After ONTAP upgrade FPolicy blocks all traffic
Applies to
- ONTAP 9
- ONTAP 9.5P18
- ONTAP 9.7P17
- External FPolicy (Commvault)
- Firewall
Issue
After enabling the FPolicy policy, the external FPolicy engine does not connect to the SVM (Vserver)
::> vserver fpolicy enable -vserver <vserver> - policy-name <policy-name> -sequence-number <sequence-number>
::> vserver fpolicy show-engine -fields server -server-status disconnected
node vserver policy-name server
---------- --------------- ------------- -------
<node> <vserver> <policy-name> <server>
::> vserver fpolicy show-engine -server <ip-address> -instance
Node: <node>
Vserver: <vserver>
Policy: <policy>
Server: <ip-address>
Server Status: disconnected
Server Type: <server type>
Time FPolicy Server was Connected: -
Time FPolicy Server was Disconnected: <date\time>
Reason for FPolicy Server Disconnection: TCP Connection to FPolicy server failed.
ID for FPolicy Server Disconnection: <id>
Session ID: -