Applies To:
Show Versions
BIG-IQ Security
- 4.5.0
About route domains
The Route Domains panel lists route domains configured from BIG-IQ Shared Security.
On BIG-IP devices, network objects such as route domains, virtual servers, self IP addresses, the management IP address, and the global firewall, all have firewalls attached to them. On BIG-IQ systems, an instance of one of these network objects is called a firewall context.
Using a BIG-IQ Security system, you can discover all firewall contexts on a BIG-IP device, and edit the firewall rules and/or policies attached to the firewall context.
From the Route Domains panel, you can create and edit route domain configurations that have VLANs, tunnels, or both, attached to them.
To close the New Route Domain properties panel without saving, click Cancel.
To get help on any panel, click the (?) icon in the upper right corner.
Adding route domains
Hover over the Route Domains header and click the (+) icon when it appears, then select New Route Domain. The panel expands to display properties on the New Route Domain screen.
Editing route domains
Hover over the name of the route domain that you want to edit and click the gear icon, then select Properties to expand the panel.
Removing route domains
Removing route domains defined on the BIG-IQ system is complex, and so a Remove button is not available for route domains as it is for other BIG-IQ Security components. To remove a route domain defined on a BIG-IQ system, reimport the route domain data to overwrite the data of the existing route domain. The configuration data to be overwritten must not have been deployed to a BIG-IP system.
Adding route domains
Use the New Route Domain screen to add and configure a new route domain. Using route domains, you can assign the same IP address to more than one device on a network, as long as each instance of the IP address resides in a separate route domain.
Adding route domains
- Hover over the Route Domains header, click the + icon when it appears, and click New Route Domain. The panel expands to display the New Route Domain properties.
- In the General Properties area of the New Route Domain screen, review and modify the
properties as needed.
Property Description Device Specifies the BIG-IP device. Select the BIG-IP device from the list. Name Specifies the unique name of the route domain. Description Specifies optional descriptive text that identifies the route domain. Partition Although pre-populated with Common (default), you can set the partition when creating route domains by entering a unique name for the partition. Note: The partition with that name must already exist on the BIG-IP device. No white space is allowed in the partition name.Id Type the identifying integer representing the route domain. The integer must be unique on the BIG-IP device, and be between 1 and 65534, including those values. An Id value of 0 is the default and indicates that all VLANs on a system pertain to this route domain. When you create new route domains, you can assign VLANs to those route domains and then move the VLANs out of the default route domain. - In the Configuration area, review or modify the configuration.
- When finished, click Add.
Editing route domains
Use the Route Domains Properties screen to edit route domain configurations.
Editing route domains
From the Route Domains panel, you can edit the route domain configuration.
- Hover over the route domain that you want to edit, click the gear icon, and select Properties to expand the panel.
- Click Edit to establish the lock and make it possible to edit the values.
- Edit the properties.
- In the General Properties area of the expanded Route Domains screen, review and modify the
properties as needed.
Property Description Device Specifies the BIG-IP device. Select the BIG-IP device from the list. Name Specifies the unique name of the route domain. Description Specifies optional descriptive text that identifies the route domain. Partition Although pre-populated with Common (default), you can set the partition when creating route domains by entering a unique name for the partition. Note: The partition with that name must already exist on the BIG-IP device. No white space is allowed in the partition name.Id Type the identifying integer representing the route domain. The integer must be unique on the BIG-IP device, and be between 1 and 65534, including those values. An Id value of 0 is the default and indicates that all VLANs on a system pertain to this route domain. When you create new route domains, you can assign VLANs to those route domains and then move the VLANs out of the default route domain. - In the Configuration area, review or modify the configuration.
- Click Save to save changes as you go.
- When you are finished, click Save and Close to save the changes, release the lock, and exit the screen.
Removing route domains
Removing route domains defined on the BIG-IQ system is complex, and so a Remove button is not available for route domains as it is for other BIG-IQ Security components. To remove a route domain defined on a BIG-IQ system, reimport the route domain data to overwrite the data of the existing route domain. The configuration data to be overwritten must not have been deployed to a BIG-IP system.
- Review the configuration of the BIG-IP system from which you plan to reimport the data, to make sure that you will not overwrite other configuration information you want to retain.
- Reimport the data from the BIG-IP system to overwrite the existing route domain data on the
BIG-IQ system, using the BIG-IQ Network Security Overview Devices panel. Note: Use care when reimporting, since it causes existing data to be overwritten.