Applies To:
Show VersionsBIG-IQ Centralized Management
- 5.1.0
How do I start to centrally manage APM configurations from BIG-IQ?
Here is an overview of your first steps for setting up an Access Policy Manager® (APM®) configuration once, and then being able to deploy that configuration from the BIG-IQ® system to other BIG-IP® devices.
Step 1. Add the BIG-IP device to the inventory list on the BIG-IQ system. You enter the IP address and credentials of the BIG-IP device you're adding, and associate it with a cluster (if applicable.
Step 2. Discover the APM and the Local Traffic Manager™ (LTM) configurations. You must discover LTM first, because APM uses some resources that are managed by LTM.
Step 3. Import the LTM configuration into the BIG-IQ system.
Step 4. Import the APM configuration into the BIG-IQ system. Importing the APM configuration requires that the device be added to an Access Group. You can create a new Access Group with the device as source-device, or you can add the device to another Access Group as non-source device.
What is the best way to create an Access group?
After you add devices to the BIG-IQ® system and discover them, you can create an Access group in either of two ways. Use whichever you prefer, based on your requirements.
- From the Access user interface, you can add multiple devices to an Access group at once. Using this method, you select multiple devices, with one device specified as the source device. Access then imports configurations from the devices, and creates the Access group.
- From the Device Management user interface, you can add one device at a time to an Access group when you import the APM service from each device.
Adding devices to the BIG-IQ inventory
Before you can add BIG-IP® devices to the BIG-IQ® inventory:
- The BIG-IP device must be located in your network.
- The BIG-IP device must be running a compatible software version. Refer to https://support.f5.com/kb/en-us/solutions/public/14000/500/sol14592.html for more information.
- Port 22 and 443 must be open to the BIG-IQ management address, or any alternative IP address used to add the BIG-IP device to the BIG-IQ inventory. These ports and the management IP address are open by default on BIG-IQ.