All systems R81.20 Take 98.
I'm looking at a Maestro setup configured as multi-site with direct connections between MHO (Sync-int, sync-ext) and dual MHO.
All connections are up and the MHO are configured as site 1, 2, id 1, id 2 per site.
Next, we have a VSX security group with Force SGM connected on the same ports on MHO1_1 and MHO1_2 on site 1, and MHO2_1 and MHO2_2 on site 2.
The SG is created and works.
According to the network integrator (outside my control and area of visibility), both sites have perfect replication in terms of L1/L2, since the SG work, this makes sense.
Site 1 |
Site 2 |
MHO1_1 |
MHO2_1 |
MHO1_2 |
MHO2_2 |
Force with uplink to each MHO |
Force with uplink to each MHO |
The administration guides were followed to create the security group, everything was done on 1_1 and the 2 sites appear in the MHO configuration.
We get an active/active system, VS0 created as singly VSX gateway with SG IP.
Now the issue are as follows:
On the 2nd site MHO, orchd/asg commands stall or don't produce output. Sometimes a command like "orchd stat" on the MHO or asg monitor will work then on another run in the same session will stall and hang.
SSH to MHO site 2 works but not HTTPS.
If we failover the SG to site 2, we get the same scenario with unreliable SSH output and policy install on VS0 fails with SSL errors in the policy installation output.
I don't have other experience with dual site so I can't compare. The network should be fine, so I'm wondering if there are extra steps or something I would have missed in the process which could make sense here.
As far as I know, we followed all administration guides and relevant SK.