clicking on one of the links a download pop-up will appear. Save the BIGIP-12.1.2.0.0.249.ALL-scsi at a convenient location. we’ll be using this later in this exercise. If the previous instruction does not work, please visit https://www.f5books.eu/building-your-own-lab/. On this website we keep updated instructions and links to the lab components necessary for the lab exercises.

91 91


Downloading the Client Virtual Machine 1. 2. 3.

To download the Client Virtual Machine, go to the following web page: https://www.f5books.eu/building-yourown-lab/ Go to the Client Virtual Machine section and select one of the download mirrors available on the webpage. Save the virtual machine image at a convenient location. we’ll be using this later in this exercise.

Downloading the Apache Server Virtual Machine 1. 2. 3.

To download the Apache Server Virtual Machine, go to the following web page: https://www.f5books.eu/building-your-own-lab/ Go to the Apache Server Virtual Machine section and select one of the download mirrors available on the webpage. Save the virtual machine image at a convenient location. we’ll be using this later in this exercise.

Importing the F5 BIG-IP Virtual Machine into VMware Workstation Player 1. 2.

Start VMware Workstation Player. You should be presented with a licensing screen. Simply select Non-Commercial use only and you will arrive at the Welcome to VMware Workstation 12 Player screen.

3.

Once you are at the welcome screen, click on the Player tab and select File > Open.

92 92


4. 5.

Navigate to the location where you saved the OVA files and select BIGIP-12.1.2.0.0.249.ALL-scsi This will launch the Import Virtual Machine wizard. Here you can rename the Virtual Machine and select where you want to store it. Make sure that the location you choose to store it has enough disk space. Once you are done, click Import.

6. 7.

Next you will receive the License Agreement for the Virtual Machine. Click Accept to continue. Now the Virtual Machine is being imported into VMware Workstation Player. This might take a while depending on what hardware you are using. Once the import is complete, the virtual machine should end up in the library list.

8.

93 93


Importing the Client Virtual Machine into VMware Workstation Player 1. 2. 3. 4. 5.

94 94

Start VMware Workstation Player. You should be presented with the library screen. Click on the Player tab and select File > Open. Navigate to the location where you saved the OVA files and select F5_Lab_Client_vX.ova. Where X represents the current version of the OVA build. This will launch the Import Virtual Machine wizard. Here you can rename the Virtual Machine and select where you want to store it. Make sure that the location you choose to store it has enough disk space. Once you are done, click Import.


6. 7.

Now the Virtual Machine is being imported into VMware Workstation Player. This might take a while depending on what hardware you are using. Once the import is complete, the virtual machine should end up in the library list.

Importing the Apache Server Virtual Machine into VMware Workstation Player 1. 2. 3. 4. 5.

95 95

Start VMware Workstation Player. You should be presented with the library screen. Click on the Player tab and select File > Open. Navigate to the location where you saved the OVA files and select F5_Lab_ApacheServer_vX.ova. Where X represents the current version of the OVA build. This will launch the Import Virtual Machine wizard. Here you can rename the Virtual Machine and select where you want to store it. Make sure that the location you choose to store it has enough disk space. Once you are done, click Import.


6. 7.

Now the Virtual Machine is being imported into VMware Workstation Player. This might take a while depending on what hardware you are using. Once the import is complete, the virtual machine should end up in the library list.

Exercise 1.3 – Editing the Virtual Machine settings Exercise Summary In this exercise, we’ll continue to set up our lab environment. You should now have all three machines imported into VMware Workstation Player. Next, we need to configure the network interfaces on each machine so that they reside on the correct network. In our lab we’ll use what is known as a LAN Segment. A LAN Segment is a private network that can be shared with other virtual machines.

96 96


Exercise Prerequisites Before you start this lab exercise make sure you have the following: â–Ş â–Ş

Successfully installed VMware Workstation Player Successfully imported the machines F5_Lab_ApacheServer, F5_Lab_Client and BIGIP-12.1.2.0.0.249.ALLscsi.

Editing the Virtual Machine Settings for the F5 BIG-IP Virtual Machine 1. 2. 3. 4. 5.

Start VMware Workstation Player. You should be presented with the library screen. Click on the virtual machine named BIGIP-12.1.2.0.0.249.ALL-scsi. Click on Edit virtual machine settings. Click on the network adapter in the top of the list.

6.

Click on LAN Segments. This will launch a separate window where you can create LAN Segments.

97 97


7. 8.

Create the first LAN Segment called MGMT by clicking Add and writing the name MGMT. Create the next two LAN Segments using the same method. Name the them, Internal and External. When you are done, it should look like this:

9. Click OK twice to save the configuration. 10. Reopen the Virtual Machine settings by click Edit virtual machine settings. 11. Now for the first Network Adapter, assign it the LAN Segment called MGMT.

98 98


12. For the second Network Adapter, assign it the LAN Segment called External.

99 99


13. For the third Network Adapter, assign it the LAN Segment called Internal.

14. Click OK to save the configuration for the virtual machine.

Editing the Virtual Machine Settings for the Client Virtual Machine 1. 2. 3.

Click on the virtual machine named F5_Lab_Client_vX Click on Edit virtual machine settings. Now for the first Network Adapter, assign it the LAN Segment called MGMT.

100 100


4.

For the second Network Adapter, assign it the LAN Segment called External.

5.

Click OK to save the configuration for the virtual machine.

Editing the Virtual Machine Settings for the Apache Server Virtual Machine 1. 2. 3.

Click on the virtual machine named F5_Lab_ApacheServer_vX Click on Edit virtual machine settings. This virtual machine only has one Network Adapter, assign it the LAN Segment called Internal.

101 101


4.

Click OK to save the configuration for the virtual machine.

Exercise 1.4 – Starting Up the Virtual Machines Exercise Summary In this exercise, we’ll start all of our virtual machines and perform some final tweaking. We’ll also make sure you can access the management interface of the BIG-IP system.

Exercise Prerequisites Before you start this lab exercise make sure you have the following: ▪ ▪

Successfully installed VMware Workstation Player Successfully imported the machines F5_Lab_ApacheServer, F5_Lab_Client and BIGIP-12.1.2.0.0.249.ALLscsi. Successfully created all of the LAN Segments and assigned to the correct interfaces.

Starting the F5 BIG-IP Virtual Machine 1. 2. 3. 4. 5. 6.

Start VMware Workstation Player. You should be presented with the library screen. Click on the virtual machine named BIGIP-12.1.2.0.0.249.ALL-scsi. Click on Play virtual machine. This will start the virtual machine. The screen will turn black and prompt the message: GRUB Loading Stage 2.. The startup of the BIG-IP might take up to 10 minutes. Simply let it be and it will eventually give you the following screen:

102 102


Starting the Apache Server Virtual Machine 1.

2. 3. 4. 5. 6.

Start another instance VMware Workstation Player. VMWare Workstation Player only has support for one machine at a time. Therefore, in order to launch more than one, simply start VMware Workstation Player again. Once you have started VMware Workstation Player you should be presented with the library screen. Click on the virtual machine named F5_Lab_ApacheServer_vX. Click on Play virtual machine. This will start the virtual machine. The screen will turn black and text from the bootup will be printed out. After a few minutes the operating system should be fully loaded and you should be presented with the following screen:

103 103


Starting the Client Virtual Machine 1. 2. 3. 4. 5. 6.

Start another instance VMware Workstation Player. Once you have started VMware Workstation Player you should be presented with the library screen. Click on the virtual machine named F5_Lab_Client_vX. Click on Play virtual machine. This will start the virtual machine. The screen will turn black and text from the bootup will be printed out. After a few minutes the operating system should be fully loaded and you should be presented with the desktop:

Changing the Keyboard Layout for the Client Virtual Machine The default keyboard layout of this Linux machine is English (US). This may not be the preferred keyboard layout and if you need to change it please perform the following steps: 1.

In the bottom right corner there is an icon of the American flag.

2. 3.

Right Click on this Icon in order to launch a menu. Click on the item named “Keyboard Layout Handler� Settings.

104 104


4.

In this window, uncheck the setting named Keep system layouts:

5. 6.

This will unlock the possibility to add/remove keyboard layouts. Click on Add and in the list of available keyboard layouts, select the layout you wish to use and simply press OK. The new keyboard layout should now be added to the list of keyboard layouts.

7.

105 105


8.

In order to eliminate the risk of the linux host changing the keyboard layout, remove the US keyboard layout by selecting it and clicking Remove. When you are done the final results should look like this:

9.

Save your settings by clicking Close.

106 106


4. Introduction to LTM - Initial Access and Installation Before we can get started load balancing traffic to our servers, we need to perform the initial installation of the BIG-IP device. This chapter will take you through each step and the options available to you.

The BIG-IP LTM Module Local Traffic Manager (LTM) is a core feature module for the Traffic Management Operating System (TMOS) that runs on BIG-IP platforms, physical or virtual. LTM is today’s version of the original product that F5 the company was created to provide. Most other modules rely upon LTM to provide their own functions. The LTM’s purpose is to manage and load balance various types of traffic, services and applications. These can be web, file, proxy, DNS or email servers, caches, voice services and even IP routers. The LTM module is highly configurable and offers a multitude of features that solve many of the challenges that service providers and enterprise companies face today. Traffic management functions relate to the many things beyond mere load balancing that LTM is capable of, including contextual traffic routing, programmatic traffic manipulation, security, monitoring and much more.

Initial Setup There are three steps you need to perform in order to get any BIG-IP system up and running: 1. 2. 3.

Configure an IP address, mask and, if required, default gateway for the dedicated Management (mgmt) interface. License the system. Use the Setup Utility in the Configuration Utility WebGUI to specify basic device configuration settings including: the root and administrator passwords, module provisioning, interfaces, VLANs and self IP addresses. If the default management interface IP addressing configuration is appropriate for your environment, then you will not have to change its values.

Configuring the Management Port IP Address The default management port IP address of the BIG-IP system is 192.168.1.245/24. There are, however, some scenarios where DHCP will try to obtain an IP address from a DHCP server and if successful, this will be assigned to the management port instead. Here are all the possible scenarios: ▪ ▪ ▪

Where DHCP is not enabled, and in the absence of any prior static configuration, the device’s management port will be assigned the address: 192.168.1.245/24. No default route is created, as no default gateway is assigned. When DHCP is enabled, but there is no DHCP server available, or DHCP fails for any reason, the 192.168.1.245/24 address is again assigned. If DHCP is enabled and works successfully, the assigned IP address (and possibly default gateway) can be observed using the LCD panel or the CLI via the serial port (using command ip address show eth0).

Physical devices are (by default) not configured to use DHCP on the management port. However, Virtual Edition virtual machine images are configured, with the exception of .iso image files.

107 107


The management interface IP address can be set or modified using any of these methods: 1. 2. 3. 4.

The LCD panel on the appliance. The config command in the CLI. tmsh (traffic management shell). The Web GUI, but only if an address is already configured.

Configuration via the LCD Panel If you have physical access to a device, you can configure the management interface IP address using the LCD panel, as follows: 1. 2.

Use the red X button to put the LCD into menu mode. Use the navigation arrows to navigate to the System menu and use the Check mark (green tick) button to select it. 3. Select Management and press the Check button. 4. Select Mgmt IP and press the Check button. 5. Enter the IP address you want to use and press the Check button. 6. Enter the relevant netmask and then press the Check button. 7. Use the navigation arrows and select Mgmt Gateway and press the Check button. 8. Enter the default gateway you would like to use and press the Check button. 9. Use the navigation arrows and select Commit and then press the Check button. 10. Select OK and then press the Check button. Here’s an image of the LCD panel:

Configuring the Management IP address Using the Touch LCD Panel (iSeries platforms) On the new iSeries platform, the LCD panel has become a touch display. In order to configure the management IP address using the touch LCD panel, use the following instructions: 1. 2. 3. 4. 5. 6. 7. 8. 9. 10.

Touch the screen to activate Menu mode for the LCD. Tap Setup. Tap Management. For the Type setting, tap to select IPv4 or IPv6. Tap IP Address. Use the arrows on the screen to configure the management IP address and the prefix length. Tap Commit to save your changes. Scroll down and tap Gateway. Use the arrows on the screen to configure the default management route. If you do not have a default route, enter 0.0.0.0.

108 108


11. Tap Commit to save your changes.

Configuration Using the Config Command You’ll need to establish a serial console connection to the device in order to use this method. For a physical device, connect to the console port using a suitable cable and a terminal application. For a virtual machine, you’ll use a hypervisor console. If the device already has an IP address assigned, you can, of course, also use SSH. When using a physical serial console port, set the baud rate in your terminal application to 19200 as this is the default.

By default, the admin user account cannot login to the CLI.

1.

Launch a terminal client such as PuTTY and use one of the following methods: a. SSH to xxx.xxx.xxx.xxx. Where xxx.xxx.xxx.xxx is the management IP address. b. Connect using the Serial Console Port. Select the COM port that is connected to the BIG-IP system. 2. Log in using the default user account root and the password default. 3. Type the following command to launch the application: config 4. On the introduction screen (shown below), press [Enter] to confirm OK. 5. On the Configure IP Address screen, you will be asked if you would like to Use Automatic Configuration of IP Address. The default value is No. Confirm this setting by pressing [Enter]. 6. On the Configure IP Address screen, enter the IP address you would like to use. When done, use [Tab] to navigate to the OK selection and press [Enter] to move forward to the next screen. 7. On the Configure Netmask screen, enter the associated netmask. Use [Tab] to navigate to the OK and press [Enter] to move forward to the next screen. 8. On the next screen, you configure the Management Route. This is the default gateway that the HMS (Host Management System) operating system uses. If you have a default gateway for the management port, select Yes. If not, then select No. 9. If you selected Yes, enter the IP address of a suitable default gateway. 10. If you selected No or after you’ve entered a default gateway on the Confirm Configuration screen, select Yes to save the configuration.

109 109


Configuration Using TMSH You’ll need to establish a serial console connection to the device in order to use this method. For a physical device, connect to the console port using a suitable cable and a terminal application. For a virtual machine, you’ll use a hypervisor console. If the device already has an IP address assigned, you can, of course, also use SSH. When using a physical serial console port, set the baud rate in your terminal application to 19200 as this is the default. By default, the admin user account cannot login to the CLI. Once you’re connected and logged in, follow these steps: 1.

2. 3.

4.

Launch a terminal client such as PuTTY and use one of the following methods: a. SSH to xxx.xxx.xxx.xxx. Where xxx.xxx.xxx.xxx is the management IP address. b. Connect using the Serial Console Port. Select the COM port that is connected to the BIG-IP system. Log in using the default user account root and the password default. You will either be at a Linux host shell prompt or directly in the tmsh. This is indicated by the prompt in the terminal program.; a. Linux Host: config # b. TMSH: (/Common)(tmos)# The Linux host shell prompt is the default for the root user. In order to enter tmsh type the following command:

tmsh 5.

In order to set the management IP address, type the following command: create /sys management-ip

[ip address/netmask] 6.

To optionally configure the management route, type the following command: create /sys management-

route default gateway [gateway ip address] 7.

In order to to save the configuration, type the following command: save /sys config partitions all

110 110


The configuration changes you make in tmsh are only saved to the running configuration. If the BIG-IP device is rebooted the settings will be lost. Therefore, you must save the running configuration to the startup configuration by utilising the command save /sys config.

Configuration Using the WebGUI This method requires the device to already have an IP address and default gateway configured. The Configuration Utility, usually called the WebGUI, is a browser-based interface that gives you secure access to your BIG-IP device for real-time configuration. An Apache OpenSSL web server runs on the BIG-IP device in the HMS to provide this interface. To access the Web GUI, browse to the management IP address of the device ensuring you use https://. You may also be able to use a self IP address of the device if configured and permitted. When accessing the BIG-IP system for the first time using the WebGUI you will be prompted to run the Setup Utility which is a setup wizard created to assist the BIG-IP administrator to perform initial configuration of the system. Using this wizard, you will have the opportunity to change the management port address. The following instructions presume that this has already been run.

To modify the management interface address, follow these steps; 1.

2. 3. 4. 5. 6. 7.

Open up a browser session to https://xxx.xxx.xxx.xxx. Where xxx.xxx.xxx.xxx is the management IP address. On the first log-on attempt for that particular browser you will be prompted with a certificate error, but this is normal. The BIG-IP system is shipped with a self-signed certificate which will not be validated by the web browser. Accept the certificate and when the webpage has been retrieved it should load up the logon screen. Log in to the BIG-IP system using the default user name admin and the password admin. Navigate to System > Platform. Under General Properties change the Management Port Configuration to Manual. Enter the required management IP address and netmask. Optionally, enter a management route (a default gateway). Save your configuration by clicking Update. The HMS runs RedHat Linux operating system and provides the various interfaces and tools used to manage the system such as the WebGUI, tmsh CLI, DNS client, SNMP and NTP.

Licensing the BIG-IP System Once the device has a management IP address, it needs to be licensed using the Web GUI. This requires a base registration key; a 27-character long string stored in the /config/RegKey.license file, which uniquely identifies the device. This is used by the F5 license server to associate the device with the licensed modules you’ve paid for and thus enable their use on the device.

111 111


Not all systems are shipped with the base registration key (for instance the Virtual Editions), in which case, it must be manually entered. The registration key is presented in the following format: AAAAA-BBBBB-CCCCC-DDDDD-EEEEEEE Make a note of the base registration key and keep it in a safe place because it uniquely identifies the device. In some scenarios, such as an upgrade, the RegKey.license file may be deleted. Subsequently, when you need to update the license of the system you won’t be able to. In order to retrieve the Base Registration Key you will have to open up a ticket with F5 Support and this might delay the process, causing a long outage of your system.

The BIG-IP system uses the base registration key to generate what is known as a dossier, which is what is actually passed to the F5’s license server. The dossier contains numerous encrypted characters that uniquely identify your system. Multiple options are stored in the dossier including registration key and the system time. To make sure nothing goes wrong when generating the dossier, verify that the system time is correct. On physical appliances the base registration key is already present on the box. If you are using a virtual edition you will most likely need to enter the registration key manually.

Automatic License Activation In order to use automatic license activation, the BIG-IP device needs Internet access to reach the F5 licensing servers. Therefore, you will need to make sure a device is configured with a suitable IP address, default route and DNS server(s). These can be configured either manually or through DHCP. We have already covered configuration of the management interface IP address, mask and default gateway (and consequently default route), but we haven’t covered manual DNS configuration. Prior to the system being licensed, the only available method to manually configure DNS servers is via the CLI, using this command: $ [tmsh] modify sys dns name-servers add { 10.11.12.99 } With the Automatic method, the BIG-IP device generates a dossier and automatically sends it to the F5 license server. The F5 license server matches the dossier against its database, generates the license and sends it back to the device. The license is then installed on the BIG-IP device. The steps required to perform automatic license activation are as follows: 1.

2. 3. 4. 5.

Open up a browser session to https://xxx.xxx.xxx.xxx. Where xxx.xxx.xxx.xxx is the management IP address. On first logon for that particular browser, you will be prompted with a certificate error, but this is normal. The BIG-IP system is shipped with a self-signed certificate which will not be validated by the web browser. Accept the certificate and when the webpage has been retrieved it should load up the logon screen. Log in to the BIG-IP system using the default user name admin and the password admin. You will be presented with the Welcome screen, click Next to launch the Setup Utility. At the License page, click Activate. If the Base Registration Key value is not present, enter it.

112 112


6. 7. 8. 9. 10.

Select Activation Method: Automatic For the Outbound Interface setting, select the mgmt interface. Click Next to activate your BIG-IP device. On the next page, press Accept to accept the EULA. Wait while the BIG-IP device communicates with the F5 licensing servers, uploads the dossier, installs the License, and verifies its configuration. 11. Click Continue to load the Resource Provision page (we’ll cover Provisioning shortly).

Once the license has been installed, it is stored in the /config/bigip.license file.

Manual License Activation This method is used when the BIG-IP device does not have direct access to the Internet. It can also be necessary if the owner of the BIG-IP device wants to keep all the dossiers that the BIG-IP device generates. This activation method is, as you’d imagine, more involved than automatic activation. The dossier must be generated and then downloaded or copied to the connecting client’s clipboard using the WebGUI. A host must then submit the dossier to the F5 licensing server via a web page and obtain the generated license. The license is then transferred back to the BIG-IP device; again, either uploaded as a file or pasted from the clipboard, where it gets activated. In most scenarios, the device that you are using to access the BIG-IP device will have Internet access, so you can do it all using the same web browser that you use to manage the BIG-IP device. The steps required to perform manual license activation are as follows: 1.

2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14.

Open up a browser session to https://xxx.xxx.xxx.xxx. Where xxx.xxx.xxx.xxx is the management IP address. On first logon for that particular browser, you will be prompted with a certificate error, but this is normal. The BIG-IP system is shipped with a self-signed certificate which will not be validated by the web browser. Accept the certificate and when the webpage has been retrieved it should load up the logon screen. Log in to the BIG-IP system using the default user name admin and the password admin. You will be presented with the Welcome screen, click Next to launch the Setup Utility. At the License, page click Activate. If the Base Registration Key value is not present, enter it. Select Activation Method: Manual and click Next On the next page the dossier has been generated. Copy the dossier to the clipboard and either click the link “Click here to access F5 Licensing Server” or open up a new web browser (tab) and browse to: http://activate.f5.com. In the text box Enter your dossier, paste in the dossier that the BIG-IP device generated and click Next. On the Accept User Legal Agreement, check the box “I have read and agree to the terms of this license” and click Next Copy the license that was generated to your clipboard. Head back to the BIG-IP device and paste the license into the License box and click Next. Wait whilst the BIG-IP device installs the License and verifies its configuration. Click Continue to load the Resource Provision page.

113 113


When performing a license reactivation, the BIG-IP system may reload the configuration which will temporarily interrupt traffic processing.

Once the license has been installed it is stored in the /config/bigip.license file.

Provisioning Before you can start working with the modules that you plan on running on your BIG-IP system, you will first need to provision them. Provisioning can be done under System > Resource Provisioning. In this list you will be able to see all modules that currently exist, but note that even though they exist in this table they are not necessarily provisioned. You see, the license will state which modules you have the right to provision by reviewing the License State. Even if the module is set to Licensed it will still not be provisioned unless you click in the box named None and select one out of five different levels.

114 114


Keep in mind that provisioning will only give you some control over how much CPU, RAM and disk resources each module uses, you cannot specify an exact value. The resources it receives will be determined by the provisioning level that you have selected. You will be able to choose between the following levels: ▪

Dedicated – You will use this if you only run one module on your BIG-IP device.

Nominal – This will give the module the minimum resources available in order to run the module, and if there are resources to spare, this will also be available for the module. It will give a majority of the system resources to the module.

Minimum – This will give the module the minimum resources available in order to function and if there are resources to spare this may be distributed to other modules.

None – None is the same as having a module turned off. Meaning that the module is not provisioned.

Lite – This is used for selected modules that grant limited features for trial purposes.

When you provision multiple modules, you choose between Nominal and Minimum (Dedicated is only used for one module and None is the same as the module being turned off). This is very limiting, as you cannot specifically configure a set amount of memory or define how many CPU cores the modules should have.

The Setup Utility The Setup Utility is a quick and easy way to get started with your BIG-IP device once it is licensed and provisioned. It helps you configure the passwords of the system, networking, HA and other management settings. Here are some examples of what is configured during the Setup Utility process: ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪ ▪

Device certificates Host name Time zone Passwords for the root (used for CLI) and the admin (used for the Web GUI) account SSH access Self-IP addresses HA VLANs NTP DNS ConfigSync Failover Mirroring

Self-IP Addresses During the Setup Utility, you will configure what is known as self-IP addresses. A self-IP address is an IP address on the BIG-IP system which you associate with a VLAN. The BIG-IP will use this IP address to communicate with hosts in that particular VLAN, whether it is monitoring or application traffic.

115 115


When the BIG-IP system is configured in a High-Availability setup, you will also configure a floating self-IP address. This is the same as a regular self-IP address, but the ownership of this address will change depending on which BIG-IP system is active. In the following lab exercises, you will configure both a self-IP address and a floating self-IP address. This is part of the Setup Utility which you will run during the lab exercise. You can configure both, even though you do not configure the BIG-IP system in a high-availability setup. In case you add another BIG-IP system later on, there will already be a floating self-IP address configured.

Lab Exercises: Initial Access and Installation Exercise 2.1 – License, Provision and Initial Setup Exercise Summary In this exercise, we’ll go through the Licensing, Provisioning and the Initial Setup of your BIG-IP system. These are the actions necessary to get your BIG-IP system up and running and you will learn the following: ▪ ▪ ▪ ▪

How to access your BIG-IP system using the WebGUI. How to license your BIG-IP system. How to provision your BIG-IP system. How to create a baseline configuration using the Setup Utility.

Exercise Prerequisites Before you start this lab exercise, make sure you have the following: Network access to the BIG-IP system’s management port. Obtained a BIG-IP system’s base registration key. Obtained through lab exercise Exercise 1.2. Access to the Internet.

▪ ▪ ▪

Access the WebGUI via the Management Port 1.

2. 3. 4.

Open up a browser session to https://192.168.1.245. You will be prompted with a certificate error, but this is normal. The BIG-IP system is shipped with a self-signed certificate which will not be validated by the web browser. Accept the certificate, this will load up the logon screen. Log in to the BIG-IP system using the default username admin and the password admin. When logging on to the BIG-IP system for the first time you should be presented with the Setup Utility. Click Next in order to start the Setup Utility. When the Setup Utility starts, it will immediately go to the License page. Click Activate button in order to start the licensing process.

116 116


License your BIG-IP system 1.

Use the Base Registration Key in order to generate a dossier. If the base registration is already prepopulated, then follow the instruction present in 1a. If the base registration key is not prepopulated, then follow the instruction present in 1b. a.

If your Base Registration Key is already prepopulated, select activation method Manual and click Next.

Setup Utility Setup Utility > License General Properties Activation Method When done, click b.

Manual Next

If your Base Registration Key is not already prepopulated, enter the following values:

Setup Utility Setup Utility > License General Properties Base Registration Key Add-On Registration Key List Activation Method When done, click Next 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14.

Make sure that Manual Method is set to Download/Upload File In the Step 1: Dossier area click Click Here to Download Dossier File. Save the dossier.do file on your client computer. In the Step 2: Licensing Server area, click Click here to access F5 Licensing Server. This will launch a new web browser session to the F5 Licensing Server. When you are at the Activate F5 Product web page under Select Your Dossier File, click on browse. Browse to the dossier.do file you just downloaded. When done, click Next. On the Accept User Legal Agreement page, check the I have read and agree to the terms of this license. When done, click Next. On the next page, click Download license. Save the license.txt file on your client computer. Go back to your web browser session that is connected to the BIG-IP system’s WebGUI. In the Step 3: License area, click Browse and browse to the license.txt file. Select the license.txt file and click Open. When done, click Next. You will be prompted with a white box stating, “BIG-IP system configuration has changed”. Once it is done, click Continue and you will be presented with the Resource Provisioning page.

117 117

Enter the base registration key you obtained in Exercise 1.2. Leave blank Manual


Provisioning Your BIG-IP System 1.

On the Resource Provisioning page, provision your BIG-IP system using the following settings:

Setup Utility Setup Utility > Resource Provisioning Module Management (MGMT) Small Local Traffic (LTM) Nominal When done, click Next Your BIG-IP system may produce a warning message stating that certain system daemons may restart, or the system may reboot causing your web browser session to wait up to several minutes. This is normal when modifying the resource provisioning of the BIG-IP system.

Configuring the Device Certificates 1.

Next, you will be presented with the Device Certificates page. Keep the default values and move on to the next page by clicking Next.

Configuring the Platform Settings 1.

On the Platform page, configure your BIG-IP system using the following settings:

Setup Utility Setup Utility > Platform General Properties Management Port Configuration Management Port

Host Name Host IP Address Time Zone User Administration Root Account

Password: f5training Confirm: f5training Password: f5training Confirm: f5training Enabled * All Addresses

Admin Account SSH Access SSH IP Allow When done, click

Manual IP Address [/prefix]: 192.168.1.245 Network Mask: 255.255.255.0 Management Route: Leave Blank bigip1.f5lab.com Leave default Select the time zone appropriate for your location

Next

You will be prompted with a notice that you have changed the password and will therefore have to re-login to the device again.

118 118


2.

Log back into the BIG-IP system using the admin account with the password f5training. Once logged in, you will be redirected to the Setup Utility > Network page.

Performing the Standard Network Configuration 1. 2.

On the Setup Utility > Network page, under the Standard Network Configuration, click Next. On the Setup Utility > Redundancy page, ensure that it contains the following settings:

Setup Utility Setup Utility > Redundancy Redundant Device Wizard Options Config Sync High Availability When done, click 3.

Check the box Display configuration synchronization options Check the box Display failover and mirroring options Select Network for the Failover Method Next

Next, we’ll configure the VLANs and start with the Internal Network configuration. Here we’ll assign the VLANs. This includes the self-IP address, netmask and network interface. On the Setup Utility > VLANs page, enter the following settings:

Setup Utility Setup Utility > VLANs Internal Network Configuration Self IP

Floating IP Internal VLAN Configuration VLAN Name VLAN Tag ID Select the following VLAN Interface and Tagging.

IP Address [/prefix]: 172.16.1.31 Network Mask: 255.255.0.0 Port Lockdown: Allow Default Address: 172.16.1.33 Port Lockdown: Allow Default internal auto VLAN Interfaces: 1.2 Tagging: Untagged

When done, click Add This should result in the following configuration: Interfaces 1.2 (untagged) When done, click Next

Move the Interface 1.2 to Untagged by selecting it and pressing the arrow key.

119 119


4.

Next, we’ll configure the VLAN for the External Network configuration. On this page, enter the following settings:

Setup Utility Setup Utility > VLANs External Network Configuration Self IP

Default Gateway Floating IP External VLAN Configuration VLAN Name VLAN Tag ID Select the following VLAN Interface and Tagging.

IP Address [/prefix]: 10.10.1.31 Network Mask: 255.255.0.0 Port Lockdown: Allow None Leave Blank Address: 10.10.1.33 Port Lockdown: Allow None external auto VLAN Interfaces: 1.1 Tagging: Untagged

When done, click Add This should result in the following configuration: Interfaces 1.1 (untagged) When done, click Next 5.

Next, we’ll configure the High Availability Network Configuration. Even though we’ll not configure our BIG-IP system in a high-availability setup we can still add the configuration to prepare it. For the High Availability communication, we’ll use the existing internal VLAN which we created earlier in the Setup Utility. On the Setup Utility > VLANs page enter the following settings:

Setup Utility Setup Utility > VLANs High Availability Network Configuration High Availability VLAN Click the Select existing VLAN button Select VLAN internal When done, click Next 6. 7. 8.

On the next page, we’ll be asked to configure NTP. This is not necessary for the lab exercises. Skip to the next page by clicking, Next. On the next page, we’ll be asked to configure DNS. This is not necessary for the lab exercises. Skip to the next page by clicking, Next. Next, we’ll configure the local address of the ConfigSync. On the Setup Utility > ConfigSync page enter the following settings:

120 120


Setup Utility Setup Utility > ConfigSync ConfigSync Configuration Local Address When done, click 9.

172.16.1.31 (internal) Next

On the next page, we’ll configure the failover configuration. On the Setup Utility > Failover page, use the default settings specified in the following table:

Setup Utility Setup Utility > Failover Failover Unicast Configuration Local Address | Port | VLAN Failover Multicast Configuration Use Failover Multicast Address When done, click

172.16.1.31 192.168.1.245

1026 1026

internal Management Address

Unchecked (Disabled) Next

10. Next, we’ll configure the mirroring configuration. On the Setup Utility > Mirroring page, use the default settings specified in the following table:

Setup Utility Setup Utility > Mirroring Mirroring Configuration Primary Local Mirror Address Secondary Local Mirror Address When done, click

172.16.1.31 None Next

11. Now we’ll finish the Setup Utility as we’ll not configure the BIG-IP system in a redundant high availability pair. On the Setup Utility > Active/Standby Pair page, under Advanced Device Management Configuration click Finished.

121 121


Once you are done with the Setup Utility you be redirected to the Statistics page and at the top of the browser you will be presented with the message Setup Utility Complete. This is presented with the following message:

12. Log out from the BIG-IP WebGUI by clicking the Log out button and close down your web browser.

Exercise 2.2 – Verifying Administrative Access Exercise Summary In this exercise, we’ll verify the access to the BIG-IP system and that everything is working as it should be after the Initial Setup and also change the Port Lockdown settings. In this lab, we’ll perform the following: ▪ ▪

Test and verify the access to the BIG-IP system. Change the Port Lockdown settings.

Exercise Prerequisites Before you start this lab exercise, make sure you have the following: Network access to the BIG-IP system’s management port. A web browser and a terminal client such as PuTTY.

▪ ▪

Verify HTTPS Access to the Management Port 1. 2.

Open up a browser session to https://192.168.1.245 Log on to the WebGUI using the account admin and the password f5training.

Were you able to connect and log in? You should be able to do this. If you cannot connect and login, you will have to verify your configuration. 3.

Log out from the BIG-IP WebGUI system by clicking the Log out button

Verify HTTPS Access to the External Port 1.

Open up a browser session to https://10.10.1.31 Were you able to connect? You should not be able to. This is because the current Port Lockdown setting of the External VLAN is set to Allow None. We configured this during the Setup Utility. This is good practice and you should never allow external access to your BIG-IP system if you do not have a specific requirement to do so. To solve this, proceed with the next step of this exercise.

2. 3. 4.

Open up a browser session to https://192.168.1.245 and login using the admin credentials. Navigate to Network > Self IPs and click on the address 10.10.1.31. This will open up the configuration for that self IP address. On the Network > Self IPs > 10.10.1.31 page, change the following configuration:

122 122


Network > Self IPs > 10.10.1.31 Configuration Port Lockdown Custom List When done, click

Select Allow Custom Check the TCP and the Port. Enter the port 443 and press Add. Update

The results should look like the following diagram:

5. 6. 7.

8.

Log out from the BIG-IP WebGUI system by clicking the Log out button. Try to access the WebGUI once again using a new browser session to https://10.10.1.31. Since we have modified the Port Lockdown setting, you should now be able to access the WebGUI on the external Interface. You will be prompted with a certificate error, but this is normal. The BIG-IP system is shipped with a selfsigned certificate which will not be validated by the web browser. Accept the certificate, this will load up the logon screen. Log in to the WebGUI using the admin credentials.

123 123


9.

Now try to access the WebGUI on the external floating self-IP address. Open up a browser session to https://10.10.1.33. Did you succeed? You should not be able to access the WebGUI on the floating self-IP address. This is again caused by the Port Lockdown setting as this is configured on a per self-IP basis. If you would like to access the WebGUI on the floating self-IP address, then use the same configuration as in the previous scenario but instead use the floating self-IP address. 10. Log out from the BIG-IP WebGUI system by clicking the Log out button.

Verify SSH Access to the Management Port 1. 2. 3.

Launch a terminal client such as PuTTY and SSH to 192.168.1.245 on port 22. You will be presented with a security alert because the BIG-IP system is presenting a certificate that is not cached on the desktop. Simply click Accept and it will continue to the log in prompt. Log on using the account root and the password f5training.

Were you able to connect and log in? You should be able to do this. If you cannot connect and login you will have to verify your configuration. 4.

Close down the SSH session by typing:

[root@bigip1:Active:Standalone] config # exit Verify SSH Access to the External Port 1.

Launch a terminal client such as PuTTY and SSH to 10.10.1.31 on port 22. Are you able to connect?

You should not be able to connect with SSH to the external port. But why? What is causing this problem? Like we mentioned in the earlier exercise, Port Lockdown prohibits access to the external port and in the earlier exercise we only allowed access for HTTPS and not SSH. In order to allow access, perform the same configuration changes but instead add TCP and Port 22.

Verify SSH Access for the Admin Account to the Management Port 1. 2.

Launch a terminal client such as PuTTY and SSH to 192.168.1.245 on port 22. Log on using the account admin and the password f5training.

What happens? Does the connection fail? By default, the admin account does not have any access to the command line, so the result should be that the SSH connection would be immediately terminated. However, this can be changed. To change this setting, continue to the next step of this exercise. 3. 4. 5.

Open a browser session to https://192.168.1.245 and login using the admin credentials. Navigate to System > Users > User List and click on the admin account. This will open the configuration of the admin account. On the System > Users > User List > admin page, change the following configuration:

System > Users > User List > admin Account Properties Terminal Access When done, click 6.

Log out from the BIG-IP WebGUI system by clicking the Log out button.

124 124

tmsh Update


7. 8. 9.

Try again to launch a terminal client and SSH to 192.168.1.245 on port 22. Log on using the admin credentials. This time you should be able to log on but you will immediately log on, to tmsh as this is the Terminal Access we specified under the admin account configuration. Close down the SSH session by typing:

admin@(bigip1)(cfg-sync Standalone)(Active)(/Common)(tmos) # quit Verify Root Access to the WebGUI 1.

Open a browser session to https://192.168.1.245 and login using the root credentials. Were you able to log in? The root account does not have access to the WebGUI therefore this attempt should fail. This behaviour is default and cannot be changed.

Exercise 2.3 – Backing up the Configuration Exercise Summary In this exercise, we’ll save the current configuration of the BIG-IP system to store a baseline configuration of the system which we can revert to when needed. It will also be used for backup purposes. In this lab, we’ll perform the following: ▪

Create a UCS archive of the BIG-IP system configuration. We’ll cover backups and UCS archives in greater detail in the Maintain Configuration chapter but to give you a short description, UCS is a compressed archive that contains a snapshot of the BIG-IP system. It contains all the configuration files, the BIG-IP license, User Accounts and their passwords. It will also contain the SSL certificates that you have uploaded to the device (including private keys if not selectively excluded).

Exercise Prerequisites Before you start this lab exercise, make sure you have the following: Network access to the BIG-IP system’s management port. Storage on your client computer where you can store the backup.

▪ ▪

Creating a UCS Archive of the BIG-IP Configuration 1. 2. 3. 4. 5. 6. 7.

Open up a browser session to https://192.168.1.245 and login using the admin credentials. Navigate to System > Archives and in the upper right corner, click Create. Under File Name enter baseline.ucs and click Finished. This will generate the UCS archive and it can take up to a couple of minutes before it is finished. Once it is finished, it will prompt a message stating: /var/local/ucs/baseline.ucs is saved. Click OK in order to get redirected back to the Archives page. On the Archives page, click on baseline.ucs. This will open up the properties of the baseline.ucs archive. Under Archive File, click the Download: baseline.ucs. This will download the UCS archive. Browse to a convenient location and save the file. Now you have a backup of the Initial Setup that you have verified.

125 125


Chapter Summary ▪

The management interface IP address can be set or modified using the LCD panel on the appliance, the CLI (bash), tmsh (traffic management shell) or the Web GUI.

When using a physical serial console port, set the baud rate in your terminal application to 19200 as this is the default.

The default account for the CLI access is root with the password default.

The BIG-IP system uses the base registration key to generate what is known as a dossier, which is what is actually passed to the F5’s license server. The dossier contains numerous encrypted characters that uniquely identify your system.

The BIG-IP system can be licensed using the Automatic or Manual Licensing Method.

Before you can start working with the modules that you plan on running on your BIG-IP device, you need to provision them. Provisioning gives you some control over how much CPU, RAM and disk resources each module uses.

The Setup Utility is a quick and easy way to get started with your BIG-IP device once it is licensed and provisioned. It helps you configure the passwords of the system, networking, HA and other management settings.

126 126


Chapter Review 1. What is the default Management Port IP Address? a. b. c. d.

192.168.1.1/24 172.16.1.245/16 192.168.1.254/24 192.168.1.245/24

2. What command is used to change the Management Port IP address from CLI (bash)? a. b. c. d.

configure edit config ipedit

3. You have established a terminal connection to your BIG-IP system using PuTTY. You are using the admin account but are unable to log in. What is the problem? a. b. c. d.

The admin account is by default not able to log into the CLI. This needs to be configured on the admin account. You have not yet run the Setup Utility. During the Setup Utility you provide the admin access to the CLI. The BIG-IP system does not have CLI access by default, this needs to configured using the WebGUI. You have configured the wrong baud rate.

4. When using the Automatic License Activation Method, what requirements do you need to fulfil? a. b. c. d.

Configure an NTP server. Provide the BIG-IP system with Internet access. Run the Setup Utility prior to running Automatic License Activation Method. Register the device with F5 support.

5. What provision level will give the module the minimum resources available to run the module and if there are resources to spare it will receive this as well? a. b. c. d.

Dedicated Lite Minimum Nominal

127 127


Chapter Review: Answers 1. What is the default Management Port IP Address? a. b. c. d.

192.168.1.1/24 172.16.1.245/16 192.168.1.254/24 192.168.1.245/24

The correct answer is: d Where DHCP is not enabled, and in the absence of any prior static configuration, the device’s management port will be assigned address: 192.168.1.245/24. No default route is created as no default gateway is assigned. 2. What command is used to change the Management Port IP address from CLI (bash)? a. b. c. d.

configure edit config ipedit

The correct answer is: c The management interface IP address can be set or modified in CLI (bash) using the following command: config 3. You have established a terminal connection to your BIG-IP system using PuTTY. You are using the admin account but are unable to log in. What is the problem? a. b. c. d.

The admin account is by default not able to log into the CLI. This needs to be configured on the admin account. You have not yet run the Setup Utility. During the Setup Utility you provide the admin access to the CLI. The BIG-IP system does not have CLI access by default, this needs to configured using the WebGUI. You have configured the wrong baud rate.

The correct answer is: a 4. When using the Automatic License Activation Method, what requirements do you need to fulfil? a. b. c. d.

Configure an NTP server. Provide the BIG-IP system with Internet access. Run the Setup Utility prior to running Automatic License Activation Method. Register the device with F5 support.

The correct answer is: b To use automatic license activation, the BIG-IP device needs Internet access to reach the F5 licensing servers. Therefore, you will need to make sure a device is configured with a suitable IP address, default route and DNS server(s). These can be configured either manually or through DHCP.

128 128


5. What provision level will give the module the minimum resources available in order to run the module and if there are resources to spare it will receive this as well? a. b. c. d.

Dedicated Lite Minimum Nominal

Nominal will give the module the minimum resources available in order to run the module, and if there is are resources to spare, this will also be available for the module. It will give a majority of the system resources to the module.

129 129


5. Local Traffic Objects The BIG-IP Local Traffic Manager (LTM) is only one of many modules that can be run on the BIG-IP system and is the one we’ll be focusing on the most throughout the chapters of this book. As we covered in the 101 Application Delivery Fundamentals Study Guide, the main purpose of LTM is to assist organisations and companies with their application delivery by load balancing traffic between servers, offloading server services such as SSL processing, monitoring applications and ensuring traffic is not sent to a faulty or offline server and adding TCP optimisation techniques. The BIG-IP system is a default deny device, meaning that it will only accept traffic if it is configured to do so. In order for the BIG-IP system to process traffic it needs to be configured with listeners. Virtual Servers are one type of listener and in order for the BIG-IP LTM to process and load balance traffic, it needs to have certain Local Traffic Objects in place. These are Nodes, Pool Members, Pools and Virtual Servers and we’ll cover them all in this chapter.

Nodes Nodes are objects which represent the real servers or other hosts on your network. Nodes are only represented by an IP address and this is important to remember. A node is uniquely identified by its IP address and therefore two nodes cannot have the same IP address (unless they are in different route domains). A node is assigned a service (port) and then added to a Pool. In this moment the node becomes a Pool Member. A single node can be added to multiple pools (or even the same pool but with a different port) and thus logically represent multiple pool members. With a node, you can configure the host’s IP address, Node Name, Health Monitor, Ratio (used with some load balancing methods) and Connection Limit. You do not need to manually create nodes as they will be automatically created when you assign Members to a Pool. However, when assigning members to a pool you cannot specify any non-default configuration options including the name.

Pool Members Pool members are, conceptually, the actual application service that you load balance traffic to. Pool members are nodes and an associated service port (TCP or UDP listening port) that are added to a pool and have traffic load balanced across them. In other words, you can say that a pool member is the server-side listener. A pool member is uniquely identified by its IP address, service port and pool name. The members of a pool can also be members of other pools using the same or a different service port.

Pools A Pool is very similar to a server farm or cluster. It is a logical object that contains one or more pool members that traffic is load balanced across. With very few exceptions, all of the members contained in a pool serve the same content. Pools have many configuration options including Health Monitors and the Load Balancing Method itself. Whenever traffic has been received by a virtual server and it is ready to pass traffic on to the pool member, the BIG-IP system will send the traffic to the pool and this is where the actual load balancing takes place. The pool will choose the best available member based on health monitors and the configured load balancing algorithm.

130 130


When adding pool members to a pool, you can either manually add them or choose from a list of previously configured nodes, but the service port must be specified in all cases. A pool is assigned to a virtual server as the Default Pool unless it will be used as a Clone or Last Hop Pool. You should note that a virtual server isn’t required to have a default pool configured. Also, a pool can still be used even if it is not assigned to a Virtual Server, as it can be referenced using an iRule or a Local Traffic Policy. The Local Traffic Policies feature was introduced in version 11.4 and is an upgraded version of HTTP Class. It has similar features to that of an iRule where you can manipulate traffic based upon certain match conditions such as HTTP header, HTTP URI, HTTP host and perform actions when matched. You can for instance enable or disable compression, forward traffic to a specific pool/node or perform redirects. The huge benefit of using Local Traffic Policies is that they evaluate conditions in parallel, making them faster than iRules. They are also considered to be built-in functions making them preferred over iRules.

Virtual Servers As we previously mentioned, the BIG-IP system is a default deny device. In order for it to take in and process traffic you have to configure a listener. A virtual server is one type of listener. Virtual servers are made up of a virtual IP address and a service port that the BIG-IP systems listens to and receives traffic on. A virtual server configured with a specific IP address is referred as a host virtual server. However, a virtual server can also be configured to listen on a network address, referred to as a network virtual server. How you configure your virtual server to listen really depends on how your application is running and what requirements you have. For a standard virtual server setup listening on a specific port using the TCP protocol, the traffic usually flows in the following manner: 1. 2. 3. 4. 5. 6.

A client wishing to access the application establishes a connection to the virtual server IP address (typically provided via DNS resolution). If the incoming request (a SYN packet) matches the IP address and service (port) of a virtual server then it permits the packet and processes it. Since the BIG-IP system is utilising a full proxy architecture it completes the three-way handshake and establishes a TCP connection with the client. Once the TCP connection is established and the client has sent an application request, the virtual server will load balance it to a particular pool member, decided by the configured load balancing algorithm. Again, since the BIG-IP system is utilising a full proxy architecture, a new TCP connection will be established between the BIG-IP and the pool member on the service (port) that the pool member is listening on. Once established, the BIG-IP system will create its own application request containing the same payload as the client’s and sent it to the pool member. This is because the client-side and server-side connection are completely separate.

It is very important to remember that the BIG-IP system utilises a full proxy architecture and that traffic is actually being listened to on the client-side and server-side of the connection. On the client-side the BIG-IP system is listening for traffic using the virtual server and its associated service (port). On the server-side the pool member is listening for traffic on its associated service (port).

131 131


Turn static files into dynamic content formats.

Create a flipbook
F5 Networks TMOS Administration Study Guide by F5 Books - Issuu