Skip to content

F5 BIG-IP

tmsh: virtual servers, pools, members, certificates and failover.

Other / vendor neutral Requires SmartCom Revisited 1.0.0 or newer

by Nathan Kirk · 77 downloads · MIT licence · revision 1 · published 14 Aug 2026

This bundle can change or destroy device state

  • Reboots or reloads the device (1 step) — Restarts the device. Any session on it drops, and anything not saved is lost.
Show exactly which steps matched
  • Reboot BIG-IP — Reboots or reloads the device (steps[1], sent text)

    tmsh reboot

Flagged automatically by matching command text. It is a prompt to read the script, not a verdict — plenty of legitimate buttons reboot things on purpose.

Download

3 sets, 91 buttons, 108 steps · 97.9 KB

File format version 1 · exported by Smartcom Revisited

Download .buttons.json
SHA-256 14dcd3ef1671536b6cf2eb49bdd759b1c4cd8ea6d117266c4ab4653e799b54bc

You get the exact file the uploader submitted, byte for byte — that checksum is what sha256sum will print. Import it from the button panel in SmartCom Revisited.

About this set

BIG-IP LTM through tmsh: virtual server and pool state, taking members in and out of service, certificate expiry, connection tables and the config-sync and failover commands.

Every button, in full

Exactly what gets sent

This is the complete script of the file below — nothing is summarised or hidden. Read it before you download it, the same way you would read a script someone emailed you.

BIG-IP - Virtual Servers & Pools

30 buttons

Virtual servers, pools, members, monitors and persistence.

Virtual Server List

Run: tmsh list ltm virtual one-line

1 step

  1. Send
    tmsh list ltm virtual one-line

    Sends Enter afterwards.

Virtual Server Status

Run: tmsh show ltm virtual

1 step

  1. Send
    tmsh show ltm virtual

    Sends Enter afterwards.

Virtual Server Detail

Run: tmsh show ltm virtual {{VSERVER}}

1 step · 1 input

  1. Send
    tmsh show ltm virtual {{VSERVER}}

    Sends Enter afterwards.

Virtual Server Config

Run: tmsh list ltm virtual {{VSERVER}}

1 step · 1 input

  1. Send
    tmsh list ltm virtual {{VSERVER}}

    Sends Enter afterwards.

Virtual Servers Down

Run: tmsh show ltm virtual | grep -B 3 -i "offline\|unavailable"

1 step

  1. Send
    tmsh show ltm virtual | grep -B 3 -i "offline\|unavailable"

    Sends Enter afterwards.

Pool List

Run: tmsh list ltm pool one-line

1 step

  1. Send
    tmsh list ltm pool one-line

    Sends Enter afterwards.

Pool Status

Run: tmsh show ltm pool

1 step

  1. Send
    tmsh show ltm pool

    Sends Enter afterwards.

Pool Detail

Run: tmsh show ltm pool {{BACKEND}}

1 step · 1 input

  1. Send
    tmsh show ltm pool {{BACKEND}}

    Sends Enter afterwards.

Pool Config

Run: tmsh list ltm pool {{BACKEND}}

1 step · 1 input

  1. Send
    tmsh list ltm pool {{BACKEND}}

    Sends Enter afterwards.

Pool Members

Run: tmsh show ltm pool {{BACKEND}} members

1 step · 1 input

  1. Send
    tmsh show ltm pool {{BACKEND}} members

    Sends Enter afterwards.

Pools with Down Members

Run: tmsh show ltm pool | grep -B 5 -i "offline"

1 step

  1. Send
    tmsh show ltm pool | grep -B 5 -i "offline"

    Sends Enter afterwards.

Node List

Run: tmsh show ltm node

1 step

  1. Send
    tmsh show ltm node

    Sends Enter afterwards.

Node Detail

Run: tmsh show ltm node {{MEMBER}}

1 step · 1 input

  1. Send
    tmsh show ltm node {{MEMBER}}

    Sends Enter afterwards.

Health Monitors

Run: tmsh list ltm monitor one-line

1 step

  1. Send
    tmsh list ltm monitor one-line

    Sends Enter afterwards.

Monitor Detail

Run: tmsh list ltm monitor http {{MONITOR}}

1 step · 1 input

  1. Send
    tmsh list ltm monitor http {{MONITOR}}

    Sends Enter afterwards.

Persistence Records

Run: tmsh show ltm persistence persist-records

1 step

  1. Send
    tmsh show ltm persistence persist-records

    Sends Enter afterwards.

Persistence for Virtual

Run: tmsh show ltm persistence persist-records virtual {{VSERVER}}

1 step · 1 input

  1. Send
    tmsh show ltm persistence persist-records virtual {{VSERVER}}

    Sends Enter afterwards.

iRules

Run: tmsh list ltm rule one-line

1 step

  1. Send
    tmsh list ltm rule one-line

    Sends Enter afterwards.

iRule Detail

Run: tmsh list ltm rule {{NAME}}

1 step · 1 input

  1. Send
    tmsh list ltm rule {{NAME}}

    Sends Enter afterwards.

Profiles on Virtual

Run: tmsh list ltm virtual {{VSERVER}} profiles

1 step · 1 input

  1. Send
    tmsh list ltm virtual {{VSERVER}} profiles

    Sends Enter afterwards.

SNAT Pools

Run: tmsh list ltm snatpool

1 step

  1. Send
    tmsh list ltm snatpool

    Sends Enter afterwards.

Traffic Statistics

Run: tmsh show ltm virtual {{VSERVER}} | grep -A 10 Traffic

1 step · 1 input

  1. Send
    tmsh show ltm virtual {{VSERVER}} | grep -A 10 Traffic

    Sends Enter afterwards.

Enable Pool Member

Run: tmsh modify ltm pool {{BACKEND}} members modify { {{MEMBER}} { state user-up session user-enabled } }

1 step · asks for confirmation before it runs · 2 inputs

  1. Send
    tmsh modify ltm pool {{BACKEND}} members modify { {{MEMBER}} { state user-up session user-enabled } }

    Sends Enter afterwards.

Enable Virtual Server

Run: tmsh modify ltm virtual {{VSERVER}} enable

1 step · asks for confirmation before it runs · 1 input

  1. Send
    tmsh modify ltm virtual {{VSERVER}} enable

    Sends Enter afterwards.

Reset Virtual Server Statistics

Run: tmsh reset-stats ltm virtual {{VSERVER}}

1 step · asks for confirmation before it runs · 1 input

  1. Send
    tmsh reset-stats ltm virtual {{VSERVER}}

    Sends Enter afterwards.

Disable Pool Member

Run: tmsh modify ltm pool {{BACKEND}} members modify { {{MEMBER}} { session user-disabled } }

2 steps · asks for confirmation before it runs · 2 inputs

  1. Confirm

    Asks yes or no: “Disable {{MEMBER}} in {{BACKEND}}. New connections stop, but existing ones continue — the usual first step before maintenance. Check the pool has other members up first. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh modify ltm pool {{BACKEND}} members modify { {{MEMBER}} { session user-disabled } }

    Sends Enter afterwards.

Force Pool Member Offline

Run: tmsh modify ltm pool {{BACKEND}} members modify { {{MEMBER}} { state user-down session user-disabled } }

2 steps · asks for confirmation before it runs · 2 inputs

  1. Confirm

    Asks yes or no: “Force {{MEMBER}} offline. Existing connections are dropped, not drained — anyone mid-request on that server sees an error. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh modify ltm pool {{BACKEND}} members modify { {{MEMBER}} { state user-down session user-disabled } }

    Sends Enter afterwards.

Disable Virtual Server

Run: tmsh modify ltm virtual {{VSERVER}} disable

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Disable {{VSERVER}}. The service it publishes stops accepting new connections — this is a user-visible outage for that application. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh modify ltm virtual {{VSERVER}} disable

    Sends Enter afterwards.

Delete Pool Member

Run: tmsh modify ltm pool {{BACKEND}} members delete { {{MEMBER}} }

2 steps · asks for confirmation before it runs · 2 inputs

  1. Confirm

    Asks yes or no: “Remove {{MEMBER}} from {{BACKEND}} entirely. Its connections drop and it must be re-added by hand. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh modify ltm pool {{BACKEND}} members delete { {{MEMBER}} }

    Sends Enter afterwards.

Delete Virtual Server

Run: tmsh delete ltm virtual {{VSERVER}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Delete {{VSERVER}}. The service disappears completely and the config must be rebuilt to restore it. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh delete ltm virtual {{VSERVER}}

    Sends Enter afterwards.

BIG-IP - Certificates & SSL

20 buttons

Certificate inventory, expiry, SSL profiles and key management.

Certificate List

Run: tmsh list sys crypto cert

1 step

  1. Send
    tmsh list sys crypto cert

    Sends Enter afterwards.

Certificate Detail

Run: tmsh list sys crypto cert {{CERT}}

1 step · 1 input

  1. Send
    tmsh list sys crypto cert {{CERT}}

    Sends Enter afterwards.

Certificate Expiry Dates

Run: tmsh list sys crypto cert | grep -E "sys crypto cert|expiration"

1 step

  1. Send
    tmsh list sys crypto cert | grep -E "sys crypto cert|expiration"

    Sends Enter afterwards.

Certificates Expiring Soon

Run: tmsh list sys crypto cert all-properties | grep -B 5 -A 2 expiration | head -60

1 step

  1. Send
    tmsh list sys crypto cert all-properties | grep -B 5 -A 2 expiration | head -60

    Sends Enter afterwards.

Key List

Run: tmsh list sys crypto key

1 step

  1. Send
    tmsh list sys crypto key

    Sends Enter afterwards.

CSR List

Run: tmsh list sys crypto csr

1 step

  1. Send
    tmsh list sys crypto csr

    Sends Enter afterwards.

Client SSL Profiles

Run: tmsh list ltm profile client-ssl one-line

1 step

  1. Send
    tmsh list ltm profile client-ssl one-line

    Sends Enter afterwards.

Client SSL Profile Detail

Run: tmsh list ltm profile client-ssl {{NAME}}

1 step · 1 input

  1. Send
    tmsh list ltm profile client-ssl {{NAME}}

    Sends Enter afterwards.

Server SSL Profiles

Run: tmsh list ltm profile server-ssl one-line

1 step

  1. Send
    tmsh list ltm profile server-ssl one-line

    Sends Enter afterwards.

Profiles Using Certificate

Run: tmsh list ltm profile client-ssl | grep -B 10 {{CERT}}

1 step · 1 input

  1. Send
    tmsh list ltm profile client-ssl | grep -B 10 {{CERT}}

    Sends Enter afterwards.

Certificate Chain Check

Run: openssl x509 -in /config/ssl/ssl.crt/{{CERT}}.crt -noout -text | head -30

1 step · 1 input

  1. Send
    openssl x509 -in /config/ssl/ssl.crt/{{CERT}}.crt -noout -text | head -30

    Sends Enter afterwards.

Certificate Subject & Dates

Run: openssl x509 -in /config/ssl/ssl.crt/{{CERT}}.crt -noout -subject -issuer -dates

1 step · 1 input

  1. Send
    openssl x509 -in /config/ssl/ssl.crt/{{CERT}}.crt -noout -subject -issuer -dates

    Sends Enter afterwards.

Verify Key Matches Certificate

The two hashes must match. If they do not, the key and certificate are not a pair.

2 steps · 1 input

  1. Send
    openssl x509 -noout -modulus -in /config/ssl/ssl.crt/{{CERT}}.crt | openssl md5

    Sends Enter afterwards.

  2. Send
    openssl rsa -noout -modulus -in /config/ssl/ssl.key/{{CERT}}.key | openssl md5

    Sends Enter afterwards.

SSL Handshake Test

Run: openssl s_client -connect {{HOST}}:{{PORT}} -servername {{FQDN}} < /dev/null 2>&1 | head -30

1 step · 3 inputs

  1. Send
    openssl s_client -connect {{HOST}}:{{PORT}} -servername {{FQDN}} < /dev/null 2>&1 | head -30

    Sends Enter afterwards.

SSL Statistics

Run: tmsh show ltm profile client-ssl {{NAME}}

1 step · 1 input

  1. Send
    tmsh show ltm profile client-ssl {{NAME}}

    Sends Enter afterwards.

Generate CSR

Run: tmsh create sys crypto csr {{CERT}} common-name {{FQDN}} key {{CERT}}

1 step · asks for confirmation before it runs · 2 inputs

  1. Send
    tmsh create sys crypto csr {{CERT}} common-name {{FQDN}} key {{CERT}}

    Sends Enter afterwards.

Generate Key and CSR

Run: tmsh create sys crypto key {{CERT}} key-size 2048 gen-csr ; tmsh list sys crypto csr {{CERT}}

2 steps · asks for confirmation before it runs · 1 input

  1. Send
    tmsh create sys crypto key {{CERT}} key-size 2048 gen-csr

    Sends Enter afterwards.

  2. Send
    tmsh list sys crypto csr {{CERT}}

    Sends Enter afterwards.

Import Certificate from File

Run: tmsh install sys crypto cert {{CERT}} from-local-file {{PATH}}

2 steps · asks for confirmation before it runs · 2 inputs

  1. Confirm

    Asks yes or no: “Install a certificate as {{CERT}}. If that name is already in use by a live SSL profile, this replaces it and every client connecting to that virtual server sees the new certificate immediately. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh install sys crypto cert {{CERT}} from-local-file {{PATH}}

    Sends Enter afterwards.

Assign Certificate to Profile

Run: tmsh modify ltm profile client-ssl {{NAME}} cert-key-chain replace-all-with { {{CERT}} { cert {{CERT}}.crt key {{CERT}}.key } }

2 steps · asks for confirmation before it runs · 2 inputs

  1. Confirm

    Asks yes or no: “Point profile {{NAME}} at certificate {{CERT}}. Every virtual server using this profile serves the new certificate at once — a wrong chain here breaks the site for all clients. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh modify ltm profile client-ssl {{NAME}} cert-key-chain replace-all-with { {{CERT}} { cert {{CERT}}.crt key {{CERT}}.key } }

    Sends Enter afterwards.

Delete Certificate

Run: tmsh delete sys crypto cert {{CERT}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Delete certificate {{CERT}}. If any SSL profile still references it, that profile — and the sites behind it — break. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh delete sys crypto cert {{CERT}}

    Sends Enter afterwards.

BIG-IP - System, HA & Diagnostics

41 buttons

Connections, resources, config sync, failover and logs.

Version & Platform

Run: tmsh show sys version

1 step

  1. Send
    tmsh show sys version

    Sends Enter afterwards.

Hardware Info

Run: tmsh show sys hardware

1 step

  1. Send
    tmsh show sys hardware

    Sends Enter afterwards.

System Uptime

Run: tmsh show sys uptime

1 step

  1. Send
    tmsh show sys uptime

    Sends Enter afterwards.

CPU Usage

Run: tmsh show sys cpu

1 step

  1. Send
    tmsh show sys cpu

    Sends Enter afterwards.

Memory Usage

Run: tmsh show sys memory

1 step

  1. Send
    tmsh show sys memory

    Sends Enter afterwards.

TMM Statistics

Run: tmsh show sys tmm-info

1 step

  1. Send
    tmsh show sys tmm-info

    Sends Enter afterwards.

Disk Usage

Run: tmsh show sys disk

1 step

  1. Send
    tmsh show sys disk

    Sends Enter afterwards.

Provisioning

Run: tmsh show sys provision

1 step

  1. Send
    tmsh show sys provision

    Sends Enter afterwards.

Licence Status

Run: tmsh show sys license detail

1 step

  1. Send
    tmsh show sys license detail

    Sends Enter afterwards.

Connection Table

Run: tmsh show sys connection

1 step

  1. Send
    tmsh show sys connection

    Sends Enter afterwards.

Connections for Host

Run: tmsh show sys connection cs-client-addr {{IP}}

1 step · 1 input

  1. Send
    tmsh show sys connection cs-client-addr {{IP}}

    Sends Enter afterwards.

Connections to Virtual

Run: tmsh show sys connection ss-server-addr {{IP}}

1 step · 1 input

  1. Send
    tmsh show sys connection ss-server-addr {{IP}}

    Sends Enter afterwards.

Connection Count

Run: tmsh show sys connection all-properties | grep -c "Conn"

1 step

  1. Send
    tmsh show sys connection all-properties | grep -c "Conn"

    Sends Enter afterwards.

Interface Status

Run: tmsh show net interface

1 step

  1. Send
    tmsh show net interface

    Sends Enter afterwards.

Trunk Status

Run: tmsh show net trunk

1 step

  1. Send
    tmsh show net trunk

    Sends Enter afterwards.

VLAN List

Run: tmsh list net vlan one-line

1 step

  1. Send
    tmsh list net vlan one-line

    Sends Enter afterwards.

Self IPs

Run: tmsh list net self one-line

1 step

  1. Send
    tmsh list net self one-line

    Sends Enter afterwards.

Routing Table

Run: tmsh show net route

1 step

  1. Send
    tmsh show net route

    Sends Enter afterwards.

ARP Table

Run: tmsh show net arp

1 step

  1. Send
    tmsh show net arp

    Sends Enter afterwards.

Device Group Status

Run: tmsh show cm sync-status

1 step

  1. Send
    tmsh show cm sync-status

    Sends Enter afterwards.

Failover Status

Run: tmsh show sys failover

1 step

  1. Send
    tmsh show sys failover

    Sends Enter afterwards.

HA Devices

Run: tmsh show cm device

1 step

  1. Send
    tmsh show cm device

    Sends Enter afterwards.

Traffic Group Status

Run: tmsh show cm traffic-group

1 step

  1. Send
    tmsh show cm traffic-group

    Sends Enter afterwards.

LTM Log Tail

Run: tail -{{LINES}} /var/log/ltm

1 step · 1 input

  1. Send
    tail -{{LINES}} /var/log/ltm

    Sends Enter afterwards.

Search LTM Log

Run: grep {{PATTERN}} /var/log/ltm | tail -{{LINES}}

1 step · 2 inputs

  1. Send
    grep {{PATTERN}} /var/log/ltm | tail -{{LINES}}

    Sends Enter afterwards.

Audit Log

Run: tail -{{LINES}} /var/log/audit

1 step · 1 input

  1. Send
    tail -{{LINES}} /var/log/audit

    Sends Enter afterwards.

System Log

Run: tail -{{LINES}} /var/log/messages

1 step · 1 input

  1. Send
    tail -{{LINES}} /var/log/messages

    Sends Enter afterwards.

Monitor Failures in Log

Run: grep -i "monitor status down" /var/log/ltm | tail -{{LINES}}

1 step · 1 input

  1. Send
    grep -i "monitor status down" /var/log/ltm | tail -{{LINES}}

    Sends Enter afterwards.

Running Services

Run: tmsh show sys service

1 step

  1. Send
    tmsh show sys service

    Sends Enter afterwards.

Config Modification Time

Run: ls -l /config/bigip.conf

1 step

  1. Send
    ls -l /config/bigip.conf

    Sends Enter afterwards.

Save Running Config

Persists config to disk. Changes made in tmsh survive a reboot only after this.

1 step · asks for confirmation before it runs

  1. Send
    tmsh save sys config

    Sends Enter afterwards.

Save Config to File

Run: tmsh save sys config file {{FILE}}

1 step · asks for confirmation before it runs · 1 input

  1. Send
    tmsh save sys config file {{FILE}}

    Sends Enter afterwards.

Create UCS Archive

Full backup including certificates and keys. Do this before any risky change.

1 step · asks for confirmation before it runs · 1 input

  1. Send
    tmsh save sys ucs {{FILE}}

    Sends Enter afterwards.

List UCS Archives

Run: ls -lh /var/local/ucs/

1 step

  1. Send
    ls -lh /var/local/ucs/

    Sends Enter afterwards.

Sync Config to Device Group

Run: tmsh run cm config-sync to-group {{GROUP}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Push this device's config to the whole group. Anything different on the peers is overwritten — make sure this unit is the one with the correct config. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh run cm config-sync to-group {{GROUP}}

    Sends Enter afterwards.

Sync Config from Device Group

Run: tmsh run cm config-sync from-group {{GROUP}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Pull the group config onto this device. Local changes that have not been synced out are lost. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh run cm config-sync from-group {{GROUP}}

    Sends Enter afterwards.

Force Failover to Standby

Run: tmsh run sys failover standby

2 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Make this unit standby so the peer takes traffic. Connections that are not mirrored drop during the switch. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh run sys failover standby

    Sends Enter afterwards.

Force Unit Offline

Run: tmsh run sys failover offline

2 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Take this unit fully offline. It stops processing traffic and will not take over even if the peer fails — leaving no redundancy at all. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh run sys failover offline

    Sends Enter afterwards.

Restore UCS Archive

Run: tmsh load sys ucs {{FILE}}

2 steps · asks for confirmation before it runs · 1 input

  1. Confirm

    Asks yes or no: “Restore the whole configuration from {{FILE}} and restart services. Everything configured since that archive is lost and traffic stops during the restore. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh load sys ucs {{FILE}}

    Sends Enter afterwards.

Restart TMM

Run: tmsh restart sys service tmm

2 steps · asks for confirmation before it runs

  1. Confirm

    Asks yes or no: “Restart the traffic management microkernel. Every connection through this BIG-IP drops — this is a full data-plane outage on this unit. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh restart sys service tmm

    Sends Enter afterwards.

Reboot BIG-IP

Run: tmsh reboot

2 steps · asks for confirmation before it runs

  • Reboots or reloads the device
  1. Confirm

    Asks yes or no: “Reboot this BIG-IP. All traffic through it stops for several minutes. Save the config and fail over to the peer first. Continue?”

    Answering no stops the script here.

  2. Send
    tmsh reboot

    Sends Enter afterwards.

Version history

  • Revision 1 current

    First published version.

    14 Aug 2026 · 97.9 KB · needs 1.0.0+ · 14dcd3ef1671536b…

Something wrong with this set?

Sign in to report it, or email abuse@smartcomrevisited.com.