LTM dual-computer configuration manual v11
I. initialize the configuration
1. Enter the config configuration management address on the command line
two。 Enter the web interface to activate license (select)
3. Update device certificate System- > Device Certificate
Note: multiple duplicate certificates need to be deleted
II. Network configuration (Network)
1. Configure VLANs
Generally create two vlan:internal and external, and select the interface
Internal Select 1.1
two。 Configure Self Ips
Generally create two selfip:internal_selfip and external_selfip, and associate vlan (internal_selfip is on the same network segment as the server)
Select Allow Default for port lock. For more information on ip address, please see the table above.
III. Equipment Management configuration (Device Management)
1. Configure synchronous ip address Device- > name (self)-> Device Connectivity- > ConfigSync and Failover
ConfigSync chooses internal (to ensure that the virtual network card and adapter are connected correctly, so that both bigip and computers can communicate with each other), Failover can choose at will.
Note: both bigip1 and bigip2 complete this step and proceed to the next step
two。 Add the trust list Device Trust- > Peer List, and fill in the management port ip address, user name and password of the other party.
After configuring the above steps, only one party needs to add it, and both parties can trust each other.
3. Add the device group Device Groups, fill in the device group type (general Sync-Failover), pull members in, and select Network Failover
4. Configure the traffic group Traffic Groups, and pull the members in. Members is the ip address + port of the server (optional, dual-active)
Note: the dual-computer synchronization of the equipment has been completed here, and the following is the configuration business test
4. Local traffic configuration (Local Traffic)
1. Configure Pools Select monitor and add members
two。 Add Virtual Servers, configure address, vlan, snat, pool
Instead of using snat here, I use aotu map to automatically reverse to internal_selfip to enter the server.