Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
tavi0906
Participant

Cluster disconnect from the New Management after 5-10min

weekend we migrated the HA gateway from a old management server to a new management (locate at different location)

 

Old management = OLD IP address

New Management = NEW IP address (At different location)

 

We have re-established SIC (OK)

We have installed policy from the New Management to the HA Cluster (OK)

The Cluster disconnect from the New Management after 5-10min, logs still incoming from the Cluster.

Test SIC failed, unbale to push policy to the Cluster.

 

This are the error shown:

ckpSSL_fwasync_connected: no connection err -1

ckpSSL GetErrorString: err_code is (-1)

ckpSSL_fwasync_connected: err_msg: (ckpssl timeout)

 

We unload the policy from the Cluster and push policy, it back to normal again, but after 5-10, the connections break again.

 

We couldn't see any deny logs from the SmartConsole.

We change the anti-spoofing from blocking mode to detect mode then the connections between Management and Cluster are stable, but we couldn't see any log drop by anti-spoofing.

4 Replies
Chris_Atkinson
Employee Employee
Employee

Please confirm the versions & JHF used for both new and old components and is each happily sync'd with NTP for their time?

CCSM R77/R80/ELITE
tavi0906
Participant

version R80.40 take 180

 

0 Kudos
HeikoAnkenbrand
Champion Champion
Champion

You write:
cut>>>
weekend we migrated the HA gateway from a old management server to a new management (locate at different location)
<<<cut

Do you have completely implemented the following SK's?

How to change the IP Address of a Security Management Server? 
How to renew SIC after changing IP Address of Security Management Server  

➜ CCSM Elite, CCME, CCTE
0 Kudos
tavi0906
Participant

We change the anti-spoofing from blocking mode to detect mode then the connections between Management and Cluster are stable, but we couldn't see any log drop by anti-spoofing

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events