Forum Discussion

Benjamin_LEGRAY's avatar
Benjamin_LEGRAY
Icon for Nimbostratus rankNimbostratus
May 05, 2014

BIGIP system can't access internet with proxy

Hi,

I'm trying to configure a LTM cluster to access internet through a proxy. The goal is to re-activate licence in automatic mode.

I tried to configure the proxy parameters with this SOL:

"Optional: If the BIG-IP system connects to the Internet using a forward proxy server, set these system database variables.

Type tmsh modify sys db proxy.host value hostname to specify the host name of the proxy server.
Type tmsh modify sys db proxy.port value port_number to specify the port number of the proxy server."

But when I click on reactivate licence I have a timeout. If anyone had a solution. Thanks

9 Replies

  • uni's avatar
    uni
    Icon for Altostratus rankAltostratus
    Does DNS resolution work from the bash shell?
  • Yes the DNS resolution works perfectly from the bash shell. The proxy address is an IP address not an URL. When I launch a TCPDUMP during the re-activate licence trying I see the bigip contact activate.f5.com without the proxy settings. Thanks for your help.
  • Can you ping from the LTM to the proxy server you are attempting to specify?

     

  • I'm wonder how to do this as well....but I'm unable to locate any SOL making claim for proxy for this. If only OP had at least sited the whole SOL number....

     

    The closest I could find that explained proxy was a "Manual Chapter: Setting Up IP Address Intelligence Blocking" which the applies to box only lists "BigIP ASM 11.2.0".

     

    Well, I need this for BigIP LTM 11.5.1

     

    For both automatic license check (should I want/need to upgrade to a newer version someday), or currently so the update check might tell me that I'm two HF's behind. Which we had enabled for such desire.

     

    The update check page didn't indicate that it was failing to connect....

     

    Not sure what happened to my mailing list subscriptions. Last release email I got was September 8th for 11.6.0....last security notification September 28th. Need to know about these updates with our F5s being in scope for PCI.

     

    Now have to explain why I'm jumping from HF4 to HF6, and prompted because our account manager had emailed our chief security officer....

     

    The last time that happened, I had already applied the HF months ago....

     

    • lcpWidgit's avatar
      lcpWidgit
      Icon for Nimbostratus rankNimbostratus
      Hi, For Enabling IP Address Intelligence: https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm-implementations-11-5-1/8.html But currently it connects via IP not FQDN, we needed to whitelist the IP and vector.brightcloud.com . Bug ID 491560. As for the Update Check, I am about to submit a RFE to add proxy details. I am guessing there is one for re-activate licence in automatic mode.
  • lkchen's avatar
    lkchen
    Icon for Nimbostratus rankNimbostratus

    I'm wonder how to do this as well....but I'm unable to locate any SOL making claim for proxy for this. If only OP had at least sited the whole SOL number....

     

    The closest I could find that explained proxy was a "Manual Chapter: Setting Up IP Address Intelligence Blocking" which the applies to box only lists "BigIP ASM 11.2.0".

     

    Well, I need this for BigIP LTM 11.5.1

     

    For both automatic license check (should I want/need to upgrade to a newer version someday), or currently so the update check might tell me that I'm two HF's behind. Which we had enabled for such desire.

     

    The update check page didn't indicate that it was failing to connect....

     

    Not sure what happened to my mailing list subscriptions. Last release email I got was September 8th for 11.6.0....last security notification September 28th. Need to know about these updates with our F5s being in scope for PCI.

     

    Now have to explain why I'm jumping from HF4 to HF6, and prompted because our account manager had emailed our chief security officer....

     

    The last time that happened, I had already applied the HF months ago....

     

    • lcpWidgit's avatar
      lcpWidgit
      Icon for Nimbostratus rankNimbostratus
      Hi, For Enabling IP Address Intelligence: https://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm-implementations-11-5-1/8.html But currently it connects via IP not FQDN, we needed to whitelist the IP and vector.brightcloud.com . Bug ID 491560. As for the Update Check, I am about to submit a RFE to add proxy details. I am guessing there is one for re-activate licence in automatic mode.
  • I am guessing there is one for re-activate licence in automatic mode.

     

    i do see this but it seems it is not going to happen.

     

    ID362765 - [RFE] Add GUI configuration to enable BIGIP to access the internet for licensing and updates using proxy