Manual Chapter : Deploying a BIG-IQ System

Applies To:

Show Versions Show Versions
Manual Chapter

Deploying a BIG-IQ System

How do I deploy a BIG-IQ system?

To manage your BIG-IP® devices using BIG-IQ® Centralized Management, you deploy a BIG-IQ system and then configure it to meet your business needs.

To deploy a BIG-IQ system, you should:

  • Prepare your network environment and architecture (refer to Planning a BIG-IQ Centralized Management Deployment in Planning a BIG-IQ Centralized Management Deployment on support.f5.com for details).
  • Install and configure the platform you plan to use to run the BIG-IQ system. The platform can either be a physical device or a virtual device. To use a physical device, you need a BIG-IQ 7000 series device. To use a virtual device, the solution you choose depends on the environment you choose. Supported platforms for this release are listed below. Use the guide appropriate for the platform you use to complete the installation. All of these guides are posted on support.f5.com.
    If you choose this platform: Refer to this guide for installation details:
    BIG-IQ 7000 Series Platform Guide: BIG-IQ 7000 Series
    Amazon Web Services F5 BIG-IQ Centralized Management 6.0.0 and Amazon Web Services: Setup
    Citrix XenServer: F5 BIG-IQ Centralized Management 6.0.0 and Citrix XenServer: Setup
    KVM F5 BIG-IQ Centralized Management 6.0.0 and Linux KVM: Setup
    Microsoft Azure F5 BIG-IQ Centralized Management 6.0.0 and Microsoft Azure: Setup
    Microsoft Hyper-V F5 BIG-IQ Centralized Management 6.0.0 and Microsoft Hyper-V: Setup
    VMware ESXi F5 BIG-IQ Centralized Management 6.0.0 and VMware ESXi: Setup
    Xen Project F5 BIG-IQ Centralized Management 6.0.0 and Linux Xen Project: Setup
  • Deploy and configure the number of BIG-IQ systems dictated by whether your architecture requires HA or multiple data centers.
  • License and configure the BIG-IQ system.

How do I license and do the basic setup to start using BIG-IQ?

After you download the software image from the F5 Downloads site and start BIG-IQ® in your virtual environment, you can license the system using the base registration key provided by F5. The base registration key is a character string the F5 license server uses to provide BIG-IQ a license to access the subscription licensing feature.

You license BIG-IQ in one of the following ways:

  • If the system has access to the Internet, you can have the BIG-IQ system contact the F5 license server and automatically activate the base registration key to get a license.
  • If the system is not connected to the Internet, you can manually license the BIG-IQ using the F5 license server web portal.
  • If the system is in a closed-circuit network (CCN) that does not allow you to export any encrypted information, you must open a case with F5 support at: support.f5.com/csp/my-support/home.

When licensing BIG-IQ, you:

  1. Activate the license.
  2. Accept the EULA.
  3. Specify the system personality as BIG-IQ Centralized Management.
  4. Specify a host name, and IP addresses for the management port, DNS server, and network time protocol (NTP) servers.
  5. Specify the master key pass phrase.
  6. Change the default admin and root passwords.

Automatic license and initial setup for BIG-IQ systems

You must have a base registration key before you can license the BIG-IQ system. If you do not have a base registration key, contact the F5 Networks sales group (f5.com). After you set up your BIG-IQ VE or set up your BIG-IQ 7000 Series, you can install the BIG-IQ software license.
If the BIG-IQ system is connected to the public internet, you can follow these steps to automatically perform the license activation and perform the initial setup.
  1. Use a browser to log in to BIG-IQ by typing https://<management_IP_address> , where <management_IP_address> is the address you specified for device management.
  2. In Base Registration Key, type or paste the BIG-IQ registration key.
    Important: If you are setting up a data collection device, you have to use a registration key that supports a data collection device license.
  3. For Activation Method, select Automatic, and click the Activate button.
  4. Click Next.
    If you are setting up this device for the first time, the Accept User Legal Agreement screen opens.
  5. To accept the license agreement, click the Agree button.
  6. Click the Next button at the bottom of the screen.
    If your license supports both BIG-IQ Data Collection Device and BIG-IQ Central Management Console, the System Personality screen displays. Otherwise the Management Address screen opens.
  7. If you are prompted with the System Personality screen, select the option you're licensed for, and then click OK. If you are not prompted, proceed to the next step.
    Important: You cannot undo this choice. Once you license a device as a BIG-IQ Management Console, you can't change your mind and license it as a Data Collection Device.
    The Management Address screen opens.
  8. In Hostname, type a fully-qualified domain name (FQDN) for the system.
    The FQDN can consist of letters and numbers, as well as the characters underscore ( _ ), dash ( - ), or period ( . ).
  9. Type the Management Port IP Address and Management Port Route.
    Note: The management port IP address must be in Classless Inter-Domain Routing (CIDR) format. For example: 10.10.10.10/24.
  10. Specify what you want the BIG-IQ to use for the Discovery Address.
    BIG-IQ advertises this address to other devices that want to communicate with it. For example BIG-IQ HA peers and DCD nodes communicate using their respective discovery addresses.
    Important: When choosing whether to use the management port or a self IP address, consider the long term ramifications. The BIG-IQ uses the address you choose for all traffic to and from the devices it manages and the DCDs that support it. Changing the discovery address involves a lengthy process that includes rediscovering all of the devices and DCDs associated with this BIG-IQ.
    • To use the management port, select Use Management Address.
    • To use the internal self IP address, select Self IP Address, and type the IP address.
      Important: If you are configuring a BIG-IQ to manage applications in a service scaling group, use the internal self IP address.
      Note: If you plan to manage both IPv4 and IPv6 devices, you must configure an additional interface. BIG-IQ does not manage both protocols on the same interface. You can use a self IP address for this. So if your deployment includes DCDs, your discovery address will use one internal self IP address and you will need to add a second self IP to facilitate discovery of both protocol types.
      Note: The self IP address must be in Classless Inter-Domain Routing (CIDR) format. For example: 10.10.10.10/24.
  11. Click the Next button at the bottom of the screen.

    The Services screen opens.

  12. In the DNS Lookup Servers field, type the IP address of your DNS server.
    You can click the Test Connection button to verify that BIG-IQ can reach that IP address.
  13. In the DNS Search Domains field, type the name of your search domain.
    The DNS search domain list allows the BIG-IQ system to search for local domain lookups to resolve local host names.
  14. In the Time Servers field, type the IP addresses of your Network Time Protocol (NTP) server.
    You can click the Test Connection button to verify that BIG-IQ can reach the IP address.
  15. From the Time Zone list, select your local time zone.
  16. Click the Next button at the bottom of the screen.
    The Master Key screen opens.
  17. For the Passphrase, type a phrase that satisfies the requirements specified on screen, and then type the same phrase for Confirm Passphrase.
    Important: The DCD uses the pass phrase to generate a Master Key. This pass phrase must be the same on all of the devices in the DCD cluster. Make sure you keep track of the pass phrase, because it cannot be recovered if you lose it
  18. Click the Next button at the bottom of the screen.
    The Password screen opens.
    Important: If you are setting up a Microsoft Azure VE, and you type an entry in any of the fields, you will not be able to continue successfully. The only way to proceed is to leave all of the fields empty and click the Next button at the bottom of the screen. This allows the system to use the first-time access credentials you specified previously.
  19. In the Old Password fields, type the default admin and root passwords, and then type a new password in the Password and Confirm Password fields.
  20. Click the Next button at the bottom of the screen.
    The screen Summary displays the details you just specified for this device configuration.
  21. If the details are as you intended, click Launch to continue; if you want to make corrections, use the Previous button to navigate back to the screen you want to change.

Manual license and initial setup for BIG-IQ systems

You must have a base registration key before you can license the BIG-IQ system. If you do not have a base registration key, contact the F5 Networks sales group (f5.com). After you set up your BIG-IQ VE or set up your BIG-IQ 7000 Series, you can install the BIG-IQ software license.
If the BIG-IQ system is not connected to the public internet, you can follow these steps to contact the F5 license web portal then perform the initial setup.
  1. Use a browser to log in to BIG-IQ by typing https://<management_IP_address> , where <management_IP_address> is the address you specified for device management.
  2. In Base Registration Key, type or paste the BIG-IQ registration key.
    Important: If you are setting up a data collection device, you have to use a registration key that supports a data collection device license.
  3. In Add-On Keys, paste any additional license key you have.
  4. For Activation Method, select Manual and click the Generate Dossier button.
    The BIG-IQ system refreshes and displays the dossier in the Device Dossier field.
  5. Select and copy the text displayed in Device Dossier.
  6. Click the Access F5 manual activation web portal link.
    The Activate F5 Product site opens.
  7. Into the Enter your dossier field, paste the dossier.
    Alternatively, if you saved the file, click the Choose File button and navigate to it.
    After a pause, the screen displays the license key text.
  8. Click Next.
    If you are setting up this device for the first time, the Accept User Legal Agreement screen opens.
  9. To accept the license agreement, select I have read and agree to the terms of this license, and click Next button.
    The licensing server creates the license key text.
  10. Copy the license key.
  11. In the License Text field on BIG-IQ, paste the license text.
  12. Click the Activate License button.
  13. Click the Next button at the bottom of the screen.
    If your license supports both BIG-IQ Data Collection Device and BIG-IQ Central Management Console, the System Personality screen displays. Otherwise the Management Address screen opens.
  14. If you are prompted with the System Personality screen, select the option you're licensed for, and then click OK. If you are not prompted, proceed to the next step.
    Important: You cannot undo this choice. Once you license a device as a BIG-IQ Management Console, you can't change your mind and license it as a Data Collection Device.
    The Management Address screen opens.
  15. In Hostname, type a fully-qualified domain name (FQDN) for the system.
    The FQDN can consist of letters and numbers, as well as the characters underscore ( _ ), dash ( - ), or period ( . ).
  16. Type the Management Port IP Address and Management Port Route.
    Note: The management port IP address must be in Classless Inter-Domain Routing (CIDR) format. For example: 10.10.10.10/24.
  17. Specify what you want the BIG-IQ to use for the Discovery Address.
    BIG-IQ advertises this address to other devices that want to communicate with it. For example BIG-IQ HA peers and DCD nodes communicate using their respective discovery addresses.
    Important: When choosing whether to use the management port or a self IP address, consider the long term ramifications. The BIG-IQ uses the address you choose for all traffic to and from the devices it manages and the DCDs that support it. Changing the discovery address involves a lengthy process that includes rediscovering all of the devices and DCDs associated with this BIG-IQ.
    • To use the management port, select Use Management Address.
    • To use the internal self IP address, select Self IP Address, and type the IP address.
      Important: If you are configuring a BIG-IQ to manage applications in a service scaling group, use the internal self IP address.
      Note: If you plan to manage both IPv4 and IPv6 devices, you must configure an additional interface. BIG-IQ does not manage both protocols on the same interface. You can use a self IP address for this. So if your deployment includes DCDs, your discovery address will use one internal self IP address and you will need to add a second self IP to facilitate discovery of both protocol types.
      Note: The self IP address must be in Classless Inter-Domain Routing (CIDR) format. For example: 10.10.10.10/24.
  18. Click the Next button at the bottom of the screen.

    The Services screen opens.

  19. In the DNS Lookup Servers field, type the IP address of your DNS server.
    You can click the Test Connection button to verify that BIG-IQ can reach that IP address.
  20. In the DNS Search Domains field, type the name of your search domain.
    The DNS search domain list allows the BIG-IQ system to search for local domain lookups to resolve local host names.
  21. In the Time Servers field, type the IP addresses of your Network Time Protocol (NTP) server.
    You can click the Test Connection button to verify that BIG-IQ can reach the IP address.
  22. From the Time Zone list, select your local time zone.
  23. Click the Next button at the bottom of the screen.
    The Master Key screen opens.
  24. Type a Passphrase that satisfies the requirements specified on screen, and then type the same phrase for Confirm Passphrase.
    Important: BIG-IQ uses the pass phrase to generate a Master Key. For High Availability and data collection device cluster configurations, this pass phrase must be the same on all related BIG-IQ systems.
    • If this BIG-IQ is not part of an HA or DCD configuration, you can change the Master Key any time from the System > THIS DEVICE > General Properties screen.

    • If this BIG-IQ is part of an HA or DCD configuration, make sure you keep track of the pass phrase, because it cannot be recovered if you lose it.

  25. Click the Next button at the bottom of the screen.
    The Password screen opens.
    Important: If you are setting up a Microsoft Azure VE, and you type an entry in any of the fields, you will not be able to continue successfully. The only way to proceed is to leave all of the fields empty and click the Next button at the bottom of the screen. This allows the system to use the first-time access credentials you specified previously.
  26. In the Old Password fields, type the default admin and root passwords, and then type a new password in the Password and Confirm Password fields.
  27. Click the Next button at the bottom of the screen.
    The screen Summary displays the details you just specified for this device configuration.
  28. If the details are as you intended, click Launch to continue; if you want to make corrections, use the Previous button to navigate back to the screen you want to change.