Ross_Vandegrift
Jul 09, 2009Nimbostratus
Wildcard forwarding VIP connections, Immediate Idle Timeout
Hi everyone,
In my LTM implementation, an HA pair of BIG-IP boxes act as the default gateway for clients that are load balanced behind it. As such, we need to provide IP service to the individual reals behind the BIG-IP.
To accomplish this I created a virtual server with VIP 0.0.0.0/0 that matches any port/protocol, type is Forwarding(IP), and the Protocol Profile is fastL4. This nicely replicates packet forwarding behavior of a normal router. With one exception: connections to/from individual nodes consume entries in the connection table. Since DNS is a major application of our installation, oubound DNS queries (which typically exchange a few packets and then evaporate) sit around for the default 300 seconds of idle time. This is around 500k sessions in my installation.
I noticed that if I create a new FastL4 profile I can change the Idle Timeout to "Immediate". This sounds like what I want - actual packet-by-packet (instead of flow-based) forwarding for non-VIP traffic.
However, the documentation says that Immediate timeout "Specifies that the system deletes idle connections immediately." But I can't find out what the definition of an idle connection is.
If a node sends a DNS request to a slow host and it takes two seconds to answer, was the connection idle for those two seconds? If so, do I risk burning CPU in connection table management? Also, in this scenario, if the BIG-IP does reap the connection and then the response comes in, is the response still forwarded? At that point it would have no session to match.
Thanks,
Ross