BIG-IP Systems Upgrading Software PDF
BIG-IP Systems Upgrading Software PDF
Version 13.0
Table of Contents
Table of Contents
Legal Notices............................................................................................................................ 69
Legal notices.................................................................................................................... 69
3
Table of Contents
4
Upgrading Version 11.x or 12.x BIG-IP Software
Note: For BIG-IP devices running version 12.1.1, or later, you can migrate the existing user
configuration set (UCS) file from the version 12.1.1, or later, device to a new device running version
12.1.1, or later. For details, please refer to K82540512: Overview of the UCS archive platform-migrate
option in the AskF5™ knowledge base at http://support.f5.com.
Important: If your version 11.x device group includes HA groups, note that an HA group applies to the
respective device in version 11.0 through 11.4.x, whereas an HA group applies to a traffic group on the
device in version 11.5, and later.
Note: When upgrading a device group from version 11.x, or later, software to the latest version software,
mirroring does not function until all devices in the device group complete rebooting to the latest version.
F5 Networks® recommends upgrading software during a scheduled maintenance window, to minimize
traffic disruption when devices run different software versions.
Upgrading Version 11.x or 12.x BIG-IP Software
When upgrading an 11.x, or later, device group to the new version software, you first need to prepare
your devices. After preparing the devices, you force Device A to offline state, and install the new version
software onto Device A. When you finish the installation of the new version software onto Device A, the
traffic groups remain in standby state on Device A, and in active state on Device B and Device C.
Important: Once Device A reboots, if the BIG-IP system is configured to use a network hardware
security module (HSM), you must reinstall network HSM client software on Device A before upgrading
Device B, to ensure that traffic groups using the network HSM function properly.
6
BIG-IP Systems: Upgrading Software
Figure 2: A device group with Device A upgraded to the new version software, and traffic groups in
standby state
With the new version software installed on Device A and all traffic groups in standby state, you force
Device B to offline state, changing the traffic groups on Device A to active state so that they can pass
traffic. You can then install the new version software onto Device B, and reboot Device B to the location
of the new version software image.
Important: Once Device B reboots, if the BIG-IP system is configured to use a network HSM, you must
reinstall network HSM client software on Device B before upgrading Device C, to ensure that traffic
groups using the network HSM function properly.
7
Upgrading Version 11.x or 12.x BIG-IP Software
Figure 3: A device group with Device B upgraded to the new version software, and traffic groups in
standby state
Once Device B reboots, you can force Device C to offline state, making traffic-group-3 active on Device
B. When you complete upgrading Device C to the new version software and reboot Device C, the BIG-IP
configuration includes traffic-group-1 and traffic-group-2 in active state on Device A, traffic-group-3 in
active state on Device B, and a device group that includes all devices. If you use HA groups, observe that
the HA group on Device A, Device B, and Device C applies to each traffic group.
Important: Once Device C reboots, if the BIG-IP system is configured to use a network HSM, you must
reinstall network HSM client software on Device C, to ensure that traffic groups using the network HSM
function properly.
8
BIG-IP Systems: Upgrading Software
Figure 4: A device group with all devices upgraded to the new version software
Once each device is upgraded to the new version software, you can reconfigure the traffic groups to
become active on the devices that you want by forcing the active traffic group on a device to standby
state. When forcing the traffic group to standby state, you can target the device upon which you want that
traffic group to run in active state. For example, you can force traffic-group-2 on Device A into standby
state, and into active state on Device B, and then force traffic-group-3 on Device B into standby state,
and into active state on Device C. Additionally, if you use HA groups, you can create a unique HA group
for each traffic group on each device.
9
Upgrading Version 11.x or 12.x BIG-IP Software
Summary of tasks
Task Description
Preparing the In preparing to upgrade the BIG-IP systems to the new version software, you need
devices in the to understand any specific configuration or functional changes from the previous
device group version, and prepare the systems. You also download the new version of software
from the AskF5™ web site (http://support.f5.com/kb/en-us.html) and
import the files onto each device.
Upgrading Device When you complete preparation of Device A, you can force that device to offline
A state, changing those traffic groups to active state on another device in the traffic
group, and then upgrade the software on Device A.
Upgrading Device When you complete preparation of Device B, you can force that device to offline
B state, changing those traffic groups to active state on another device in the traffic
group, and then upgrade the software on Device B.
10
BIG-IP Systems: Upgrading Software
Task Description
Upgrading Device When you complete preparation of Device C, you can force that device to offline
C state, changing those traffic groups to active state on another device in the traffic
group, and then upgrade the software on Device C.
Changing states of When you finish upgrading all of the devices, you can restore the configuration of
traffic groups active traffic groups on each device.
Verifying the Finally, you should verify that the BIG-IP device group is functioning properly.
upgrade
Configuring HA When you finish upgrading a device, the HA group on the device (in version 11.5,
groups and later) applies to a traffic group, as opposed to the device. You can create a
unique HA group for each traffic group on each device, as necessary.
Configuring According to your understanding of the configuration and functional changes
module-specific from the previous version, you can reconfigure any customized module settings.
settings
DSC components
Device service clustering (DSC®) is based on a few key components.
Devices
A device is a physical or virtual BIG-IP® system, as well as a member of a local trust domain and a
device group. Each device member has a set of unique identification properties that the BIG-IP
system generates. For device groups configured for failover, it is important that the device with the
smallest capacity has the capacity to process all traffic groups. This ensures application availability in
the event that all but one device in the device group become unavailable for any reason.
Device groups
A device group is a collection of BIG-IP devices that trust each other and can synchronize, and
sometimes fail over, their BIG-IP configuration data. A Sync-Failover device group contains devices
that synchronize configuration data and support traffic groups for failover purposes when a device
becomes unavailable. The BIG-IP system supports either homogeneous or heterogeneous hardware
platforms within a device group.
Important: BIG-IP module provisioning must be equivalent on all devices within a device group. For
example, module provisioning is equivalent when all device group members are provisioned to run
BIG-IP® Local Traffic Manager™ (LTM®) and BIG-IP® Application Security Manager™ (ASM™) only.
Maintaining equivalent module provisioning on all devices ensures that any device in the device
group can process module-specific application traffic in the event of failover from another device.
Traffic groups
A traffic group is a collection of related configuration objects (such as a virtual IP address and a self
IP address) that run on a BIG-IP device and process a particular type of application traffic. When a
11
Upgrading Version 11.x or 12.x BIG-IP Software
BIG-IP device becomes unavailable, a traffic group can float to another device in a device group to
ensure that application traffic continues to be processed with little to no interruption in service.
Folders
Folders are containers for the configuration objects on a BIG-IP device. For every administrative
partition on the BIG-IP system, there is a high-level folder. At the highest level of the folder hierarchy
is a folder named root. The BIG-IP system uses folders to affect the level of granularity to which it
synchronizes configuration data to other devices in the device group.
Note: A Sync-Failover device group can support a maximum of 127 floating traffic groups.
12
BIG-IP Systems: Upgrading Software
Note: When you force a chassis system offline, the Traffic Management Microkernel (TMM) interfaces
remain configured until the unit is rebooted. If the chassis is rebooted while Force Offline is enabled, the
system marks all TMM interfaces as Uninitialized or Missing. This behavior is by design. The
system will not attempt to initialize and bring up TMM interfaces while the system is in the offline state.
When you force VIPRION platforms offline, make sure to manage the system by using the management
port or console. The system terminates connections to self IP addresses when you force the platform
offline.
You will want to force the standby devices offline before you change the redundancy state (such as
resetting the device trust for a device group). Forcing standby devices into offline state prevents a
standby device from unexpectedly becoming active.
Task summary
The upgrade process involves preparation of the BIG-IP® devices (Device A, Device B, and Device C)
configured in device group, followed by the installation and verification of the new version software on
each device. When you upgrade each device, you perform several tasks. Completing these tasks results in
a successful upgrade to the new version software on all BIG-IP devices, with the device group configured
properly.
Preparing BIG-IP modules for an upgrade from version 11.x, or later
Preparing RAID drives for an upgrade
Preparing BIG-IP device groups for an upgrade
Upgrading the Device A system
Upgrading the Device B system
Upgrading the Device C system
Changing states of the traffic groups
Verifying a BIG-IP device group upgrade
Preparation activities
Before you upgrade the BIG-IP® Application Acceleration Manager™ (AAM®) modules from version
11.x, or later, to the new version software, you need to prepare the systems, based on your configuration.
The following table summarizes the applicable tasks that you need to complete.
13
Upgrading Version 11.x or 12.x BIG-IP Software
Post-upgrade activities
When you finish upgrading to the new version software, you should consider the following feature or
functionality changes that occur for the Access Policy Manager systems. Depending on your
configuration, you might need to perform these changes after you upgrade your systems.
14
BIG-IP Systems: Upgrading Software
Preparation activities
You should complete these activities before upgrading Global Traffic Manager systems from version
11.x, or later, to the new version software (BIG-IP® DNS).
Important: In BIG-IP version 12.0, BIG-IP Global Traffic Manager is renamed to BIG-IP DNS. After
you upgrade, you will see the new name in the product and documentation.
Activity Instructions
Verify that the device certificates are current, and 1. On the Main menu, click System > Device
that expiration does not occur until after Certificates > Device Certificate.
upgrading. 2. Verify the Expires date.
Disable configuration synchronization and DNS 1. On the Main menu, click DNS > Settings >
zone files synchronization. GSLB > General.
2. Clear the Synchronize check box.
Note: To use a backup UCS file without
3. Clear the Synchronize DNS Zone Files check
synchronizing the GTM configuration, disable
box.
synchronization. If synchronization is enabled,
restoring the UCS backup file loads the
configuration and initiates synchronization.
Post-upgrade activities
You should complete these tasks after upgrading BIG-IP DNS systems from 11.x, or later, to the new
version software.
Important: In BIG-IP version 12.0, BIG-IP Global Traffic Manager is renamed to BIG-IP DNS. After
you upgrade, you will see the new name in the product and documentation.
• From the command line, run the big3d_install script on the first BIG-IP DNS system that you
upgraded, so that you can monitor other BIG-IP DNS systems.
Important: Run this script only once, only from the first BIG-IP DNS system that you upgraded. This
step momentary degrades monitoring performance as new big3d agents start.
• On each device, verify the configuration.
• On each device, test queries against listeners.
• On each device, verify iQuery® connections by using the tmsh command tmsh show /gtm iquery
all.
• Enable synchronization on each device.
• Verify configuration synchronization by using a dummy test object; for example, by using an object
that can be deleted after the configuration synchronization is verified as operational.
15
Upgrading Version 11.x or 12.x BIG-IP Software
Sys::Raid::Array: MD1
--------------------
Size (MB) 305245
Sys::Raid::ArrayMembers
Bay ID Serial Number Name Array Member Array Status
---------------------------------------------------------
1 WD-WCAT18586780 HD2 yes failed
2 WD-WCAT1E733419 HD1 yes ok
In this example, the array is labeled MD1 and disk HD2 indicates an error.
3. Verify Current_Pending_Sector data displays a RAW_VALUE entry of less than 1 on RAID
systems.
Option Description
For version 11.4.0, and Run the platform check utility: (tmos)# run util
later platform_check
For version 11.3.x, and At the command line, run the smartctl utility: smartctl -t long -
earlier d ata /dev/<sda|sdb|hda|hdc>
16
BIG-IP Systems: Upgrading Software
• Check /var/log/user.log for LBA messages indicating failure to recover, for example,
recovery of LBA:226300793 not complete.
• Check /var/log/kern.log for ATA error entries.
The health of all RAID drives is assessed, enabling you to resolve any issues before proceeding with the
BIG-IP® software upgrade.
Note: If you prefer to closely observe the upgrade of each device, you can optionally connect to the serial
console port of the device that you are upgrading.
1. For each device, complete the following steps to prepare the configuration and settings.
a) Examine the Release Notes for specific configuration requirements, and reconfigure the systems,
as necessary.
b) Examine the Release Notes for specific changes to settings that occur when upgrading from
version 11.x, or later, to the new version, and complete any in-process settings.
2. From the device that is running the latest configuration, synchronize the configuration to the devices
in the device group.
Option Description
For version 11.2, 1. On the Main menu, click Device Management > Device Groups. A list
and earlier. of device groups appears.
2. In the Group Name column, click the name of a device group.
3. On the menu bar, click ConfigSync.
4. Click Synchronize To Group.
For version 11.3, 1. On the Main menu, click Device Management > Overview. A message
and later. appears for the Status Message.
2. In the Devices area of the screen, in the Sync Status column, click the
device that shows a sync status of Changes Pending.
3. Click Synchronize Device to Group.
17
Upgrading Version 11.x or 12.x BIG-IP Software
Note: For additional support information about backing up and restoring BIG-IP system
configuration files, refer to SOL11318 on www.askf5.com.
5. Download either the latest BIG-IP system hotfix image file, if available, or the new version software
image file from the AskF5 downloads web site (http://support.f5.com/kb/en-us.html) to a
preferred location.
Important: If you want to upgrade to a BIG-IP system hotfix image file that applies to incremental
major version software, you must download the incremental version software and the hotfix image
file. For example, if you want to upgrade from BIG-IP version 11.x software to a 12.x hotfix image
file, then you must download a version 12.x software image file and the hotfix image file.
6. Import either the latest BIG-IP system hotfix image file, if available, or the new version software
upgrade image file to each device.
Option Description
Import the 1. On the Main menu, click System > Software Management > Hotfix List >
latest BIG-IP Import.
system hotfix 2. Click Browse, locate and click the SIG file (Hotfix-BIGIP-hf-
image and xx.x.x.x.x.xxxx.HFx.iso.384.sig), click Open, and click Import.
SIG file
3. Click Browse, locate and click the image file, click Open, and click Import.
4. When the hotfix image file completes uploading to the BIG-IP device, click
OK. A link to the image file appears in the Software Image list.
Import the 1. On the Main menu, click System > Software Management > Image List >
new version Import.
software 2. Click Browse, locate and click the SIG file (BIGIP-13.x.x.x.x.xxxx.iso.384.sig),
image and click Open, and click Import.
SIG file
3. Click Browse, locate and click the upgrade image file, click Open, and click
Import.
Note: BIG-IP version 13.x, and later, provides upgrade and recovery image
files. An upgrade image file (for example, BIGIP-13.x.x.x.x.xxxx.iso) omits End
User Diagnostics (EUD) software, which includes tests that report on hardware
components. A recovery image file (for example, BIGIP-
RECOVERY-13.x.x.x.x.xxx.iso) includes EUD software.
4. When the software image file completes uploading to the BIG-IP device, click
OK. A link to the image file appears in the Software Image list.
18
BIG-IP Systems: Upgrading Software
Option Description
Use SIG 1. At the command line, determine the filename of the applicable public key
verification file.
(recommended)
Example: # ls /usr/lib/install/archive.pubkey*pem. The list of
archive.pubkey files appears.
2. Using the openssl utility, verify the integrity of the imported software image
file.
Example: # openssl dgst -sha384 -verify usr/lib/install/
archive.pubkey.xxxxxxxxx.pem -signature shared/images/
BIGIP-13.x.x.x.x.xxxx.iso.384.sig shared/images/
BIGIP-13.x.x.x.x.xxxx.iso
Note: You must use openssl version 1.0.0, or later. Type openssl version
at the command line to determine the version.
The openssl utility verifies the integrity of the software image file and
displays the results.
# openssl dgst -sha384 -verify usr/lib/install/
archive.pubkey.xxxxxxxxx.pem -signature shared/images/
BIGIP-13.x.x.x.x.xxxx.iso.384.sig shared/images/
BIGIP-13.x.x.x.x.xxxx.iso
Verified OK
Use an MD5 • Using a tool or utility that computes an md5 checksum, you can verify the
checksum integrity of the BIG-IP system latest hotfix .iso file or new version .iso
file.
8. If the BIG-IP system is configured to use a network hardware security module (HSM), the HSM
client software must be available for reinstallation.
Important: Make sure that the available version of HSM client software supports the new version of
BIG-IP software.
The BIG-IP devices are prepared to install the latest hotfix or new version software.
Important: If you want to upgrade to a BIG-IP® system hotfix image file that applies to incremental
major version software, you must install the incremental version software before installing the hotfix
image file. For example, if you want to upgrade from BIG-IP version 11.x software to a 12.x hotfix
image file, then you must install a version 12.x software image file before you install the hotfix image
file.
After you prepare each device for upgrading the software, you force the device offline, reactivate the
software license, and install the new version software onto Device A.
1. Force Device A to offline state.
19
Upgrading Version 11.x or 12.x BIG-IP Software
Important: Once Device A changes to offline state, ensure that traffic passes normally for all
active traffic groups on the other devices.
Note: When Force Offline is enabled, make sure to manage the system using the management
port or console. Connections to self IP addresses are terminated when Force Offline is enabled.
Important: If you want to upgrade to a BIG-IP system hotfix image file that applies to incremental
major version software, you must install the incremental version software before installing the hotfix
image file. For example, if you want to upgrade from BIG-IP version 11.x software to a 12.x hotfix
image file, then you must install a version 12.x software image file before you install the hotfix image
file.
Option Description
Install the 1. On the Main menu, click System > Software Management > Hotfix List.
latest hotfix 2. In the Available Images area, select the check box for the hotfix image, and
image click Install. The Install Software Hotfix popup screen opens.
3. From the Volume set name list, select the location of the new version
software volume to install the hotfix image, and click Install.
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
Note: The format for a volume set name is lower case only, alphanumeric with
hyphenation, and limited to 32 characters.
Install the new 1. On the Main menu, click System > Software Management > Image List.
version 2. In the Available Images area, select the check box for the new version
software software image, and click Install. The Install Software Image popup screen
opens.
3. From the Volume set name list, select a location to install the image, and
click Install.
20
BIG-IP Systems: Upgrading Software
Option Description
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
Note: The format for a volume set name is lower case only, alphanumeric with
hyphenation, and limited to 32 characters.
4. Reboot the device to the location of the installed new software image.
Note: When upgrading a device group from version 11.x, or later, software to the latest version
software, mirroring does not function until all devices in the device group complete rebooting to the
latest version. F5 Networks® recommends upgrading software during a scheduled maintenance
window, to minimize traffic disruption when devices run different software versions.
Option Description
Reboot 1. On the Main menu, click System > Software Management > Boot Locations.
from 2. In the Boot Location list, click the boot location of the installed new software
version image.
11.3.0, or
earlier Note: Upgrading from version 11.3.0, or earlier, automatically installs the
configuration of that version to the new boot location.
3. Click Activate. Device A reboots to the new software image boot location in
offline state.
Note: If the device appears to be taking a long time to reboot, do not cycle the power
off and on. Instead, verify the status of the device by connecting to its serial console
port. The device might be performing firmware upgrades.
Reboot 1. On the Main menu, click System > Software Management > Boot Locations.
from 2. In the Boot Location list, click the boot location of the installed new software
version image.
11.4.0, or
3. From the Install Configuration list, select Yes. The Source Volume list appears.
later
4. From the Source Volume list, select the location of the configuration to install
when activating the boot location of the new software image. For example, for an
installation of a new software image on HD1.3, selecting HD1.2:11.6.0 installs the
version 11.6.0 configuration.
5. Click Activate. Device A reboots to the new software image boot location in
offline state.
Note: If the device appears to be taking a long time to reboot, do not cycle the power
off and on. Instead, verify the status of the device by connecting to its serial console
port. The device might be performing firmware upgrades.
5. If the BIG-IP system is configured to use a network hardware security module (HSM), reinstall and
configure the HSM client software.
Important: You must reinstall network HSM client software on this device before upgrading another
device in the device group, to ensure that traffic groups using the network HSM function properly.
21
Upgrading Version 11.x or 12.x BIG-IP Software
Important: If you want to upgrade to a BIG-IP® system hotfix image file that applies to incremental
major version software, you must install the incremental version software before installing the hotfix
image file. For example, if you want to upgrade from BIG-IP version 11.x software to a 12.x hotfix
image file, then you must install a version 12.x software image file before you install the hotfix image
file.
• If the BIG-IP system is configured to use a network hardware security module (HSM), you must
reinstall network HSM client software on Device A before upgrading Device B, to ensure that traffic
groups using the network HSM function properly.
• Device A (the new version BIG-IP® device) is in standby state.
After you prepare Device B for upgrading the software, you force the device offline, reactivate the
software license, and install the new version software.
1. Force Device B to offline state.
a) On the Main menu, click Device Management > Devices.
b) Click the name of Device B.
The device properties screen opens.
c) Click Force Offline.
Device B changes to offline state.
Important: Once Device B changes to offline state, ensure that Device A passes traffic normally
for all active traffic groups.
Note: When Force Offline is enabled, make sure to manage the system using the management
port or console. Connections to self IP addresses are terminated when Force Offline is enabled.
22
BIG-IP Systems: Upgrading Software
Important: If you want to upgrade to a BIG-IP system hotfix image file that applies to incremental
major version software, you must install the incremental version software before installing the hotfix
image file. For example, if you want to upgrade from BIG-IP version 11.x software to a 12.x hotfix
image file, then you must install a version 12.x software image file before you install the hotfix image
file.
Option Description
Install the 1. On the Main menu, click System > Software Management > Hotfix List.
latest hotfix 2. In the Available Images area, select the check box for the hotfix image, and
image click Install. The Install Software Hotfix popup screen opens.
3. From the Volume set name list, select the location of the new version
software volume to install the hotfix image, and click Install.
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
Note: The format for a volume set name is lower case only, alphanumeric with
hyphenation, and limited to 32 characters.
Install the new 1. On the Main menu, click System > Software Management > Image List.
version 2. In the Available Images area, select the check box for the new version
software software image, and click Install. The Install Software Image popup screen
opens.
3. From the Volume set name list, select a location to install the image, and
click Install.
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
Note: The format for a volume set name is lower case only, alphanumeric with
hyphenation, and limited to 32 characters.
4. Reboot the Device B to the location of the installed new software image.
Note: When upgrading a device group from version 11.x, or later, software to the latest version
software, mirroring does not function until all devices in the device group complete rebooting to the
latest version. F5 Networks® recommends upgrading software during a scheduled maintenance
window, to minimize traffic disruption when devices run different software versions.
Option Description
Reboot 1. On the Main menu, click System > Software Management > Boot Locations.
from 2. In the Boot Location list, click the boot location of the installed new software
version image.
11.3.0, or
earlier Note: Upgrading from version 11.3.0, or earlier, automatically installs the
configuration of that version to the new boot location.
3. Click Activate. Device B reboots to the new software image boot location in
offline state.
23
Upgrading Version 11.x or 12.x BIG-IP Software
Option Description
Note: If the device appears to be taking a long time to reboot, do not cycle the power
off and on. Instead, verify the status of the device by connecting to its serial console
port. The device might be performing firmware upgrades.
Reboot 1. On the Main menu, click System > Software Management > Boot Locations.
from 2. In the Boot Location list, click the boot location of the installed new software
version image.
11.4.0, or
3. From the Install Configuration list, select Yes. The Source Volume list appears.
later
4. From the Source Volume list, select the location of the configuration to install
when activating the boot location of the new software image. For example, for an
installation of a new software image on HD1.3, selecting HD1.2:11.6.0 installs a
version 11.6.0 configuration.
5. Click Activate. Device B reboots to the new software image boot location in
offline state.
Note: If the device appears to be taking a long time to reboot, do not cycle the power
off and on. Instead, verify the status of the device by connecting to its serial console
port. The device might be performing firmware upgrades.
5. If the BIG-IP system is configured to use a network HSM, reinstall and configure the HSM client
software.
Important: You must reinstall network HSM client software on this device before upgrading another
device in the device group, to ensure that traffic groups using the network HSM function properly.
Important: If you want to upgrade to a BIG-IP® system hotfix image file that applies to incremental
major version software, you must install the incremental version software before installing the hotfix
image file. For example, if you want to upgrade from BIG-IP version 11.x software to a 12.x hotfix
image file, then you must install a version 12.x software image file before you install the hotfix image
file.
• If the BIG-IP system is configured to use a network hardware security module (HSM), you must
reinstall network HSM client software on Device B before upgrading Device C, to ensure that traffic
groups using the network HSM function properly.
• Device C is in active state.
24
BIG-IP Systems: Upgrading Software
After you prepare Device C for upgrading the software, you force the device offline, reactivate the
software license, and install the new version software.
1. Force Device C to offline state.
a) On the Main menu, click Device Management > Devices.
b) Click the name of Device C.
The device properties screen opens.
c) Click Force Offline.
Device C changes to offline state.
Important: Once Device C changes to offline state, ensure that the other devices pass traffic
normally for all active traffic groups.
Note: When Force Offline is enabled, make sure to manage the system using the management
port or console. Connections to self IP addresses are terminated when Force Offline is enabled.
Important: If you want to upgrade to a BIG-IP system hotfix image file that applies to incremental
major version software, you must install the incremental version software before installing the hotfix
image file. For example, if you want to upgrade from BIG-IP version 11.x software to a 12.x hotfix
image file, then you must install a version 12.x software image file before you install the hotfix image
file.
Option Description
Install the 1. On the Main menu, click System > Software Management > Hotfix List.
latest hotfix 2. In the Available Images area, select the check box for the hotfix image, and
image click Install. The Install Software Hotfix popup screen opens.
3. From the Volume set name list, select the location of the new version
software volume to install the hotfix image, and click Install.
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
Note: The format for a volume set name is lower case only, alphanumeric with
hyphenation, and limited to 32 characters.
Install the new 1. On the Main menu, click System > Software Management > Image List.
version 2. In the Available Images area, select the check box for the new version
software software image, and click Install. The Install Software Image popup screen
opens.
25
Upgrading Version 11.x or 12.x BIG-IP Software
Option Description
3. From the Volume set name list, select a location to install the image, and
click Install.
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
Note: The format for a volume set name is lower case only, alphanumeric with
hyphenation, and limited to 32 characters.
Note: When upgrading a device group from version 11.x, or later, software to the latest version
software, mirroring does not function until all devices in the device group complete rebooting to the
latest version. F5 Networks® recommends upgrading software during a scheduled maintenance
window, to minimize traffic disruption when devices run different software versions.
Option Description
Reboot 1. On the Main menu, click System > Software Management > Boot Locations.
from 2. In the Boot Location list, click the boot location of the installed new software
version image.
11.3.0, or
earlier Note: Upgrading from version 11.3.0, or earlier, automatically installs the
configuration of that version to the new boot location.
3. Click Activate. Device C reboots to the new software image boot location in
offline state.
Note: If the device appears to be taking a long time to reboot, do not cycle the power
off and on. Instead, verify the status of the device by connecting to its serial console
port. The device might be performing firmware upgrades.
Reboot 1. On the Main menu, click System > Software Management > Boot Locations.
from 2. In the Boot Location list, click the boot location of the installed new software
version image.
11.4.0, or
3. From the Install Configuration list, select Yes. The Source Volume list appears.
later
4. From the Source Volume list, select the location of the configuration to install
when activating the boot location of the new software image. For example, for an
installation of a new software image on HD1.3, selecting HD1.2:11.6.0 installs a
version 11.6.0 configuration.
5. Click Activate. Device C reboots to the new software image boot location in
offline state.
Note: If the device appears to be taking a long time to reboot, do not cycle the power
off and on. Instead, verify the status of the device by connecting to its serial console
port. The device might be performing firmware upgrades.
5. If the BIG-IP system is configured to use a network hardware security module (HSM), reinstall and
configure the HSM client software.
26
BIG-IP Systems: Upgrading Software
Important: You must reinstall network HSM client software on this device, to ensure that traffic
groups using the network HSM function properly.
27
Upgrading Version 11.x or 12.x BIG-IP Software
• If the device group has two members only, click Force to Standby. This displays the list of traffic
groups for the device group and causes the local device to appear in the Next Active Device
column.
• If the device group has more than two members, then from the Target Device list, select a value
and click Force to Standby.
The selected traffic group is now in a standby state on the local device and active on another device in the
device group.
Note: Ensure that all information for each peer device appears correctly and completely.
Implementation result
Your upgrade of the BIG-IP® device group from version 11.x or 12.x to the new version software is now
complete. The new version software configuration includes a device group with three devices (Device A,
Device B, and Device C) and three traffic groups (traffic-group-1, traffic-group-2, and
traffic-group-3), with a traffic group on each device in active state.
28
BIG-IP Systems: Upgrading Software
29
Upgrading Version 11.x or 12.x BIG-IP Software
30
Upgrading Version 10.x BIG-IP Active-Standby Systems
Important: In order to upgrade version 10.0.0 or 10.0.1 to the new version software, you must first
upgrade to version 10.1.0 or 10.2.x, and then upgrade version 10.1.0 or 10.2.x to the new version
software. Additionally, you can only upgrade version 10.1.0 or 10.2.x to version 12.x if you have not
provisioned Global Traffic Manager™ (GTM™).
After preparing the devices for an upgrade to the new version software, you force Device B to offline
mode, and then install the new version software onto Device B (the offline device). When you finish the
installation of the new version software onto Device B, it creates a traffic group called traffic-
group-1. The new version software traffic group is in standby state on Device B, and Device A (the
version 10.x device) is in active mode. Note that the Unit ID that was used in version 10.x becomes
obsolete in the new version software.
Upgrading Version 10.x BIG-IP Active-Standby Systems
Important: Once Device B reboots, if the BIG-IP system is configured to use a network hardware
security module (HSM), you must reinstall network HSM client software on Device B before upgrading
Device A, to ensure that traffic groups using the network HSM function properly.
Figure 8: A version 10.x device in active mode and a new software version traffic group in standby
state
With the new version software installed on Device B and traffic-group-1 in standby state, you can
force Device A to offline mode, changing Device B to active state so that it can pass traffic, and then
install the new software version onto Device A. When installation of the new version software onto
Device A completes, you can reboot Device A to the location of the new version software image.
Important: Once Device A reboots, if the BIG-IP system is configured to use a network HSM, you must
reinstall network HSM client software on Device A to ensure that traffic groups using the network HSM
function properly.
When you complete upgrading both devices to the new version software, the BIG-IP configuration
includes a traffic group in active state on Device B, a traffic group in standby state on Device A, and a
device group that includes both devices.
32
BIG-IP Systems: Upgrading Software
Figure 9: A new version software traffic group in active and standby states
An upgrade of BIG-IP active-standby systems to the new version software involves the following tasks.
Task Description
Preparing Device A (the active mode BIG-IP 1 In preparing to upgrade the active-standby BIG-IP
system) and Device B (the standby mode BIG-IP 2 systems to the new version software, you need to
system) understand any specific configuration or functional
changes from the previous version, and prepare the
systems. You also download the new version of
software from the AskF5 web site (http://
support.f5.com/kb/en-us.html) and import
the files onto each device.
Forcing Device B to offline mode When you complete preparation of Device B, you
can force Device B to offline mode.
Upgrading Device B (the offline mode BIG-IP 2 Once Device B is in offline mode, you can upgrade
system) the software on that device, and then reboot
Device B to the location of the new version
software image. Device B completes rebooting
with traffic-group-1 in standby state.
33
Upgrading Version 10.x BIG-IP Active-Standby Systems
Task Description
Upgrading Device A (the offline mode BIG-IP 1 Once Device A is in offline mode, you can
system) upgrade the software on Device A, and then reboot
Device A to the location of the new version
software image. When Device A completes
rebooting, traffic-group-1 is in standby state
on Device A and in active state on Device B.
Verifying the upgrade Finally, you should verify that your active and
standby BIG-IP systems are functioning properly.
Configuring module-specific settings According to your understanding of the
configuration and functional changes from the
previous version, you can reconfigure any
customized module settings.
DSC components
Device service clustering (DSC®) is based on a few key components.
Devices
A device is a physical or virtual BIG-IP® system, as well as a member of a local trust domain and a
device group. Each device member has a set of unique identification properties that the BIG-IP
system generates. For device groups configured for failover, it is important that the device with the
smallest capacity has the capacity to process all traffic groups. This ensures application availability in
the event that all but one device in the device group become unavailable for any reason.
Device groups
A device group is a collection of BIG-IP devices that trust each other and can synchronize, and
sometimes fail over, their BIG-IP configuration data. A Sync-Failover device group contains devices
that synchronize configuration data and support traffic groups for failover purposes when a device
becomes unavailable. The BIG-IP system supports either homogeneous or heterogeneous hardware
platforms within a device group.
Important: BIG-IP module provisioning must be equivalent on all devices within a device group. For
example, module provisioning is equivalent when all device group members are provisioned to run
BIG-IP® Local Traffic Manager™ (LTM®) and BIG-IP® Application Security Manager™ (ASM™) only.
Maintaining equivalent module provisioning on all devices ensures that any device in the device
group can process module-specific application traffic in the event of failover from another device.
34
BIG-IP Systems: Upgrading Software
Traffic groups
A traffic group is a collection of related configuration objects (such as a virtual IP address and a self
IP address) that run on a BIG-IP device and process a particular type of application traffic. When a
BIG-IP device becomes unavailable, a traffic group can float to another device in a device group to
ensure that application traffic continues to be processed with little to no interruption in service.
Folders
Folders are containers for the configuration objects on a BIG-IP device. For every administrative
partition on the BIG-IP system, there is a high-level folder. At the highest level of the folder hierarchy
is a folder named root. The BIG-IP system uses folders to affect the level of granularity to which it
synchronizes configuration data to other devices in the device group.
Note: A Sync-Failover device group can support a maximum of 127 floating traffic groups.
Task summary
The upgrade process involves preparation of the two BIG-IP® devices (Device A and Device B)
configured in an active-standby implementation, followed by the installation and verification of the new
version software on each device. When you upgrade each device, you perform several tasks. Completing
these tasks results in a successful upgrade to the new version software on both BIG-IP devices, with a
traffic group configured properly for an active-standby implementation.
Important: In order to upgrade version 10.0.0 or 10.0.1 to the new version software, you must first
upgrade to version 10.1.0 or 10.2.x, and then upgrade version 10.1.0 or 10.2.x to the new version
software. Additionally, you can only upgrade version 10.1.0 or 10.2.x to version 12.x if you have not
provisioned Global Traffic Manager™ (GTM™).
Preparing BIG-IP modules for an upgrade from version 10.x to the new version software
Preparing RAID drives for an upgrade
Preparing BIG-IP active-standby systems for an upgrade
35
Upgrading Version 10.x BIG-IP Active-Standby Systems
Preparing BIG-IP modules for an upgrade from version 10.x to the new version
software
Before you upgrade the BIG-IP® system from version 10.x to the new version software, you might need
to manually prepare settings or configurations for specific modules.
Post-upgrade activities
When you complete upgrading to the new version software, you should consider the following feature or
functionality changes that occur for the Access Policy Manager systems. Depending on your
configuration, you might need to perform these changes after you upgrade your systems.
when CLIENT_ACCEPTED {
36
BIG-IP Systems: Upgrading Software
ACCESS::restrict_irule_events disable
}
Preparation Activities
Before you upgrade Global Traffic Manager systems that are in a synchronization group, from any
software version to the new version software, you must install the software on an inactive volume on
37
Upgrading Version 10.x BIG-IP Active-Standby Systems
each device using Live Install. After you upgrade each device, you then switch all devices to the new
volume at the same time. This is required because devices in a synchronization group that includes the
new version software device, cannot effectively probe each other.
Post-upgrade changes
Important: In BIG-IP version 12.0, BIG-IP Global Traffic Manager is renamed to BIG-IP DNS. After
you upgrade, you will see the new name in the product and documentation.
The following feature or functionality changes occur after you complete the upgrade process to the new
version software:
Note: If you configured MAC Masquerade addresses for VLANs on the version 10.x devices, one of the
addresses will be included automatically in the MAC Masquerade Address field for traffic-group-1
during the upgrade.
Preparation activities
Before you upgrade the BIG-IP® WebAccelerator™ modules from version 10.x to an Application
Acceleration Manager new software version, you need to prepare the systems, based on your
configuration. The following table summarizes the applicable tasks that you need to complete.
38
BIG-IP Systems: Upgrading Software
Post-upgrade activities
When you complete upgrading to the new version software, you should consider the following feature or
functionality changes that occur for the Application Acceleration Manager modules. Depending upon
your configuration, you might need to perform these changes after you upgrade the systems.
39
Upgrading Version 10.x BIG-IP Active-Standby Systems
Sys::Raid::Array: MD1
--------------------
Size (MB) 305245
40
BIG-IP Systems: Upgrading Software
Sys::Raid::ArrayMembers
Bay ID Serial Number Name Array Member Array Status
---------------------------------------------------------
1 WD-WCAT18586780 HD2 yes failed
2 WD-WCAT1E733419 HD1 yes ok
In this example, the array is labeled MD1 and disk HD2 indicates an error.
3. Verify Current_Pending_Sector data displays a RAW_VALUE entry of less than 1 on RAID
systems.
Option Description
For version 11.4.0, and Run the platform check utility: (tmos)# run util
later platform_check
For version 11.3.x, and At the command line, run the smartctl utility: smartctl -t long -
earlier d ata /dev/<sda|sdb|hda|hdc>
Note: If you prefer to closely observe the upgrade of each device, you can optionally connect to the serial
console port of the device that you are upgrading.
1. For each device, complete the following steps to prepare the configuration and settings.
a) Examine the Release Notes for specific configuration requirements, and reconfigure the systems,
as necessary.
For example, you must reconfigure version 10.x symmetric BIG-IP® WebAccelerator™ modules as
asymmetric systems before upgrading to the new version software.
b) Examine the Release Notes for specific changes to settings that occur when upgrading from
version 10.x to the new version software, and complete any in-process settings.
For example, you must publish any unpublished WebAccelerator module policies in order for
them to migrate to the new software version.
2. From the device that is running the latest configuration, synchronize the configuration to the peer
unit.
a) On the Main menu, click System > High Availability > ConfigSync.
41
Upgrading Version 10.x BIG-IP Active-Standby Systems
Note: For additional support information about backing up and restoring BIG-IP system
configuration files, refer to SOL11318 on www.askf5.com.
5. Download the BIG-IP new version software .iso file, and, if available, the latest hotfix .iso file
from the AskF5™ downloads web site (https://downloads.f5.com) to a preferred location.
6. Import either the latest BIG-IP hotfix image file, if available, or the new version software upgrade
image file to each device.
Option Description
Import the 1. On the Main menu, click System > Software Management > Hotfix List >
latest BIG-IP Import.
system hotfix 2. Click Browse, locate and click the SIG file (Hotfix-BIGIP-hf-
image and xx.x.x.x.x.xxxx.HFx.iso.384.sig), click Open, and click Import.
SIG file
3. Click Browse, locate and click the image file, click Open, and click Import.
4. When the hotfix image file completes uploading to the BIG-IP device, click
OK. A link to the image file appears in the Software Image list.
Import the 1. On the Main menu, click System > Software Management > Image List >
new version Import.
software 2. Click Browse, locate and click the SIG file (BIGIP-13.x.x.x.x.xxxx.iso.384.sig),
image and click Open, and click Import.
SIG file
3. Click Browse, locate and click the upgrade image file, click Open, and click
Import.
Note: BIG-IP version 13.x, and later, provides upgrade and recovery image
files. An upgrade image file (for example, BIGIP-13.x.x.x.x.xxx.iso) omits End
User Diagnostics (EUD) software, which includes tests that report on hardware
components. A recovery image file (for example, BIGIP-
RECOVERY-13.x.x.x.x.xxx.iso) includes EUD software.
4. When the software image file completes uploading to the BIG-IP device, click
OK. A link to the image file appears in the Software Image list.
42
BIG-IP Systems: Upgrading Software
Option Description
Note: You must use openssl version 1.0.0, or later. Type openssl version
at the command line to determine the version.
The openssl utility verifies the integrity of the software image file and
displays the results.
# openssl dgst -sha384 -verify usr/lib/install/
archive.pubkey.xxxxxxxxx.pem -signature shared/images/
BIGIP-13.x.x.x.x.xxxx.iso.384.sig shared/images/
BIGIP-13.x.x.x.x.xxxx.iso
Verified OK
Use an MD5 • Using a tool or utility that computes an md5 checksum, you can verify the
checksum integrity of the BIG-IP system latest hotfix .iso file or new version .iso
file.
The BIG-IP devices are prepared to install the latest hotfix or new version software onto Device B (the
standby BIG-IP 2 device).
43
Upgrading Version 10.x BIG-IP Active-Standby Systems
Option Description
Install the 1. On the Main menu, click System > Software Management > Hotfix List.
latest hotfix 2. In the Available Images area, select the check box for the hotfix image, and
image click Install. The Install Software Hotfix popup screen opens.
3. From the Volume set name list, select the location of the new version
software volume to install the hotfix image, and click Install.
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
Install the new 1. On the Main menu, click System > Software Management > Image List.
version 2. In the Available Images area, select the check box for the new software
software version image, and click Install. The Install Software Image popup screen
opens.
3. From the Volume set name list, select a location to install the image, and
click Install.
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
4. Reboot the device to the location of the installed new version software software image.
Important: Once Device B reboots, if the BIG-IP system is configured to use a network hardware
security module (HSM), you must reinstall network HSM client software on Device B before
upgrading Device A, to ensure that traffic groups using the network HSM function properly.
a) On the Main menu, click System > Software Management > Boot Locations.
b) In the Boot Location list, click the boot location of the installed new version software software
image.
c) Click Activate.
The BIG-IP device reboots to the new version software boot location with traffic-group-1 in
standby state.
Note: If the device appears to be taking a long time to reboot, do not cycle the power off and on.
Instead, verify the status of the device by connecting to its serial console port. The device might be
performing firmware upgrades.
The new version software is installed on Device B, with traffic-group-1 in standby state.
44
BIG-IP Systems: Upgrading Software
Important: Once the peer BIG-IP device (Device B) changes to active state, ensure that it passes
traffic normally.
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
Install the new 1. On the Main menu, click System > Software Management > Image List.
version 2. In the Available Images area, select the check box for the new version
software software image, and click Install. The Install Software Image popup screen
opens.
3. From the Volume set name list, select a location to install the image, and
click Install.
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
4. Reboot the BIG-IP device (Device A) to the location of the installed new version software image.
a) On the Main menu, click System > Software Management > Boot Locations.
b) In the Boot Location list, click the boot location of the installed the new version software image.
c) Click Activate.
The BIG-IP device (Device A) reboots to the new version software boot location with traffic-
group-1 in standby state.
Note: If the device appears to be taking a long time to reboot, do not cycle the power off and on.
Instead, verify the status of the device by connecting to its serial console port. The device might be
performing firmware upgrades.
45
Upgrading Version 10.x BIG-IP Active-Standby Systems
Note: Ensure that all information for the peer device appears correctly and complete.
Implementation result
Your upgrade of the BIG-IP® active-standby pair from version 10.x to the new version software is now
complete. The new version software configuration includes a device group with two devices (Device A
and Device B) and a traffic group (traffic-group-1), with the traffic group on one device (Device B)
in active state and the traffic group on the other device (Device A) in standby state.
46
BIG-IP Systems: Upgrading Software
Figure 10: A new version software device group and traffic group
47
Upgrading Version 10.x BIG-IP Active-Standby Systems
48
Upgrading Version 10.x BIG-IP Active-Active Systems
Important: In order to upgrade version 10.0.0 or 10.0.1 to the new version software, you must first
upgrade to version 10.1.0 or 10.2.x, and then upgrade version 10.1.0 or 10.2.x to the new version
software. Additionally, you can only upgrade version 10.1.0 or 10.2.x to version 12.x if you have not
provisioned Global Traffic Manager™ (GTM™).
After preparing the devices for an upgrade to the new version software, you force Device B to offline
mode, and then install the new version software onto Device B (the offline device).
Important: Once Device B reboots, if the BIG-IP system is configured to use a network hardware
security module (HSM), you must reinstall network HSM client software on Device B before upgrading
Device A, to ensure that traffic groups using the network HSM function properly.
Upgrading Version 10.x BIG-IP Active-Active Systems
When you finish the installation of the new version software onto Device B, it creates two traffic groups
called traffic-group-1 and traffic-group-2. Each traffic group is in standby state on Device B,
and Device A (the version 10.x device) is in active mode. You can then force Device A to offline mode,
changing both the new version software traffic groups to active state on Device B. Note that the Unit ID
that was used in version 10.x becomes obsolete in the new version software.
50
BIG-IP Systems: Upgrading Software
Figure 13: A version 10.x device in offline mode and the new version software traffic groups in
active state
Important: Once Device A reboots, if the BIG-IP system is configured to use a network HSM, you must
reinstall network HSM client software on Device A to ensure that traffic groups using the network HSM
function properly.
When you complete upgrading both devices to the new version software, the BIG-IP system
configuration includes traffic-group-1 and traffic-group-2 in active state on Device B, a
traffic-group-1 and traffic-group-2 in standby state on Device A, and a device group that
includes both devices.
51
Upgrading Version 10.x BIG-IP Active-Active Systems
Figure 14: The new version software traffic groups in active state on an upgraded device
Once each device is upgraded to the new version software, you can reconfigure the traffic groups to
become active on the devices that you want by forcing the active traffic group on a device to standby
state. When forcing the traffic group to standby state, you can target the device upon which you want that
traffic group to run in active state. For example, you can force traffic-group-1 on Device B into
standby state, and into active state on Device A. Additionally, if you use HA groups, you can create a
unique HA group for each traffic group on each device.
52
BIG-IP Systems: Upgrading Software
Figure 15: The new version software traffic groups in active state on two different devices
An upgrade of BIG-IP active-active systems to the new version software involves the following tasks.
Task Description
Preparing Device A (active mode on the BIG-IP 1 In preparing to upgrade the active-active BIG-IP
system) and Device B (active mode on the BIG-IP systems to the new version software, you need to
2 system) understand any specific configuration or functional
changes from the previous version, and prepare the
systems. You also download the new version of
software from the AskF5 web site
(www.askf5.com) and import the files onto each
device.
Forcing Device B to offline mode When you complete preparing the Device B, you
can force Device B to offline mode.
Upgrading Device B (the offline mode BIG-IP 2 Once Device B is in offline mode, you can upgrade
system) the software on that device, and reboot Device B to
the location of the new version software image.
Device B completes rebooting with traffic-
group1 and traffic-group-2 in standby state.
53
Upgrading Version 10.x BIG-IP Active-Active Systems
Task Description
Changing states of traffic groups When you finish upgrading all of the devices, you
can restore the configuration of active traffic
groups on each device.
Verifying the upgrade Finally, you should verify that your active traffic
groups on the BIG-IP systems are functioning
properly.
Configuring HA groups When you finish upgrading a device, the HA group
on the device (in version 11.5, and later) applies to
a traffic group, as opposed to the device. You can
create a unique HA group for each traffic group on
each device, as necessary.
Configuring module-specific settings According to your understanding of the
configuration and functional changes from the
previous version, you can reconfigure any
customized module settings.
DSC components
Device service clustering (DSC®) is based on a few key components.
Devices
A device is a physical or virtual BIG-IP® system, as well as a member of a local trust domain and a
device group. Each device member has a set of unique identification properties that the BIG-IP
system generates. For device groups configured for failover, it is important that the device with the
smallest capacity has the capacity to process all traffic groups. This ensures application availability in
the event that all but one device in the device group become unavailable for any reason.
Device groups
A device group is a collection of BIG-IP devices that trust each other and can synchronize, and
sometimes fail over, their BIG-IP configuration data. A Sync-Failover device group contains devices
54
BIG-IP Systems: Upgrading Software
that synchronize configuration data and support traffic groups for failover purposes when a device
becomes unavailable. The BIG-IP system supports either homogeneous or heterogeneous hardware
platforms within a device group.
Important: BIG-IP module provisioning must be equivalent on all devices within a device group. For
example, module provisioning is equivalent when all device group members are provisioned to run
BIG-IP® Local Traffic Manager™ (LTM®) and BIG-IP® Application Security Manager™ (ASM™) only.
Maintaining equivalent module provisioning on all devices ensures that any device in the device
group can process module-specific application traffic in the event of failover from another device.
Traffic groups
A traffic group is a collection of related configuration objects (such as a virtual IP address and a self
IP address) that run on a BIG-IP device and process a particular type of application traffic. When a
BIG-IP device becomes unavailable, a traffic group can float to another device in a device group to
ensure that application traffic continues to be processed with little to no interruption in service.
Folders
Folders are containers for the configuration objects on a BIG-IP device. For every administrative
partition on the BIG-IP system, there is a high-level folder. At the highest level of the folder hierarchy
is a folder named root. The BIG-IP system uses folders to affect the level of granularity to which it
synchronizes configuration data to other devices in the device group.
Note: A Sync-Failover device group can support a maximum of 127 floating traffic groups.
Task summary
The upgrade process involves preparation of the two BIG-IP® devices (Device A and Device B)
configured in an active-active implementation, followed by the installation and verification of the new
version software on each device. When you upgrade each device, you perform several tasks. Completing
55
Upgrading Version 10.x BIG-IP Active-Active Systems
these tasks results in a successful upgrade to the new version software on both BIG-IP devices, with an
active traffic group configured properly on each device.
Important: In order to upgrade version 10.0.0 or 10.0.1 to the new version software, you must first
upgrade to version 10.1.0 or 10.2.x, and then upgrade version 10.1.0 or 10.2.x to the new version
software. Additionally, you can only upgrade version 10.1.0 or 10.2.x to version 12.x if you have not
provisioned Global Traffic Manager™ (GTM™).
Preparing BIG-IP modules for an upgrade from version 10.x to the new version software
Preparing RAID drives for an upgrade
Preparing BIG-IP active-active systems for an upgrade
Upgrading the active BIG-IP 2 system
Upgrading the active BIG-IP 1 system
Changing states of the traffic groups
Verifying a BIG-IP system active-active upgrade
Preparing BIG-IP modules for an upgrade from version 10.x to the new version
software
Before you upgrade the BIG-IP® system from version 10.x to the new version software, you might need
to manually prepare settings or configurations for specific modules.
56
BIG-IP Systems: Upgrading Software
Preparation Activities
Before you upgrade Global Traffic Manager systems that are in a synchronization group, from any
software version to the new version software, you must install the software on an inactive volume on
each device using Live Install. After you upgrade each device, you then switch all devices to the new
volume at the same time. This is required because devices in a synchronization group that includes the
new version software device, cannot effectively probe each other.
Post-upgrade changes
Important: In BIG-IP version 12.0, BIG-IP Global Traffic Manager is renamed to BIG-IP DNS. After
you upgrade, you will see the new name in the product and documentation.
The following feature or functionality changes occur after you complete the upgrade process to the new
version software:
Note: If you configured MAC Masquerade addresses for VLANs on the version 10.x devices, one of the
addresses will be included automatically in the MAC Masquerade Address field for traffic-group-1
during the upgrade.
57
Upgrading Version 10.x BIG-IP Active-Active Systems
Preparation activities
Before you upgrade the BIG-IP® WebAccelerator™ modules from version 10.x to an Application
Acceleration Manager new software version, you need to prepare the systems, based on your
configuration. The following table summarizes the applicable tasks that you need to complete.
Post-upgrade activities
When you complete upgrading to the new version software, you should consider the following feature or
functionality changes that occur for the Application Acceleration Manager modules. Depending upon
your configuration, you might need to perform these changes after you upgrade the systems.
58
BIG-IP Systems: Upgrading Software
59
Upgrading Version 10.x BIG-IP Active-Active Systems
Sys::Raid::Array: MD1
--------------------
Size (MB) 305245
Sys::Raid::ArrayMembers
Bay ID Serial Number Name Array Member Array Status
---------------------------------------------------------
1 WD-WCAT18586780 HD2 yes failed
2 WD-WCAT1E733419 HD1 yes ok
In this example, the array is labeled MD1 and disk HD2 indicates an error.
3. Verify Current_Pending_Sector data displays a RAW_VALUE entry of less than 1 on RAID
systems.
Option Description
For version 11.4.0, and Run the platform check utility: (tmos)# run util
later platform_check
For version 11.3.x, and At the command line, run the smartctl utility: smartctl -t long -
earlier d ata /dev/<sda|sdb|hda|hdc>
Note: If you prefer to closely observe the upgrade of each device, you can optionally connect to the serial
console port of the device that you are upgrading.
1. For each device, complete the following steps to prepare the configuration and settings.
a) Examine the Release Notes for specific configuration requirements, and reconfigure the systems,
as necessary.
For example, you must reconfigure version 10.x symmetric WebAccelerator modules as
asymmetric systems before upgrading to the new version software.
b) Examine the Release Notes for specific changes to settings that occur when upgrading from
version 10.x to the new version software, and complete any in-process settings.
For example, you must publish any unpublished BIG-IP® WebAccelerator™ module policies in
order for them to migrate to the new version software.
60
BIG-IP Systems: Upgrading Software
2. From the device that is running the latest configuration, synchronize the configuration to the peer
unit.
a) On the Main menu, click System > High Availability > ConfigSync.
A message appears for the Status Message.
b) Click Synchronize TO Peer.
3. For each device, click System > High Availability > Redundancy, and, from the Redundancy State
Preference list, select None.
4. For each device, create a backup file.
a) Access the tmsh command line utility.
b) At the prompt, type save /sys ucs /shared/filename.ucs.
c) Copy the backup file to a safe location on your network.
5. Download the BIG-IP new version software .iso file, and, if available, latest hotfix .iso file from
the AskF5™ downloads web site (https://downloads.f5.com) to a preferred location.
6. Import either the latest BIG-IP system hotfix image file, if available, or the new version software
upgrade image file to each device.
Option Description
Import the 1. On the Main menu, click System > Software Management > Hotfix List >
latest BIG-IP Import.
system hotfix 2. Click Browse, locate and click the SIG file (Hotfix-BIGIP-hf-
image and xx.x.x.x.x.xxxx.HFx.iso.384.sig), click Open, and click Import.
SIG file
3. Click Browse, locate and click the image file, click Open, and click Import.
4. When the hotfix image file completes uploading to the BIG-IP device, click
OK. A link to the image file appears in the Software Image list.
Import the 1. On the Main menu, click System > Software Management > Image List >
new version Import.
software 2. Click Browse, locate and click the SIG file (BIGIP-13.x.x.x.x.xxxx.iso.384.sig),
image and click Open, and click Import.
SIG file
3. Click Browse, locate and click the upgrade image file, click Open, and click
Import.
Note: BIG-IP version 13.x, and later, provides upgrade and recovery image
files. An upgrade image file (for example, BIGIP-13.x.x.x.x.xxx.iso) omits End
User Diagnostics (EUD) software, which includes tests that report on hardware
components. A recovery image file (for example, BIGIP-
RECOVERY-13.x.x.x.x.xxx.iso) includes EUD software.
4. When the software image file completes uploading to the BIG-IP device, click
OK. A link to the image file appears in the Software Image list.
61
Upgrading Version 10.x BIG-IP Active-Active Systems
Option Description
Note: You must use openssl version 1.0.0, or later. Type openssl version
at the command line to determine the version.
The openssl utility verifies the integrity of the software image file and
displays the results.
# openssl dgst -sha384 -verify usr/lib/install/
archive.pubkey.xxxxxxxxx.pem -signature shared/images/
BIGIP-13.x.x.x.x.xxxx.iso.384.sig shared/images/
BIGIP-13.x.x.x.x.xxxx.iso
Verified OK
Use an MD5 • Using a tool or utility that computes an md5 checksum, you can verify the
checksum integrity of the BIG-IP system latest hotfix .iso file or new version .iso
file.
The BIG-IP devices are now prepared to install the latest hotfix or new version software onto Device B
(the active BIG-IP 2 device).
62
BIG-IP Systems: Upgrading Software
Option Description
2. In the Available Images area, select the check box for the hotfix image, and
click Install. The Install Software Hotfix popup screen opens.
3. From the Volume set name list, select the location of the new version
software volume to install the hotfix image, and click Install.
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
Install the new 1. On the Main menu, click System > Software Management > Image List.
version 2. In the Available Images area, select the check box for the new version
software software image, and click Install. The Install Software Image popup screen
opens.
3. From the Volume set name list, select a location to install the image, and
click Install.
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
4. Reboot the device to the location of the installed new version software image.
a) On the Main menu, click System > Software Management > Boot Locations.
b) In the Boot Location list, click the boot location of the installed new version software image.
c) Click Activate.
The BIG-IP device reboots to the new version software boot location.
Note: If the device appears to be taking a long time to reboot, do not cycle the power off and on.
Instead, verify the status of the device by connecting to its serial console port. The device might be
performing firmware upgrades.
The new version software is installed on Device B, with traffic-group-1 and traffic-group-2 in
standby state.
63
Upgrading Version 10.x BIG-IP Active-Active Systems
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
Install the new 1. On the Main menu, click System > Software Management > Image List.
version 2. In the Available Images area, select the check box for the new version
software software image, and click Install. The Install Software Image popup screen
opens.
3. From the Volume set name list, select a location to install the image, and
click Install.
Important: In the Install Status list for the specified location, a progress bar
indicates the status of the installation. Ensure that installation successfully
completes, as indicated by the progress bar, before proceeding.
4. Reboot the BIG-IP device (Device A) to the location of the installed new version software image.
Important: Once Device A reboots, if the BIG-IP system is configured to use a network HSM, you
must reinstall network HSM client software on Device A to ensure that traffic groups using the
network HSM function properly.
a) On the Main menu, click System > Software Management > Boot Locations.
b) In the Boot Location list, click the boot location of the installed new version software image.
c) Click Activate.
The BIG-IP device (Device A) reboots to the new version software boot location with traffic-
group-1 and traffic-group-2 in standby state.
Note: If the device appears to be taking a long time to reboot, do not cycle the power off and on.
Instead, verify the status of the device by connecting to its serial console port. The device might be
performing firmware upgrades.
64
BIG-IP Systems: Upgrading Software
The new version software is now installed on Device A, with traffic-group-1 and traffic-
group-2 in standby state.
65
Upgrading Version 10.x BIG-IP Active-Active Systems
Note: Ensure that all information for the peer device appears correctly and complete.
Implementation result
Your upgrade of the BIG-IP® active-active pair from version 10.x to the new version software is now
complete. The new version software configuration includes a device group with two devices (Device A
and Device B) and two traffic groups (traffic-group-1 and traffic-group-2), with the first
traffic group (traffic-group-1) on one device (Device A) in active state and the second traffic group
(traffic-group-2) on the other device (Device B) in active state.
66
BIG-IP Systems: Upgrading Software
Figure 16: The new version software device group and two traffic groups in active state on
different devices
67
Upgrading Version 10.x BIG-IP Active-Active Systems
68
Legal Notices
Legal notices
Publication Date
This document was published on March 2, 2017.
Publication Number
MAN-0587-01
Copyright
Copyright © 2017, F5 Networks, Inc. All rights reserved.
F5 Networks, Inc. (F5) believes the information it furnishes to be accurate and reliable. However, F5
assumes no responsibility for the use of this information, nor any infringement of patents or other rights
of third parties which may result from its use. No license is granted by implication or otherwise under
any patent, copyright, or other intellectual property right of F5 except as specifically described by
applicable user licenses. F5 reserves the right to change specifications at any time without notice.
Trademarks
For a current list of F5 trademarks and service marks, see http://www.f5.com/about/guidelines-policies/
trademarks.
All other product and company names herein may be trademarks of their respective owners.
Patents
This product may be protected by one or more patents indicated at: https://f5.com/about-us/policies/
patents.
RF Interference Warning
This is a Class A product. In a domestic environment this product may cause radio interference, in which
case the user may be required to take adequate measures.
FCC Compliance
This equipment has been tested and found to comply with the limits for a Class A digital device pursuant
to Part 15 of FCC rules. These limits are designed to provide reasonable protection against harmful
interference when the equipment is operated in a commercial environment. This unit generates, uses, and
can radiate radio frequency energy and, if not installed and used in accordance with the instruction
manual, may cause harmful interference to radio communications. Operation of this equipment in a
Legal Notices
residential area is likely to cause harmful interference, in which case the user, at his own expense, will be
required to take whatever measures may be required to correct the interference.
Any modifications to this device, unless expressly approved by the manufacturer, can void the user's
authority to operate this equipment under part 15 of the FCC rules.
Standards Compliance
This product conforms to the IEC, European Union, ANSI/UL and Canadian CSA standards applicable to
Information Technology products at the time of manufacture.
70
Index
Index
device groups (continued)
11.x software upgrade upgrading Device C system 24
example diagrams 5 device objects
introduction 5 defined 11, 34, 54
overview 5 device trust
12.x software upgrade defined 11, 34, 54
example diagrams 5 devices
introduction 5 about forcing offline 12
overview 5 defined 11, 34, 54
selecting for failover 12, 35, 55
A drives
preparing for upgrade 16, 40, 59
active-active software upgrade
overview 49
results 66 F
task summary 55 failover
active-active system upgrade and traffic groups 12, 35, 55
preparing for 60 failover status
upgrading BIG-IP 1 system 63 of traffic groups 27, 65
upgrading BIG-IP 2 system 62 folders
active-active systems defined 11, 34, 54
upgrading 49
active-standby software upgrade
overview 31 H
preparing BIG-IP system 41
results 46 HA load factor
task summary 35 viewing 27, 65
active-standby systems
upgrading 31 I
availability
during failover 12, 35, 55 implementation results
for software upgrade 28
B
M
BIG-IP system
overview for upgrade 49 migration
preparing for upgrade 16, 17, 40, 41, 59, 60 preparation 37, 38, 56, 57
upgrading active BIG-IP 1 system 44 preparation for APM 36, 56
upgrading Device A system 19 preparing for AAM 13
upgrading Device B system 22 preparing for APM 14
upgrading Device C system 24 preparing for ASM 14
upgrading standby BIG-IP 2 system 43 preparing for Link Controller 15
upgrading to version 11.x 43, 44, 62, 63 preparing for LTM 16
upgrading to version 12.x 43, 44, 62, 63 preparing for PEM 14, 16
BIG-IP system version 11.x upgrade WA preparation 38, 57
verifying 28, 46, 65 WOM preparation 40, 59
BIG-IP system version 12.x upgrade migration preparation
verifying 28, 46, 65 for Global Traffic Manager 15
D R
device availability relative load value
defined 12, 35, 55 viewing 27, 65
device groups results
defined 11, 34, 54 for software upgrade 28
preparing for upgrade 17
upgrading Device A system 19
upgrading Device B system 22
71
Index
S
software upgrade
overview for active-active system 49
preparing for active-active system 60
task summary 13, 27, 65
upgrading BIG-IP 1 system 63
upgrading BIG-IP 2 system 62
software upgrade results 28
standby state
forcing to 27, 65
T
traffic groups
defined 11, 12, 34, 35, 54, 55
for remote devices 27, 65
forcing to standby state 27, 65
maximum number supported 12, 35, 55
viewing list of 27, 65
U
upgrade
for BIG-IP 1 system 63
for BIG-IP 2 system 62
overview for active-active software 49
preparing for active-active system 60
upgrade process
and ASM 14
and two redundant ASM systems 14
for Global Traffic Manager 15
preparing BIG-IP device groups for 17
preparing BIG-IP drives for 16, 40, 59
preparing for AAM 13
preparing for APM 14
preparing for ASM 14
preparing for Link Controller 15
preparing for LTM 16
preparing for PEM 14, 16
upgrading Device A system 19
upgrading Device B system 22
upgrading Device C system 24
upgrading
and ASM 37, 56
and two redundant ASM systems 37, 56
preparation 37, 38, 56, 57
preparation for APM 36, 56
WA preparation 38, 57
WOM preparation 40, 59
V
version 11.x upgrade
preparing BIG-IP modules 13, 36, 56
version 12.x upgrade
preparing BIG-IP modules 13, 36, 56
72