Wednesday, August 1, 2012

iFile list - F5 hosting files

iFile list is really a cool feature which allows F5 to host files via iRule.

1) Upload your static resources - e.g. file named wpad.dat
System -> File Management -> iFile List -> Import
Choose your file and provide a label (e.g. wpad-file)
Make sure free disk is available.

2) Create an iRule
Local Traffic ->  iRules ->  iRule List

when HTTP_REQUEST {
    if { [HTTP::uri] eq "/wpad.dat" } {
        HTTP::respond 200 content [ifile get  wpad-file]
    }
    else { discard }
}

3) Associate iRule with virtual server

4) Access the file
http://virtual-server-ip/wpad.dat


Wednesday, June 6, 2012

Finding serial no

BigIP 10.x version

Serial no. format f5-xxxx-xxxx

Command line
Login into console (advanced shell)
tmsh show sys hardware | grep -i chassis

Output will look like:
Chassis Serial f5-xxxx-xxxx

(or)
b platform | grep -i serial

Output will look like:
Chassis   serial f5-xxxx-xxxx


GUI
System -> Configuration -> Chassis Serial Number

Tuesday, May 22, 2012

iRule to route traffic to different pools

1. Set the virtual server to ipaddress:any


2. Associate iRule
when CLIENT_ACCEPTED { if {[TCP::local_port] equals 5000} { pool mypool1} elseif {[TCP::local_port] equals 5001} { pool mypool2}}

Monday, May 21, 2012

Configuring syslog

1) SSH into F5 management IP as admin with advanced shell

2) Execute the commands
2a) #bigpipe syslog remote server {my-syslog-server1 {host syslog-server-ip-address} my-syslog-server1 {host syslog-server-ip-address}}

Examples:
#bigpipe syslog remote server {mysolarwinds {host 10.101.102.103}}
#bigpipe syslog remote server {mysplunk {host 10.101.102.104} my-arcsight {host 10.101.102.105}}

2b) #bigpipe save

3) Restart syslog-ng utility
#bigstart restart syslog-ng

4) Verify
#b syslog remote server show

Friday, November 18, 2011

Implementing ProxyPass iRule in LTM

Scenario
You want to proxypass www.customersite.com to www.internalsite.com without replacing browser URL.

Solution

1) Download the proxypass iRule from the following links based on your BigIp version.


2) Add the iRule to the iRules section

3) Note down the pool names for customersite and internalsite websites
Assume the following names

Virtual Server: customersite-vs
Pools: customersite-pool and internalsite-pool exist in LTM

4) Create a Data Group Navigate to iRules -> Data group
Name: ProxyPasscustomersite-vs 

Please note the name should follow the convention above where customersite-vs should match the virtual server name.

Type: String 

BigIP 10
Name: /customerdir1 
Value: /internaldir1 internalsite-pool

When you add an entry, it will be of the format
/customerdir1 := /internaldir1 internalsite-pool

BigIP 9
String: /customerdir1 Value: /internaldir1 internalsite-pool


You can add more directory mappings as desired.

You can also map the above Value to direct URL mapping in case you do not want to map to a pool.
/customerdir1 := my-new-internal-site.com/internaldir1

5) Associate the iRule to customersite-vs virtual server.

6) Test the URL www.customersite.com/customerdir1. The webpages get loaded from www.internalsite.com/internaldir1 without replacing the browser URL.

Proxypass in F5 is similar to Apache ProxyPass functionality.

Wednesday, July 14, 2010

F5 BigIP LTM commands

1) SSH into LTM, update /config/bigip.conf with desired changes.
Load the file:
bigpipe load
bigpipe save

2) Create qkview from command line

qkview -c -s 0 -f /shared/tmp/`/bin/hostname`_qkview_`date +%Y%d%m%H%M`.tgz

-c refers to config and -s 0 refers to largest size


3) Miscellaneous commands

vim tmm
/usr/libexec/bigpipe daol
cd partitions/INT
tmsh
tmsh load sys config
tmsh save sys config
tail /var/log/ltm --lines=50
touch /service/mcpd/forceload
curl --user C1148904:emendez@rccl.com --upload-file C1148904-1.cap



Thursday, March 18, 2010

F5 BigIP LTM iRules

1) To redirect http requests to https
-------------------------------------------------------------------------
when HTTP_REQUEST {
HTTP::redirect https://[HTTP::host][HTTP::uri]
}
-------------------------------------------------------------------------
Please check Redirect Rewrite to Matching in HTTP Profile used
Associate the iRule with Virtual Server Profile

2) To modify cookie domain for JSESSIONID.
-------------------------------------------------------------------------
when HTTP_RESPONSE {

   if {[HTTP::cookie count] > 0 } {
      foreach aCookie [HTTP::cookie names] {
         log local0. "Cookie name: $aCookie"
         if { $aCookie == "JSESSIONID" } {
            HTTP::cookie domain $aCookie yourwiderdomain.com
         }
      }
   }
}
-------------------------------------------------------------------------

This iRule will help to issue the same JSESSIONID when switching between different subdomains.
In JBOSS by default, you will get two different JSession IDs when you make requests to www.domain.com and secure.domain.com. If you examine the JSESSIONID cookie, you will see the domain name is set to complete www.domain.com and secure.domain.com respectively.

To avoid this issue and get a single JSESSIONID , create an iRule as above and set the cookie domain at wider level, ex: domain.com. Associate the iRule to virtual server in the resources section. Hit the URLs again, the domain name in JSESSIONID will be set to domain.com. 

3) Issue 301 redirect and resolve to desired URI
-------------------------------------------------------------------------
when HTTP_REQUEST {
if { not ([HTTP::host] starts_with "www") }
{
   HTTP::respond 301 Location "http://www.[HTTP::host]/urigoeshere"
}
elseif { [HTTP::uri] equals "/" }{
   HTTP::respond 301 Location "http://[HTTP::host]/urigoeshere"
}
}

Another flavor with or condition

when HTTP_REQUEST {
   if { not ([HTTP::host] starts_with "www"
         or [HTTP::host] starts_with "somename"
       )
     }{
           HTTP::respond 301 Location "http://www.[HTTP::host]/web/cs?a=5"
   }
   elseif { [HTTP::uri] equals "/" }{
     HTTP::respond 301 Location "http://[HTTP::host]/web/cs?a=5"
   }
 }

-------------------------------------------------------------------------
This iRule will avoid multiple redirects.

4) Insert X-Forwarded-Proto
-------------------------------------------------------------------------
iRule for port 80
when HTTP_REQUEST {
   HTTP::header remove X-Forwarded-Proto
   HTTP::header insert X-Forwarded-Proto http
}

iRule for port 443
when HTTP_REQUEST {
   HTTP::header remove X-Forwarded-Proto
   HTTP::header insert X-Forwarded-Proto https
}
-------------------------------------------------------------------------
This iRule is useful to identify the client protocol is either http or https. This iRule helps the when the SSL gets decrypted in load balancer or web server and backed requests are sent to application server as http. If the application uses http servlet isSecure method, setting the iRule on port 443 will return isSecure as true. Please note the XForwardProto filter will also have to be applied on application server to get the correct value for isSecure or getScheme.


4) Logging 
-------------------------------------------------------------------------
log local0. "value1= $somevariable and value2= $somevariableothervariable "
log local0. " IP: [IP::client_addr] "
log local0. " uri= [HTTP::uri] path= [HTTP::path] query= [HTTP::query] 
-------------------------------------------------------------------------
The log command can be inserted to iRule to provide useful debug information.

Newer›  ‹Older