Forum Discussion

badmojo42_14014's avatar
badmojo42_14014
Icon for Nimbostratus rankNimbostratus
Dec 18, 2013

Standby interfaces stay active

I have two LTM 4000's in an Active/Standby configuration. They are connected to two Palo Alto firewalls and a Cisco 6500 VSS core. I have two interfaces on each PAN connected to the F5's so that the F5's can fail-over without having to fail-over a PAN as well. The issue I am seeing is that the PAN is trying to send traffic to the stanby F5. Why are the interfaces active for a stanby unit? I can see on the PAN the IP address and MAC of the standby unit and not the active unit. I have a ticket in with support, but they have not been able to figure this out so far. I also tried using the MAC Masquerade on the traffic group, which works but it still tries to send data to the standby unit, so it works really poorly. 50% ping loss.

 

Thoughts anyone?

 

7 Replies

  • Why are the interfaces active for a stanby unit? The Standby unit is not offline, it is still processing traffic for the non floating self-IP or IP's associated to the vlan for which that interface is listed as a resource in the configuration. The non-floating IP's are always reachable on the standby unit, it is the floating IP for the VLAN of the HA pair that swaps back and forth based on the Active or Standy status. The interface does not go down.

     

    When you look at the ARP tables on the firewalls is the MAC for the floating IP consistent or does it change when you failover/failback?

     

    • badmojo42_14014's avatar
      badmojo42_14014
      Icon for Nimbostratus rankNimbostratus
      It shows both floating and the local address for the standby device. When I try to connect to the website, the arp table shows (incomplete)
  • Did you clear the arp table on the firewall after configuring MAC Masquerading? Sounds like the firewalls are dropping the gratuitous ARP, as they should, which is why you should be using MAC Masquerading. It sounds like for a short bit the MAC of the standby unit was learned by the firewalls, and needed to either be cleared or wait for them to timeout.

     

    Eric

     

  • Can you verify the peering is setup correctly? I have seen this behavior from standby units in the past when the trust is corrupted and needs to be re-established. This may arise if you have multiple traffic groups and the standby unit cannot connect to the active. Also, have you experienced trouble syncing or have you applied updates that may have corrupted the db?

     

    • badmojo42_14014's avatar
      badmojo42_14014
      Icon for Nimbostratus rankNimbostratus
      good idea. I recreated the trusts but no luck. :( same issue is still there.
  • bwolmarans_1284's avatar
    bwolmarans_1284
    Historic F5 Account

    Keep this in mind as you troubleshoot: http://support.f5.com/kb/en-us/solutions/public/7000/500/sol7577.html

     

  • please, show the command sho cm traffic-group traffic-group-1 field-fmt

     

    I have problem equal you.

     

    _S(/S2-green-P:Active)(/Common)(tmos) sho cm traffic-group traffic-group-1 field-fmt cm traffic-group-device traffic-group-1:DCLB_TVT_RJO_VCMP04_P.cielo.com.br { auto-failback-time 10 device-name DCLB_TVT_RJO_VCMP04_P.cielo.com.br failover-state offline - look how undustrud the other divece score 13406 traffic-group traffic-group-1 } cm traffic-group-device traffic-group-1:DCLB_TVT_RJO_VCMP04_S.cielo.com.br { auto-failback-time 10 device-name DCLB_TVT_RJO_VCMP04_S.cielo.com.br failover-state active score 5550 traffic-group traffic-group-1 } r Active)(/Common)(tmos)

     

    root@DCLB_TVT_RJO_VCMP04_P(/S2-green-P:Standby)(/Common)(tmos) sho cm traffic-group traffic-group-1 field-fmt cm traffic-group-device traffic-group-1:DCLB_TVT_RJO_VCMP04_P.cielo.com.br { auto-failback-time 10 device-name DCLB_TVT_RJO_VCMP04_P.cielo.com.br failover-state standby score 13406 traffic-group traffic-group-1 } cm traffic-group-device traffic-group-1:DCLB_TVT_RJO_VCMP04_S.cielo.com.br { auto-failback-time 10 device-name DCLB_TVT_RJO_VCMP04_S.cielo.com.br failover-state active score 5550 traffic-group traffic-group-1 } root@DCLB_TVT_RJO_VCMP04_P(/S2-green-P:Standby)(/Common)(tmos)

     

    can someone help