Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Kaspars_Zibarts
Authority
Authority

Only half of connections synchronised during MVC upgrade, VSX R80.30 to R80.40

Had an interesting dilemma last night, just before cutover to R80.40 I normally collect CPVIEW stats on cluster member still running R80.30 so I have some quick baseline and then also compare connections table on upgraded member.

Funny (not!) enough upgraded member had only synchronised approx half of all connections on all VSes.

Not too sure if screenshot is big enough but it shows that at MVC state connections table is much smaller:

image.png

We proceeded just because we had "out of state" connections enabled, so I knew impact would be rather small but still interesting case. Had not noticed that before on my previous upgrades with non-VSX FWs nor other two clusters of VSX.

I even searched for a specific connection that I could find in R80.30 table and it was not present in R80.40

I have checked and most services apart from DNS are synched in cluster.

Was wondering if anyone else has noticed it?

 

0 Kudos
4 Replies
Magnus-Holmberg
Advisor

Kaspars you are our guinea pig for VSX upgrades, my personal view is never upgrade before HFA100. (just came out as ongoing)
I thought that MVC was just supported from R80.40 and above not going to R80.40.

Regards,
Magnus

https://www.youtube.com/c/MagnusHolmberg-NetSec
0 Kudos
Kaspars_Zibarts
Authority
Authority

Actually MVC is supported from R80.40 and works like a clock! Worked flawlessly on my VSLS cluster and regular FWs.

So i'm not too sure if it's the fact that we went with take 94 (previously we used take 91) or the fact that this was VSX HA no VSLS cluster.

As for guinea-pig.. this time we were "forced" to upgrade to fix problems 😞

Normally we stick to 100 rule too 🙂

_Val_
Admin
Admin

Could it be that most of those "missing" connections are marked as delayed sync services?

0 Kudos
Kaspars_Zibarts
Authority
Authority

Actually i suspected that but it was not the case. It was my own SSH connection to VSX mgmt and I have checked all TCP-22 objects and none has delayed sync.

I wonder if R&D would want to look at it as I dumped tables on both R80.30 and R80.40 🙂 

0 Kudos