6.
Click
Retrieve Device Information
.
The screen shows Verify Device Certificates (Step 2 of 3).
7.
Click
Device Certificate Matches
.
The screen shows Add Device (Step 3 of 3).
8.
In the
Name
field, type the name of the device you are adding.
9.
Click
Add Device
.
At the upper right, next to the F5 logo, the status of your device should show
ONLINE (ACTIVE)
and
Connected
, with a green indicator next to them showing its active and connected status.
Creating a sync-failover device group
For an HA configuration, you need to establish failover capability between two or more BIG-IP
®
devices.
Then, if an active device in a sync-failover device group becomes unavailable, the configuration objects
fail over to another member of the device group, and traffic processing is unaffected. You perform this
task on any one of the authority devices within the local trust domain.
1.
On the Main tab, click
Device Management
>
Device Groups
.
The Device Group List screen opens.
2.
Click
Create
.
The New Device Group screen opens.
3.
In the General Properties area, name your new device group and select the group type.
a) In the
Name
field, type the name of your device group.
b) From the
Group Type
list, select
Sync-Failover
.
4.
For the
Configuration
setting, retain the
Basic
configuration type, and then select members and
define the sync type.
a) In the
Members
setting, select available devices from the
Available
list and add them to the
Includes
list.
b) From the
Sync Type
list, select
Manual with Incremental Sync
.
Note: You must do a manual sync. If you select Automatic with Incremental Sync, your HA
deployment will fail.
5.
Click
Finished
.
The Device Groups list screen opens, listing your new device group. The ConfigSync Status column will
indicate
waiting Initial Sync
.
Synchronizing the device group
For an HA configuration, you need to synchronize the BIG-IP
®
configuration data from the local device
to the devices in the device group. This synchronization ensures that devices in the device group operate
properly. When synchronizing self IP addresses, the BIG-IP system synchronizes floating self IP
addresses only.
1.
Next to the F5 logo, click
Awaiting Initial Sync
.
On the Main tab, you can also click
Device Management
>
Overview
.
The Device Management Overview screen opens, showing your Device Groups.
2.
In the Sync Issues area, select
ha
to expand the Devices and Sync Options areas of the screen.
3.
In the Devices area, select the device showing
Changes Pending
.
4.
In the Sync Options area, select
Push the selected device configuration to the group
.
5.
Click
Sync
.
You have now completed your F5
®
Herculon
™
SSL Orchestrator
™
HA deployment. Next, set up a basic
configuration for deployment on your active device.
F5 Herculon SSL Orchestrator: Setup
43
Summary of Contents for Herculon SSL Orchestrator
Page 1: ...F5 Herculon SSL Orchestrator Setup Version 13 1 3 0 ...
Page 2: ......
Page 6: ...What is F5 Herculon SSL Orchestrator 6 ...
Page 26: ...Setting Up a Basic Configuration 26 ...
Page 38: ...Importing and Exporting Configurations for Deployment 38 ...
Page 54: ...Using Herculon SSL Orchestrator Analytics 54 ...