External Key manager unreachable from a management LIF
Applies to
- ONTAP 9
- External Key Manager Server (KMIP)
Issue
- KMIP boot interfaces using the incorrect port.
::*> security key-manager external boot-interfaces show
Address Network Override
Node Type Address/Mask Gateway Port Default?
-------- ------- ------------------ --------------- ----- --------
node1
ipv4 10.148.137.7/26 10.148.137.1 e0e false
node2
ipv4 192.168.139.103/24 192.168.139.1 e0c false
2 entries were displayed.
::*> debug kenv show -node node1
kmip.init.gateway: 10.148.137.1
kmip.init.interface: e0e
kmip.init.ipaddr: 10.148.137.7
kmip.init.netmask: 255.255.255.192
- Cannot ping the KMIP server using one node management interface. The LIF
node1_mgmt_2
cannot communicate to the KMIP server. The LIFnode1_mgmt_1
can:
::*> network ping -vserver Admin_svm -lif node1_mgmt_2 -destination x.x.x.x
no answer from x.x.x.x
::*> network ping -vserver Admin_svm -lif node1_mgmt_1 -destination x.x.x.x
x.x.x.x is alive