Solution: Does Fiorano have a document describing best practices for configuring BigIP to work without interfering with the
Fiorano failover mechanism?
Please check out the attached PPT. It highlights the 2 BIG configuration styles.
1. IP Forwarding/Routing [ Depending on the BigIP features, see if Dynamic option (refer slide2) is possible]
2. Data/Port forwarding
IP forwarding/routing is easy and its guaranteed to work.
In this case the BigIP device needs to be configured as a firewall/gateway device, to provide
an external (public) IP for the FMQ machines...and open -only- TCP data access on 1856 port.
There is no need to open any other ports, for e.g ping, ftp, 80, 443 etc... to the
fmq machines. This prevents FMQ servers from being attacked on those ports.
The data/port forwarding technique will cause issues with the FMQ HA.
Let me know if you would like to have a call with your network
admins to go over these configurations. I can dial into the call.
|