Big-IP VE requirements
Big-IP VE requirements
Big-IP VE requirements
F5 Networks, Inc.
3
BIG-IQ 7.0 Setup Guide Documentation
4
BIG-IQ 7.0 Centralized Management Quick Setup Guide
1
Description: This guide will focus on the basic setup steps for BIG-IQ CM.
Prerequisites: None, this is entry level for a person not familiar with BIG-IQ Centralized Management.
1.1 Overview
This unofficial document details the technical steps needed to set up BIG-IQ v7.0 for testing in a test
environment. This guide assumes a small environment that requires high availability.
1.1.1 Infrastructure
F5 BIG-IQ Centralized Management is a platform that you use as a tool to help you manage BIG-IP devices
and all of their services (such as LTM, AFM, ASM, and so forth), from one location. BIG-IQ can manage up
to 600 (physical, virtual, or vCMP) BIG-IP devices and handle licensing for up to 5,000 unmanaged devices.
Using BIG-IQ helps you more efficiently manage your BIG-IP devices. That means you and your co-workers
don’t have to log in to individual BIG-IP systems to get your job done. Instead, you can discover, upgrade,
deploy policy changes, manage licenses, and more, from just one place.
From BIG-IQ, you can manage a variety of tasks from software updates to health monitoring, and traffic
to security. And because permissions for users are role-based, you can limit access to just a few trusted
administrators to minimize downtime and potential security issues. You can also allow users to view or edit
only those BIG-IP objects that they need to do their job.
An F5 BIG-IQ Centralized Management solution can involve a number of different elements. The topology
for these elements depends on your needs, and on whether you include data collection devices (DCDs) in
your solution. A typical solution can include the following elements:
• BIG-IQ system(s)
• BIG-IP devices
• Data collection devices
• Remote storage devices
5
BIG-IQ 7.0 Setup Guide Documentation
Note: We recommend that all work for this lab be performed from your local Web browser or from the
windows jumphost. No installation with your local system is required.
Goal:
In this module, you will learn how to provision BIG-IQ Centralized Manager (CM) and Data Collection Device
(DCD) in supported platforms.
Description:
This lab will deploy both BIG-IQ CM and DCD in VMware ESXi. Refer to below AskF5 link if you need
further details.
AskF5 Reference
The vSphere virtual machine guest environment for the BIG-IQ Virtual Edition (VE), at minimum, must
include:
• 4 virtual CPUs
• 16 GB RAM
• Important: When you provision the amount of RAM allocated to the virtual machine, it must match the
amount of reserve RAM.
• 1 VMXNET3 virtual network adapter
• 1 virtual network adapter
• At least 128GB disk
Description:
In this lab, we will deploy both BIG-IQ CM and DCD in AWS cloud. Refer to below AskF5 link if you need
further details.
AskF5 Reference
Before you deploy BIG-IQ in AWS, ensure that you meet below requirements:
• An active AWS account
• Access to the AWS Marketplace
• Valid BIG-IQ CM and BIG-IQ DCD registration keys (Contact your F5 Sales representative for this)
..NOTE:: Single or Multi Region is supported
Important: Per AWS best practice, this is required to get ssh access to the instance after boot. After
login, you can change the admin password for access to the GUI
3. Management subnet (public) For BIG-IQ GUI access, data sync between Primary/Secondary
4. External subnet (public) - For Elasticsearch Cluster traffic between BIG-IQ CM and BIG-IQ DCD (log-
ging node) - For BIG-IP device discovery, management, monitoring
5. Security group configuration. Configure your security group so that it meets below criteria: - Criteria
1 = allow-only-ssh-https from the source IP of your location for management access - Criteria 2 =
allow-all-traffic from the internal AWS subnet 10.0.0.0/16 for traffic between BIG-IQ devices
6. Internet gateway (for initial BIG-IQ activation) - If you cannot allow internet access, you will need to do
manual activation for BIG-IQ and BIG-IP pool licenses
7. Route Table configuration (association) - To allow access to internet for management and external
subnets
Important: DCD is required to use analytics, application dashboard, and other visualization features.
1. Search using keywords F5 BIG-IQ Note that F5 BIG-IQ Virtual Edition and F5 BIG-IP Cloud Edi-
tion deploy the same instance of BIG-IQ Centralized Manager.
2. Click Continue
4. Enter in 2 for number of instances to provision Primary and Secondary BIG-IQ CM devices. Select
your VPC and then management subnet.
5. Launch with 2 network interfaces. Select the External subnet for the additional NIC. Click Review and
Launch
6. For storage size, you can set it to 500GB. Select General Purpose SSD and click Next: Add Tags
8. Select the existing security group you created earlier, then click Review and Launch
9. Click Launch
10. Select the existing key pair you created earlier, then click Launch Instances
Goal:
In this module, you will learn how to complete the setup wizard for BIG-IQ CM and DCD.
Description:
In this lab, we will complete the setup wizard for BIG-IQ CM and DCD in Vmware ESXi. You will then
discover the DCD and activate service you want to monitor. Refer to below AskF5 link for official documen-
tation.
AskF5 Reference
Follow below steps to setup both BIG-IQ CM and DCD devices. The only difference will be step (2) below.
1. When you first log into the BIG-IQ, you must complete the setup wizard. The first step is licensing.
Enter in the Base Registration Key for your BIG-IQ CM, click agree to accept EULA and activate. Click
Next to proceed to the next step
2. Select BIG-IQ Central Management for CM. Select BIG-IQ Data Collection Device when configuring
your logging node, click Next
3. Specify the first BIG-IQ Hostname, Management Port IP Address, Management Port Route. Select
Self-IP for discovery address (recommended) and enter an IP address from the internal subnet con-
figured for your second network adapter in ESXi, click Next
4. Configure your DNS, Time Server, and set your Time Zone, click Next
Important: If this BIG-IQ is part of an HA or DCD configuration, make sure you keep track of the
pass phrase, because it cannot be recovered if you lose it.
6. Enter in the default (admin/admin, root/default) and new passwords for admin and root, click Next
8. Once your DCD setup is complete. Make sure you discover it on your CM device. Click System >
BIG-IQ DATA COLLECTION > BIG-IQ Data Collection Devices > click Add
10. Confirm that the Listener Address specifies the correct self-IP address on the data collection device,
then click Activate for every service you want to add
Description:
In this lab, we will complete the setup wizard for BIG-IQ CM and DCD in AWS cloud. You will then discover
the DCD and activate service you want to monitor. Refer to below AskF5 link for official documentation.
AskF5 Reference
Follow below steps to setup your BIG-IQ CM and DCD devices. The only difference will be step (2) below.
1. When you first log into the BIG-IQ, you must complete the setup wizard. The first step is licensing.
Enter in the Base Registration Key for your BIG-IQ CM, accept EULA and activate.
2. Select BIG-IQ Central Management for CM. Select BIG-IQ Data Collection Device when configuring
your logging node
3. In AWS, the Hostname, Management Port IP Address, Management Port Route are automatically set
by DHCP. Select Self-IP for discovery address (recommended) and enter in the internal IP assigned
to your second network interface using the appropriate netmask
4. Configure your Time Server using Amazon Time Sync Service and set your time zone
8. Once your DCD setup is complete. Make sure you discover it on your CM device. Click System >
BIG-IQ DATA COLLECTION > BIG-IQ Data Collection Devices > click Add
10. Confirm that the Listener Address specifies the correct self-IP address on the data collection device,
then click Activate for every service you want to add
Goal:
In this module, you will learn how to complete High Availability setup for BIG-IQ CM. Starting in BIG-IQ v7.0,
you have the option to chose Manual or Auto failover.
The steps are identical for AWS and VMware.
Description
In this lab, we will configure High Availability (Manual) for BIG-IQ CM. Refer to below AskF5 link if you need
further details.
AskF5 Reference
For the high availability pair to synchronize properly, each system must be running the same BIG-IQ version,
and the clocks on each system must be synchronized to within 60 seconds.
1. Click System > BIG-IQ HA > Add Secondary and enter in the secondary device connectivity infor-
mation
• Use self-ip of peer BIG-IQ. Depending on your network configuration you may use the
management-ip instead.
• Enter in admin and root password that you configured in the setup wizard (required)
• Click Manual Failover
2. Click Add to add the HA Peer Device
This completes the BIG-IQ High Availability (Manual) configuration.
Description
In this lab, we will configure High Availability (Auto) for BIG-IQ CM. When configuring auto failover, you’ll
also create or select an existing Data Collection Device (DCD) as a quorum device. A quorum DCD is used
as the deciding vote to determine which BIG-IQ becomes active if communication is disrupted between the
active and standby BIG-IQ in the HA pair.
Refer to below AskF5 link if you need further details.
AskF5 Reference
For the high availability pair to synchronize properly, each system must be running the same BIG-IQ version,
and the clocks on each system must be synchronized to within 60 seconds.
1. Click System > BIG-IQ HA > Add Standby and enter in the standby device connectivity information
• Use self-ip of peer BIG-IQ. Depending on your network configuration you may use the
management-ip instead
• Enter in admin and root password that you configured in the setup wizard (required)
• Click Auto Failover
• Select the DCD device that you discovered in the setup lab and enter in its root password
• Click Enable Floating IP and enter in an IP in the management subnet. You cannot use the
self-IP segment here
Note: Floating IP addresses are not support in public cloud due to limitations in those environ-
ments
Goal:
In this module, you will learn how to create BIG-IP templates in VMware for VE creation. Starting in BIG-IQ
v7.0, you can provision a new BIG-IP image from a template. This is tested on VMware vCenter v6.5, but
should also work on later versions.
AskF5 Reference
F5 Clouddocs Reference
Description
In this lab, we will create templates used for provisioning BIG-IP with DHCP issued IPs. Refer to below
AskF5 links if you need further details.
AskF5 Reference
F5 Clouddocs Reference
1. Access https://downloads.f5.com/
2. Navigate to your desired BIG-IP version and from the Virtual-Edition list of images, select the BIGIP-
<version>.ALL_1SLOT-vmware.ova. In test environments, this image will help to save on disk space.
1. Right click the host or folder and select Deploy OVF Template. . .
2. Select Local file > click Choose Files > select the downloaded ova file
1.5. Module 4: BIG-IP Template Creation for VMware (DHCP and IP Pools/Static) 27
BIG-IQ 7.0 Setup Guide Documentation
5. Review details
1.5. Module 4: BIG-IP Template Creation for VMware (DHCP and IP Pools/Static) 29
BIG-IQ 7.0 Setup Guide Documentation
7. Select 4 CPUs/8192 MB RAM (this can be adjusted as needed depending on what you provision and
configure on BIG-IP)
1.5. Module 4: BIG-IP Template Creation for VMware (DHCP and IP Pools/Static) 31
BIG-IQ 7.0 Setup Guide Documentation
9. For networks, ensure that the Management NIC is associated with the network that has DHCP en-
abled and confirm other NIC networks. You can ignore the IP allocation settings
1.5. Module 4: BIG-IP Template Creation for VMware (DHCP and IP Pools/Static) 33
BIG-IQ 7.0 Setup Guide Documentation
AskF5 Reference
1. Open the web console and log into device using default credentials (root/default). Change password
to a strong password as required from v14.1.0
2. Delete f5-rest-device-id directory file. This forces the REST device ID files to be uniquely generated
the next time you start the clone
rm -f /config/f5-rest-device-id
3. Delete the BIG-IP VE clone instance-generated SSH keys
rm -f /config/ssh/ssh_host_*
rm -f /shared/ssh/ssh_host_*
4. (BIG-IP 14.1.0 and later only) Reset the device administrative account passwords to their default
values
echo "root:default" | chpasswd
echo "admin:admin" | chpasswd
5. Power off the BIG-IP VE clone template instance
shutdown -h now
This completes the BIG-IP Template Creation - DHCP.
Description
In this lab, we will create templates used for provisioning BIG-IP with Static IPs from BIG-IQ CM. Refer to
below AskF5 links if you need further details.
AskF5 Reference
F5 Clouddocs Reference
1. Access https://downloads.f5.com/
2. Navigate to your desired BIG-IP version and from the Virtual-Edition list of images, select the BIGIP-
<version>.ALL_1SLOT-vmware.ova. In test environments, this image will help to save on disk space.
1. Right click the host or folder and select Deploy OVF Template. . .
1.5. Module 4: BIG-IP Template Creation for VMware (DHCP and IP Pools/Static) 35
BIG-IQ 7.0 Setup Guide Documentation
2. Select Local file > click Choose Files > select the downloaded ova file
5. Review details
1.5. Module 4: BIG-IP Template Creation for VMware (DHCP and IP Pools/Static) 37
BIG-IQ 7.0 Setup Guide Documentation
7. Select 4 CPUs/8192 MB RAM (this can be adjusted as needed depending on what you provision and
configure on BIG-IP)
1.5. Module 4: BIG-IP Template Creation for VMware (DHCP and IP Pools/Static) 39
BIG-IQ 7.0 Setup Guide Documentation
9. For networks, ensure that the Management NIC is associated with the network that has DHCP dis-
abled and confirm other NIC networks. On BIG-IQ you must then configure IP Pools for these net-
works. You can ignore the IP allocation settings
1.5. Module 4: BIG-IP Template Creation for VMware (DHCP and IP Pools/Static) 41
BIG-IQ 7.0 Setup Guide Documentation
AskF5 Reference
1. Open the web console and log into device using default credentials (root/default). Change password
to a strong password as required from v14.1.0
2. Delete f5-rest-device-id directory file. This forces the REST device ID files to be uniquely generated
the next time you start the clone
rm -f /config/f5-rest-device-id
3. Delete the BIG-IP VE clone instance-generated SSH keys
rm -f /config/ssh/ssh_host_*
rm -f /shared/ssh/ssh_host_*
1.5. Module 4: BIG-IP Template Creation for VMware (DHCP and IP Pools/Static) 43
BIG-IQ 7.0 Setup Guide Documentation
4. (BIG-IP 14.1.0 and later only) Reset the device administrative account passwords to their default
values
echo "root:default" | chpasswd
echo "admin:admin" | chpasswd
5. From tmsh prompt, disable DHCP for management IP and save configuration
modify sys global-settings mgmt-dhcp disable
save sys config
6. Power off the BIG-IP VE clone template instance
shutdown -h now
This completes the BIG-IP Template Creation - IP Pools/Static.