Sunday, August 12, 2012

BIG IP F5 LTM Tutorial - Part 2


BIG IP F5 LTM:

Historical Overview: -

Historically, there have been two ways to build Application Delivery Networking
Appliances—build them for performance or build them for intelligence. In the open market, customers have traditionally selected solutions that exhibit the best performance. As a result, most vendors have built their devices on faster, packet based designs instead of the poorer performing proxy-based architecture. As the need for intelligence in these devices has grown, vendors find themselves in a precarious position: the more intelligence they add to the devices in response to
Customer demand, the closer they resemble a proxy and the worse they perform.

F5 initially took the packet-based path, but simultaneously started addressing the root problem—making an intelligent solution that also delivers high performance. The result is the F5 TMOS® architecture, a collection of real-time features and functions, purpose-built and designed as a full-proxy solution with the power and performance required in today’s network infrastructure.


TMOS Platform ( Time Management Operating System )

A unified product platform that delivers complete control and scalability: -

TMOS is the universal product platform shared by F5 BIG-IP products. No single competing technology can solve such a wide variety of application delivery problems over networks.
With its application control plane architecture, TMOS gives you intelligent control over the acceleration, security, and availability services your applications require. TMOS establishes a virtual, unified pool of highly scalable, resilient, and reusable services that can dynamically adapt to the changing conditions in data centres and virtual and cloud infrastructures

 TMOS is a collective term used to describe the completely purpose-built, custom architecture which F5 spent years and significant investment developing as the foundation for F5 products going forward. From a high-level, TMOS is:

Ø  A Collection of Modules: networking driver module, an Ethernet module, an ARP module, an IP module, a TCP module, and so on.
Ø  Self-Contained and Autonomous : TMOS-based device has a form of Linux running on it but TMOS & Linux are two different parts & It is important to note that this Linux system is not involved in any aspect of the traffic flowing through TMOS.
Ø  A Real-Time Operating System: A real-time operating system means TMOS does not have a preemptive CPU scheduler.
Ø  Both Hardware and Software: Because TMOS is inherently modular in design; it doesn’t matter whether individual functions are handled by software or by hardware. With TMOS, everything can be done in software utilizing highly optimized and purpose built modules.
Ø  Stateful inspection
Ø  Dynamic Packet Filtering : Bu default deny all policy in F5

Note: For more detail please refer http://www.f5.com/pdf/white-papers/tmos-wp.pdf

BIG IP F5 LTM Tutorial - Part 1


WELCOME TO F5
BIG IP LTM 



Application Delivery Network appliance is known as load balancers & it was used to manage the applications or server farm which delivers services to end users or customer.

Server load balancing is the process of distributing service requests across a cluster of servers. There are many benefits to this process, these include:

Benefits of Application Delivery Network:

Ø  Improves performance - The highest performance is achieved when the processing power of servers is used intelligently. Advanced server load balancing products can direct end-user service requests to the servers that are least busy and therefore capable of providing the fastest response times.
Ø  Creates Resilience - high-availability pairs for load balancer resilience, and creates fault-tolerance for your back-end servers.
Ø  Adds Intelligence - Content inspection rules allow you to send requests for certain web pages to specific groups of servers.
Ø  Improves Reliability - By continually monitoring the health of your back-end servers, failed servers are automatically detected and removed from the cluster until they recover.
Ø  Ease of Use - Easy to install and configure, and include a secure, web-based graphical user interface which provides you with visual alerting, health monitoring and cluster diagnostics.
Ø  One-Click Session Persistence - If sticky sessions are required for your web application, just turn on session affinity with one click.
Ø  Improved flexibility and scalability - Many content intensive applications have scaled beyond the point where a single server can provide adequate processing power. Both enterprises and service providers need the flexibility to deploy additional servers quickly and transparently to end-users.
Ø  Enhanced availability - server load balancing is its ability to improve application availability. If an application or server fails, load balancing can automatically redistribute end-user service requests to other servers within a server farm or to servers in another location.
Ø  Less disruption - Server load balancing also prevents planned outages for software or hardware maintenance from disrupting service to end users.


Distributed server load balancing products can also provide disaster recovery services by redirecting service requests to a backup location when a catastrophic failure disables the primary site which is known as GSLB (Global Server Load Balancing)



Monday, May 28, 2012



Cisco Nexus 2000 Series Overview : - Fabric Extenders


Cisco Nexus® 2000 Series Fabric Extenders have transformed data center designs and enabled data
center architects to gain new design flexibility while simplifying cabling infrastructure and reducing management complexity. Cisco Nexus fabric extenders act like remote line card which which gives you design flexibility for your data center.


Fabric extender work with parent nexus switches i.e. N7K , N5K & Cisco UCS. Fabric extender work as additional remote line card for parent switches. All fabric extenders connected to parent switches can be configured from parent itself. Logically it act as one device or you can say as chassis device.


To setup these fabric extender & configuration is very easy, below is the configuration for fabric extenders :-


Nexus(config)# feature fex
Nexus(config)# interface e1/10 - 12 (Port Channel for HA)
Nexus(config-if-range)# channel-group 160
Nexus(config-if-range)# no shut
Nexus(config-if-range)# exit


Nexus(config)# interface po160
Nexus(config-if)# switchport mode fex-fabric
Nexus(config-if)# fex associate 160
Nexus(config-if)# no shut
Nexus(config-if)# exit



This is what you need to configure to make your fabric extender to work. Now you can see that you Fabric extender will come online & all fabric extender Ports will be mapped with your port-channel.

For Example : Here we had used Port-Channel 160, Now if you want to configure Fabric Extender ports then you need to configure " interface eth160/1/1"
160 is your port channel , 1/1 is your Fabric Extender port.

Show commands :

@ sh run fex
@ sh fex detail
@ sh int po160 fex-fabric
@ sh module fex
@ sh int status fex 160

Also you can connect this fabric extender to separate Nexus switch & create VPC's for HA. For that you need to config VPC's under port-channel & also you need to configure VPC's domain & peer link between both nexus switches. Below is test scenario for same :

                                     Nexus Fabric Ext
                                          =         =
                                        =              =
                                     =                     =
                                  =                           =
                                N5K-1 ==========  N5K-2
                                          vpc peer link

 

In this type of design is highly recommend because of redundancy. In next post i will come up with Virtual Port Channel known as VPC's.









 




Saturday, May 19, 2012

Active Blog : Comeback

Hi Guys

From long time the blog was not active due to my work, but now onward the blog will be active & i will come up will all available technologies that is used in Service Provider , Enterprise Network & Data Center which include Routing & Switching , Security , MPLS , Load Balancer & Cisco Data Center 3.0.

I will come up with all major IT vendor i.e. Cisco, Juniper, Check Point, BigIP F5 etc.

As we know that the IT world is changing so rapidly that we can't stick to single vendor & technologies.
Now the Virtualization is the key component for IT Department because it reduce cost & increase productivity.
So the new name of Virtualization is "Cloud Computing".

Cisco is having very impressive product line for this Virtualization . ( For more detail check www.cisco.com for Cisco Data Center 3.0)

So Cisco came up with New Certification  CCIE Data Center or we can say it is enhance version of CCIE Storage.

So stick to this blog & get more detail on above technologies.

Chetan Kumar

Monday, May 23, 2011

CCIE SP v3 Sample Lab

Vincent Zhou had published the CCIE SP v3 Sample LAB's in Cisco Learning Network.

There are total 8 part which describe the new CCIE SP v3 LAB senario & the Question which help us for preparing the CCIE SP LAB.

Click the below link : CCIE SP v3 Sample LAB

Tuesday, May 10, 2011

How to Save Configuration in Cisco IOS-On-UNIX (IOU)

In my earlier post you saw how to run CISCO IOU on VMware machine, But the problem is that you can't save configuration because you are running CISCO IOU from Live CD & when you will restart the VMware machine then the configuration will be removed .

Here i am going to explain you how to save the configuration in CISCO IOU , so that you can have that configured topology any time when ever you want , So now you can review the configuration & use the old configured topology for you LAB practice.

The requirement to save configuration is the same one that we using for LIVE CD, Here we are going to use the Ubuntu OS for GUI mode, But how know the CLI he can go with CLI mode without having Ubuntu OS.

1] Download the Ubuntu OS & install in VMware machine.
2] Run VMware machine with the CISCO IOU TS1 & TS2 Live CD with auto mount option.


3] Use "df" Command to view disk usage.You will get below screen.


Here you will see the "/media/sda1" which is your hard drive that is allocated to Ubuntu OS.

4] To save the configuration we have to copy the following files from CD to hard drive.
    Below files need to copy from CD to Hard drive.

 

5] Use the below command to create folder in sda1 so that we can copy the flies from CD to hard drive folder.

#mkdir IOU



6] Use below command to copy the files from CD to Hard Drive & verify.

#cp -r * /media/sda1/home/xyz/IOU_1

 xyz        ==> Home folder of Ubuntu OS.
IOU_1   ==> Folder that we create to copy files from CD to Hard drive.




 
7] Now all required files are copied to Hard drive & when ever you want to run IOU then you should boot with live CD & then go to home folder then run & instructed in LIVE CD.


 



8] Now you can telnet to routers & save the configuration. All configuration is saved in your Ubuntu hard drive . If you want to see you can login to Ubuntu & enjoy !!!!!


Note : The IOU will not run from Ubuntu  ,To run IOU you have boot from LIVE CD & then go to hard drive folder where you had copied & then run the TS1 & TS2 Topology.

  

Saturday, May 7, 2011

Cisco Simulator : Cisco IOS-On-UNIX (Cisco IOU)

Cisco Learning Labs for routing and switching are real bundles of practice labs, powered by Cisco IOS Software on UNIX.


Cisco IOS-On-UNIX is a Cisco simulator, Cisco use IOU for IOS testing & CCIE R&S Trouble shooting. Also Cisco Conduct CCIE R&S Trouble shotting on Cisco IOS-On-UNIX.


Cisco IOS-On-UNIX is cisco internal simulator used by internal employ.


Now Cisco IOU has been leaked & available on internet. You can download the Cisco IOS-On-UNIX for CCIE LAB practice.


Cisco IOS-On-UNIX support all feature & it come with advance enterprise IOS.


Also Cisco has now announce officially Cisco Learning LAB where you can buy Cisco Rental LAB for preparation of CCIE R&S or MPLS LABS.


From Below link you will know more about Cisco IOS-On-UNIX  


1] Cisco IOU -- Part 1
2] Cisco IOU -- Part 2
3] Cisco IOU -- Part 3
4] Cisco IOU -- Part 4
5] Cisco IOU -- Part 5

Cisco IOU -- Part 5

How you can Telnet the Cisco IOU routes ?

You can telnet all router that you are running in Cisco IOU. Please follow the below steps :-


Check the IP address of VMware machine with "ifconfig" command. VMware machine will automatically get IP address because of DHCP, DHCP is enable in VMware so when ever you will run VMware machine the you will get IP address. (Default) 


For example your IP address is 192.168.120.110 then open Putty or Telnet or use SecureCRT to do telnet.
You will do telnet to IP address : "telnet 192.168.120.110 2001 "  2001 is the port number.

So you will get R1 prompt , In this way yo can start telnet using port number till 2030 in TS1 & TS2.

For Example : 


"telnet 192.168.120.110 2001 "
"telnet 192.168.120.110 2002 "
"telnet 192.168.120.110 2003 "
"telnet 192.168.120.110 2004 "  


Use Secure CRT to save the session , So that you can use those session any time .




Note : In Cisco IOU you will not able to save the configuration because you are running topology in LIVE CD, In up coming post i will show you how to save the configuration in Cisco IOU for TS1 & TS2 or any other.

Cisco IOU -- Part 4

How to run Cisco IOU on your machine ?

@ Below are the link from where you can download the Cisco IOU .
@ Install the VMware 
@ Create machine & allocate at least 2GB Ram.( Don't install any OS in that )
@ From below link you will get ISO image for Cisco IOU & boot that machine with this image.
@ You will see that machine will start with Linux OS 
@ Then you will get ROOT prompt & then type "ls" command to view file in root directory.
@ To start TS1 or TS2 topology you can type blow command : 

#TS1
TS1#one  ====> " Type one to start the topology"
#TS2
TS2#two   ====> " Type two to start the topology"

Type "off" to turn off the routers.


Please ignore thet below error : 

Waitting on port 2030
Process Id For child is 1681,parent is 1679
UNIX ERR:tcgetattr:Invalid argument

You can download the Cisco IOU from below links with different topology : 

1] Cisco IOU LiveCD v1  ===> 6 Routers  

2] Cisco IOU CCIE v4 TS 1 & 2 Rack LiveCD v2.0 == > Used for Troubleshooting in CCIE R&S Lab

In v2.0 you can have two topology i.e. TS1 & TS2 .
TS1 : This is troubleshooting ready topology that used in CCIE R&S Lab exam.
TS2 : This is troubleshooting ready topology that used in CCIE R&S Lab exam.

Below are the topology diagram for TS1 & TS2

TS 1 Topology : 25+ routers 


TS 2 Topology : 25+ routers




Note : If you are not able to start all router then increase the RAM.

Cisco IOU -- Part 3

Here’s a simple NETMAP file:

101:0
101:18 102:2
102:0

There are two routers represented here, identified by “application ID” values 101 and 102 (which you pass to the IOU images when starting them up).

The first and last lines represent an interface which is connected to nothing. The second line shows that the interface on 101 identified by 18 is connected to the interface on 102 identified by 2. Where do these numbers come from you ask?

Unlike Dynamips/Dynagen, “NETMAP” does not use interface names but, rather, interface IDs. The IDs are not tied to a specific interface type (e.g. Serial or Ethernet). When launching an IOU instance, you can specify (via the command-line) which interfaces you want and how many. The ID used for Serial1/2 and Ethernet1/2 would be the same and, as such, it’s impossible to have both of those interfaces in an single instance.

To calculate the ID used by “interface x/y”, you would use the following formula:

id = x + (y * 16)

Examples:

    interface 0/0 = 0
    interface 0/3 = 48
    interface 1/2 = 33
    interface 12/1 = 28

Based on this formula, we can see that in the second line of the example NETMAP file, 101′s interface 2/1 is connected to 102′s interface 2/0.

Using this formula (and the resulting values), it should be fairly easily to construct your own NETMAP files from scratch.

Note that you can’t, unfortunately, “bridge” an IOU instance to a physical network without the use of another piece of software named “IOUlive”