资源描述
,Click to edit Master title style,Click to edit Master text styles,Second level,Third level,Fourth level,Fifth level,*,F5 Networks,Inc.,目录,N+M,介绍,最佳实践,配置步骤,Troubleshooting,V11-Device Service Clusters,Active/Active,Active/Standby,2 Active/1 Standby,5 Active,在设备组中同步配置,简单的,Active-Active,部署,手动自动同步,提升扩展能力,更高的设备利用率,V11,DSC,基本逻辑,最基本的逻辑是配置多个设备组和多个流量组,设备组,设备组是能够支撑某个业务的设备的集群,该业务可以在这个设备组中进行配置同步或高可用切换,流量组:流量组是某个或某些业务的组。该组为人工设定切换或自动切换的基本单位。,每个流量组在特定的设备组中进行高可用,每个流量组都可以独立切换。从而实现,即:台设备为主设备,台设备为被设备。,什么是设备组,(,Device Group,),?,设备组就是处于信任关系中的两台或多台BIG-IP设备,它们可共享资源并确保应用交付的高可用性,。,两类设备组,,即同步设备组,(,sync,only),与同步故障切换设备组,(,syncfailover)。,设,备组将系统的冗余扩展为,N+M,模式,即可能为,A/S,A/A,A/A/S,A/S/S,A/A/A/A,A/A/A/S,A/S/A/S,等,支持v11平台,:,VIPRION,、,机架式,或虚拟版本,配置设备组之前必须建立设备间的信任关系。,设备同步组,(,synconly,),设备同步用于文件夹级别的配置对象同步,;,对单个设备上的同步类型设备组的数目没有硬性限性,一个,设备可以加入多个同步类型设备组中,。,ISO、OPSWAT与QUOVA,更新不能,在组内,同步,设备同步组(,synconly,续),对设备进行分组,,,并建立它们间的信任关系,(设备证书),1.,有一台机器会作,为,Authority,角,色,它拥有,dtca.crt,;,2.,有可能有多台其他机器也为,Authority,的角色,这些,Authority,也,拥证书,,但没有私钥,3.,所有剩下的其他机器都作为,Nonauthority,角色,4.,所有的机器都有一张自己的,dtdi.crt,证书,这张证书是用于鉴别,该设,备的机器,名;,只要拥有,dtca,签发出来的证书的设备均可以加入到,trustgroup,中。,更改配置,后,可以将,更改在整组内同步,同步故障切换,模式,用于同步面向,发生,故障,时整,个,设备配置。(替换,HA,高可用性),各成,员,必须是同一平台,并拥有相同的,License,许可,。,每台设备只允许一个同步故障切换组,。,避免应用服务的中断,设备故障切换同步,组,(,Fail-over Sync,),Sync-,only,类型用于配置同步,例如,GTM,的配置同步。,Sync-,only,类,型支持,8,台设备。,Sync-Failover,类型用于,高可,用的切换,例如,LTM,的主备切换,。,Sync-Failover,类型支持,32,台设备。,设备,组的两种类型应用场景,Traffic Groups,是可以切换的,VS,、,SNAT,、,NAT,等的集合,创建流量组,并指定应用到流量组中,分配集群成员到流量组,如果某个设备中没有活动的流量组,则该设备处于备机状态。,如果设备出现故障,流量组迁移到集群中的另一台,BIG-IP,设备,什么是流量组,(,T,raffic group,),?,流量组就是一组floating IP地址,、虚拟地址与SNAT,它们可在BIG-IP设备组中的设备间漂移以维持高可用性。,流量组-1,默认设备:,设备2,流量组-2,默认设备:,设备1,流量组-3,默认设备:,设备3,虚拟地址-4,虚拟地址-3,虚拟地址-2,虚拟地址-1,虚拟地址-8,虚拟地址-7,虚拟地址-6,虚拟地址-5,虚拟地址-12,虚拟地址-11,虚拟地址-10,虚拟地址-9,流量组,只有虚拟地址,、floating IP、,NAT与SNAT,地址,转换,可以加入流量组,。,一个,虚拟地址、floating IP、,NAT与SNAT,地址,转换只能作为成员,加入,一个,流量组,。因此,一个应用程序不能同时在两个设备上处于活动状态。,每,个流量,组均,存在一个,默认设备,,即该流量组对象中的活动设备,。,在,v11.3,版本及之,前版本,不能通过设置策略确定,故障,时,切换,到哪台设备,,,当故障切换事件发生时,,流量组,的接管概率,是均匀分布的(,通过,流量组,对每台设备的计数打分,)。,但是可以指定手动切换的接管顺序。,V11.4,之后可以指定在故障切换时的接管顺序,。,流量组-1,默认设备:,设备2,流量组-2,默认设备:,设备1,流量组-3,默认设备:,设备3,虚拟地址-4,虚拟地址-3,虚拟地址-2,虚拟地址-1,虚拟地址-8,虚拟地址-7,虚拟地址-6,虚拟地址-5,虚拟地址-12,虚拟地址-11,虚拟地址-10,虚拟地址-9,流量组,的,类型,Active/Standby,在,配置,过程中,,创建,一个同步故障切换设备组,;,所有流量对象,(虚拟地址,、floating IP、NAT,与 SNAT,地址,转换,)都将会分配到单个流量组中,。,Active Device,将被,标记为默认设备,。,流量组-1,默认设备:,设备1,设备1,设备2,设备组-2,类型:同步故障切换,虚拟地址-4,虚拟地址-3,虚拟地址-2,虚拟地址-1,流量组类型(续),Active/Active,创建,第二个,流量组,将流量对象,设定,到新,流量,组中,,请,确保所有与应用程序,有关联的流量对象,都加入了同一流量组,将默认设备设置为设备,2,流量组类型(续),Active/Active/Standby,在授权,设备,1,与设备,3间建立设备间的信任关系,将设备,3,添加,到设备组中,相应地调整流量组成员和默认设备,(例如,Traffic1,和,2,的默认设备设为,device1,,,traffic3,的默认设备设为,device3,),目录,N+M,介绍,最佳实践,配置步骤,Troubleshooting,多活模式最佳实践,根据实际情况和各用户的情况来看,建议采用,3+1,或,4+2,的模式。,根据需,要建议把所有业务分为,N,类,每类业务运行在一台,F5,设备,。,切换顺序,建议前两个顺序手动设置,后面的顺序自动选择。,双活模式建议,DC1,DC2,APP1,APP2,Active,APP2,APP1,Active,目录,N+M,介绍,最佳实践,配置步骤,Troubleshooting,前期准备,NTP,设置。,确认设备软件版本一致。,确认设备,license,一致。,设备,mgmt,地址,掩码,路由。,当然设备,TMOS,必须得是,v11.x,且版本一样。,确保用于同步的,Vlan,的,Port Lockdown,选项不为,Allow None,。,基础信息确认方法,设备,DSC,基础配置(每台设备分别配置),设备,Config Sync,地址:,设备,DSC,基础配置,设备,failover,地址:,所指定的,Failover IP,地址必须属于,route domain 0,。,设备,DSC,基础配置,设备,Mirror,地址:,只能做,TCP,和,UDP,的,mirror,不支持不同硬件平台之间,mirror,,最大可以,mirror 15,台设备。,配置,peer list,通过此选项把多台远程设备加入到,local trust domain,。,Device IP Address:,建议配置,Device Connectivity,中配置的地址,Administrator Username:,admin,Administrator Password:,adminpassword,查看设备状态,把多台设备加入到,local trust domain,后可以通过,Device List,看到这些设备的信息。点击设备名称还可以看到每个设备具体的,license,,,SN,,,time zone,等。,Create Device Groups,Sync-Failover Type,Sync-only Type,Sync-failover,比,Sync-only,只多一个,Network failover,。,Device Group,配置选项说明,名称,含义,Name,Device group,名称,Description,注释,Group Type,Device group,类型,,sync-only,或者,sync-failover,Members,添加属于此,Device group,的成员,前提是先要在,peer list,中添加,Network Failover,是否对此,Device group,的设备进行,Network Failover,Automatic Sync,是否让设备间进行自动同步。,Full Sync,是全局同步还是增量同步,默认不勾选为增量同步。,Maximum Incremental Sync Size(KB),默认值为,1024KB,,增量最大到,1024k,,如果增量的配置超过,1024k,自动变为,full sync,。,Create Traffic Group,Traffic Group,配置选项说明,只有当配置了,Failover Order,时,,A,uto-failback,才能生效,,,如果配置,failover order,,且,failover order,中没有,available,设备时,才会执行,HA Load Factor,(,load-aware,)。,名称,含义,Name,Traffic group,名称,Description,注释,HA Load Factor,设备的负载值,用于,load-aware,MAC Masquerade Address,创建虚拟,MAC,欺骗地址,Auto Failback,是否进行自动回切。如果,auto-failback,开启,但是在,Failover Order list,中,first device,是,unavailable,,不会进行,auto-failback,行为。,Auto Failback Timeout,可以设置的值为,0-300,秒,默认是,60,秒,为了保障,mirror,工作正常,建议设置为,40-60,秒。,Failover Order,指定切换顺序,如果下一个为,unavailable,,跳过此设备,直到切换到,available,设备。,目录,N+M,介绍,最佳实践,配置步骤,T,roubleshooting,Troubleshooting,当,cluster,发生问题的时候,,,Troubleshooting,步骤为:,1,、排,查所有,device group,成员的各,种同步参,数是否正,确(,ConfigSync operation),。,2,、排,查,Device Service Clustering,。如果同步错误,,BIG-IP,会产生同步状态信息,可以通过这些信息来排查错误。,1.,ConfigSync operation,1.1,确定,DSC/ConfigSync,的基本元素:,Requirement,Description,GUI location,tmsh,Licensing/provisioning,Devices in a device group must match as closely as possible with respect to product licensing and module provisioning.,System,License,tmsh show/sys licensetmsh show/sys provision,Software versions,The device group members must run the same BIG-IP software version.,System,Software Management,tmsh show/sys software,Management IP,Each device must have a unique mgmt IP address,a netmask,and a mgmt route.,System,Platform,list/sys management-iplist/sys management-route,NTP,NTP is required for all device group members.,System,Configuration,Device,NTP,tmsh list/sys ntp servers,ConfigSync IP,The self IP addresses used for ConfigSync must be defined and be routable between device group members.F5 recommends that the addresses reside on a dedicated HA VLAN.,Device Management,Devices,tmsh list/cm device configsync-ip,Failover IP,The self IP addresses used for failover must be defined and routable between device group members(for sync-failover device groups).,Device Management,Devices,tmsh list/cm device unicast-address,Ports,The device group members should be able to communicate over ports 443,4353,1026(UDP),and 22(recommended).,N/A,N/A,Device trust,Device trust must be established for device group members.,Device Management,Device Trust,tmsh show/cm device-group device_trust_group,1.,ConfigSync operation,1.2,确定,commit ID,:,运行,tmsh,命令:,tmsh,run/cm,watch-devicegroup-device,在每台设备上执行上述命令,查看结果中的,cid.id,是否相同,如果不同,则说明某台设备缺少了最新的配置,则进行下一步的强制同步。,1.,ConfigSync operation,1.3,验证配置同步操作:,通过,GUI,,,Device Management,Overview,Devices,,选择上一步看到的,cid.id,最大的设备,进行强制配置同步,或者运行,tmsh,命令:,tmsh run,/cm config-sync to-group,tmsh run,/cm config-sync,from-group,1.,ConfigSync operation,1.4,确定同步状态:,通过,GUI,,,Device Management,Overview,:,或者运行,tmsh,命令:,tmsh show/cm,sync-status,1.,ConfigSync operation,1.5,Device Group,同步状态信息说明(一):,Sync Status,Summary,Details,Recommendation,Awaiting Initial Sync,The device group is awaiting the initial ConfigSync,The device group was recently created and has either not yet made an initial sync,or the device has no configuration changes to be synced.,Sync one of the devices to the group,Awaiting Initial Sync,hostname-1,hostname-2,etc.awaiting the initial config sync,One or more device group member has either not yet synchronized its data to the device group members or has not yet received a sync from other member.,Sync the device with the most current configuration to the sync group,Changes Pending,Changes Pending,One or more device group member has recent configuration changes that have not yet been synchronized to the other members of the device group.,Sync the device with the most current configuration to the sync group,Changes Pending,There is a possible change conflict between hostname-1,hostname-2,etc.,There is a possible conflict among two or more devices because more than one device contains changes that have not been synchronized to the device group.,View the individual sync status of each device group member,and then sync the device with the most current configuration to the device group,Not All Devices Synced,hostname-1,hostname-2,etc.did not receive last sync successfully,One or more of the devices in the device group does not contain the most current configuration.,View the individual sync status of each device group member,and then sync the device with the most current configuration to the device group,1.,ConfigSync operation,1.5 Device Group,同步状态信息说明(二):,Sync Status,Summary,Details,Recommendation,Sync Failure,A validation error occurred while syncing to a remote device,The device was unable to accept a sync due to a validation error.,Review the,/var/log/ltm,log file on the affected device,Unknown,The local device is not a member of the selected device group,The device that you are logged in to is not a member of the selected device group.,Add the local device to the device group,Unknown,Not logged in to the primary cluster member,The system cannot determine the sync status of the device group because you are logged in to a secondary cluster member instead of the primary cluster member.Pertains to VIPRION systems only.,Log in to the primary cluster member,using the primary cluster IP address,Unknown,Error in trust domain,The trust relationships among devices in the device group are not properly established.,On the local device,reset device trust and then re-add all relevant devices to the local trust domain,None,X devices with Y different configurations,The configuration time for two or more devices in the device group differs from the configuration time of the other device group members.This condition causes one of these status messages to appear for each relevant device:Device_name awaiting initial config syncDevice_name made last configuration change on date_time,Sync the device with the most current configuration to the sync group,1.,ConfigSync operation,1.6,Device,同步状态信息说明(一):,Sync Status,Summary,Recommendation,Awaiting Initial Sync,The local device is awaiting the initial ConfigSync.The device has not yet received a sync from another device and has no configuration changes to be synced to other members of the device group.,Determine what device has the latest/desired configuration and perform a ConfigSync from the device,Changes Pending,The device has recent configuration changes that have not yet been synchronized to the other members of the device group.,Synchronize the device to the group,Awaiting Initial Sync with Changes Pending,The configuration on the device has changed since joining the device group,or the device has not received a sync from another device but has configuration changes to be synced to other members of the device group.,Determine the device with the latest/desired configuration and perform a ConfigSync from the device,Does not have the last synced configuration,and has changes pending,The device received at least one sync previously but did not receive the last synced configuration,and the configuration on the device has changed since the last sync.,Determine the device with the latest/desired configuration and perform a ConfigSync from the device,1.,ConfigSync operation,1.6,Device,同步状态信息说明(二):,Sync Status,Summary,Recommendation,Disconnected,The iQuery communication channel between the devices was terminated or disrupted.This may be a result of one of the following:*The disconnected device is not a member of the local trust domain*The disconnected device does not have network access to one or more device group members,*Join the disconnected device to the local trust domain*Verify that the devices have network access using the ConfigSync IP addresses,Device does not recognize membership in this group,The local device does not recognize that it is a member of the device group.,Add the device to the device group,No config sync address has been specified for this device,The device does not have a ConfigSync address.,Configure a ConfigSync IP address for the device,Does not have the last synced configuration,The device previously received the configuration from other members of the device group but did not receive the last synced configuration.,Perform a ConfigSync operation which syncs the group to the local device,1.,ConfigSync operation,1.7,确定,log,信息:,运行,linux,命令:,查看,/var/log/ltm,文件,:,cat,/var/log/ltm,查看有关,DSC/CMI,的信息:,grep,-i cmi/var/log/ltm,查,看有关,ConfigSync,的信息:,grep,-i configsync/var/log/ltm,2.,Device Service Clustering,2.1,确定,device trust,状态:,运,行,tmsh,命令,:,tmsh,show/cm,device-group device_trust_group,2.,Device Service Clustering,2.1,确定,device trust,状态:,运,行,tmsh,命令,:,tmsh,show/cm,device-group device_trust_group,2.,Device Service Clustering,2.2,确定,device group,成员的同步时间:,运行,linux,命,令,:,date;tmsh list/sys ntp,在每台设备上运行该命令,确认每台设备的时间,2.,Device Service Clustering,2.3,确,认设备同步的地址:,确认同步地址:,tmsh,list/cm device,configsync-ip,确认网络连通性:,ping,确,认进程信息:,netstat,-pan|grep-E,6699,确认,DSC,同步状态信息:,run,/cm sniff-updates,在每台设备上运行该命令,确认每台设备的时间,2.,Device Service Clustering,2.4,确,认守护进程信息:,DSC,需要下列守护进程:,devmgmtd,:Responsible for establishing/maintaining device group,functionality,mcpd,:Allows,userland,daemons to communicate with,tmm,sod,:Provides failover and restart,capability,tmm,:Performs traffic management for the system,使用命令确认其信息:,bigstart,status devmgmtd mcpd sod,tmm,2.,Device Service Clustering,2.5,重新设置,Device trust,关系(一):,通过,GUI,,,Device Management,Device TrustLocal DomainReset Device Trust,:,2.,Device Service Clustering,2.5,重新设置,Device trust,关系(二):,通过,GUI,,,Device Management,Device TrustPeer List Add,,重新建立,trust,关系,:,2.,Device Service Clustering,2.6,重新设置所有,device trust,关系:,分别登陆各台设备,重建所有设备的,trust,关系,Troubleshooting,工具:,最后提供部分,Troubleshooting,工具,可以查看需要的信息:,使用方法:,tmsh run/cm sniff-updates,tmsh run/cm watch-devicegroup-device,tmsh run/cm watch-sys-device,tmsh run/cm watch-trafficgroup-device,
展开阅读全文