Updated Date: 07/07/2026
System Settings
You can access system settings in the webUI.
The Alarms & Events screen lists alert information for system components (such as PSU, firmware, and LCD) that have currently crossed a performance or health threshold. Use this screen to identify the specific component that is affected.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Alarm & Events.
-
Choose from one of these actions:
- To refresh the alarms or events list, click the Refresh icon on the right of the screen.
- To display events result by time preference, click the down arrow next to the Refresh icon and select a value from the list. The default value is one hour. For example, select five minutes to display any event that occurred in the last five minutes.
- To display events by severity, select a value from the Severity list. The default value is WARNING.
Option Description Emergency Emergency system panic messages Alert Serious errors that require administrator intervention Critical Critical errors, including hardware and file system failures Error Non-critical, but possibly important, error messages Warning Warning messages that should be logged and reviewed Notice Messages that contain useful information, but might be ignored Informational Messages that contain useful information, but might be ignored Debug Detailed messages used for troubleshooting
You can view or change settings for the management interface from the webUI.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Management Interface.
-
For DHCP, select either Enabled or Disabled.
-
For Address, select either IPv4, IPv6, or IPv4 & IPv6.
Additional fields display, depending on which address type you selected.
-
Under IPv4 and IPv6, you can configure one or more management IP addresses for the system:
-
For IP Address, type an IPv4 or IPv6 address.
-
For Prefix Length, specify a number from 1-32.
-
For Gateway, type the gateway IP address.
-
-
Under Interface Settings, you can configure the management port:
-
For State, select either Enabled or Disabled.
-
For Auto-negotiation, select either Enabled or Disabled.
If you enable auto-negotiation, port speed and duplex mode are set automatically.
-
For Port Speed, select one of these options: SPEED_1GB, SPEED_10MB, or SPEED_100MB.
-
For Duplex Mode, select FULL or HALF.
-
-
Click Save.
An allow list enables you to add either an IPv4 or IPv6 address as an accepted source that can access the system.
When the IP address is configured and saved to your allow list, only traffic coming from that IP address and port is accepted by the system’s management interface. You can also edit or delete entries in the allow list after you have configured them.
You can add an IP address to the Allow List from the webUI.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Allow List.
The Allow List displays.
-
Click Add.
-
Type a name for the allow list entry.
-
From the IPv4/ IPv6 list, select an address type.
-
In the Address field, type the IP address you want to add to the system allow list.
-
For Port, select one of these options:
Port Type 443 HTTPS 80 HTTP 8888 RESTCONF 161 SNMP 7001 VCONSOLE -
Click Save & Close.
You can configure or delete an IP address in the system allow list from the webUI.
You must have added an IP address to the allow list before you can edit or delete an entry.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Allow List.
The Allow List displays.
-
Select the IP address that you want to edit from the Allow List.
The IP address details display. You cannot edit the designated name, but you can change all other fields.
-
Click Save & Close.
-
To delete the IP address, select an IP address and click Delete.
When you are asked to confirm that you want to delete the IP address from the allow list, click OK.
You can configure your system to allow specific IP addresses from the CLI.
-
Log in to the command line interface (CLI) of the system using an account with admin access.
When you log in to the system, you are in user (operational) mode.
-
Change to config mode.
configThe CLI prompt changes to include
(config). -
Configure the system to allow traffic only from specified IP addresses.
Note: This is applicable only for ports 161, 8888, 443, 80, and 7001.
system allowed-ips allowed-ip <*allowlist-profile-name*> config [ ipv4 | ipv6 ] address <*ip-address*> port <*port-number*>This example adds a specified IPv4 address to the system allow list:
appliance-1(config)# system allowed-ips allowed-ip test config ipv4 address 192.0.2.33 port 161 -
Commit the configuration changes.
commit
The Software Management screen on the webUI includes options for uploading, importing and updating Base OS software for the system.
You can manage software images from the webUI.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Software Management.
-
To add a Base OS image by importing from the URL:
-
Click Import.
-
For URL, type the URL of the remote image server.
F5 recommends that the remote host be an HTTPS server with PUT/POST enabled and have a valid CA-signed certificate. You can opt to select the Ignore Certificate Warnings check box if you want to skip the certificate check.
-
For Username, type the user name for an account on the remote image server, if required.
-
For Password, type the password for the account, if required.
-
Select Ignore Certificate Warnings to skip the certificate check.
-
Click Add Image.
Note: Depending on the image file size and network availability, the import might take a few minutes. When the import is successful, the software image is listed in the webUI.
-
-
To add a Base OS image that you have downloaded to your local workstation:
-
Click Upload.
-
Navigate to the image file and select it.
-
Click Open.
-
-
To delete a Base OS image, select the image and click Delete.
Software images that are in use cannot be deleted.
View the status of image imports under Image Import Status, which shows information about Remote Host, File, Status, and Time.
Before you begin, you must also have added or uploaded an updated software image before you can do the update.
You can update Base OS software while the system is up and running from the webUI.
Important: During a software update, there is an interruption to traffic, so F5 recommends that you perform the update during a maintenance window
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Software Management.
-
In the Update Base OS Software section, for Update Software:
- To install a full F5OS-A version release, select Bundled.
- To install F5OS-A and service version releases independently, select Unbundled.
-
For ISO Image, select the full version release ISO image from the drop-down.
This field is available when Bundled is selected.
-
For Base OS Version, select the F5OS version from the drop-down.
This field is available when Unbundled is selected.
-
For Service Version, select the service version release from the drop-down.
This field is available when Unbundled is selected.
You can configure DNS for the system from the webUI. This is used for name resolution such as when setting up the system.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > DNS.
-
Under DNS Lookup Servers, specify the name servers that the system uses to validate DNS lookups, and resolve host names. For each name server you want to add:
-
Click Add.
-
For Lookup Server, type the IP address of the name server that you want to add to the list.
-
Click Save & Close.
-
-
Under DNS Search Domains, specify the domains that the system searches for local domain lookups and to resolve local host names. For each domain you want to add:
-
Click Add.
-
For Search Domain, type the domain name of the name server that you want to add to the list.
For example, DNSsearch.com.
-
Click Save & Close.
-
DNS lookup servers and search domains are now specified for the system.
You can add and display information about configured remote log servers from the webUI. You can also change the log severity level for individual software components and services.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Log Settings.
-
To add access to a Remote Log Server, click Add.
-
In the Server field, type the IPv4 address, IPv6 address, or Fully Qualified Domain Name (FQDN) of the remote server.
-
In the Port field, type the port number of the remote server.
The default port value is 514.
-
For Protocol, select UDP or TCP to choose between TCP or UDP input.
-
From the Facility list, select LOCAL0.
F5OS supports only the LOCAL0 logging facility. All logs are directed to this facility, and it is the only one that you can use for remote logging.
-
From the Severity list, select the severity level of the messages to log.
Option Description Emergency Emergency system panic messages Alert Serious errors that require administrator intervention Critical Critical errors, including hardware and file system failures Error Non-critical, but possibly important, error messages Warning Warning messages that should be logged and reviewed Notice Messages that contain useful information, but might be ignored Informational Messages that contain useful information, but might be ignored Debug Verbose messages used for troubleshooting -
Click Save & Close.
-
On the Log Settings screen, review the software component log levels for individual software components and adjust them as needed. Click Save if you made changes.
The log levels determine at what level events (and all higher levels) are logged for each service. Informational is the default so all except debug-level events are logged.
-
To delete a remote log server, select the server and click Delete.
You can import, export, download, or delete files asynchronously depending on which directory you select to work in. All file transfers are done using the HTTPS protocol.
You can import a file from an external server into the system from either the webUI or the CLI. HTTPS is the supported protocol. The remote host should be an HTTPS server with PUT/POST enabled and have a valid CA-signed certificate.
Note: If you want to import the contents of a tar file, you need to extract the contents first before you can import them onto the F5 system.
You can import files into these directories on the system:
- configs/
- diags/shared
- images/import
- images/staging
- images/tenant
You can download files in these directories from the system to your local workstation from the webUI:
- configs
- diags/core
- diags/crash
- diags/shared
- log/confd
- log/system
You can upload files in these directories from your local workstation to the system from the webUI:
- configs
- images/staging
- images/tenant
You can export a file from the system to an external server from either the webUI or the CLI. HTTPS is the supported protocol. The remote host should be an HTTPS server with PUT/POST enabled and have a valid CA-signed certificate.
You can export files into these directories from the system:
- configs
- log/
- log/confd
- log/controller
- log/host
- log/system
- diags/
- diags/core
- diags/crash
- diags/shared
- images/
- images/import
- images/staging
- images/tenant
You can delete files (to which you have file permissions) on the system only from the diags/shared or configs directories from either the webUI or the CLI.
File Utilities are available in the webUI. You can use File Utilities to import, export, and/or delete files asynchronously depending on which directory you select to work in. All file transfers are done using HTTPS protocol.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > File Utilities.
-
From the Base Directory list, browse the directories and click subfolders to view their contents and the commands that are available from each one.
From a subfolder, click the left arrow next to the path to navigate back to the main folder.
-
To import a file:
-
Click Import.
-
In the popup, type the URL of the file to import.
-
Provide the Username and Password only if required by the remote host.
-
Select Ignore Certificate Warnings if you want to skip warnings when importing files (such as if the remote host does not have a valid CA-signed certificate).
-
Click Import File to begin the import.
-
-
To export a file:
-
Select the file and click Export.
-
In the popup, type the Server URL for where to export the file.
-
Provide the Username and Password only if required by the remote host.
-
Select Ignore Certificate Warnings if you want to skip warnings when importing files.
-
Click Export File to begin the export.
-
-
To delete a file, select the file and click Delete.
You can delete files from the
diags/shareddirectory.
You can view the status of a file transfer operation to view its progress and see if it was successful. If an operation fails, hover over the warning icon to see the error that occurred.
Note: A runtime error displays in the File Transfer status area, if an invalid operation is performed.
You can import a file from an external server into the system or export a file to an external server from the system using the CLI.
-
Log in to the command line interface (CLI) of the system using an account with admin access.
When you log in to the system, you are in user (operational) mode.
-
Import a file.
file import remote-url <*ip-address-and-file-path*> local-file <*local-file-path*> username <*user*> password [ remote-port <*port-number*> ] [ protocol [ https | scp | sftp ]] [insecure]Note: The insecure option ignores certificate warnings during the transfer.
This example shows how to import a Base OS ISO to the system:
appliance-1# file import remote-url https://files.company.com/images/F5OS-A-1.1.x-xxxxx.R5R10.iso local-file images/staging username admin password Enter the password at the prompt: Value for 'password' (<string>): ******** result File transfer is initiated.(images/staging/F5OS-A-1.1.x-xxxxx.R5R10.iso)Note: If the file import doesn’t work, you can alternatively use secure copy (SCP) to copy the image file to the
images/stagingdirectory of the system. -
Optionally, you can check the file transfer status.
appliance-1# file transfer-statusWhen the file transfer completes, the
StatusdisplaysComplete. -
Export a file.
file export remote-url <*ip-address-and-file-path*> local-file <*local-file-path*> username <*user*> password [ remote-port <*port-number*> ] [ protocol [ https | scp | sftp ]] [insecure]This example shows how to import a Base OS ISO to the system:
appliance-1# file export local-file configs/backup1.xml remote-file /tmp/backup1.xml remote-host 192.51.100.75 username rootThe system requests the password for the remote account.
Value for 'password' (<string>): ******* result File transfer is initiated.(configs/backup1.xml) -
Delete a file.
file delete local-file diags/shared/<*file-name.xml*>This example shows how to delete a file:
appliance-1# file delete local-file diags/shared/backup1.xmlYou can only delete files from the
diags/sharedorconfigsdirectory.
After the system license is activated, you can configure Network Time Protocol (NTP) servers and time zone. The NTP server ensures that the system clock is synchronized with Coordinated Universal Time (UTC). You can specify a list of servers that you want the system to use when updating the time on network systems. You can configure time settings for the system from the webUI.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Time Settings.
-
To synchronize the system clock with an NTP server, for NTP Service, click Enabled.
The NTP Service is set to Disabled, by default.
-
To specify an NTP server:
-
Click Add.
-
In the NTP Server field, type the IPv4 address, IPv6 or the Fully Qualified Domain Name (FQDN) of the NTP server.
Note: If specifying an FQDN, you must configure a resolvable DNS server for the system.
-
Click Save & Close.
-
-
To set the time zone, select the time zone area from the Locations list.
-
Click Save.
Before rSeries systems can exchange data with one another, they need to exchange device certificates, that is, digital certificates and keys used for secure communication.
If you are using LDAP with transport layer security (TLS) for user authentication, you can choose to require TLS Certificate Validation in the authentication settings. You can add a certificate and key into the system, and when you create a certificate signing request (CSR), it saves the generated key and certificate to these directories:
system/aaa/tls/config/keysystem/aaa/tls/config/certificate
Before you can install device certificates, you must enable LDAP as an authentication method in the system (USER MANAGEMENT > Auth Settings).
You can view a certificate from the webUI.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Certificate Management.
-
To display a TLS Certificate, a TLS Key that was previously installed, or the TLS Details, click Show.
A text area opens and displays the certificate, key, or details.
Before you can install device certificates, you must enable LDAP as an authentication method in the system (USER MANAGEMENT > Auth Settings).
You can create or view a self-signed certificate from the webUI.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Certificate Management.
-
Click Create Certificate.
A form appears to enter certificate information.
-
In the Name field, enter a name for the certificate. For example, the server’s hostname.
-
In the Email field, enter the email address for the certificate contact.
-
In the City field, enter the city or locality name.
-
In the State field, enter the state, county, or region.
-
In the Country field, enter the two-letter country code. For example, US for United States.
-
In the Organization field, enter the certificate originator name. For example, your company’s name.
-
In the Unit field, enter the organizational unit name. For example, IT.
-
In the Version field, specify the version number for the certificate.
-
In the Days Valid field, specify the number of days the certificate is valid.
-
In the Key Type field, choose ECDSA or RSA as your key type.
-
In the Store TLS field, choose whether to store your TLS information.
-
Click Save.
Before you can install device certificates, you must enable LDAP as an authentication method in the system (USER MANAGEMENT > Auth Settings).
You can create and view certificate signing requests (CSRs) from the webUI.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Certificate Management.
-
To create a Certificate Signing Request, click Create CSR.
A form appears to enter certificate information.
-
In the Name field, enter a name for the certificate. For example, the server’s hostname.
-
In the Email field, enter the email address for the certificate contact.
-
In the City field, enter the city or locality name.
-
In the State field, enter the state, county, or region.
-
In the Country field, enter the two-letter country code.
For example, US for United States.
-
In the Organization field, enter the certificate originator name.
For example, your company’s name.
-
In the Unit field, enter the organizational unit name.
For example, IT.
-
In the Version field, specify the version number for the certificate.
-
Click Save.
If you have any concerns about your system operation, you can use the qkview utility to generate a system report to collect configuration and diagnostic information from the rSeries system. The QKView report contains machine-readable (JSON) diagnostic data and combines the data into a single compressed tar.gz format file. You can upload the QKView file to F5 iHealth where you can get help verifying proper operation of the system, understanding and troubleshooting any issues you might be having, and ensuring that the system is operating at its maximum efficiency.
You can generate a QKView report from the webUI. The report contains diagnostic information, such as configuration data, log files, and platform information.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > System Reports.
The System Reports screen displays. A list of QKView reports that were previously generated are shown with any reports that were uploaded to iHealth.
-
To generate a system report, click Generate QKView in the upper right corner of the screen.
The Generate QKView box displays these additional options:
|
Option |
Description |
|---|---|
|
Filename |
Specify a name for the file to which QKView report data is written. The default filename is <system-name>.qkview. |
|
Timeout Value |
Specify the time in seconds after which to stop QKView report data collection. The default value is 0, which indicates no timeout. |
|
Max File Size |
Exclude all files greater than the specified size (in MB). The range is from 2 MB to 1000 MB. The default value for maximum file size is 500 MB. |
|
Max Core Size |
Exclude core files greater than this size (in MB). The range is from 2 MB to 1000 MB. The default value for maximum core size is 25 MB. |
|
Exclude Cores |
Specify whether core files should be excluded from the QKView report. The default is to include core files. |
**Note:** The system runs many commands to collect the diagnostic information, so generating the report might affect its performance.
It takes a few minutes for the system to finish creating the report and list it on the screen. The QKView Status changes to `File generated successfully` when it is done.
-
If you want to upload the report to the F5 iHealth server, select the check box next to the QKView name, and click Upload to iHealth.
To do the upload, the system must have DNS configured, and have Internet access to these services using the HTTPS/443 remote service/port:
- api.f5.com
- ihealth-api.f5.com The QKView tar file uploads to iHealth, where you can get help to diagnose the health and proper operation of the system.
-
To delete a QKView report, select it and click Delete.
You can back up the system configuration from the webUI.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Configuration Backup.
-
Click Create.
The Create Configuration Backup popup opens.
-
In the Name field, type a name for the backup (for example, system-12-21-21).
-
Click Create.
The backup is created and added to the list.
-
To delete a backup file, select the file and click Delete.
System configuration backups are stored in configs/. Backups should be stored on off the system.
You can restore configurations from the CLI. For more information on saving and restoring the configuration, see the Complete backup and restore overview section.
You can activate a license for the rSeries system from either the CLI or webUI. There is one license per rSeries system, which is also used by any tenants.
There are two ways to license the system:
- Automatically
- If your system is connected to the Internet, use the Automatic method to prompt the system to contact the F5 license server and activate the license.
- Manually
- If your system is not connected to the Internet, use a management workstation that is connected to the Internet to retrieve an activation key from F5 and then transfer it to the system.
Important:
Adding or reactivating a license on an active rSeries system might impact traffic on tenants. Traffic processing will stop briefly on the tenants, and then restart automatically. This occurs when the tenant receives a new or reactivated license causing a configuration reload on the tenants. For more information, see these other references:
- F5 rSeries Systems: Installation and Upgrade at the F5OS Knowledge Center
- K7752: Licensing the BIG-IP system
- Additional information about BIG-IP Next licensing may be available on the F5 beta portal.
You can license a system using the automatic method from the webUI, as long as the system has Internet access.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Licensing.
-
For the Base Registration Key field, the registration key is auto-populated.
You can choose to overwrite this field with a new registration key by clicking Reactivate and overwriting the field.
-
For the Add-On Keys field, the associated add-on keys are auto-populated.
You can choose to change these keys by clicking Reactivate and then click + or x to add or remove additional add-on keys.
-
For the Activation Method, select Automatic.
-
Click Activate.
The End User License Agreement (EULA) displays.
-
Click Agree to accept the EULA.
The system is now licensed. If a base registration key or add-on key fails to activate, try re-activating the license or contact F5 Support at support.f5.com.
You can license a system without access to the Internet using the manual activation method from the webUI.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > Licensing.
-
For the Base Registration Key field, the registration key is auto-populated.
You can choose to overwrite this field with a new registration key by clicking Reactivate and overwriting the field.
-
For the Add-On Keys field, the associated add-on keys are auto-populated.
You can choose to change these keys by clicking Reactivate and then click + or x to add or remove additional add-on keys.
-
For the Activation Method, select Manual.
-
For the Device Dossier, click Get Dossier.
The system refreshes and displays the dossier.
-
Copy the dossier text in the Device Dossier field.
-
Click Click here to access F5 Licensing Server.
The Activate F5 Product page displays.
-
Paste the dossier in the Enter Your Dossier field.
-
Click Next.
The license key text displays.
-
Copy the license key text.
Alternatively, you can use the F5 license activation portal at activate.f5.com/license.
-
In the License Text field, paste the license key text.
-
Click Activate.
The End User License Agreement (EULA) displays.
-
Click Agree to accept the EULA.
The system is now licensed. If a base registration key or add-on key fails to activate, try re-activating the license or contact F5 Support at support.f5.com.
You can activate the rSeries system license manually from the system CLI.
-
Log in to the command line interface (CLI) of the system using an account with admin access.
When you log in to the system, you are in user (operational) mode.
-
Change to config mode.
configThe CLI prompt changes to include
(config). -
Get the system dossier.
system licensing get-dossier [registration-key XXXXX-XXXXX-XXXXX-XXXXX-XXXXXXX]The registration key is optional. If it is not included, the system uses the one already pre-installed. If no registration key is found, you receive an error.
The dossier for the system displays.
-
Get the license file using the dossier output you just received by going to the F5 siteactivate.f5.com/license/dossier.jsp.
-
Copy the license file text.
-
Install the license.
system licensing manual-install license -
Paste the license file content in multiline mode, then press Ctrl+D.
appliance-1(config)# system licensing manual-install license Value for 'license' (<string>): [Multiline mode, exit with ctrl-D.] >
The rSeries system is licensed. The license applies to the system and tenants.
For automatic rSeries system licensing, the system needs to be able to connect to the F5 licensing server either through the Internet or another means of networking. You need to have the Base Registration Key (five sets of characters separated by hyphens) provided by F5, and any add-on keys (two sets of 7 characters separated by a hyphen) that you have purchased. The Base Registration Key with associated add-on keys are pre-installed on a new rSeries system.
You can activate the rSeries system license automatically from the CLI.
-
Log in to the command line interface (CLI) of the system using an account with admin access.
When you log in to the system, you are in user (operational) mode.
-
Change to config mode.
configThe CLI prompt changes to include
(config). -
Apply a license to the system.
system licensing install registration-key <*key*>The registration key is optional. If it is not included, the system uses the one that is already pre-installed. If no registration key is found, you receive an error.
This example applies a specified base registration license to the system:
appliance-1(config)# system licensing install registration-key I1234-12345-12345-12345-1234567 result License installed successfully. -
Apply any add-on keys.
system licensing install add-on-keys <*add-on-keys*>This example enables the additional features associated with the three specified add-on-keys, along with the entitlements of the base registration key:
appliance-1(config)# system licensing install add-on-keys [1234567-1234567 2345678-2345678 3456789-3456789] result License installed successfully.
The rSeries system is licensed. The license and any add-on keys apply to the system and all tenants.
You can display the license and associated information of an rSeries system from the CLI.
-
Log in to the command line interface (CLI) of the system using an account with admin access.
When you log in to the system, you are in user (operational) mode.
-
Display the system license.
show system licensingA summary similar to this example displays:
appliance-1# show system licensing system licensing license Licensed version 1.1.0 Registration Key I1234-12345-12345-12345-1234567 Licensed date 2022/02/08 License start 2022/02/07 License end 2022/03/11 Service check date 2022/02/08 Platform ID C128 Appliance SN f5-nhlh-lule Active Modules Local Traffic Manager, r10900 (S680352-1548257) LTM to Best Upgrade, r109XX Rate Shaping DNSSEC Anti-Virus Checks Base Endpoint Security Checks Firewall Checks Machine Certificate Checks Network Access Protected Workspace Secure Virtual Keyboard APM, Web Application App Tunnel Remote Desktop DNS Rate Fallback, Unlimited DNS Licensed Objects, Unlimited DNS Rate Limit, Unlimited QPS GTM Rate Fallback, (UNLIMITED) GTM Licensed Objects, Unlimited GTM Rate, Unlimited Carrier Grade NAT (AFM ONLY) APM, Limited Routing Bundle Protocol Security Manager Access Policy Manager, Base, r109XX Advanced Web Application Firewall, r10XXX Max SSL, r10900 Max Compression, r10900 DNS Max, rSeries Advanced Firewall Manager, r10XXX -
Display the entire license file content received from the F5 license server.
show running-config system licensing
The rSeries system is licensed. The license applies to the system and tenants.
F5 r10000 platforms include two storage drives that support drive mirroring using a redundant array of independent disks (RAID) by default. You can manage the software RAID array from either the CLI or the webUI.
Important: If you need to swap out a faulty drive, you must first remove the drive from the software RAID array before physically removing the drive from the platform.
You can configure a software RAID (redundant array of independent disks) for the system from the webUI.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > RAID Configuration.
-
To remove a drive from the software RAID array:
-
Select the drive to remove.
-
Click Remove.
When prompted, click OK to confirm drive removal.
-
-
To add a drive to the software RAID array:
-
Select the drive to add.
-
Click Add.
When prompted, click OK to confirm drive addition.
-
You can configure a software RAID (redundant array of independent disks) for the system from the CLI.
-
Log in to the command line interface (CLI) of the system using an account with admin access.
When you log in to the system, you are in user (operational) mode.
-
Change to config mode.
configThe CLI prompt changes to include
(config). -
Remove a drive from the software RAID array.
system raid remove drive ssd2A summary similar to this example displays:
appliance-1(config)# system raid remove drive ssd2 status Remove of RAID SSD2 initiated. [11084.434517] md/raid1:md121: Disk failure on nvme1n1p3, disabling device. [11084.434517] md/raid1:md121: Operation continuing on 1 devices. [11084.449528] md/raid1:md122: Disk failure on nvme1n1p4, disabling device. [11084.449528] md/raid1:md122: Operation continuing on 1 devices. [11084.464098] md/raid1:md123: Disk failure on nvme1n1p5, disabling device. [11084.464098] md/raid1:md123: Operation continuing on 1 devices. [11084.478342] md/raid1:md124: Disk failure on nvme1n1p1, disabling device. [11084.478342] md/raid1:md124: Operation continuing on 1 devices. [11084.492509] md/raid1:md127: Disk failure on nvme1n1p2, disabling device. [11084.492509] md/raid1:md127: Operation continuing on 1 devices. status Remove of RAID SSD2 initiated. -
Add the replacement drive to the array.
system raid add drive ssd2A summary similar to this example displays:
appliance-1(config)# system raid add drive ssd2 status Add RAID SSD2 initiated.The array status for the new drive should change to
replicating, and the STAT LED should change to solid green. The replication process typically takes between 15 and 45 minutes.
You can configure general system settings for the rSeries system, such as system hostname, login banner, message of the day (MOTD) banner, and appliance mode. Depending on which setting you want to configure, you can use either the CLI or the webUI.
You can configure the hostname, login banner, and a message of the day (MOTD) banner for the system from the webUI.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > General.
-
For Hostname, enter a custom hostname for the system.
-
For Login Banner, enter any text to be shown when users log in to the system.
-
For MOTD Banner, enter any text to be used as a MOTD when users log in to the system.
-
Click Save.
You can run the system in appliance mode. Appliance mode adds a layer of security removing user access to Root and Bash. Enabling appliance mode disables all Root and Bash shell access for the system.
You can enable appliance mode at each of these levels:
- System
- Tenant
Appliance mode is disabled at all levels, by default. You can enable it from the webUI or the CLI. The appliance mode option for the system is available to users with admin access under SYSTEM SETTINGS > General in the webUI. For tenants, it is available in the webUI under TENANT MANAGEMENT > Tenant Deployments.
These are the effects of enabling appliance mode at each of the different levels.
System-level appliance mode
- Root or Bash access is disabled on the system.
- Console access: Root or Bash access is disabled on the system. Users can log in to the system CLI from the console using an admin account.
Tenant appliance mode
- Root access to the tenant is disabled by all means. Bash access is disabled for users (with a terminal shell flag enabled) inside the tenant.
- Users can access the tenant only through the webUI or the CLI.
- Tenant console access: Users can log in to the CLI from the virtual console using an admin account (with a terminal shell flag enabled).
You can enable or disable appliance mode from the webUI. Enable appliance mode to disable all root and Bash shell access.
Note: The appliance mode option for tenants is available in the webUI under TENANT MANAGEMENT > Tenant Deployments.
-
Log in to the webUI using an account with admin access.
-
On the left, click SYSTEM SETTINGS > General.
-
For Appliance Mode, select Enabled to enable it, or Disabled to disable it.
The default value is Disabled.
-
Click Save.