F5 Modernization with Ansible Automation Platform

F5 DevCentral CommunityAbout 5 min readAug 14, 2025Watch original
THE SUMMARYAI-generated

Key Concepts

  • iSeries i10800: The source F5 BIG-IP appliance being migrated from.
  • Velos Tenant OS Partition: The destination F5OS tenant on a Velos chassis where the configuration is being migrated to.
  • Ansible Automation Platform: The automation tool used to orchestrate the migration process.
  • UCS (User Configuration Set) File: An archive containing the configuration of a BIG-IP system.
  • Master Key: A cryptographic key used to encrypt sensitive data within the UCS file.
  • VLANs (Virtual LANs): Logical networks used to segment traffic.
  • Self IPs: IP addresses assigned to the BIG-IP system for management and traffic processing.
  • LTM (Local Traffic Manager): BIG-IP module for load balancing and traffic management.
  • ASM (Application Security Manager): BIG-IP module for web application firewall (WAF) functionality.
  • APM (Access Policy Manager): BIG-IP module for access control and authentication.
  • F5OS: The operating system for the Velos chassis.

Migration Demonstration from iSeries to Velos Tenant OS Partition Using Ansible

This demonstration showcases a migration process from an F5 iSeries i10800 BIG-IP appliance to a Velos tenant OS partition using Ansible Automation Platform. The workflow is designed to automate the various stages of the migration, ensuring a smooth transition of configurations and services.

1. Source BIG-IP (i10800) Configuration

The demonstration begins by logging into the source i10800 BIG-IP appliance to review its configuration.

  • Tenants and Applications: Multiple tenants and applications are deployed on the i10800, with varying operational statuses.
  • Device Information: The i10800 is running version 15.1.10.6.
  • Resource Provisioning: LTM, ASM, and APM modules are provisioned on the device.
  • Network Configuration: Self IPs with addresses ending in ".80" and associated VLANs are identified for migration. The IP address management for the system is 14.80.

2. Destination Velos Chassis Partition

The next step involves logging into the Velos chassis partition to verify its initial state.

  • Tenant Images: Only a 17.5 tenant image is present.
  • VLANs: No VLANs are configured within the partition.

3. Backup and Configuration Gathering (Stages 1-3)

These stages focus on backing up critical configurations from the source i10800.

  • Master Key Backup: The Ansible playbook retrieves the master key from the i10800. This key is essential for decrypting sensitive data within the UCS file. The master key is then stored on a remote server for safekeeping.
  • UCS File Backup: A UCS file is created on the i10800, capturing the entire system configuration. This file is stored both locally on the BIG-IP and on the remote server, providing redundancy.
  • Configuration Information Gathering: Ansible modules are used to gather essential information from the i10800, including:
    • Hostname (verified as I10800)
    • Self IP addresses
    • VLAN configurations

4. Disabling Source BIG-IP and Creating Tenant OS Partition (Stages 3-4)

This section details the steps to prepare the environment for the migration.

  • Disabling Source BIG-IP: The i10800 is disabled to prevent IP address conflicts during the restoration process.
  • Verification of Backup Files: The Ansible playbook verifies that the inventory file, master key file, and UCS file are all present on the remote server.
  • VLAN and Tenant OS Partition Creation: Using the gathered information, the playbook creates the necessary VLANs and the tenant OS partition on the Velos chassis. VLANs like 30004 and 102 are created and assigned to the tenant. A management VLAN (314) with a unique management IP address is also configured to avoid conflicts. This is programmed from a template within Ansible Automation Platform.
  • Tenant Startup: The newly created tenant OS partition is started.

5. Ping Tests and Verification

  • Ping Tests: Ping tests are performed to verify network connectivity to the new tenant.
  • Access Verification: Access to the tenant's web interface is confirmed. The hostname is "localhost" and the address is 14.85, programmed for this tenant OS partition.

6. Restoration on New Tenant OS Partition (Stages 5-6)

These stages involve restoring the backed-up configuration onto the Velos tenant OS partition.

  • Master Key Restoration: The master key from the i10800 is restored onto the new tenant OS partition, overwriting the existing key. The crypto password is also set.
  • UCS File Restoration: The UCS file is uploaded from the remote server to the Velos tenant. A special command with a migration flag is used to initiate the restoration process. The system automatically upgrades the configuration from version 15.1.10.6 to 17.5.

7. Post-Migration Verification

After the restoration, the configuration of the Velos tenant is verified.

  • Version and Hostname: The version is confirmed as 17.5, and the hostname is the same as the original i10800.
  • Platform: The system is now running on a blade configuration, reflecting the Velos chassis architecture.
  • VLANs: All VLANs from the original configuration are present.
  • Virtual Servers: The tenants and their configurations are restored, with some being functional and others not, mirroring the state of the original i10800.
  • IP Address Conflicts: No IP address conflicts exist between the old and new systems. The old TMM configuration is down, and the management address of the new tenant was purposefully changed.
  • Resource Provisioning: LTM, ASM, and APM modules are provisioned.
  • Backup File: The UCS backup file is still located on the device, providing a third point of backup.

8. Migration Time

The total migration time was 23 minutes and 36 seconds. The creation and restoration of the Velos partition took the longest.

Conclusion

The demonstration successfully showcases the migration of an F5 BIG-IP configuration from an iSeries i10800 appliance to a Velos tenant OS partition using Ansible Automation Platform. The automated workflow streamlines the process, ensuring a consistent and efficient migration while minimizing downtime and potential errors.

AI summaries can miss context or contain errors. Check important details against the original video.

Go a little deeper.

Have a question about this video? Load its transcript to open the video chat.