Forum Discussion

stan_peachey_86's avatar
Oct 03, 2016

choosing self-IPs for iQuery communication

I'm looking for advise on choosing self-ips for iQuery communication between BigIP-DNS (GTM) and LTM. We considered using the LTM virtual server self-IPs, but that net is most likely to experience external (ddos) attacks. We could configure a small network just for iQuery, but that seems like overkill. I'm curious to hear any thoughts/best practices regarding how self-IPs were chosen for bigip_add to exchange iquery SSL certificates with a remote BIG-IP system and ongoing iQuery communication.

 

3 Replies

  • Iquery should be on a different VLAN than your DNS traffic... Do you have a Firewall?--Adds another degree of security.

     

    'bigip_add' is the IP in which your GTM and LTM's will communicate. If you want a different IP, then you will have to readd your LTM and/or GTM's, via bigip_add with a different IP.

     

    Also your DNS Listener should be using a different IP than your Self IP's.

     

  • Lookup GTM DataCenter. It will lead you how to setup different "groups" and configure the LTM's under each "location"

     

    --When you configure host in a Datacenter, you will specify two IP's, monitored by big3d. The GTM will know when one or the other LTM is down, but keep your WIPs UP. The IP's will be the non-floating Self IP of the IP/VLAN your VIPs communicate.

     

    You also will want to research Topology.--Based on a users location, Topology will look at the user's IP and send them to that VS.

     

  • I've used the self-ips that the VSs are behind or on before, one of the advantages of doing this depending on your topology is that you are following the application traffic path inband therefore a more realistic view of the actual availability.