Forum Discussion

Ahmed_Saied's avatar
Ahmed_Saied
Icon for Altocumulus rankAltocumulus
Sep 26, 2024

DNS LTM adding recommendation

Hello,

 

What is the recommendation in adding GTM and LTM/AWAF devices in multi datacenter 

 

More explanation 

if we have HQ and DR datacenters 

HQ data center 

GTM device (One device)

LTM/AWAF Device (Pair)

 

DR data center 

GTM device (One device)

LTM/AWAF Device (Pair)

 

shall we add DR LTM/AWAF to HQ GTM by using DR LTM/AWAF self IP reachable through internet or internally?

Please highlight pros and cons for each method 

 

Why are we think to add DR LTM/AWAF to HQ GTM is to ensure that HQ GTM will see  VS on DR LTM/AWAF down when internet link is down in DR 

 

If there another way to ensure that by monitoring links please clarify

  • Hi

     

    We should add the lTM devices to all GTM for sync. If you have a requirement for DNS for the VIPs in those device

    You can add the lTM using self ips and the self ip should allow required port(port lockdown settings)

    You can use the link for adding the LTM to GTMs

    https://my.f5.com/manage/s/article/K43300744

  • Yes, we will add all devices for sure 

    but question here is on HQ GTM shall will add DR devices to it ( DR GTM device and another pair LTM/ASM)

    by self IP though internet or internally?

     

    which pros and cons of each way?

  • I hope you have internal connectivity towards DC(MPLS). So better to connect via internal self ip. For our infra. i done like the same. So GTM will have all the DC and DR vips and if the DC goes down traffic will switch to DR VIP.

    i dont think you will have F5 self ip access from internet. its not secure. Please limit your self/management ip access from internal network