Manual Chapter :
Common elements for tunnel tasks
Applies To:
Show VersionsBIG-IP AAM
- 15.1.9, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0, 14.1.5, 14.1.4, 14.1.3, 14.1.2, 14.1.0
BIG-IP APM
- 17.0.0, 16.1.4, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.9, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0, 14.1.5, 14.1.4, 14.1.3, 14.1.2, 14.1.0
BIG-IP Link Controller
- 17.0.0, 16.1.4, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.9, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0, 14.1.5, 14.1.4, 14.1.3, 14.1.2, 14.1.0
BIG-IP LTM
- 17.0.0, 16.1.4, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.9, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0, 14.1.5, 14.1.4, 14.1.3, 14.1.2, 14.1.0
BIG-IP AFM
- 17.0.0, 16.1.4, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.9, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0, 14.1.5, 14.1.4, 14.1.3, 14.1.2, 14.1.0
BIG-IP ASM
- 17.0.0, 16.1.4, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.9, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0, 14.1.5, 14.1.4, 14.1.3, 14.1.2, 14.1.0
Common elements for tunnel tasks
- On the Main tab, clickor .The New Tunnel screen opens.
- On the Main tab, click.The New Tunnel screen opens.
- On the Main tab, click, orThe New Tunnel screen opens.
- On the Main tab, clickThe New Tunnel screen opens.
- In theNamefield, type a unique name for the tunnel.
- From theProfilelist, select the type that corresponds to the encapsulation protocol you want to use.The selectionipipis the same asip4ip4, butipipis compatible with configurations from an earlier release.
- From theProfilelist, select the tunnel profile you created for network virtualization.This selection must be a profile based on either thegreorvxlanparent profile, depending on your virtualized network environment.
- From theProfilelist, selectfec.This setting tells the system which tunnel profile to use. The system-suppliedfecprofile is configured for adaptive behavior for the number of source and repair packets. If you create a new FEC profile with custom settings, the profile then appears in this list, where you can select it.
- From theProfilelist, selectvxlan.This setting tells the system which tunnel profile to use. The system-supplied VXLAN profile specifies port4789. To change the port number, you can create a new VXLAN profile, which then appears in this list.
- From theProfilelist, selectvxlan-multipoint.
- From theProfilelist, selectvxlan-gpe.This setting tells the system which tunnel profile to use. The system-suppliedvxlan-gpeprofile specifies port4790. To change the port number, you can create a new VXLAN-GPE profile, which then appears in this list.
- From theProfilelist, selectnvgre.This setting tells the system which tunnel profile to use. The system-supplied NVGRE profile is adequate. To change the settings, you can create a new NVGRE profile, which then appears in this list.
- From theProfilelist, selectipiporgre.Theipipselection can also be one of the IPIP variations:ip4ip4,ip4ip6,ip6ip4, orip6ip6.
- From theProfilelist, selectdslite.
- From theProfilelist, selectip4ip6.
- From theProfilelist, selectIPsec.
- From theProfilelist, selectv6rd.
- From theProfilelist, selectlw4o6or the lw4o6 profile you created previously.
- From theProfilelist, select the MAP profile you created previously.
- In theLocal Addressfield, type the IP address of the BIG-IP system.
- In theLocal Addressfield, type the IP address of the local endpoint.If you are using an iSession connection, use the same IP address you used for the iSession local endpoint. Otherwise, use any self IP address on the BIG-IP system.
- In theLocal Addressfield, type the IPv6 address of the local BIG-IP device.
- In theLocal Addressfield, type the IPv4 address of the BIG-IP device you are configuring.
- In theLocal Addressfield, type0.0.0.0for an IPv4 network or::for an IPv6 network.
- In theLocal Addressfield, type the self IP address of the VLAN through which the remote hypervisor is reachable.
- In theLocal Addressfield, type the floating IP address to be used for redundancy.
- In theLocal Addressfield, type the local endpoint IP address.This should be a floating self IP address.
- In theSecondary Addressfield, selectSpecify, and type the non-floating local IP address of the tunnel, for use with locally initiated traffic, such as monitor traffic.
- In theSecondary Addressfield, selectSpecify, and type the non-floating local IP address of the tunnel.
- From theRemote Addresslist, selectSpecify, and type the IP address of the device at the other end of the tunnel.
- From theRemote Addresslist, retain the default selection,Any.This entry means that you do not have to specify the IP address of the remote end of the tunnel, which allows multiple devices to use the same tunnel.
- For theRemote Addresslist, retain the default selection,Any.
- From theRemote Addresslist, selectSpecify, and type the IP address of the BIG-IP device at the other end of the tunnel.
- From theRemote Addresslist, selectSpecify, and type the IPv6 address of the BIG-IP device at the other end of the tunnel.
- From theRemote Addresslist, selectSpecify, and type the IPv6 address of the BIG-IP system used as an AFTR device at the other end of the tunnel.
- From theRemote Addresslist, retain the default selection,Any.This entry means that you do not have to specify the IP address of the remote end of the tunnel, which allows multiple devices to use the same tunnel.
- For theRemote Addresssetting, retain the default selection,Any, which indicates a wildcard IP address.
- For theRemote Addresslist, retain the default selection,Any.
- In theRemote Addressfield, type the multicast group address associated with the VXLAN segment.
- In theRemote Addressfield, selectAny, or selectSpecifyand type the multicast group address associated with the VXLAN-GPE segment.
- For theModelist, retain the default selection,Bidirectional.
- From theModelist, selectInbound.
- Select theTransparentcheck box.
- In theMTUfield, type the maximum transmission unit of the tunnel.The default value is0. The valid range is from0to65515.
- For theUse PMTU(Path MTU) setting, select or clear the check box.
- If enabled and the tunnel MTU is set to0, the tunnel will use the PMTU information.
- If enabled and the tunnel MTU is fixed to a non-zero value, the tunnel will use the minimum of PMTU and MTU.
- If disabled, the tunnel will use fixed MTU or calculate its MTU using tunnel encapsulation configurations
- From theTOSlist, selectPreserve, or selectSpecifyand type a Type of Service (TOS) value.The valid range is from0to255.
- From theAuto-Last Hoplist, select a value.
- ChooseDefaultif you want the system to use the globalAuto Last Hopsetting (if enabled).
- ChooseEnabledif you want this setting to take precedence over the globalAuto Last Hopsetting, for this tunnel only.
- ChooseDisabledif you want to disable auto last hop behavior for this tunnel only.
- In theKeyfield, type the VNI (Virtual Network Identifier) to use for the VXLAN tunnel.This field appears above theProfilefield when you select a profile that requires this setting.
- In theKeyfield, type the VNI (Virtual Network Identifier) to use for the VXLAN-GPE tunnel.This field appears above theProfilefield when you select a profile that requires this setting.
- In theKeyfield, type the VNI (Virtual Network Identifier) to use for the tunnel.This field appears above theProfilefield when you select a profile that requires this setting.
- In theKeyfield, type the VNI (Virtual Network Identifier) to use for a VXLAN tunnel or the Virtual Subnet Identifier (VSID) to use for a NVGRE tunnel.This field appears above theProfilefield when you select a profile that requires this setting.
- In theKeyfield, type the Virtual Subnet Identifier (VSID) to use for the NVGRE tunnel.This field appears above theProfilefield when you select a profile that requires this setting.
- In theKeyfield, type the special Virtual Subnet Identifier (VSID) that is used by Hyper-V Network Virtualization distributed routers to forward all routed packets to a gateway.This field appears above theProfilefield when you select a profile that requires this setting.
- From theTraffic Grouplist, selecttraffic-group-local-only.
- For theTraffic Grouplist, retain the default selection,None.
- From theTraffic Grouplist, select the traffic group that includes the local IP address for the tunnel.
- ClickFinished.
The inbound tunnel maps inbound packets from the special VSID to the correct VSID
and tunnel for forwarding.