Manual Chapter :
Deploying a BIG-IQ System
Applies To:
Show VersionsBIG-IQ Centralized Management
- 6.0.1
Deploying a BIG-IQ System
How do I deploy a
BIG-IQ system?
To manage your BIG-IP devices using BIG-IQ Centralized
Management, you deploy a BIG-IQ system and then configure it to meet your business
needs.
To deploy a BIG-IQ system, you should:
- Prepare your network environment and architecture (refer toPlanning a BIG-IQ Centralized Management DeploymentinPlanning a BIG-IQ Centralized Management Deploymentonsupport.f5.comfor details).
- Install and configure the platform you plan to use to run the BIG-IQ system. The platform can either be a physical device or a virtual device. To use a physical device, you need a BIG-IQ 7000 series device. To use a virtual device, the solution you choose depends on the environment you choose. Supported platforms for this release are listed below. Use the guide appropriate for the platform you use to complete the installation. All of these guides are posted onsupport.f5.com.If you choose this platform:Refer to this guide for installation details:BIG-IQ 7000 SeriesPlatform Guide: BIG-IQ 7000 SeriesAmazon Web ServicesF5 BIG-IQ Centralized Management 6.0.0 and Amazon Web Services: SetupCitrix XenServer:F5 BIG-IQ Centralized Management 6.0.0 and Citrix XenServer: SetupKVMF5 BIG-IQ Centralized Management 6.0.0 and Linux KVM: SetupMicrosoft AzureF5 BIG-IQ Centralized Management 6.0.0 and Microsoft Azure: SetupMicrosoft Hyper-VF5 BIG-IQ Centralized Management 6.0.0 and Microsoft Hyper-V: SetupVMwareF5 BIG-IQ Centralized Management 6.0.0 and VMware ESXi: SetupXen ProjectF5 BIG-IQ Centralized Management 6.0.0 and Linux Xen Project: Setup
- Deploy and configure the number of BIG-IQ systems dictated by whether your architecture requires HA or multiple data centers.
- License and configure the BIG-IQ system.
How do I license and do the basic setup to start using BIG-IQ?
After you download the software image from the F5 Downloads site and start BIG-IQ in your virtual environment, you can license the system using the base
registration key provided by F5. The
base registration key
is a character string
the F5 license server uses to provide BIG-IQ a license to access the subscription licensing
feature. You license BIG-IQ in one of the following ways:
- If the system has access to the Internet, you can have the BIG-IQ system contact the F5 license server and automatically activate the base registration key to get a license.
- If the system is not connected to the Internet, you can manually license the BIG-IQ using the F5 license server web portal.
- If the system is in a closed-circuit network (CCN) that does not allow you to export any encrypted information, you must open a case with F5 support at: support.f5.com/csp/my-support/home.
When licensing BIG-IQ, you:
- Activate the license.
- Accept the EULA.
- Specify the system personality as BIG-IQ Centralized Management.
- Specify a host name, and IP addresses for the management port, DNS server, and network time protocol (NTP) servers.
- Specify the master key pass phrase.
- Change the default admin and root passwords.
Automatic license and initial setup for BIG-IQ systems
You must have a base
registration key before you can license the BIG-IQ system. If you do not have a base
registration key, contact the F5 Networks sales group (
f5.com
). If the BIG-IQ system is connected to the public
internet, you can follow these steps to automatically perform the license activation and
perform the initial setup.
- Use a browser to log in to BIG-IQ by typinghttps://, where<management_IP_address><management_IP_address>is the address you specified for device management.
- In theBase Registration Keyfield, type or paste the BIG-IQ registration key.If you are setting up a data collection device, you have to use a registration key that supports a data collection device license.
- In theAdd-On Keysfield, paste any additional license key you have.
- To add another additional add-on key, click the+sign and paste the additional key in the newAdd-On Keysfield.
- For theActivation Methodsetting, selectAutomatic, and click theActivatebutton.
- ClickNext.If you are setting up this device for the first time, the Accept User Legal Agreement screen opens.
- To accept the license agreement, click theAgreebutton.
- Click theNextbutton at the bottom of the screen.If your license supports both BIG-IQ Data Collection Device and BIG-IQ Central Management Console, the System Personality screen displays. Otherwise the Management Address screen opens.
- If you are prompted with the System Personality screen, select the option you're licensed for, and then clickOK. If you are not prompted, proceed to the next step.You cannot undo this choice. Once you license a device as a BIG-IQ Management Console, you can't change your mind and license it as a Data Collection Device.The Management Address screen opens.
- In theHostnamefield, type a fully-qualified domain name (FQDN) for the system.The FQDN can consist of letters and numbers, as well as the characters underscore ( _ ), dash ( - ), or period ( . ).
- In theManagement Port IP AddressandManagement Port Routefields, type the IP address for the management port IP address and route.The management port IP address must be in Classless Inter-Domain Routing (CIDR) format. For example:10.10.10.10/24.
- Specify what you want the BIG-IQ to use for theDiscovery Address.BIG-IQ advertises this address to other devices that want to communicate with it. For example BIG-IQ HA peers and DCD nodes communicate using their respective discovery addresses.When choosing whether to use the management port or a self IP address, consider the long term ramifications. The BIG-IQ uses the address you choose for all traffic to and from the devices it manages and the DCDs that support it. Changing the discovery address involves a lengthy process that includes rediscovering all of the devices and DCDs associated with this BIG-IQ.
- To use the management port, selectUse Management Address.
- To use the internal self IP address, selectSelf IP Address, and type the IP address.If you are configuring a BIG-IQ to manage applications in a service scaling group, use the internal self IP address. The management port or self IP address has to be routable to all BIG-IP devices you plan to manage.If you plan to manage both IPv4 and IPv6 devices, you must configure an additional interface. BIG-IQ does not manage both protocols on the same interface. You can use a self IP address for this. So if your deployment includes DCDs, your discovery address will use one internal self IP address and you will need to add a second self IP to facilitate discovery of both protocol types.The self IP address must be in Classless Inter-Domain Routing (CIDR) format. For example:10.10.10.10/24.
- Click theNextbutton at the bottom of the screen.The Services screen opens.
- In theDNS Lookup Serversfield, type the IP address of your DNS server.You can click theTest Connectionbutton to verify that BIG-IQ can reach that IP address.
- In theDNS Search Domainsfield, type the name of your search domain.The DNS search domain list allows the BIG-IQ system to search for local domain lookups to resolve local host names.
- In theTime Serversfield, type the IP addresses of your Network Time Protocol (NTP) server.You can click theTest Connectionbutton to verify that BIG-IQ can reach the IP address.
- From theTime Zonelist, select your local time zone.
- Click theNextbutton at the bottom of the screen.The Master Key screen opens.
- For thePassphrase, type a phrase that satisfies the requirements specified on screen, and then type the same phrase forConfirm Passphrase.The DCD uses the pass phrase to generate a Master Key. This pass phrase must be the same on all of the devices in the DCD cluster. Make sure you keep track of the pass phrase, because it cannot be recovered if you lose it
- Click theNextbutton at the bottom of the screen.The Password screen opens.If you are setting up a Microsoft Azure VE, and you type an entry in any of the fields, you will not be able to continue successfully. The only way to proceed is to leave all of the fields empty and click theNextbutton at the bottom of the screen. This allows the system to use the first-time access credentials you specified previously.
- In theOld Passwordfields, type the default admin and root passwords, and then type a new password in thePasswordandConfirm Passwordfields.
- Click theNextbutton at the bottom of the screen.The screen Summary displays the details you just specified for this device configuration.
- If the details are as you intended, clickLaunchto continue; if you want to make corrections, use thePreviousbutton to navigate back to the screen you want to change.
Manual license and initial setup for BIG-IQ systems
You must have a base
registration key before you can license the BIG-IQ system. If you do not have a base
registration key, contact the F5 Networks sales group (
f5.com
). If the BIG-IQ system is not connected
to the public internet, you can follow these steps to contact the F5 license
web portal then perform the initial setup.
- Use a browser to log in to BIG-IQ by typinghttps://, where<management_IP_address><management_IP_address>is the address you specified for device management.
- In theBase Registration Keyfield, type or paste the BIG-IQ registration key.If you are setting up a data collection device, you have to use a registration key that supports a data collection device license.
- In theAdd-On Keysfield, paste any additional license key you have.
- For theActivation Methodsetting, selectManualand click theGenerate Dossierbutton.The BIG-IQ system refreshes and displays the dossier in theDevice Dossierfield.
- Select and copy the text displayed in theDevice Dossierfield.
- Click theAccess F5 manual activation web portallink.The Activate F5 Product site opens.
- Into theEnter your dossierfield, paste the dossier.Alternatively, if you saved the file, click theChoose Filebutton and navigate to it.After a pause, the screen displays the license key text.
- ClickNext.If you are setting up this device for the first time, the Accept User Legal Agreement screen opens.
- To accept the license agreement, selectI have read and agree to the terms of this license, and clickNext. button.The licensing server creates the license key text.
- Copy the license key.
- In theLicense Textfield on BIG-IQ, paste the license text.
- Click theActivate Licensebutton.
- Click theNextbutton at the bottom of the screen.If your license supports both BIG-IQ Data Collection Device and BIG-IQ Central Management Console, the System Personality screen displays. Otherwise the Management Address screen opens.
- If you are prompted with the System Personality screen, select the option you're licensed for, and then clickOK. If you are not prompted, proceed to the next step.You cannot undo this choice. Once you license a device as a BIG-IQ Management Console, you can't change your mind and license it as a Data Collection Device.The Management Address screen opens.
- In theHostnamefield, type a fully-qualified domain name (FQDN) for the system.The FQDN can consist of letters and numbers, as well as the characters underscore ( _ ), dash ( - ), or period ( . ).
- In theManagement Port IP AddressandManagement Port Routefields, type the IP address for the management port IP address and route.The management port IP address must be in Classless Inter-Domain Routing (CIDR) format. For example:10.10.10.10/24.
- Specify what you want the BIG-IQ to use for theDiscovery Address.BIG-IQ advertises this address to other devices that want to communicate with it. For example BIG-IQ HA peers and DCD nodes communicate using their respective discovery addresses.When choosing whether to use the management port or a self IP address, consider the long term ramifications. The BIG-IQ uses the address you choose for all traffic to and from the devices it manages and the DCDs that support it. Changing the discovery address involves a lengthy process that includes rediscovering all of the devices and DCDs associated with this BIG-IQ.
- To use the management port, selectUse Management Address.
- To use the internal self IP address, selectSelf IP Address, and type the IP address.If you are configuring a BIG-IQ to manage applications in a service scaling group, use the internal self IP address. The management port or self IP address has to be routable to all BIG-IP devices you plan to manage.If you plan to manage both IPv4 and IPv6 devices, you must configure an additional interface. BIG-IQ does not manage both protocols on the same interface. You can use a self IP address for this. So if your deployment includes DCDs, your discovery address will use one internal self IP address and you will need to add a second self IP to facilitate discovery of both protocol types.The self IP address must be in Classless Inter-Domain Routing (CIDR) format. For example:10.10.10.10/24.
- Click theNextbutton at the bottom of the screen.The Services screen opens.
- In theDNS Lookup Serversfield, type the IP address of your DNS server.You can click theTest Connectionbutton to verify that BIG-IQ can reach that IP address.
- In theDNS Search Domainsfield, type the name of your search domain.The DNS search domain list allows the BIG-IQ system to search for local domain lookups to resolve local host names.
- In theTime Serversfield, type the IP addresses of your Network Time Protocol (NTP) server.You can click theTest Connectionbutton to verify that BIG-IQ can reach the IP address.
- From theTime Zonelist, select your local time zone.
- Click theNextbutton at the bottom of the screen.The Master Key screen opens.
- For thePassphrase, type a phrase that satisfies the requirements specified on screen, and then type the same phrase forConfirm Passphrase.BIG-IQ uses the pass phrase to generate a Master Key. For High Availability and data collection device cluster configurations, this pass phrase must be the same on all related BIG-IQ systems.
- If this BIG-IQ is not part of an HA or DCD configuration, you can change the Master Key any time from thescreen.
- If this BIG-IQ is part of an HA or DCD configuration, make sure you keep track of the pass phrase, because it cannot be recovered if you lose it.
- Click theNextbutton at the bottom of the screen.The Password screen opens.If you are setting up a Microsoft Azure VE, and you type an entry in any of the fields, you will not be able to continue successfully. The only way to proceed is to leave all of the fields empty and click theNextbutton at the bottom of the screen. This allows the system to use the first-time access credentials you specified previously.
- In theOld Passwordfields, type the default admin and root passwords, and then type a new password in thePasswordandConfirm Passwordfields.
- Click theNextbutton at the bottom of the screen.The screen Summary displays the details you just specified for this device configuration.
- If the details are as you intended, clickLaunchto continue; if you want to make corrections, use thePreviousbutton to navigate back to the screen you want to change.
Monitoring BIG-IP statistics in BIG-IQ
Visibility of statistics in BIG-IQ depends on the version of
your managed BIG-IP devices. Devices running versions 13.1.X, or earlier, have limited
statistics visibility support within BIG-IQ. Below outlines the compatibility and what to
expect when accessing Analytics (AVR) data within BIG-IQ. For more information, see the
supporting documentation found in the
BIG-IQ Centralized
Management: Monitoring and Reports
guide.Statistics visibility of managed BIG-IP devices
The format in which statistics are presented in the BIG-IQ environment, depends on the managed version of BIG-IP and the service presented. Refer to the table to access statistics visibility, based on the managed device version. Ensure that the managed device configuration meets the requirements outlined below.
Minimum configuration requirements:
- BIG-IP Version 13.1.x or earlier
- Ports 22 and 443 on each BIG-IP device must be open for the BIG-IQ DCD to retrieve data.
- There must be a Data Collection Device (DCD) configured to your BIG-IQ.
- BIG-IP Version 13.1.0.5 or later
- You must have AVR provisioned for each BIG-IP device.
- BIG-IQ needs to provide access on Port 443 to receive BIG-IP AVR data.
- There must be a Data Collection Device (DCD) configured to your BIG-IQ.To view statistics, ensure that the licenses for your managed BIG-IP devices include root access. A BIG-IP license running in Appliance Mode, will not allow for statistics visibility in the BIG-IQ environment.
Where to view statistics
BIG-IP v12.1 | BIG-IP v13.0 | BIG-IP v13.1 | BIG-IP v13.1.0.5 | BIG-IP v14.0 | BIG-IP v14.1 | BIG-IP v15.0 or later | |
---|---|---|---|---|---|---|---|
Device Traffic | |||||||
Local Traffic (General) | |||||||
Local Traffic (HTTP) | Not available to this version | ||||||
DNS (General)* | |||||||
Network Firewall (General) | Network Firewall information is
provided by ACL, IP Reputation, and IPS. | ||||||
Network Firewall (ACL) | Not applicable to
this version | ||||||
Network Security (IP Reputation) | Not applicable to this version | ||||||
Network Firewall (IPS) | Not applicable to
this version | ||||||
Web Application Security (General) | |||||||
Web Application Security (Bot) | Not
available to this version | ||||||
DDoS (Shared Security) | Not available to
this version | ||||||
Application Summary | (limited statistics visibility) | ||||||
Secure Web Gateway | Not available to this version | ||||||
SSLO** | Not available to
this version | ||||||
Access | Not available to this
version |
*Top Charts are only available to BIG-IP version 13.1.0.5 or later.
**SSLO support is available to versions 5.4 to 5.9.