After preparing the devices for an upgrade to the new version software, you force Device B to offline mode, and then install the new version software onto Device B (the offline device).
When you finish the installation of the new version software onto Device B, it creates two traffic groups called traffic-group-1 and traffic-group-2. Each traffic group is in standby state on Device B, and Device A (the version 10.x device) is in active mode. You can then force Device A to offline mode, changing both the new version software traffic groups to active state on Device B. Note that the Unit ID that was used in version 10.x becomes obsolete in the new version software.
When you complete upgrading both devices to the new version software, the BIG-IP system configuration includes traffic-group-1 and traffic-group-2 in active state on Device B, a traffic-group-1 and traffic-group-2 in standby state on Device A, and a device group that includes both devices.
Once each device is upgraded to the new version software, you can reconfigure the traffic groups to become active on the devices that you want by forcing the active traffic group on a device to standby state. When forcing the traffic group to standby state, you can target the device upon which you want that traffic group to run in active state. For example, you can force traffic-group-1 on Device B into standby state, and into active state on Device A. Additionally, if you use HA groups, you can create a unique HA group for each traffic group on each device.
An upgrade of BIG-IP active-active systems to the new version software involves the following tasks.
|Preparing Device A (active mode on the BIG-IP 1 system) and Device B (active mode on the BIG-IP 2 system)||In preparing to upgrade the active-active BIG-IP systems to the new version software, you need to understand any specific configuration or functional changes from the previous version, and prepare the systems. You also download the new version of software from the AskF5 web site (www.askf5.com) and import the files onto each device.|
|Forcing Device B to offline mode||When you complete preparing the Device B, you can force Device B to offline mode.|
|Upgrading Device B (the offline mode BIG-IP 2 system)||Once Device B is in offline mode, you can upgrade the software on that device, and
reboot Device B to the location of the new version software image. Device B completes rebooting with
traffic-group1 and traffic-group-2 in standby
Important: Once Device B reboots, if the BIG-IP system is configured to use a network hardware security module (HSM), you must reinstall network HSM client software on Device B before upgrading Device A, to ensure that traffic groups using the network HSM function properly.
|Forcing Device A to offline mode||When Device B completes rebooting to the location of the new version software image, you can force Device A to offline mode, changing traffic-group-1 and traffic-group-2 on Device B to active state.|
|Upgrading Device A (the offline mode BIG-IP 1 system)||Once Device A is in offline mode, you can upgrade the software on Device A. When Device
A completes rebooting, traffic-group-1 and traffic-group-2 are in standby state on Device
Important: Once Device A reboots, if the BIG-IP system is configured to use a network HSM, you must reinstall network HSM client software on Device A to ensure that traffic groups using the network HSM function properly.
|Changing states of traffic groups||When you finish upgrading all of the devices, you can restore the configuration of active traffic groups on each device.|
|Verifying the upgrade||Finally, you should verify that your active traffic groups on the BIG-IP systems are functioning properly.|
|Configuring HA groups||When you finish upgrading a device, the HA group on the device (in version 11.5, and later) applies to a traffic group, as opposed to the device. You can create a unique HA group for each traffic group on each device, as necessary.|
|Configuring module-specific settings||According to your understanding of the configuration and functional changes from the previous version, you can reconfigure any customized module settings.|
Device service clustering (DSC) is based on a few key components.
A traffic group is a collection of related configuration objects, such as a floating self IP address, a virtual IP address, and a SNAT translation address, that run on a BIG-IP device. Together, these objects process a particular type of application traffic on that device. When a BIG-IP device becomes unavailable, a traffic group floats (that is, fails over) to another device in a device group to ensure that application traffic continues to be processed with little to no interruption in service. In general, a traffic group ensures that when a device becomes unavailable, all of the failover objects in the traffic group fail over to any one of the available devices in the device group.
A traffic group is initially active on the device on which you create it, until the traffic group fails over to another device. For example, if you initially create three traffic groups on Device A, these traffic groups remain active on Device A until one or more traffic groups fail over to another device. If you want an active traffic group to become active on a different device in the device group when failover has not occurred, you can intentionally force the traffic group to switch to a standby state, thereby causing failover to another device.
Only objects with floating IP addresses can be members of a traffic group.
An example of a set of objects in a traffic group is an iApps application service. If a device with this traffic group is a member of a device group, and the device becomes unavailable, the traffic group floats to another member of the device group, and that member becomes the device that processes the application traffic.
Access Policy Manager is not supported in an Active-Active configuration.
Access Policy Manager is supported in an Active-Standby configuration with two BIG-IP systems only.
The BIG-IP Application Security Manager (ASM) system does not require specific preparation when upgrading from version 10.x to the new version software. No additional configuration is required after completing the upgrade to the new software version.
If you update two redundant systems that are running as an active-standby pair with BIG-IP Application Security Manager (ASM) and BIG-IP Local Traffic Manager (LTM) provisioned, the system maintains the active-standby status and automatically creates a Sync-Failover device group and a traffic group containing both systems. The device group is enabled for BIG-IP ASM (because both systems have ASM provisioned).
You can manually push or pull the updates (including BIG-IP LTM and ASM configurations and policies) from one system to the other (Config Sync and choose Synchronize TO/FROM Group)., then click
BIG-IP Global Traffic Manager systems require specific preparation tasks and changes to upgrade from version 10.x to the new version software.
Before you upgrade Global Traffic Manager systems that are in a synchronization group, from any software version to the new version software, you must install the software on an inactive volume on each device using Live Install. After you upgrade each device, you then switch all devices to the new volume at the same time. This is required because devices in a synchronization group that includes the new version software device, cannot effectively probe each other.
The following feature or functionality changes occur after you complete the upgrade process to the new version software:
|Feature or Functionality||Description|
|Assigning a BIG-IP system to probe a server to gather health and performance data||Assigning a single BIG-IP system to probe a server to gather health and performance data, in version 10.x, is replaced by a Prober pool in the new software version.|
The BIG-IP Link Controller (LC) system does not require specific preparation when upgrading from version 10.x to the new version software. No additional configuration is required after completing the upgrade to the new version software.
The BIG-IP Local Traffic Manager (LTM) system does not require specific preparation when upgrading from version 10.x to the new version software. No additional configuration is required after completing the upgrade to the new version software.
|Import the latest BIG-IP system hotfix image file||
|Import the new version software image file||
|Install the latest hotfix image||
|Install the new version software||
|Install the latest hotfix image||
|Install the new version software||
Manually configuring active state traffic groups across devices within a device group involves forcing an active state traffic group on a device to standby state, and retargeting that active state traffic group to a different device. Completing these tasks results in active state traffic groups on the appropriate devices in a device group.
Performing this task causes the selected traffic group on the local device to switch to a Standby state. By forcing the traffic group into a Standby state, the traffic group becomes active on another device in the device group. For device groups with more than two members, you can choose the specific device to which the traffic group fails over.
Your upgrade of the BIG-IP active-active pair from version 10.x to the new version software is now complete. The new version software configuration includes a device group with two devices (Device A and Device B) and two traffic groups (traffic-group-1 and traffic-group-2), with the first traffic group (traffic-group-1) on one device (Device A) in active state and the second traffic group (traffic-group-2) on the other device (Device B) in active state.