#amazon(4873110653) #amazon(4797368535)
 
 

初期設定

Management Port Setup

[root@bigip:Active] / # config
 BigIP Management Port Setup
 ------------------------------------------------------------------------------



     +---------------------Configuration Utility------------------------+
     | Use this utility to add an IP address, netmask and default       |
     | route for the management port on this system.                    |
     |   You must add an IP address and netmask for the management      |
     | port before you can use the web-based Setup utililty.            |
     |                                                                  |
     |                                                                  |
     |                                                                  |
     |                                                                  |
     |                                                                  |
     +------------------------------------------------------------------+
     |                             <  OK  >                             |
     +------------------------------------------------------------------+
 BigIP Management Port Setup
 ------------------------------------------------------------------------------




     +--------------------qqConfigure IP Address------------------------+
     | IP Address                                                       |
     | +--------------------------------------------------------------+ |
     | |192.168.8.31                                                  | |
     | +--------------------------------------------------------------+ |
     |                                                                  |
     |                                                                  |
     +------------------------------------------------------------------+
     |                   <  OK  >          <Cancel>                     |
     +------------------------------------------------------------------+
 BigIP Management Port Setup
 ------------------------------------------------------------------------------




     +-----------------------Configure Netmask--------------------------+
     | Netmask                                                          |
     | +--------------------------------------------------------------+ |
     | |255.255.255.0                                                 | |
     | +--------------------------------------------------------------+ |
     |                                                                  |
     |                                                                  |
     +------------------------------------------------------------------+
     |                   <  OK  >          <Cancel>                     |
     +------------------------------------------------------------------+
 BigIP Management Port Setup
 ------------------------------------------------------------------------------




     +------------------------Management Route--------------------------+
     | Do you want to create a default route for the management port?   |
     | This is required if you want to connect to the management port   |
     | from another subnet.                                             |
     |                                                                  |
     |                                                                  |
     |                                                                  |
     +------------------------------------------------------------------+
     |                   < Yes >          < No  >                       |
     +------------------------------------------------------------------+
 BigIP Management Port Setup
 ------------------------------------------------------------------------------




     +-------------------Configure Management Route---------------------+
     | Management Route                                                 |
     | +--------------------------------------------------------------+ |
     | |192.168.8.254                                                 | |
     | +--------------------------------------------------------------+ |
     |                                                                  |
     |                                                                  |
     +------------------------------------------------------------------+
     |                   <  OK  >          <Cancel>                     |
     +------------------------------------------------------------------+
 BigIP Management Port Setup
 ------------------------------------------------------------------------------




     +---------------------Confirm Configuration------------------------+
     | Accept these settings?                                           |
     | IP: 192.168.8.31                                                 |
     | Netmask: 255.255.0.0                                             |
     | Route: 192.168.8.254                                             |
     |                                                                  |
     |                                                                  |
     +------------------------------------------------------------------+
     |                   < Yes >          < No  >                       |
     +------------------------------------------------------------------+

Setup Utility

Platform Setup

Options

Network (1/2)

Network (2/2)

ルーティング

設定

[root@bigip:Active] / # bigpipe route ip-addr/netmask { gateway next-hop }

デフォルト ルート

[root@bigip:Active] / # bigpipe route default inet { gateway next-hop }

確認

設定情報を出力

[root@bigip:Active] / # bigpipe route inet list
route 192.168.10.0 netmask 255.255.255.0 {
   gateway 10.0.0.10
}
route 192.168.11.0 netmask 255.255.255.0 {
   gateway 10.0.0.11
}

スタータスを出力

簡易形式で出力

[root@bigip:Active] / # bigpipe route inet gateway show
ROUTE 192.168.10.0/24 - gateway 10.0.0.10
ROUTE 192.168.11.0/24 - gateway 10.0.0.11

OS レベルの情報

[root@bigip:Active] / # netstat -rn
Kernel IP routing table
Destination     Gateway         Genmask         Flags   MSS Window  irtt Iface
192.168.10.0    10.0.0.10       255.255.255.0   UGH       0 0          0 A-IF
192.168.11.0    10.0.0.11       255.255.255.0   UGH       0 0          0 A-IF

削除

[root@bigip:Active] / # bigpipe route ip-addr/netmask delete

SNAT (Secure NAT)

概要

設定

[root@bigip:Active] / # bigpipe snat name { option... }
オプション説明
origin ip-addrNAT を許可する送信元アドレス
any も指定可能
translation ip-addrNAT 後の IP アドレス
automapNAT 後のアドレスを BIG-IP 自身の IP アドレスでオーバーロードする
冗長化している場合は仮想 IP アドレスでオーバーロードする
vlan name (enable|disable)NAT を許可する VLAN 名

確認

  1. 設定の確認
    [root@bigip:Active] / # bigpipe snat [name] list
    
  2. 動作状況の確認
    [root@bigip:Active] / # bigpipe snat [name] show
    

削除

[root@bigip:Active] / # bigpipe snat name delete

冗長化

概要

  1. Hardwired Failover
    • 最も一般的な方法
    • 2 台の BIG-IP をハードワイヤ ケーブルで接続する
    • Standby 側は Active 側からの電気信号を監視し、これが途絶えた場合にフェイルオーバーを行う
  2. Network Failover
    • 2 台の BIG-IP 間で 1028/tcp のセッションを張り、これが途絶えた場合にフェイルオーバーを行う

設定

手動 Failover

[root@bigip:Active] / # bigpipe failover standby

確認

ステータスの確認

Failover のログ

その他の設定

Auto last hop

MAC マスカレード

[root@bigip:Active] / # bigpipe interface ifname mac masq mac-addr

IEEE 802.1Q

設定

[root@bigip:Active] / # bigpipe interface ifname vlans enable

確認

[root@bigip:Active] / # bigpipe interface ifname vlans show

コンフィグ

ファイル

/config/bigip.conf

/config/bigip_base.conf

/config/BigDB.dat

保存

[root@bigip:Active] / # bigpipe save
/config/bigip.conf was renamed to /config/bigip.conf.bak (n lines).
[root@bigip:Active] / # bigpipe save all
/config/bigip_base.conf was renamed to /config/bigip_base.conf.bak (n lines).
/config/bigip.conf was renamed to /config/bigip.conf.bak (n lines).

リロード

マージ

[root@bigip:Active] config # bigpipe merge /config/bigip-AAA.conf
Reading configuration from /config/bigip-AAA.conf.
[root@bigip:Active] config # bigpipe verify merge /config/bigip-AAA.conf
BIGpipe is only validating the commands.
Reading configuration from /config/bigip-AAA.conf.
No problems found.

バックアップ

バックアップ

[root@bigip:Active] / # bigpipe config save path/filename.ucs
Saving active configuration...
Creating UCS for config save request...

リストア

[root@bigip:Active] / # bigpipe config install path/filename.ucs
Saving active configuration...
Creating UCS for config save request...
Reading configuration from /config/bigip_base.conf.
Reading configuration from /usr/bin/monitors/base_monitors.conf.
Reading configuration from /config/profile_base.conf.
Reading configuration from /config/bigip.conf.
Loading the configuration ...

対向機器への転送

[root@bigip:Active] / # bigpipe config sync [all]
Operation Status
Configsync Mode: Push
Transferring UCS to peer...
Installing UCS on peer...
Obtaining results of remote configuration installation...
Hostname of UCS file is lb01.foobar.com, local hostname is lb00.foobar.com
Installing shared configuration on host lb00.foobar.com
Saving active configuration...
Creating UCS for config save request...
Reading configuration from /config/bigip_base.conf.
Reading configuration from /usr/bin/monitors/base_monitors.conf.
Reading configuration from /config/profile_base.conf.
Reading configuration from /config/bigip.conf.
Loading the configuration ...

Saving active configuration...
Creating UCS for config sync all request...

その他

再起動

シャットダウン

[root@bigip:Active] / # sync
[root@bigip:Active] / # sync
[root@bigip:Active] / # sync
[root@bigip:Active] / # halt

ハードウェア ステータス

[root@bigip:Active] / # bigpipe platform show [all]

リソース情報

[root@bigip:Active] / # tmstat
 CPU:   8% busy    78% idle   14% sleep                          DDD MMM DD HH:MM:SS YYYY
 
       Memory Allocated                        New Flow     Old Flow         Poll
   76,542,564 / 834,666,496                      48,098       39,891          462 Cycles
  [  .  :  .  |  .  :  .==]                         108        4,114    6,046,493 Total
 
         Tcp            Crypto Ops       Random Class                       1,510 Timers
         992 Open          105 (total)      452 (total)                         0 Stats
          92 Accepts         0 rsa            0 Pseudo
          94 Connects        1 full hs        0 Entropy              Virtual Class
             Wait           94 record       452 Secure            15,502,629 (total)
           1 Rtx             0 cipher                             10,485,780 mco db
         141 Del ACK        11 (unseen)                            2,792,692 ssl
                                                                   2,126,805 tcl
[ . : . | . : . ]                [ . : . | . : . ]                    97,352 (unseen)
               0b rx      0 link             0b tx
[ . : . | . : . ]                [ . : . | . : . ]                      Umem Class
               0b rx      0 link             0b tx                   274,057 (total)
[ . : . | . : . ]                [ . : . | . : . ]                   262,039 ssl session c
               0b rx      0 link             0b tx                     3,587 rtm_internal
[ . : . | . : . ]                [ . : . | . : . ]                     1,855 connflow cach
               0b rx      0 link             0b tx                     1,357 pool member c
[ . : . | . : . ]                [ . : . | . : . ]                       808 xfrag cache
               0b rx      0 link             0b tx                     4,411 (unseen)

qkview

バージョン情報

[root@bigip:Active] / # bigpipe version | head
Kernel:
Linux 2.4.21-9.1.2.37.0smp
Package:
BIG-IP Version 9.1.2 97.0
Hotfix Version HF7
  Edition

Hot fixes:
   CR34771   Packages:  i686/tmm i686/tmm-debug i686/tmm-strict
   CR45656   Packages:  i686/bigpipe
 

トップ   編集 凍結 差分 バックアップ 添付 複製 名前変更 リロード   新規 一覧 検索 最終更新   ヘルプ   最終更新のRSS
Last-modified: 2020-07-08 (水) 18:10:14