Skip to content
CBT Nuggets
DemoBook a Demo

Configuring Health Monitors

This skill focuses on configuring health monitors within the BIG-IP environment to ensure the health and availability of member servers. It covers various types of health monitors, including address checks, service checks, and content checks, and explains how to apply these monitors to nodes, pools, and pool members. The skill also highlights the importance of understanding health icons and the impact of network traffic on monitoring. Practical examples and step-by-step instructions are provided to demonstrate the configuration and testing of different health monitors.

Full skill from F5CAB3. Preview the IT training 23,000+ organizations trust.

46m

Skill 1 of 3 in F5CAB3

Introduction

Within our environment it's very important that we know the health status of our member servers. If they are down or unresponsive this will affect our users experience and can cause errors and delays which we want to avoid. Let's take some time to learn about the health monitoring options available within the Big-IP. Then we'll set some up and see our health monitoring in action.

Health Monitors

Health monitors can track the health of our member servers and make decisions based on their health. Let's take a look at health icons used within the Big-IP and where we can apply these health monitors.

Knowledge Check

Match the health icon with it's health status.

This interactive assessment is available in the full learning experience.

Want to answer questions like this yourself?
with no purchase required. Already have an account?

Types of Health Monitors

Now it's time to discuss the various types of health monitors available within the Big-IP and what each of them does. We'll discuss how they work and when you might want to use one over another.

Knowledge Check

Match the health monitor with it's functionality.

This interactive assessment is available in the full learning experience.

Want to answer questions like this yourself?
with no purchase required. Already have an account?

Configuring a Basic Health Monitor

It's time to jump onto the Big-IP and configure a couple different health monitors. We're going to compare the ICMP and HTTP monitors to see how they work differently.

Knowledge Check

ICMP health monitors are great for checking to see if a service such as HTTPS is up and running.

Monitoring Content Health

Just monitoring whether a service is running or not isn't always the best option. Sometimes we need to ensure the content being served up by a service is accurate. For example, we may want to verify content to make sure a back-end database is connected to our application. So let's see how to set up content health monitoring.

Knowledge Check

When creating custom monitors it's common practice to edit the default system monitors.

Health of Members Versus Nodes

Members and nodes are two different types of objects within the Big-IP. This is very important to remember when configuring health monitors. Let's take a look at the difference between the two when it comes to health monitors.

Knowledge Check

Members automatically inherit health monitors configured on their parent pool.

Validation

  • In this skill we setup a custom health monitor for our HTTPS pool. I would like for you to create a custom health monitor named "APP1-HTTPS" using the monitor type of HTTPS. You'll also want to get creative and use something other than "Congratulations!" in the Receive String portion of the custom monitor.
  • If you need some assistance refer to the "Monitoring Content Health" nugget above.
  • I've also created a solution video below in case you want to check your work.

Knowledge Check

How comfortable are you with setting up health monitors on the Big-IP?

This interactive assessment is available in the full learning experience.

Want to answer questions like this yourself?
with no purchase required. Already have an account?

View Transcript

Health Monitors

0:00<v Instructor>All right, it's time</v>

0:01to cover health monitors,

0:02that's what we're talking about today.

0:04So, the big question is, what are health monitors?

0:07Well, I'm sure you could take a wild guess

0:10and probably get it right

0:12because we're wanting to monitor the health of something.

0:15So, on our BIG-IP,

0:19well, we set up a virtual server that runs on there,

0:23and then what do we do?

0:24We assign a pool to that virtual server

0:27and that pool distributes connections

0:31over to our members of that pool.

0:35So, we've got all these members over here,

0:38and I have a question for you,

0:39how does the BIG-IP know

0:42whether or not that these members over here are up or down?

0:47Because if they're all down,

0:49when it forwards those connections to them,

0:51our users are gonna get some type of error,

0:54and that's something that we want to avoid.

0:57So, we need a way for the BIG-IP to know

1:00if these members over here are up or down,

1:04and that's where health monitors come into play,

1:07as you can imagine.

1:09And there's lots of different types of health monitors,

1:11and we're gonna get into that.

1:12But first of all, we're gonna start with a table.

1:15That's right, these are a table of health symbols.

1:18So, when we go into our BIG-IP

1:21and we're looking at pools

1:23and we're looking at members,

1:25we're going to see these symbols here,

1:28so we really need to understand what each of these means.

1:32We're starting off with the green circle,

1:34and green means go, it means good, right?

1:37Absolutely, a green circle means that a member

1:42or a pool is healthy and available.

1:47So, that's a good thing.

1:48Ooh, but then we get into the red,

1:49red's usually not a good thing.

1:51And here is a red diamond,

1:53and this means that a pool or member is unhealthy

1:59and, as you could imagine, unavailable.

2:03All right, that makes sense,

2:04but then I get this blue square over here,

2:06what could that be?

2:08Well, if it's a blue square, it represents unknown.

2:12And generally, this is when we first set something up

2:15and we've connected some members,

2:18but we don't have any health monitors.

2:21So, it is basically unknown

2:23if this is up or down at this point.

2:26Okay, so that's a blue square,

2:27then we come into a yellow triangle,

2:29and that generally means like a caution

2:31when we see that yellow.

2:33And that's really what this is.

2:35This is stating that a member

2:37is unavailable for some reason.

2:41And this for some reason is, I wanna state here,

2:44other than being offline.

2:48Because if it's offline, you're gonna get a red triangle.

2:52This usually means that it's unavailable

2:54because it's reached its connection limit

2:57or something along those lines.

2:59So, that is our yellow triangle

3:01kind of our caution, if you will.

3:03Then, we have a black circle,

3:06and this means that an active member

3:11has been disabled by the admin.

3:13So, an admin has disabled an active member,

3:18and this may be done so they can take it offline

3:21to do maintenance, or they're doing testing,

3:23or something along those lines.

3:25Then, we have a black triangle,

3:27and this means that an admin

3:29has disabled an inactive member.

3:34So, if a member is unactive or unavailable

3:37and we just go in there

3:38and manually as an admin disable it,

3:41well, then that's where we're gonna get that black triangle.

3:44Then, we come down to the different gray icons,

3:47and this simply indicates that this object is unavailable

3:53due to some sort of reliance on a disabled object.

3:58So, maybe this is tied to another member

4:01or something along those lines

4:03and it's unavailable because something else

4:06has been disabled which kind of impacts it,

4:08so this is kind of like a secondary impact.

4:12So, when one thing gets disabled,

4:14it kind of snowballs into a second object,

4:17and that's where we would see these gray icons.

4:20So, it's very important to remember what these are,

4:23especially when it comes to our healthy

4:25and our unhealthy and our unknown.

4:28Those are the three that you're gonna see the most often

4:31and it's very important.

4:32But we also, of course, need to be aware

4:34of these others as well

4:35because you're gonna run into them from time to time.

4:39All right, let's talk about our health monitor settings,

4:41so it says you can apply health monitors to various things.

4:46So, when it comes to these health monitors,

4:48we can apply them to four things.

4:49Number one is a node.

4:51Now, if you think back to a node,

4:54it is an IP address as the object that is a node.

4:59So, we can apply health monitors to nodes.

5:02We can also apply health monitors to pools.

5:05All right, that's pretty cool.

5:07And be aware of this,

5:10when you apply a health monitor to a pool,

5:14it's actually automatically inherited

5:16by the members of that pool.

5:20So, those members will inherit those health monitors,

5:25and we'll see that when we get into the BIG-IP.

5:28And then, we can also assign health monitors

5:30to pool members directly,

5:32and we'll see that as well when we get in there

5:34and start playing around with our health monitors.

5:36And then lastly, our links,

5:40and these are outside of the LTM,

5:42they're not within our local traffic monitor.

5:44This comes to when we're using our BIG-IP DNS

5:49and the link controller features.

5:52So, these links are connections elsewhere,

5:55and what we're doing is monitoring those connections

5:58and whether they are up or down,

6:00and that's where that health monitor comes into play.

6:02So, those are the four places

6:04that you can apply a health monitor to,

6:06our nodes, our pools, our pool members, and links.

6:11All right, super,

6:13so let's take a look at some health monitor settings here.

6:17Now, the first term we're gonna look at is interval,

6:20and this is the number of seconds between each test.

6:25And the default here is five seconds.

6:30So, when we're talking about our health monitors,

6:32we've got a monitor set up.

6:33We'll just put an M here for a monitor.

6:35Then, we've got our pool members over here, right there,

6:39and/or a pool, whatever we're monitoring.

6:41But the idea is this monitor is gonna go out

6:44and try to connect to or communicate

6:46with each of these members every five seconds by default.

6:51And it just depends

6:52on what type of health monitor you're using

6:54as to what type of communications are being done.

6:57And we're gonna dig into that,

6:58so don't get too hung up on that just yet.

7:00All right, so that's our interval,

7:02then we have timeout.

7:06And a timeout is the number of seconds

7:08before device is marked unavailable.

7:12Okay, and the default

7:14is three times the interval plus one second.

7:19So, if that's being set,

7:21our default interval is five seconds

7:26and that means that our default timeout

7:30is going to be what?

7:32Let's think about this.

7:33So, our interval is five seconds.

7:36Okay, that's our default.

7:37And our default timeout

7:39is three times the interval plus one second,

7:42so that would be 3 times 5 seconds plus 1 second,

7:47which would be, that's right, 16 seconds.

7:50That is your default timeout within the BIG-IP.

7:56Now, you can change this,

7:57you can go into these monitors

7:59and you can definitely change these values here,

8:03our interval and our timeout.

8:05And you can do that, have at it if you want to,

8:08but I'm just letting you know that these are the defaults.

8:11All right, that wraps up our intro to the health monitors.

8:14In the next nugget, we're gonna jump in

8:15and start talking about different types of health monitors.

Types of Health Monitors

0:00<v Instructor>Now it's time to start to analyze</v>

0:03the different types of health monitors

0:05that we have available to us.

0:07And I want you to take a look over here on the right,

0:08and this is a screenshot of our monitors list

0:12within the big IP, and this is your default monitors.

0:15And we see several here like gateway_icmp, http.

0:20There's some http with the head keyword in there, https,

0:24icmp, inband.

0:25But what do all these things mean?

0:28Well, we're gonna talk about that right now.

0:31Now, the first one we're talking about

0:33is something called an address check monitor.

0:36Now, the key word here is address.

0:40And that's because our big IP is going to go out

0:43and check the IP address

0:48of each of our member servers.

0:50And it's gonna do so in a couple different ways.

0:53Number one is using ping, okay?

0:56And that's where we're going to use an ICMP monitor

1:01or the Gateway ICMP monitor.

1:04But it's basically just going to go out

1:06and ping a member server and see if it responds.

1:09If it responds, then it is up.

1:12If it does not within that 16 seconds,

1:14then it will be marked as down.

1:16Now, there's another way you can do that,

1:18and you can do something called a TCP Echo,

1:22and a TCP Echo is still just connecting to the host

1:27to see if it's alive.

1:29It's really not checking a service or anything like that.

1:31So, really, we're just checking to see do we get a response

1:34or do we not get a response?

1:36That's what we're checking for.

1:38Now, the thing is, remember, we are checking

1:41the hosts, whether it's up or down.

1:42We are not checking the service.

1:48And what I mean by that is if we're running

1:49http for a web server, we're not checking

1:52to see if http is actually up and running and responding.

1:56We're just looking to see if the operating system

1:58of that host is up and running and networking is functional.

2:01That's all we're doing.

2:02And we're gonna see how that plays out

2:04when we get into our labs.

2:06The next one is known as a service check monitor.

2:09Now, this is different.

2:10This is where we're checking the keyword here, service.

2:14We're checking to see if that service is up or down.

2:17And we're just gonna reference an HTTP service

2:19'cause it's a web server that we're dealing with here.

2:21So, it initiates a connection to a specific service

2:25to make sure that it's running.

2:27And it could be, again, HTTP.

2:28It could be DNS or STP or SSH, lots of different services.

2:32So what it does, how this works.

2:34We know that when we're dealing with the TCP communications,

2:37there are three steps to this, right?

2:39We've got the initiator that sends a SYN

2:42to our target over here,

2:44and the target will respond with a SYN/ACK,

2:48and then the customer will respond finally with an ACK.

2:52And at that point, we have an active session,

2:54and data can flow back and forth.

2:56Well, the big IP does this a little different

2:59because we don't want to establish a session

3:02every five seconds when we're testing.

3:04That would be absolutely a waste of resources.

3:07So the way this works, the big IP, we'll go out.

3:10Let's say we're using server C here.

3:12We'll go out and send a SYN to our server

3:17to see if it's awake, okay?

3:18And that the web service on port 80, our HTTP service,

3:22is running, and that server's gonna respond with a SYN/ACK.

3:26And that's pretty normal so far

3:28when we look at TCP communications over here.

3:31But then things change.

3:33What's gonna happen is the big IP is going to respond here

3:37with a reset to reset the connection.

3:40And that way, we do not establish a session

3:47because we don't wanna do that.

3:48When you do that, it opens up and dedicates resources

3:51for communications, which would use up resources

3:54on both of our devices here.

3:55And we don't wanna do that.

3:56We simply wanna make sure we get a response here,

3:59and then we're gonna reset that connection.

4:01So, that's how a service check monitor works.

4:03It verifies that a service is running and responding.

4:07However, what it does not check is the content.

4:12So, that service could be up and running,

4:15but it could be handing out incorrect information,

4:18maybe if there was a problem with a config file

4:20or something like that along those lines.

4:22Now, when we're dealing with this,

4:23let's talk about some names of the types of monitors

4:26we're dealing with.

4:27Generally, these are going to be HTTP, HTTP2.

4:33We're gonna see HTTPS, HTTPS2 and three,

4:39and so on and so forth.

4:41So, when we're seeing these protocol names,

4:43those we should associate with a service check monitor.

4:48All right, super.

4:48So those are our service checks. Onto the next.

4:51Now, this is different. This is a content check monitor.

4:54So here, I'm gonna put content.

4:56That's our keyword, and here's what we're doing.

4:59We are going to, or well, the big IP is going to,

5:03it's gonna go ahead and it's gonna send out a SYN.

5:06All right? Super.

5:07The server's gonna send back our SYN/ACK,

5:10but then, we're not gonna send a reset.

5:14Absolutely not.

5:15What's gonna happen is we're gonna send an ACK, okay?

5:18And then we're going to send an HTTP GET command

5:23to this host by default.

5:26Now, you can change the command if you want to,

5:28but this simply says, get a copy of the webpage.

5:31It's just a web request is all it is.

5:33And then, our server's going to respond with the webpage.

5:39All right, that's great.

5:40And that means that I can then set a key word or phrase,

5:48and this webpage response is going to be analyzed

5:51to see if this key word or phrase

5:54resides in the response from the web server.

5:57So, it could be certain words that are on the webpage,

6:00and it's gonna check for those

6:01to see if they're there or not.

6:03And if they are, well, then it's good. It's up.

6:05That content is good.

6:06Otherwise, it's down. It's not good.

6:08Now, there are no default content check monitors,

6:13so I'm not gonna give you any names or anything, okay?

6:16Because you have to create all of these,

6:18and it's very simple to do.

6:20I'm gonna show you how to do it,

6:21but we're going to use the HTTP or HTTPS

6:26as a template, okay?

6:28So that we're dealing with this.

6:29And then we're gonna configure our HTTP command

6:34and our key words and, or phrases to look for

6:41within that web response.

6:44Now, the thing is, let's jump back real quick.

6:47I'm gonna jump back here to our address check monitor.

6:49And remember, this is where we're dealing with our pings

6:51and our ICMPs.

6:53This creates very little network traffic,

6:59as you can imagine.

7:00It's a simple ping, all right?

7:02So, very little network traffic.

7:04Now, as we get more complex,

7:07such as going to our service check monitor,

7:09this creates a little more network traffic,

7:15but we're not establishing a full session there,

7:18and we're not sending web data back and forth.

7:21Now, as we get to the most complicated,

7:23our content check monitor,

7:25this uses the most network traffic,

7:28or it generates the most network traffic

7:31out of all of our monitors.

7:32So, just keep that in mind.

7:34So if you're looking for something

7:35that wants to make sure a service is running,

7:38but use little bit of network traffic as possible, well,

7:42you're gonna want to use our service check monitor, okay?

7:46But if you're wanting to use the least amount

7:48of network traffic at all, and you don't care about

7:50checking to see if the service is up or not,

7:52well, then we'd go to our address checking monitor.

7:55All right, super. All right, got two more to look at.

7:58And the next one is passive monitor.

8:03Now what this does, it's passive.

8:05It doesn't actually reach out to our member servers

8:09to check to see if they're alive or not.

8:11It doesn't do that.

8:12What it does, it sends a connection to them,

8:15and this is just your standard connections

8:17from our users out here, our consumers.

8:20It goes ahead and it routes those connections to them.

8:23And what it does is it monitors the responses

8:28and the communications at Layer 4.

8:34So, here we're talking about TCP and UDP communications.

8:37It monitors those to see if everything is working properly.

8:42And if it is, then it's up.

8:45If it's not working properly, well, then it's down.

8:49And this is known as an inband monitor,

8:53and that's simply because the monitor is actually

8:56inside the big IP.

8:58It doesn't reach out to communicate with member servers.

9:01So it is inband, and that's known as a passive monitor.

9:03And as you can imagine, this creates no,

9:08big keyword there, no additional network traffic

9:12when it's doing its monitoring

9:13because it's just monitoring normal communications

9:16at Layer 4 to see if things are okay or not.

9:19And we've got our final one here, WMI,

9:21or Windows Management Instrumentation monitor.

9:25Now, the key word is Windows,

9:27because this only works on Windows servers.

9:31That's because WMI is a service that runs

9:35on a Windows server

9:36and it allows connections to be made to it

9:39and it will provide information

9:41such as performance statistics.

9:45And that's exactly what's happening here.

9:48Our host here, our big IP, is reaching out

9:51to a Windows server via WMI,

9:54and it's saying, "Hey, I'd like your statistics."

9:57It's gonna pass it back,

9:58and then the big IP is gonna analyze it,

10:01and it's gonna say, "Oh wow, you are really loaded down.

10:04I should give you less connections."

10:07It's gonna go out and check with this one,

10:08and it's going to respond "Boop, boop, boop, boop,"

10:11via, of course, WMI.

10:13And it's gonna say, "Oh, guess what?

10:15I have very little resources in use,

10:17so send me more connections."

10:20And that's how this works.

10:21Now, you do have to be running WMI on your Windows host,

10:25and it does require a little bit of configuration, okay?

10:28Now, this is a custom type of monitor,

10:33so what you do is you go down and you create a new monitor.

10:37And from the type you're gonna be selecting,

10:39you guessed it, WMI.

10:42So, those are different types of monitors

10:45that we can use within the big IP,

10:47and in the next nugget,

10:48we're gonna start configuring these things.

10:50We're gonna jump into the big IP.

10:51We're gonna get our hands dirty,

10:52and we're gonna monitor anything

10:54and everything that we can come up with, okay?

10:56Sounds like fun. See you there.

Configuring a Basic Health Monitor

0:00<v Instructor>All right, let's get</v>

0:01to configuring some health monitors in our BIG-IP.

0:04Here we are, I've already logged into BIG-IP,

0:06and what I wanna do, I wanna go to Local Traffic,

0:09and then I wanna go to Network Map.

0:10It's gonna open up this new tab here.

0:12And what we see here is our HTTP-APP1 pool

0:16and our HTTPS-APP1 pool and we see a bunch of blue squares.

0:19Now what do the blue squares mean? Anybody?

0:23That's right, unknown because the BIG-IP doesn't know

0:27if these things are up or not.

0:29And we've got a virtual server,

0:31our pool here and our pool members,

0:33it just doesn't know if they're up or down.

0:35We need to fix that.

0:37So I'm gonna jump back over to the BIG-IP, there we go.

0:40And what we're going to do here is we are going

0:45to go down to Monitors here

0:48and we're gonna click on that, and super.

0:51And this is the default monitors that come on your BIG-IP.

0:55Now here's the thing, we do not want to edit these.

0:59That's right, we don't want to edit them.

1:01So what we wanna do is create new ones

1:04when it comes to creating monitors.

1:06Now let's take a look at one though,

1:07just so we can see some defaults.

1:08Let's pick our http.

1:10All right, we're gonna let that load up.

1:12And as we can see here, let me zoom in a little bit.

1:16We wanna come down here under the Configuration.

1:19Our default interval is five seconds,

1:21and we had talked about that.

1:22We talked about our Interval and Timeout,

1:24and our timeout was three times the interval

1:27plus one second.

1:28So then we end up with our default 16 seconds.

1:31Now we also talked about our content health monitors.

1:35So we're checking our content.

1:37And we said we sent a string, which is like an HTTP GET,

1:41and then we receive information back

1:43and we can do some comparison here with a Receive String.

1:48And that's what we're going to do a little later on.

1:51So right now I just wanted to kind of get in here

1:52to show you some of the basics in here.

1:55So now what we're gonna do,

1:56we're gonna go back to our Monitors here.

1:58All right, there they are.

1:59I'm gonna zoom out just a little bit.

2:02Now let's go over to our Pools down here.

2:07There we go, go to our Pool List

2:09and we're gonna pick on our HTTP pool.

2:11So I'm gonna go ahead and click on that, excellent.

2:14And down here at the bottom,

2:16we have Health Monitors and we played

2:18with this a little bit earlier on in a nugget

2:20where we set up one of these real quick

2:22so we could do some testing.

2:23And what we could do here is this is

2:25where we would add a monitor for this pool, all right?

2:29Now remember also,

2:30all of our member servers will inherit the health monitor

2:34of their parent pool.

2:36Keep that in mind.

2:37So let's say we go ahead and start out

2:41by looking at our Availability here.

2:44Now our Availability is a blue square, which is Unknown.

2:47It's enabled, but it's unknown,

2:48and that just means we don't have service checking enabled

2:51or there's no service check results available just yet

2:54and we're gonna fix that.

2:56So we're gonna come in here

2:56and we are going to select our gateway_icmp.

3:01We're gonna add that and we're gonna say Update, all right?

3:05And you see, it still says Unknown,

3:06so we'll give it just a couple of seconds.

3:09I'll go ahead and refresh this.

3:12And now we have our Availability as Available,

3:15green circle, and Enabled.

3:17So the pool is available, excellent.

3:21Now I want to go ahead and click on members over here,

3:24and we see we have a green circle on all of our members.

3:27And if I click on a member,

3:29we can see down here under Health Monitors,

3:32it inherited that gateway_icmp, just like I said it would,

3:36but this is how we can come in

3:37and verify that it actually does.

3:40Now if for some reason,

3:41you wanted to use a different type of monitor

3:44for a certain member, then you can change that.

3:47So we scroll down here

3:48and we look for Health Monitors down here,

3:51and there it is right there.

3:53Now that's because it's set to Advanced.

3:55If I change this to Basic, Health Monitors disappears.

3:58So if you're going down here

3:59and you don't see Health Monitors,

4:00go up and click on Advanced, there you go.

4:03Now what I can do is look at the default,

4:05which is Inherit From Pool, but I can change that.

4:08I can do Member Specific

4:10and I can add my own type of monitor that I want to

4:13for this specific member.

4:15So just because a pool member inherits from its parent pool,

4:19doesn't mean it has to use the same health monitor

4:23as its parent pool.

4:24But I'm gonna put this back to Inherit From Pool.

4:26All right, super.

4:27I'm gonna go ahead and update just

4:28to make sure everything's kosher here.

4:30There we go, super duper.

4:31All right, so we now have an ICMP,

4:34actually a gateway_icmp monitor running

4:39on this pool and its members.

4:41So now I wanna take a look at something.

4:42We're gonna run a test here

4:44and here's what we are going to do.

4:47I'm gonna run over to my Windows here, there we go,

4:51and let's just make sure everything's working as it should

4:54before we make any changes.

4:56So we'll let this open up.

4:58All right, now I'm gonna open an incognito window,

5:01and go ahead and access our servers.

5:04There we go, that's Server 1.

5:06Let's try another one, and Server 2.

5:09So it looks like it's working fine, excellent.

5:11So now I'm gonna go back to my BIG-IP

5:13and I'm gonna go back to the Properties of the pool here.

5:18We see we have our gateway_icmp

5:24monitor enabled and it's working 'cause it's available here.

5:27So I'm gonna go back to my Members real quick.

5:29Now what I wanna do is run a test.

5:32Now we're using ICMP to monitor these hosts.

5:36So what I'm gonna do is disable two of them right there.

5:39Super, and that is a black circle.

5:41So it means they've been disabled

5:43and they were active members that were disabled by an admin.

5:46That's what that black circle means,

5:47but I still have a green one here, okay, my Server 1.

5:50So now I'm gonna go over to Server 1.

5:52Let's see, there it is, F5-SVR-1.

5:54I'm gonna open this up and I'm gonna run a command here.

5:57And this command is /opt/bitnami/ctlscript.sh,

6:09and I put stop right there, stop.

6:12So what I did was stop the web services

6:14from running on this host.

6:16However, it will still respond to a ping.

6:19So if I go over here now back to my F5,

6:23remember, I'm pinging this, so if I do a refresh here,

6:25I want to, let's see here, go up and refresh this.

6:32I'm still green and I'm still able to ping that host.

6:35But remember, I turned the web service off.

6:37So what does that mean is gonna happen?

6:39Well, let's go to our page. Oh, "Site cannot be reached."

6:42Let's open an incognito window, try it again.

6:47"Site cannot be reached."

6:49Now here's what I'm trying to make a point about.

6:53When you're using ICMP to monitor application hosts,

6:58it only is checking the networking.

7:01So here, the networking's up.

7:02It thinks this host is up and just ready

7:05to take all the connections you can send to it.

7:08But in reality, the web service isn't running.

7:11So this is not a good monitor

7:14for an application host, okay?

7:16We really wanna monitor the service.

7:19And so now let's go back over.

7:20Actually, I'm gonna go ahead and re-enable these two.

7:25There we go, and now if I go back to my Windows machine,

7:27this should work.

7:29I should just get Server 2 or 3, and I get Server 2.

7:33Now I wanna go over here

7:34and I'm gonna hit the up arrow key on my Server 1

7:37and I'm gonna change that stop to start.

7:41There we go, now I started the services back, all right.

7:44So now what I want to do is go back over here

7:47and we're gonna change the monitors, okay?

7:50So what I'm gonna go back is to the pool Properties,

7:53and I'm gonna take this gateway_icmp.

7:55I'm gonna put it back over there.

7:57Now what I wanna do is I wanna grab an http monitor,

8:00put it over here, and go ahead and Update.

8:04Right now, we see our status is Unknown.

8:09So what we're gonna do is give that a couple seconds

8:11and we'll go ahead and refresh this.

8:14And now we show Available Enabled.

8:16All right, super, now let's go to Members,

8:19and we're gonna do the same thing again.

8:21I'm gonna go to here and here and disable those two.

8:26All right, they're disabled,

8:27but I still have this one up and running.

8:29So let's go make sure things are still working as it should.

8:31I should only get Server 1 at this point.

8:34Let's go ahead and Enter, there we go.

8:36Server 1, close it out, grab another incognito.

8:40Go there and Server 1 again.

8:42That's 'cause Server 1's the only one running.

8:44But if I go back to my Server 1 now

8:47and I hit the up arrow key twice

8:49so that I'm stopping that service, hit stop in 16 seconds.

8:54Over here on the BIG-IP,

8:56and actually I can come over here now to my network monitor

9:00and I can refresh the network monitor.

9:02And these are my two disabled servers over here.

9:05So let me zoom in so it's a little easier to see.

9:10There we go, so I have my two disabled,

9:13but I still have a green one over here.

9:14That's 'cause I have to wait about 16 seconds

9:16for that to go off.

9:17Let me hit this again.

9:19Now we see that this has gone to a red diamond,

9:23which means it's unavailable and offline.

9:26And my virtual server and my app pool have gone gray,

9:30which means that they're unavailable

9:32because of something they're relying on,

9:34which (laughs) are the pool members.

9:37And if I go over to my Windows host back here

9:40and I open an incognito window,

9:41what do you think is gonna happen

9:42when I try to go to the server?

9:45That's right, I'm gonna get an error

9:46because that web service isn't running.

9:48Aha, and it's in this instance,

9:52it'll be really great if I had configured a fallback host

9:55that we had talked about previously

9:56because now I would get a message saying,

9:58"Hey, we're having technical difficulties, check back soon."

10:01So what we're gonna do to fix this,

10:03we're gonna bring our web service back up over here.

10:04I'm gonna hit the up arrow twice to go back to our start.

10:08I'm gonna hit Enter.

10:10Now that has started,

10:11if I go back to my monitor here and I wait 16 seconds,

10:15well, these are gonna come back up.

10:17Now my bottom two,

10:18Server 2 and 3 are still gonna be black

10:19because I had disabled those manually.

10:21But this diamond's gonna go away

10:22and it's gonna turn into a green circle

10:24along with the green circles

10:25up at my virtual server and my pool.

10:27So let's go ahead and refresh that and see it happen.

10:31And there it goes, absolutely.

10:32Now if I go back to my Windows host, there we go,

10:35and I go ahead and hit this again,

10:37I should get my Server 1.

10:38And there it goes, absolutely.

10:40So that is why, I'm gonna go back here one more time.

10:43I'm go ahead and re-enable these.

10:45So don't forget about 'em, there we go.

10:47That's why it's very important to remember the difference

10:50between an ICMP monitor and a service monitor.

10:53ICMP is network only, service focuses on your service.

10:57If you're running web app servers

11:00or some type of service server, then yeah,

11:02you need to be using a service

11:04if there's one available in here that matches it

11:06so that you can make sure your service is up and running.

11:10All right, that wraps up our first setup

11:13on some health monitors dealing with ICMP

11:16and service-specific monitors.

11:18Now in the next nugget,

11:20we're going to set up a content health monitor,

11:24and that's really cool, so I'll see you there shortly.

Monitoring Content Health

0:00<v Instructor>All right, here we are on our BIG-IP,</v>

0:02and now we're gonna set up a content health monitor.

0:06So this is where we're gonna check the specific content

0:08that's being served up to us by a server

0:10to make sure it matches a keyword or string.

0:13So let's start by going into our pools, there we go.

0:16We're gonna look at our HTTP pool,

0:18that's the one we've been working on.

0:20And I'm gonna go down here and remove the health monitor,

0:23I don't want any on there at this point in time.

0:25Go ahead and update that.

0:27All right, super.

0:28Now, here's what we're gonna do.

0:30We need to create a new monitor.

0:31So let's go down to our monitors, click on that, super.

0:35And we're gonna scroll over to the side because again,

0:37we're not gonna change these default monitors.

0:39I'm gonna go over here and click create.

0:41Excellent, scroll back over. And I'm gonna give it a name,

0:44I'm gonna call this APP1-Content-Monitor, excellent.

0:51The type is going to be HTTP.

0:55And there we go, super.

0:57It brought me into the big page here,

0:59and it is an HTTP Monitor, there's my name,

1:02the parent monitor is HTTP, that's fine.

1:04Now the send string, I just want a simple HTTP get,

1:07which is just gonna pull the webpage, that's perfect.

1:10In my receive string, I need to put something in here

1:14that lets me know if a server is providing me

1:18with the correct content or not.

1:21So how are we gonna do that?

1:22Well, let's go over here to our ESX host

1:25and let's take a look at one of these pages.

1:27Now, what on this page could we use

1:31to check to make sure this page loaded correctly?

1:34So we want this to be the same across all of our servers,

1:38and I'll show you why.

1:39Let's say we've used the word Server 1.

1:42Okay, so now I'm gonna go over here

1:45and I'm gonna put in here simply Server 1.

1:49All right, go down here and click finished.

1:54All right, now I have my APP1-Content-Monitor,

1:57health monitor.

1:58So now I'm gonna go to my pools, go to my pool list,

2:02select my HTTP pool right here.

2:06Excellent.

2:07Now under my health monitors, I want that APP1 right there.

2:11There we go.

2:12And update, super.

2:16Now, oh, jumped right into available and enabled,

2:19the pool is enabled.

2:20Super, let's go to members.

2:21Oh, whoa, what's going on here? Interesting.

2:24I see a green and two blue,

2:26maybe I just need to wait a minute.

2:28Let me go ahead and click around.

2:30Let's go to policies, let's go back to pools

2:33and back to our HTTP.

2:35Okay, we're green, go back to members

2:37and oh, now look what happened.

2:41I have a green here, but I have two reds.

2:43It means they're unhealthy and unavailable.

2:46And that means if I go over to my Windows host,

2:49then I should only get Server 1, Server 1, Server 1.

2:54Let's close that out.

2:55New incognito.

2:57Server 1, yep, Server 1 again, Server 1.

3:00So interesting, and if I go to my network map over here,

3:03let me refresh this.

3:06It shows that in my HTTP pool only Server 1 is available.

3:09The others aren't, but they should be, but they're not,

3:13and here's why.

3:15If I go back over here and I go to my monitors,

3:19I go to my APP1-Content-Monitor, I put Server 1 in here.

3:23Well, that only applies to my Server 1

3:26because Server 2's website says Server 2,

3:28Server 3's websites says Server 3.

3:30I need to put something in here that's the same

3:32across all of the member servers' webpages,

3:36which would be, let's try, congratulations.

3:40Alright, let's put that in there.

3:41Congratulations!

3:45Now I'm gonna scroll down, hit update.

3:48All right, super, now let's go back to our pools,

3:52go back to our pool over here, go back to our members,

3:56and they're all green.

3:58So if I go to my network map and I do a refresh,

4:02they're all green.

4:03So now if I go back to my Windows and I hit refresh,

4:07am I gonna continue to get Server 1?

4:08Nope, I just went to Server 2 and Server 2 and Server 2.

4:13You see, that is key.

4:15When we're monitoring the health of our content,

4:18we need to make sure that that content

4:20is the same across all of our member servers.

4:23So you can't rely on something

4:24that's unique on each member server,

4:26that is a very key lesson here, because if you do,

4:29it's gonna cause you some big old headaches.

4:32So now we have three healthy hosts

4:34and we have a nice healthy pool,

4:36and we're checking for valid content.

4:39That's exactly what we want to do.

4:42So that wraps up this nugget,

4:44and in the next we're gonna talk about the difference

4:46when we're setting up health monitors

4:48between members versus nodes.

Health of Members Versus Nodes

0:00<v Instructor>All right, now it's time to talk</v>

0:01about the difference between nodes and members

0:06when it comes to health monitors.

0:08So I'll tell you what, let's start with our Pool,

0:09let's go to a Pool List.

0:11We'll select our HTTP Pool because it's nice and happy.

0:15Go to Members, excellent,

0:17all of our members here are happy.

0:20Now, quick reminder, remember a member is an IP address

0:23followed by a port number like 80 right here.

0:26For HTTP, that is a member.

0:28A node is only the IP address.

0:32They are two different objects within the BIG-IP.

0:36So let's click on one of these members already

0:37'cause this is nice and green and happy.

0:39So let's click in there.

0:40Super, we got that loaded up,

0:43and down here, Availability is Available.

0:45Enabled health monitors,

0:47we're using our APP1-Content-Monitor, all is good.

0:49However, do you see a blue square in there?

0:51Because I sure do.

0:52That's because this is the Parent Node.

0:55This is the IP address of our member

0:58and it is showing blue square.

1:00But, but wait, I had set up a health monitor.

1:03Why is it not monitoring my node?

1:06Well that's because we set up a health monitor earlier

1:08for members.

1:10We need to do the same thing for our nodes

1:12if we want to monitor our nodes.

1:14So we're gonna do that by coming down here to Nodes.

1:17click on our Node List, have our three nodes,

1:19and of course, they're all blue squares.

1:22Now there's a couple different ways we can go

1:23about doing this.

1:24Number one, we can come up to the top.

1:26We got Default Monitor up here.

1:27Let's go ahead and click on that, there we go, super.

1:31And I can come in here

1:33and select a basic monitor and I'm gonna do that.

1:35I'm gonna say icmp just 'cause I want a simple ping

1:38because I'm monitoring a node, which is an IP address.

1:42I just wanna know if that IP is up or not.

1:44I'm not monitoring a service

1:45because a service is part of a member.

1:48All right, super, so I'm gonna say Update.

1:51Hey, there we go, all right, super.

1:53Let's go back to our Node List now.

1:55And you'll see our nodes are no longer a blue square,

1:57but a green circle, meaning they are up in fantabulous.

2:01All right, but that's not the only way we can do this.

2:03We can do this another way.

2:05We can click on an individual node here

2:06and let's just go into the server one here.

2:09All right, super.

2:11And here we see our availability is green, we're good to go.

2:14Our health monitor is icmp here.

2:17And if we scroll to the bottom, we see Health Monitors,

2:21and this is set to Node Default.

2:23So it's gonna be whatever the default setting is

2:26that we just set for the nodes.

2:28But I can go in here and say Node Specific if I want

2:31and check one of these others,

2:33I can use something like SNMP or gateway_icmp.

2:37I can do those if I want or I can say None.

2:41Now if I say None and do an Update,

2:42what do you think's gonna happen?

2:44That's right, we're gonna get that blue square

2:46just like that again and we want to avoid that.

2:49So let's go ahead and we'll just leave it at Node Default

2:52for now and go ahead and Update.

2:54And it's checking the Health Monitor, that's pretty cool,

2:56a little clock.

2:58There it goes and we'll let it refresh here

3:02and we'll click off of there, we'll go to Pools,

3:04and then back to Nodes and there we go.

3:08Our node is healthy again with icmp.

3:11So again, if we go back to Nodes,

3:13let's go back to our Nodes List there.

3:15You can set your Default Monitor up here at the top,

3:17or you can go into individual nodes

3:19and set them there if you would like.

3:21But either way we should think

3:23about setting up health monitors at the node level,

3:26so we can monitor those as well.

3:29All right, super, that wraps up our health

3:32of members versus nodes.

Validation

0:00<v ->Alright, for the skill validation, you have been asked</v>

0:02to set up a custom health monitor for our

0:05HTTPS pool.

0:08Alright, super.

0:09So what we're supposed to do is go in

0:11and create a custom health monitor named app one dash

0:14HTTPS, using the HTTPS type of monitor.

0:18Alright, super.

0:19And use something other than the word congratulations.

0:22So let's go ahead and do this.

0:23So let's go ahead and take a look at our HTTPS.

0:25We can see here that it is a blue square, so we know

0:29that it's unknown at this point.

0:31So we need to create a custom monitor.

0:32And the way we do that, is come down to our monitors,

0:35click on that, and we scroll to the right

0:38and we select create.

0:40And it said here, we're supposed to use the name.

0:43Let's put this in here, H, app one dash HTTPS.

0:48All right, super, and the type is supposed to be HTTPS.

0:53All right, that's easy enough, there we go.

0:55And the receive string is what we have to change

0:58to do a content check.

1:00So we need to put something in here

1:01that resides on all of our webpages.

1:03So let's go back over to our Windows host

1:05and I don't need that.

1:07So let's close this out there.

1:09Alright, so what on here could I use to check to make sure

1:14that this webpage loaded correctly?

1:16Well, I could basically just copy this, how about that?

1:19Let's just do that, but I'm not gonna be able

1:22to copy and paste it over there.

1:23So let's do this.

1:24It says you are now running NGINX open source

1:26packaged by Bitnami.

1:28So let's, let's use this, NGINX,

1:30open source packaged by Bitnami.

1:33NGINX open source.

1:35Alright, so we're gonna go in here, NGINX.

1:38Oh, I should check to see if it's capitalized

1:40because that may, open source packaged by Bitnami.

1:43Okay, open source, packaged by Bitnami.

1:49There we go, that should work.

1:51All right, so now let's go ahead and scroll to the bottom

1:54and say finished.

1:57Now I have my app one HTTPS health monitor, super.

2:01So let's go now to our pools.

2:04Go to our pool list,

2:05'cause I wanted to apply this to my HTTPS pool.

2:08We're gonna go here, under our health monitors,

2:11we're gonna select our app one HTTPS, slide it on over

2:13and click update.

2:15All right, super.

2:17Now we need to go ahead

2:19and click on our members up here and lookie there.

2:22They're all green, so that is good.

2:25Lemme go back to properties and make sure

2:26it has come up as well.

2:27Yep, our pool available enabled this pool is enabled, super.

2:31Members, now let's go to make sure it works.

2:34And here I'm going to change this to HTTPS.

2:38So here, https colon slash slash enter and there it goes,

2:44server two.

2:45And try it again, still server two.

2:49Let me open up a new incognito window just to make sure.

2:53Here we go, new incognito.

2:56And I'm gonna go HTTPS, colon 172 dot 16 dot 101 dot 11.

3:00And there we go.

3:02Not private, yeah, there we go.

3:03Advanced, proceed, there it goes, and server two.

3:07So yes, it is absolutely working.

3:10Alright, congratulations on setting up your custom

3:13HTTPS content monitor.

3:16I hope this has been informative for you

3:18and I'd like to thank you for viewing.

Team training path

Turn this skill into assignable team training

This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.

What's next?

Ready to keep going?

For your team

Bring this training to your team

See how CBT Nuggets helps IT teams close skills gaps, hit compliance targets, and prove training ROI.

Book a Demo
Just need F5CAB3?

Learning on your own? Browse individual plans ($49/month, billed annually)

Not ready to buy?
with no purchase required. Already have an account?
Book a Demo