IdP3.3.0/Big IP F5

Greg Haverkamp gahaverkamp at lbl.gov
Thu Jul 6 23:17:47 EDT 2017


On Thu, Jul 6, 2017 at 6:41 PM, Mailvaganam, Hari <hari.mailvaganam at ubc.ca>
wrote:

> Wondering if anyone has set up a clustered IdPv3 behind BIG IP's F5?
>

Clustered how?  We run several behind an F5; the primaries (we run several
different configurations) are in a an active/standby config using priority
groups.


> We have one over here – that is experiencing the occasional
> ERR_CONNECTION_RESET – we are peeling of the layers F5 config, Apache
> setting, network etc to zero in on the potential cause.
>
>
>
> If anyone has this set up on F5 – wondering if can compare our F5 config,
> Apache settings etc.
>
>
>
> Our set up:
>
>
>
>    - Apache proxy traffic via AJP to Tomcat
>    - SSL to Big IP/F% -- and SSL again to the server endpoints (both
>    Gandi)
>    - HSTS commented out on Apache; SELinux disabled (for troubleshooting)
>
> My setup is sufficiently different to provide little direct help.  We
terminate TLS on the BigIP, run everything through a dispatching iRule, and
go in the clear to the Jetty IdPs (everything lives on a dedicated IAM
network and hardware), no Apache httpd.

Do your LTM logs have anything useful?  We did at one point have problems
with virtual servers flapping; we (i.e., I) had scheduled health checks too
regularly, and apparently the BigIPs couldn't handle it and bogged down,
marking first one and then eventually the other pool members down,
occasionally both, which would take the virtual servers offline.  And then
people would get reset connections. (There was more than just the IdP's;
still, I remain surprised that high-frequency health checks would do that.)

Greg
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170706/0e87664e/attachment.html>


More information about the users mailing list