Tuesday, January 24, 2012

F5 BIG-IP - Turn off your Healthchecks!

Actually don't...  But if you have a little lab going, and you are playing with NAT/SNAT, you might find that you are looking at the tcp connections on the server to confirm the source address the server is seeing, e.g. You should see the internal floating self ip of the F5 if you are auto-snatting for example.  But when you run your netstat command you will see the self ip appear for lots of www and https connections even though you have turned off auto-snat..

So.... Turn off your healthchecks!  I had 3, my_http,  my_https and my_ssh on each associated pool.  Once off, your netstat command output will be much clearer.  I'm assuming there are many cooler and less crude ways to massage the output but I like this test becuase I can see the ports the F5 is using for healthchecks and I can see for myself which self-ip its using for its monitors.

Oh and Don't turn off your healthchecks! unless you are in a lab of course ;)

0 comments: