<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote">On Thu, Jul 6, 2017 at 6:41 PM, Mailvaganam, Hari <span dir="ltr"><<a href="mailto:hari.mailvaganam@ubc.ca" target="_blank">hari.mailvaganam@ubc.ca</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div bgcolor="white" lang="EN-US" link="#0563C1" vlink="#954F72">
<div class="m_-4198193335085589288WordSection1">
<p class="MsoNormal"><span style="font-size:11pt">Wondering if anyone has set up a clustered IdPv3 behind BIG IP's F5?</span></p></div></div></blockquote><div><br></div><div>Clustered how? We run several behind an F5; the primaries (we run several different configurations) are in a an active/standby config using priority groups.</div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div bgcolor="white" lang="EN-US" link="#0563C1" vlink="#954F72"><div class="m_-4198193335085589288WordSection1"><p class="MsoNormal"><span style="font-size:11pt">We have one over here – that is experiencing the occasional ERR_CONNECTION_RESET – we are peeling of the layers F5 config, Apache setting, network etc to zero in on the potential cause.</span><br></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">If anyone has this set up on F5 – wondering if can compare our F5 config, Apache settings etc.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt">Our set up:<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt"><u></u> <u></u></span></p>
<ul style="margin-top:0cm" type="disc">
<li class="m_-4198193335085589288MsoListParagraph" style="margin-left:0cm"><span style="font-size:11.0pt">Apache proxy traffic via AJP to Tomcat<u></u><u></u></span></li><li class="m_-4198193335085589288MsoListParagraph" style="margin-left:0cm"><span style="font-size:11.0pt">SSL to Big IP/F% -- and SSL again to the server endpoints (both Gandi)<u></u><u></u></span></li><li class="m_-4198193335085589288MsoListParagraph" style="margin-left:0cm"><span style="font-size:11.0pt">HSTS commented out on Apache; SELinux disabled (for troubleshooting)</span></li></ul></div></div></blockquote><div>My setup is sufficiently different to provide little direct help. We terminate TLS on the BigIP, run everything through a dispatching iRule, and go in the clear to the Jetty IdPs (everything lives on a dedicated IAM network and hardware), no Apache httpd.</div><div><br></div><div>Do your LTM logs have anything useful? We did at one point have problems with virtual servers flapping; we (i.e., I) had scheduled health checks too regularly, and apparently the BigIPs couldn't handle it and bogged down, marking first one and then eventually the other pool members down, occasionally both, which would take the virtual servers offline. And then people would get reset connections. (There was more than just the IdP's; still, I remain surprised that high-frequency health checks would do that.)</div><div><br></div><div>Greg</div></div></div></div>