F5Networks / f5-google-gdm-templates

Google Deployment Templates for quickly deploying BIG-IP services in Google Cloud Platform
28 stars 45 forks source link

3-NIC Failover via LB HA Deployment Does Not Set Proper Firewall or Port Lockdown Settings #43

Closed xags closed 4 years ago

xags commented 4 years ago

Do you already have an issue opened with F5 support?

No

Description

When deploying a 3-NIC BYOL n1-standard-8 instances for failover via-lb the DSC group does not get created properly. Upon inspection the required port to from the trust (TCP/443) is not setup in the port lockdown setting for the internal (interface 1.3) selfIP. This port is also missing in the gFirewall console. Adding both and manually forming the trust works as expected.

Template

f5-existing-stack-same-net-cluster-byol-3nic-bigip.yaml

Severity Level

Severity: 1