Evening,
We've recently deployed a new Maestro stack that comprises the following:
2 x MHO-140s (single site)
3 x 9800 SGMs
VSX mode enabled
R81.20 T84
1 x VFW
We've configured both a Generic Data Centre Object & a Cisco ACI object to use the ESGs and ExternalEPGs in firewall policy. The GDO points to a JSON file stored in GitHub that contains the ExternalEPG information (we had to use this as a workaround due to the Cisco ACI object lacking the ability to query ExternalEPGs). The VFW policy uses the ESGs & ExternalEPGs as source & destination objects.
Connectivity testing commenced today, with intermittent results. I could see in the logs that some traffic was being accepted and some being dropped by the cleanup rule. Further analysis showed that the accepted traffic was for the SMO (member ID 1_1) and all dropped traffic was on members 1_2 & 1_3 (side note - it would be great if this field could be selected as a view option in dashboard!).
When logging into the SMO, switching to vsenv 1 and running dynamic_objects -cfo_show, the contents/IP ranges of the GDO object are displayed as expected. When moving to members 2 & 3 and switching to vsenv 1, the dynamic_objects -cfo_show command returns a "File not found" message.
I assumed that the SMO would have copied the GDO objects to the other SGMs, but it would appear that's not happening.
Has anyone seen this behaviour before? Or have any suggestions as to why the GDO objects aren't being copied to all members?
Thanks,
Aaron.