Bug ID 780857: HA failover network disruption triggered by addition and removal of cluster managment IP

Last Modified: May 24, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP All(all modules)

Known Affected Versions:
14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.4, 14.1.0.5

Opened: May 09, 2019
Severity: 3-Major

Symptoms

If the cluster management IP address is added to the list of failover network unicast addresses, then removed, the blade management IP addresses in the unicast mesh will stop functiong

Impact

The blade management IP addresses in the failover network unicast mesh stop functioning: [root@VIP2200-R75-S5:/S1-green-P::Standby:In Sync] config # tmctl -w 200 -S sod_tg_conn_stat entry_key local_failover_addr remote_device_name pkts_received transitions last_msg status ----------------------------- ------------------- ------------------------------ ------------- ----------- ---------- ------ 10.200.75.8->10.10.10.1:1026 10.10.10.1:1026 VIP2200-R75-S8.sin.pslab.local 3249 3 1555399271 1 10.200.75.8->10.200.75.3:1026 10.200.75.3:1026 VIP2200-R75-S8.sin.pslab.local 0 1 0 0 <-- 10.200.75.8->10.200.75.4:1026 10.200.75.4:1026 VIP2200-R75-S8.sin.pslab.local 0 1 0 0 <--

Conditions

Add the cluster management IP address to the failover network unicast mesh, then remove it.

Workaround

Refer to this article for instructions on how to properly set up network failover for VIPRION systems: https://support.f5.com/csp/article/K37361453#7 As stated in the section "Defining a unicast mesh", do not add the cluster IP address to your unicast failover configuration. In the event that this address has been added and removed already, you can run: tmsh modify security firewall management-ip-rules rules add { accept_udp_1026 { place-before first ip-protocol udp destination { ports add { 1026 } } action accept } } This will add a firewall policy so port 1026 is no longer locked down, and the blade management IP addresses in the unicast mesh should begin to function properly again.

Fix Information

None

Behavior Change