Manual Chapter :
Common Elements for route domain tasks
Applies To:
Show VersionsBIG-IP APM
- 15.0.1, 15.0.0
Common Elements for route domain tasks
Ensure that you have at least one VLAN configured before you create a
route domain.
If you have a BIG-IP
DNS on your
network, and your network has multiple route domains, ensure that virtual server
discovery (autoconf) is disabled on the server you are configuring, because virtual
server discovery does not discover translation IP addresses.
You can create a route domain on a BIG-IP system to segment (isolate)
network traffic on your network.
- On the Main tab, click.The Route Domain List screen opens.
- In the Name column, click the name of the relevant route domain.
- In the Name column, click0.
- ClickCreate.The New Route Domain screen opens.
- In theNamefield, type a name for the route domain.This name must be unique within the administrative partition in which the route domain resides.
- In theIDfield, type an ID number for the route domain.This ID must be unique on the BIG-IP system; that is, no other route domain on the system can have this ID.An example of a route domain ID is1.
- In theDescriptionfield, type a description of the route domain.For example:This route domain applies to application traffic for Customer A.
- For theStrict Isolationsetting, select theEnabledcheck box to restrict traffic in this route domain from crossing into another route domain.
- From theParent IDlist, select a parent ID.
- For theParent Namesetting, retain the default value.
- For theVLANssetting, from theAvailablelist, select a VLAN name and move it to theMemberslist.Select the VLAN that processes the application traffic relevant to this route domain.Configuring this setting ensures that the BIG-IP system immediately associates any self IP addresses pertaining to the selected VLANs with this route domain.
- For theVLANssetting, from theAvailablelist, select a VLAN name and move it to theMemberslist.The VLANs you select should be those pertaining to the customer for which you are creating this route domain.For example, you can select VLANsext_custAandint_custA.
- For theVLANssetting, from theAvailablelist, selectexternaland move it to theMemberslist.
- For theVLANssetting, move theexternalandinternalVLANs from theAvailablelist, to theMemberslist.Configuring this setting ensures that the BIG-IP system immediately associates any self IP addresses pertaining to the selected VLANs with this route domain.
- For theDynamic Routing Protocolssetting, from theAvailablelist, select one or more protocol names and move them to theEnabledlist.You can enable any number of listed protocols for this route domain.
- From theBandwidth Controllerlist, select a static bandwidth control policy to enforce a throughput limit on traffic for this route domain.
- From theIP Intelligence Policylist, select an IP Intelligence policy to enforce on this route domain.
- In theConnection Limitfield, type the maximum number of concurrent connections allowed for the route domain. Setting this to0turns off connection limits. The default is0.
- From theEviction Policylist, select an eviction policy to apply to this route domain.
- From thePartition Default Route Domainlist, retain the default value,Another route domain (0) is the Partition Default Route Domain.Retaining the default value designates route domain0as the default route domain for the current administrative partition.
- From thePartition Default Route Domainlist, selectMake this route domain the Partition Default Route Domain.With this setting, you can designate this route domain to be the default route domain for the current administrative partition.
- From thePartition Default Route Domainlist, selectMake this route domain the Partition Default Route Domain.This value designates this route domain to be the default route domain for the current administrative partition.ThePartition Default Route Domainsetting appears only when the current partition is set to a partition other thanCommon.After choosing this value, you are not required to append the route domain ID to any self IP or virtual IP address that you create later for this route domain. Instead, the BIG-IP system automatically associates an IP address with the default route domain in the partition, as long as you set this partition to be the current partition when you create the address.
- From thePartition Default Route Domainlist, select eitherAnother route domain (0) is the Partition Default Route DomainorMake this route domain the Partition Default Route Domain.This setting does not appear if the current administrative partition is partitionCommon.When you configure this setting, either route domain0or this route domain becomes the default route domain for the current administrative partition.
- To enforce rules from a firewall policy on the route domain: in the Network Firewall area: from theEnforcementlist, selectEnabledand then select the firewall policy to enforce from thePolicylist.
- To enforce any inline rules that apply to the route domain, and not apply a firewall policy: in the Network Firewall area, from theEnforcementlist, selectInline Rules.
- To stage rules from a firewall policy on the route domain: in the Network Firewall area, from theStaginglist, selectEnabledand then select the firewall policy to stage from thePolicylist.
- On the Main tab, clickSecurity.The Route Domain Security screen opens.
- From the Network Address Translation list, select the NAT policy to apply to route domain traffic.When a NAT policy is specified on a more specific context, that policy is applied. For example, a NAT policy on a route domain takes precedence over a global policy, and a policy on a virtual server takes precedence over a route domain policy.
- ClickFinished.The system displays a list of route domains on the BIG-IP system.
- ClickFinished.The system displays a list of route domains on the BIG-IP system, including the new route domain.
- Click theRepeatbutton.The Configuration utility saves the new route domain, and you can now create another route domain.
- ClickUpdate.The system displays the list of route domains on the BIG-IP system.
- Locate thePartitionlist in the upper right area of the BIG-IP Configuration utility screen, to the left of theLog outbutton.
- From thePartitionlist, select the partition in which you want to create local traffic objects.
- From thePartitionlist, confirm or select partitionCommon.
The BIG-IP system has one or more route domains for isolating traffic on
the network.