Manual Chapter : Use BIG-IQ as a License Manager for BIG-IP Subscription and Enterprise License Agreement Programs

Applies To:

  • BIG-IQ Centralized Management

    7.1.0, 7.0.0

Use BIG-IQ as a License Manager for BIG-IP Subscription and Enterprise License Agreement Programs

There are just a few steps to deploying and licensing F5 BIG-IQ Centralized Management as a license manager.

  1. Download a BIG-IP VE from F5.
  2. Install and configure the BIG-IQ VE.
  3. License the BIG-IQ.
  4. Activate your subscription key on the BIG-IQ.
  5. Assign, revoke, or change license subscriptions.
  6. Create license usage reports and submit to F5.

To complete these tasks, you need the following items from F5:

  • BIG-IQ VE software
  • BIG-IQ License Manager registration key
  • BIG-IP VE subscription licensing registration key

BIG-IQ Virtual Edition (VE) is a version of the BIG-IQ system that runs as a virtual machine in specifically-supported hypervisors. BIG-IQ VE emulates a hardware-based BIG-IQ system running a VE-compatible version of BIG-IQ software.

To manage your BIG-IP devices using BIG-IQ Centralized Management, you deploy a BIG-IQ system and then configure it to meet your business needs.

To deploy a BIG-IQ system, you need to:

  • Prepare your network environment and architecture (refer to Planning a BIG-IQ Centralized Management Deployment in Planning a BIG-IQ Centralized Management Deployment on support.f5.com for details).

  • Install and configure the BIG-IQ VE platform you plan to use to run the BIG-IQ system. The platform can either be a physical device or a virtual device. To use a physical device, you need a BIG-IQ 7000 series device. To use a virtual device, the solution you choose depends on the environment you choose. Use the platform-specific guide appropriate to complete the BIG-IQ VE installation. All of these guides are posted on support.f5.com.

    If you choose this platform: Refer to this guide for installation details:
    BIG-IQ 7000 Series Platform Guide: BIG-IQ 7000 Series
    Amazon Web Services F5 BIG-IQ Centralized Management 6.x and Amazon Web Services: Setup
    Citrix XenServer: F5 BIG-IQ Centralized Management 6.x and Citrix XenServer: Setup
    KVM F5 BIG-IQ Centralized Management 6.x and Linux KVM: Setup
    Microsoft Azure F5 BIG-IQ Centralized Management 6.x and Microsoft Azure: Setup
    Microsoft Hyper-V F5 BIG-IQ Centralized Management 6.x and Microsoft Hyper-V: Setup
    VMware ESXi F5 BIG-IQ Centralized Management 6.x and VMware ESXi: Setup
    Xen Project F5 BIG-IQ Centralized Management 6.x and Linux Xen Project: Setup

    Note: Hypervisor guest definition requirements vary depending on the platform you choose. These requirements are detailed in the setup guide for each platform.

  • Deploy and configure the number of BIG-IQ systems dictated by whether your architecture requires HA or multiple data centers.

  • License and configure the BIG-IQ system.

After you download the software image from the F5 Downloads site and start BIG-IQ in your virtual environment, you can license the system using the base registration key provided by F5. The base registration key is a character string the F5 license server uses to provide BIG-IQ a license to access the licensing features for your subscription or ELA program.

You must have a base registration key before you can license the BIG-IQ system. If you do not have a base registration key, contact the F5 Networks sales group (f5.com). After you set up your BIG-IQ VE or set up your BIG-IQ 7000 Series, you can install the BIG-IQ software license.

If the BIG-IQ system is connected to the public internet, you can follow these steps to automatically perform the license activation and perform the initial setup.

  1. Use a browser to log in to BIG-IQ by typing https://*&lt;management\_IP\_address&gt;*, where <management_IP_address> is the address you specified for device management.

  2. In the Base Registration Key box, type or past the BIG-IQ registration key.

  3. For Activation Method, select Automatic, click the Activate button, and then click the Next button.

    If you are setting up this device for the first time, the Accept User Legal Agreement screen opens.

  4. To accept the license agreement, click the Agree button, and then click the Next button.

  5. Click the Next button at the bottom of the screen.

  6. f you are prompted with the System Personality screen, select the option BIG-IQ central Management Console, and then click OK. If you are not prompted, proceed to the next step.

  7. In Hostname, type a fully-qualified domain name (FQDN) for the system.

    The FQDN can consist of letters and numbers, as well as the characters underscore ( _ ), dash ( - ), or period ( . ).

  8. Type the Management Port IP Address and Management Port Route.

    Note: The management port IP address must be in Classless Inter-Domain Routing (CIDR) format. For example: 10.10.10.10/24.

  9. Click the Next button at the bottom of the screen.

  10. In the DNS Lookup Servers field, type the IP address of your DNS server.

    You can click the Test Connection button to verify that BIG-IQ can reach that IP address.

  11. In the DNS Search Domains field, type the name of your search domain.

    The DNS search domain list allows the BIG-IQ system to search for local domain lookups to resolve local host names.

  12. In the Time Servers field, type the IP addresses of your Network Time Protocol (NTP) server.

    You can click the Test Connection button to verify that BIG-IQ can reach the IP address.

  13. From the Time Zone list, select your local time zone.

  14. Click the Next button at the bottom of the screen.

  15. Type a Passphrase that satisfies the requirements specified on screen, and then type the same phrase for Confirm Passphrase.

    Important: BIG-IQ uses the pass phrase to generate a Master Key. For High Availability and data collection device cluster configurations, this pass phrase must be the same on all related BIG-IQ systems or these systems will not be able to communicate with each other.

    • Make sure you keep track of the pass phrase, because it cannot be recovered if you lose it. To protect the security of this device, you must have the passphrase used to generate the master key before you can change the master key.
    • If this BIG-IQ is not part of an HA or DCD configuration, you can change the Master Key any time from the System > THIS DEVICE > General Properties screen.
    • To add a BIG-IQ to an HA or DCD configuration, its master key must match the key for the other devices in the HA or DCD configuration. So if the passphrase is different and you do not know what it is, the only way to add that BIG-IQ to a cluster is to reset it to it’s factory defaults; However, that reset destroys any data on that BIG-IQ.
    • Finally, when you backup and restore a BIG-IQ, the master key is backed up with the rest of the data, and you cannot restore that data onto a BIG-IQ that has a different master key, so without that key you will be unable to have this BIG-IQ and it’s data in an HA or DCD configuration.
  16. In the Old Password fields, type the default admin and root passwords, and then type a new password in the Password field and click the Next button at the bottom of the screen.

    If your license supports both BIG-IQ Data Collection Device and BIG-IQ Central Management Console, the System Personality screen displays. Otherwise the Management Address screen opens.

  17. If the details are as you intended, click Launch to continue; if you want to make corrections, use the Previous button to navigate back to the screen you want to change.

Before you can set up F5 BIG-IQ Centralized Management in a high availability (HA) pair, you must have two licensed BIG-IQ systems and you must have added the primary and secondary SSL certificate to the primary BIG-IQ system.

For the high-availability pair to synchronize properly, each system must be running the same BIG-IQ version, and the clocks on each system must be synchronized to within 60 seconds. To make sure the clocks are in sync, take a look at the NTP settings on each system before you add a peer.

Configuring BIG-IQ in a high availability (HA) pair means that you can still manage your BIG-IP devices even if one BIG-IQ systems fails.

Note: Do not install the standby BIG-IQ on the same hardware as the active BIG-IQ. That way, if a hardware issue takes the active BIG-IQ offline, it can failover to the standby BIG-IQ installed on another hardware platform so you can continue to manage your BIG-IP devices.

  1. At the top of the screen, click System.

  2. On the left, click BIG-IQ HA.

  3. Click the Add Secondary button.

  4. Type the properties for the BIG-IQ system that you are adding.

    For the IP address, be sure to specify the Discovery Address of the BIG-IQ you are adding.

    BIG-IQ does not support iPv6 short format for high availability configuration.

  5. Click the Add button at the bottom of the screen.

The BIG-IQ system synchronize. Once they are finished, both appear as ready (green).