Task summary for deploying in a high availability environment
To ensure that your F5
®
Herculon
™
SSL Orchestrator
™
high availability (HA) deployment succeeds, it is
critical that you closely follow each deployment step, as well as the assumptions and dependencies, for
both devices in the device group. In addition, you should adhere to all prerequisites. If the systems in the
device group are not configured consistently, the deployment synchronization process might suffer errors
or fail.
Use the following tasks to ensure your HA deployment succeeds:
•
Installing an updated RPM file
•
Configuring the network for high availability
•
Configuring the ConfigSync and Failover IP address
•
Adding a device to the local trust domain
•
Creating a Sync-Failover device group
•
Synchronizing the device group
•
Setting up a basic configuration for deployment
Note: See the Diagnosing your Herculon SSL Orchestrator deployment section for more detailed
information on how to monitor the success or failure of your configuration modification.
Prerequisites
Before configuring the network for high availability, make sure these prerequisites are in place:
• The information used to configure your devices is identical on both devices. Without identical
information on both devices, the HA deployment process can suffer from errors or fail.
• The most current RPM file is successfully installed on the first device (the Active device). See the
section
Installing an updated RPM file
to ensure that this prerequisite has been properly completed.
• Successfully set up an HA ConfigSync device group prior to starting the configuration. See the
section
Configuring the network for high availability
and its subsections to ensure that this
prerequisite has been properly completed. For additional information, refer to the
BIG-IP Device
Service Clustering: Administration
document, section
Managing Configuration Synchronization
.
• Herculon SSL Orchestrator is installed with the appropriate license information using the Herculon
SSL Orchestrator Setup Wizard (or the CLI) and made sure your device setup information is identical
on both devices:
• While using the Herculon SSL Orchestrator Setup Wizard, you have noted the details used for
NTP and DNS setup and made sure they will be identical on both devices. To verify duplication,
on the Main tab, click
System
>
Configuration
>
Device
and select
NTP
or
DNS
.
• Ensure that any certificates used in the configuration are copied to all devices.
• Ensure that information is identical on all devices. This information should include any of the
following that are needed:
• Client network
• External network
• Decrypt zone network
• Decrypt zone control network
• Networks providing access to ICAP devices and Receive-only devices
• Ensure that the log publishers are configured and named the same.
• Ensure that all systems use the same interfaces for any services. (If interface 1.1 is used to send
traffic to an inline Layer 2 device on system A, then interface 1.1 must also be used on systems B,
C, and D.)
Setting up Herculon SSL Orchestrator in a High Availability Environment
40
Содержание Herculon SSL Orchestrator
Страница 1: ...F5 Herculon SSL Orchestrator Setup Version 13 1 3 0 ...
Страница 2: ......
Страница 6: ...What is F5 Herculon SSL Orchestrator 6 ...
Страница 26: ...Setting Up a Basic Configuration 26 ...
Страница 38: ...Importing and Exporting Configurations for Deployment 38 ...
Страница 54: ...Using Herculon SSL Orchestrator Analytics 54 ...