Page 1
Platform Guide: 6900 and 8900 MAN-0297-03...
Page 3
Accelerator, SYN Check, Traffic Management Operating System, TMOS, TrafficShield, Transparent Data Reduction, uRoam, VIPRION, WANJet, WAN Optimization Module, WOM, WebAccelerator, WA, and ZoneRunner are trademarks or service marks of F5 Networks, Inc., in the U.S. and other countries, and may not be used without F5's express written consent.
Page 4
Standards Compliance This product conforms to the IEC, European Union, ANSI/UL and Canadian CSA standards applicable to Information Technology products at the time of manufacture. VCCI Class A Compliance This is a Class A product. In a domestic environment, this product may cause radio interference, in which case the user may be required to take corrective actions.
Table of Contents The 6900/8900 Platform About the 6900/8900 platform ....................1-1 Getting started with the 6900/8900 platform ..............1-2 Technical support resources ......................1-5 Installing the 6900/8900 Platform Installing and connecting the hardware ..................2-1 General recommendations for mounting a unit in a rack ..........2-2 Attaching the front bezel to the unit ................2-2 Installing the unit using a front-mounting kit ..............2-3 Installing the unit using a rail-mounting kit ..............2-5...
Page 8
Table of Contents Configuring and Maintaining a FIPS Security Domain Understanding the FIPS implementation ...................6-1 Installing the BIG-IP systems and connecting a serial console ..........6-1 Creating the FIPS security domain ....................6-2 Initializing the first unit in a redundant system ...............6-2 Initializing the peer system ....................6-2 Running the Configuration utility ....................6-3 Running the fipscardsync utility to synchronize the FIPS HSMs ...........6-3...
Page 9
Table of Contents Working with Environmental Guidelines for the 6900/8900 Platform Environmental requirements ..................... 11-1 General environmental guidelines ................... 11-1 Understanding Platform Airflow Reviewing platform airflow information ................. 12-1 Airflow for the 6900/8900 platform ................12-1 Reviewing Hardware Specifications General specifications for system features ................13-1 6900 platform hardware and operating specifications ............
(SFP) transceivers (LC connector type), two SFP+ transceivers, and sixteen 10/100/1000 interfaces. Important F5 Networks provides support only for F5-branded optics. For detailed specifications of the 6900 and 8900 platforms, see Chapter 13, Reviewing Hardware Specifications. Platform Guide: 6900 and 8900...
Chapter 1 Getting started with the 6900/8900 platform You need to be familiar with both the front and back layout of the 6900 or 8900 platform that you are using. Figure 1.1 illustrates the front of a 6900 platform. On the back of the unit, you can turn the unit off and on. On the front of the unit, you can reset the unit using the LCD panel and view the indicator LEDs for hard disk access.
Page 15
The 6900/8900 Platform 1. Management port 2. USB ports 3. Console port 4. Hard-wired failover port 5. 10/100/1000 interfaces 6. SFP ports 7. SFP+ ports 8. Indicator LEDs 9. LCD display 10. LCD control buttons Figure 1.2 Front view of an 8900 platform Figure 1.3 illustrates the back of the 6900 and 8900 platforms.
Page 16
Chapter 1 Components provided with the 6900/8900 platform The 6900/8900 platform comes with the hardware that you need for installation. However, you must also provide standard peripheral hardware, such as a serial terminal, if you want to administer the 6900/8900 platform directly.
• Updates for guides (in PDF form) • Technical notes • Answers to frequently asked questions • The Ask F5 Knowledge Base To gain access to this site, you need to register at https://support.f5.com. Platform Guide: 6900 and 8900 1 - 5...
Installing the 6900/8900 Platform Installing and connecting the hardware After you have reviewed the hardware requirements and become familiar with the 6900/8900 platform, as described in Getting started with the 6900/8900 platform, on page 1-2, you can install the unit. The 6900/8900 platform comes with two types of rack mounting kits: stationary front-mounting and sliding rail-mounting.
Chapter 2 General recommendations for mounting a unit in a rack Although not required, a 1U space between units makes it easier for you to remove the unit from the rack in the event that the unit requires service. A 1U space between units also provides additional cable routing options.
Installing the 6900/8900 Platform Installing the unit using a front-mounting kit When you received your 6900/8900 platform, the unit included front-mounting brackets, suited for front mounting the unit. With front-mounting brackets, the unit is bolted directly to the rack. A shelf or similar device is required to support the unit if a single person is installing the unit.
Page 24
Chapter 2 3. Secure the unit to the rack using screws provided by the rack manufacturer. The unit must be securely fastened to the rack to provide adequate stability and to prevent the unit from falling out of the rack. If the rack you have does not provide adequate support for the unit, you may need a shelf kit.
Installing the 6900/8900 Platform Installing the unit using a rail-mounting kit When you received your 6900/8900 platform, the unit also included a rail-mounting kit that enables you to slide the unit in and out of the rack at will. To install the rail-mounting kit and install the unit into the rails, you need to perform the following tasks: •...
Page 26
Chapter 2 Figure 2.3 An inner rail installed onto a unit To attach the inner rails to the unit 1. Separate the inner rail from the outer rail. 2. Align the large holes in the inner rail with the pins on the unit and then push toward the back of the unit to lock the pins to the inner rail, as shown in Figure 2.3.
Page 27
Installing the 6900/8900 Platform Attaching the outer rails and mounting brackets Once you have installed the inner rails to the unit, you can prepare the outer rails and rail mounting brackets for installation onto the rack. The mounting brackets are reversible for use in either a fixed three-hole spaced rack or a two-hole spaced rack.
Page 28
Chapter 2 Figure 2.6 shows an outer rail and mounting brackets attached to a rack. Figure 2.6 Outer rail and mounting bracket attached to a rack Once the inner rails are installed onto the unit, and the outer rails and mounting brackets are installed onto the rack, you can easily install the unit into the rack.
Page 29
Installing the 6900/8900 Platform Installing the unit into a rail-mount rack The 6900/8900 platform includes hardware that you install to secure the unit to the rack. To install the unit into the rack 1. Extend the outer rails to the fully locked position. 2.
1. Connect the system to a management workstation or network: • If you are using a serial terminal as the console, connect the serial console cable supplied by F5 Networks to the console port (number 3 in Figure 1.1, on page 1-2).
Operating the LCD Panel Introducing the LCD panel The liquid crystal display, or LCD panel, provides the ability to control the unit without attaching a console or network cable. Figure 3.1 shows the LCD panel for the 6900 platform, which is identical to the LCD panel for the 8900 platform.
Chapter 3 Using the LCD panel You can configure the LCD panel to meet your needs. The following section describes how to perform a number of tasks with the LCD panel: • Pause on a screen • Use the LCD menus •...
Operating the LCD Panel 4. Press the Check button. 5. Press the Check button again at the confirmation screen. 6. Wait 30 seconds before powering the machine off or rebooting it. Powering down the unit Hold the X button for four seconds to power down the unit. We recommend that you halt the system before you power down the system in this manner.
Chapter 3 Navigating through the LCD menus To use the LCD menus, you must first put the LCD panel in Menu mode. To put the LCD panel in Menu mode, press the X button. After you put the LCD in menu mode, use the Left Arrow, Right Arrow, Up Arrow, and Down Arrow buttons to select menu options.
Operating the LCD Panel Screens menu You can use the Screens menu options to view various statistics and information about the system. Table 3.2 lists all the general information screens and describes them. You can use the Check button to place a check mark next to the name of the screens you want to appear when the screens cycle.
Chapter 3 System menu The System menu provides various options for rebooting, halting, or netbooting the hardware. This menu also provides options for configuring the network on the management interface. Table 3.3 lists the options available in the System menu and describes them. Option Description Management...
Using Additional 6900/8900 Platform Functionality Understanding indicator LED behavior It helps to understand the indicator LED behavior of the BIG-IP software, on the 6900/8900 platform. Indicator LED behavior The appearance and behavior of each LED indicate the status of the system. Table 4.1 defines the indicator LED behavior.
Chapter 4 When the system is in a standard operating state, the two power supply LEDs appear in a defined manner. Table 4.3 defines the standard operating states for the power supply LEDs. State Description Power 1 No power supply present in slot 1. green Power supply present in slot 1.
Using Additional 6900/8900 Platform Functionality To configure indicator LEDs to display node status 1. From the command line interface, type the following command: cd /config 2. Using a text editor, such as vi or pico, open the user_alert.conf file. 3. Add the lines shown in Figure 4.1 to the end of the file. 4.
Chapter 4 Working with interfaces You can perform configuration tasks such as displaying interface status and settings and setting the media type using the bigpipe utility. When using the bigpipe interface command, you can either apply the command to all interfaces or to a specific interface key (for example, 1.1). Status and settings for interfaces From the command line interface, use the following syntax to display the current status and the setting for a specific interface:...
We recommend that you configure any network equipment that you plan to use with the BIG-IP system to auto-negotiate speed and duplex settings. F5 Networks strongly recommends you do not change the default settings, but if you do connect the BIG-IP system to network devices...
Page 46
Chapter 4 The valid media types for this command are: • auto • 10baseT half • 10baseT full • 100baseTX half • 100baseTX full • 1000baseT half • 1000baseT full • 1000baseSX full • 1000baseLX full • 10GbaseT full • 10GbaseSR full •...
Using Additional 6900/8900 Platform Functionality Network interface LED behavior The appearance and behavior of each network interface LED indicate network traffic activity, interface speed, and interface duplexity. The network interface speed LED behavior is defined in Table 4.6. Interface Speed LED Appearance No Link The LED is not lit and does not display any color.
Page 48
Chapter 4 The appearance and behavior of the LEDs for the SFP ports correspond with traffic activity. The SFP port interface status LED behavior is defined in Table 4.9. Interface Status LED Appearance Idle The LED is not lit and does not display any color. Full duplex The LED blinks green.
Using Always-On Management Introducing Always-On Management The Always-On Management (AOM) subsystem provides you the capability to manage the 6900/8900 platform remotely using SSH or a serial console, even if the host is powered down. AOM consists of the following elements: ◆...
Chapter 5 Accessing the AOM Command Menu You can access the AOM Command Menu through the host console shell (hostconsh) using the front panel serial console, or remotely through SSH. The following section describes how to access the command menu both through the serial console and with an SSH client to the management interface.
Using Always-On Management Setting up Always-On Management SSH access You can use the AOM Command Menu to set up remote SSH access to the BIG-IP system. To set up remote access, use the AOM network configuration utility (Option N in the command menu) to configure an IP address, netmask, and gateway for the AOM subsystem.
Page 54
Chapter 5 Each of these options is described in Table 5.1. Note that some of these commands are not intended for use by end users. Table 5.1 also specifies which commands are not recommended for use by users. Option Description Exits the AOM Command Menu and returns to terminal emulation mode.
Configuring and Maintaining a FIPS Security Domain • Understanding the FIPS implementation • Installing the BIG-IP systems and connecting a serial console • Creating the FIPS security domain • Running the Configuration utility • Running the fipscardsync utility to synchronize the FIPS HSMs •...
Configuring and Maintaining a FIPS Security Domain Understanding the FIPS implementation ® The BIG-IP system includes the option to install a FIPS hardware security module (HSM). Currently, the FIPS HSM is available in the BIG-IP 6900/8900 platform. With this release, the HSM and the BIG-IP key management software provide FIPS-140 level 2 support.
Chapter 6 Creating the FIPS security domain The first task in creating a FIPS security domain is to initialize the FIPS HSM and create a security officer (SO) password. The SO password is required to re-initialize the HSM. When you are configuring a redundant system, you need to initialize the security domain on one unit, and then initialize the card on the peer unit using the same security domain name you used on the first unit.
For details about running the Configuration utility and creating a base network configuration, see the BIG-IP Quick Start Instructions. These instructions are included in the BIG-IP Resource Kit shipped with each unit. You can also access these instructions at https://support.f5.com. Running the fipscardsync utility to synchronize the FIPS HSMs After you set up the system with the Configuration utility, you can synchronize the FIPS HSMs with the fipscardsync utility.
Chapter 6 Managing FIPS keys The web-based Configuration utility provides a key management interface. You can use the Configuration utility to create FIPS keys, convert existing keys to FIPS keys, and import existing keys into the system. Note Once a key is converted to FIPS, the process cannot be reversed. To create FIPS keys using the Configuration utility 1.
Page 61
Configuring and Maintaining a FIPS Security Domain To import existing keys using the Configuration utility 1. On the Main tab of the navigation pane, expand Local Traffic and click SSL Certificates. This displays the list of existing certificates. 2. In the upper right corner of the screen, click Import. 3.
Chapter 6 Planning for system recovery There are three different ways you can plan for a system recovery. You can maintain a redundant system. In the event of a failure, the ◆ standby unit becomes active and handles incoming traffic. ◆...
1. Ensure that current BIG-IP software is configured and install your saved UCS on the new replacement system. See https://support.f5.com for information on backup and recovery of a BIG-IP UCS file. 2. Connect the currently active unit to new replacement unit.
Replacing AC Power Supplies About the AC power supply The 6900/8900 platform contains, by default, a total of two hot swappable AC power supplies. The platform supports power redundancy, which ensures that the system is unaffected if a single power supply fails. WARNING Running without both power supplies installed in the platform can affect cooling and electromagnetic interference (EMI).
Chapter 7 Replacing a power supply The design of the 6900/8900 platform is such that you can remove a power supply from the chassis without powering down the system, provided that there is at least one power supply operating during the replacement process. To replace a power supply 1.
Page 69
Replacing AC Power Supplies 7. Tighten the screw into place using an appropriate screwdriver. The power supply is connected to the system when you tighten the screw completely. 8. Attach the power cord to the new power supply. 9. Ensure that the power switch, located on the power supply next to the screw, is in the ON position.
Replacing DC Power Supplies About the DC power supply The 6900/8900 platform is available with hot swappable DC power supplies. The platform supports power redundancy, which ensures that the system is unaffected if a single power supply fails. The DC power supply does not have an on/off switch. You can control the power from the rack switch or the DC power source.
Page 74
Chapter 8 Note The 6900/8900 platform must be grounded to a common bonding network (CBN). Note The battery return terminals on the 6900/8900 system are in an isolated DC return (DC-I) configuration. Note The 6900/8900 platform must be installed in a restricted access location such as a central office or customer premises environment.
Replacing DC Power Supplies About the DC power supply and wiring block Figure 8.1 shows the DC power supply and the DC wiring block for the 6900/8900 platform. Figure 8.1 The 6900/8900 Platform DC power supply and wiring block Figure 8.2 shows the individual components of the DC wiring block for the 6900/8900 platform.
1. Review the power supply label and determine the correct wire size for your installation. Note: F5 Networks recommends that you use 14 AWG copper wire. 2. Use the wire stripping tool to remove 3/8 in. (9.56 mm) of insulation.
The DC power supply does not have an on/off switch. You can control the power from the rack switch or the DC power source. Important When you connect the DC power source, F5 Networks recommends that you follow the safety requirements defined for the facilities where the DC-powered platforms will be installed.
Chapter 8 5. Slide the DC power supply into the power supply slot. 6. Connect the wiring block that you assembled earlier to the DC power source and be sure to connect the ground wire to a common bonding network (CBN). 7.
Page 79
Replacing DC Power Supplies 4. Remove the power supply from the system by pulling straight toward you. 5. Ensure that the latch on the new power supply is in the down position, and then slide the power supply into the power supply slot until the latch engages.
Chapter 8 Guidelines for DC-powered equipment A DC-powered installation must meet the following requirements: • Install the unit using a 20 Amp external branch circuit protection device. • For permanently-connected equipment, incorporate a readily accessible disconnect in the fixed wiring. •...
Replacing the Fan Tray About the fan tray The 6900/8900 platform has a removable fan tray that is designed to maintain the airflow throughout the chassis. You can change or replace the fan tray as part of the routine maintenance of the unit or in the event of a fan failure.
Chapter 9 Replacing the fan tray You do not need special tools to replace the fan tray. You can perform this maintenance while the unit is running. You do not need to power down the unit when replacing the fan tray; however, we highly recommend that you do not leave the unit operating without a fan tray for longer than 30 seconds.
Replacing Hard Drives • About the hard drives • If a hard drive fails • Hard drive replacement on a BIG-IP 10.1.0 system • Hard drive replacement on a BIG-IP 10.0.1 system...
Replacing Hard Drives About the hard drives ® The BIG-IP 6900 and 8900 platforms have two removable hard drives. You can change or replace the hard drives as part of the routine maintenance of the unit or in the event of a drive failure. Important We recommend that you back up your BIG-IP configuration files any time you change them.
If you would like to get the system up and running while you wait for a ◆ ® replacement hard drive from F5 Networks , you can perform the following steps: 1. Swap the hard drives. 2. Reinstall the BIG-IP software.
If you are running a manufacturing installation of the BIG-IP version 10.1.0 software, your system supports hard drive mirroring using RAID. You can add the replacement hard drive that you received from F5 Networks to the new system. 1. Hard drive bay 1 2.
MD1 remove HD2 Next, you can remove the faulty hard drive and replace it with the new one you received from F5 Networks. Replacing the hard drive To replace the hard drive 1.
Page 91
Replacing Hard Drives 3. Remove the faulty hard drive: a) Loosen the hard drive screw by turning it counterclockwise, using an appropriate screwdriver if necessary. Note: The screws that hold the hard drives to the chassis are captive and cannot be removed. b) Grasp the ejector handle and pull straight toward you to eject the hard drive from the system.
Chapter 10 Hard drive replacement on a BIG-IP 10.0.1 system If you are running version 10.0.1 of the BIG-IP software and have previously used the sparedisk utility to copy the contents of your primary hard drive to the spare hard drive, you can move the spare hard drive to the primary hard drive bay.
Replacing Hard Drives Replacing the primary hard drive with the spare hard drive If you have run the sparedisk utility previously, you can move the spare hard drive to the primary hard drive bay. To replace the primary hard drive with the spare hard drive 1.
Adding the replacement hard drive After you have replaced the primary hard drive with the spare hard drive, you can add the replacement hard drive that you received from F5 Networks to the new system. To add the replacement hard drive 1.
Replacing Hard Drives 2. Type the following command: sparedisk This process takes several minutes. As the new hard drive is written, you will see status updates on the screen. 3. Verify the status of the spare disk by typing the following command: sparedisk --query Output similar to the following example displays:...
Working with Environmental Guidelines for the 6900/8900 Platform Environmental requirements Before you install the 6900/8900 platform, review the following guidelines to make sure that you are installing and using the platform in the appropriate environment. General environmental guidelines The 6900/8900 platform is an industrial network appliance, designed to be mounted in a standard 19-inch EIA rack.
Understanding Platform Airflow Reviewing platform airflow information When you install the 6900/8900 platform into a rack, it is important to understand the unit’s airflow direction so that you can ensure proper cooling. Airflow for the 6900/8900 platform The 6900/8900 platform employs a negative pressure fan system, which draws cold air in from the front of the chassis and exhausts hot air out the back, as shown in Figure 12.1.
Reviewing Hardware Specifications • General specifications for system features • 6900 platform hardware and operating specifications • 8900 platform hardware and operating specifications • Acoustic, airflow, and altitude specifications...
Reviewing Hardware Specifications General specifications for system features Table 13.1 contains general specifications for BIG-IP system features that are available on the 6900/8900 platform. Item Specification Server/Node operating Load balancing of any TCP/IP operating system, system compatibility ® including Windows 95, Windows 98, Windows NT, Windows 2000, Windows XP, Windows Vista;...
Chapter 13 6900 platform hardware and operating specifications Table 13.2 lists hardware and operating specifications that apply to the 6900 platform. Item Specification Dimensions 3.5"H x 17.75"W x 20.75"D (8.89 cm H x 45.09 cm x 52.71 cm D) per unit 2U industry standard rack-mount chassis Mounts in a standard 19-inch EIA rack Weight...
Page 109
Reviewing Hardware Specifications Item Specification Maximum heat 1502 BTUs generated Operating temperature 32° to 104° F (0° to 40° C) Relative humidity 5 to 85% @ 104° F (40° C) Safety agency UL 60950 (UL1950-3) approval CSA-C22.2 No. 60950-00 (Bi-national standard with UL 60950) CB TEST CERTIFICATION TO IEC 950 EN 60950...
Chapter 13 8900 platform hardware and operating specifications Table 13.3 lists hardware and operating specifications that apply to the 8900 platform. Item Specification Dimensions 3.5"H x 17.75"W x 20.75"D (8.89 cm H x 45.09 cm x 52.71 cm D) per unit 2U industry standard rack-mount chassis Mounts in a standard 19-inch EIA rack Weight...
Page 111
Reviewing Hardware Specifications Item Specification Maximum heat 1826 BTUs generated Operating temperature 32° to 104° F (0° to 40° C) Relative humidity 5 to 85% @ 104° F (40° C) Safety agency UL 60950 (UL1950-3) approval CSA-C22.2 No. 60950-00 (Bi-national standard with UL 60950) CB TEST CERTIFICATION TO IEC 950 EN 60950...
Chapter 13 Acoustic, airflow, and altitude specifications Table 13.4 describes acoustic level, airflow movement, and operational altitude specifications for the BIG-IP 6900/8900 platform. Detail Units 6900 8900 Acoustic [1] Front Rear Left Right Altitude [2] Operational Feet 13,000 13,000 Non-operational...
Platform-Specific Hazardous Substance Levels for China 6900 platform This table lists hazardous substances controlled by China and shows how the ® F5 Networks 6900 platform components conform to the standards. Platform Guide: 6900 and 8900 A - 1...
Appendix A 8900 platform This table lists hazardous substances controlled by China and shows how the ® F5 Networks 8900 platform components conform to the standards. A - 2...
Page 119
Glossary Always-On Management The Always-On Management (AOM) subsystem provides you the capability to manage the 6900/8900 platform remotely using SSH or a serial console, even if the host subsystem is powered down. bigpipe The bigpipe utility provides command line access to the BIG-IP software. chassis A chassis refers to the housing component of the 6900/8900 platform.
Page 120
Glossary SSL (Secure Sockets Layer) SSL is a protocol that uses a public key to encrypt data transmitted through the Internet over an SSL connection. URLs using an SSL connection start with HTTPS instead of HTTP. subnetwork The portion of a network that shares a common address component is called a subnetwork.
Page 123
Index AC power cord DC power supply and replacing a power supply 7-2 and connecting the DC power source 8-5 AC power supply and specifications 13-2, 13-4 and specifications 13-2, 13-4 DC power supply support 8-1 acoustic specifications 13-6 DC wiring block administrative environment support 13-1 assembling and preparing 8-4 airflow...
Page 124
Index configuring 4-3 displaying node status 4-3 halt operation 3-2 for alert conditions 4-2 hard drive capacity 13-2, 13-4 for SFP ports 4-7, 4-8 hard drive replacement for special conditions 4-3 and BIG-IP version 10.0.0 10-2 locating 1-2 and BIG-IP version 10.0.1 10-2, 10-6 when green 4-3 and BIG-IP version 10.1.0 10-2, 10-3 when yellow 4-3...
Page 125
SSH access, setting up 5-3 operating temperature 13-3, 13-5 replaceable components optic modules 13-2, 13-4 and AC power supply 7-2 and support by F5 Networks 1-1 and DC power supply 8-6 and fan tray 9-2 and hard drives 10-2 Rotate mode 3-2...
Page 126
Index SFP+ port and inclusion in platform 1-1 and LED appearance 4-8 SFP+ port LEDs and appearance 4-8 and behavior 4-8 SO, see security officer sparedisk utility 10-2 specifications, hardware for 6900 platform 13-2 for 8900 platform 13-4 for China, material content A-1, A-2 for system features 13-1 and AOM Command Menu 5-2 SSH access, remote 5-3...
Need help?
Do you have a question about the BIG-IP 6900 and is the answer not in the manual?
Questions and answers