Workload Security configuration fails for ONTAP SVMs due to agent server firewall setup
- Views:
- 441
- Visibility:
- Public
- Votes:
- 0
- Category:
- data-infrastructure-insights
- Specialty:
- bluexp_insights
- Last Updated:
Applies to
- ONTAP 9.x
- Workload Security (WS)
- RHEL/CentOS Workload security agent
Issue
- Adding ONTAP SVMs as data collectors fail in WS through cluster IP
- Workload Security agent and the ONTAP can be in same subnet and no external firewall is configured between them
- If there is external firewall present, required ports are allowed and firewall logs show traffic
- Error in GUI:
Connector is in error state. Service.name: audit. Reason for failure: External fpolicy server terminated
FPOLICY-MLOG-TXT.GZ
:
[kern_fpolicy:error:7503] LIF_availability_check call Failed with error[-1]. [0x0x807e78a00] src/fsm/fsm_external_engine.cc:5139
[kern_fpolicy:error:7503] Establish TCP connection returned error.[0x0x807e78a00] src/fsm/fsm_external_engine.cc:5042
[virtual smdb_error fpolicy_appcfg_server_status_db_iterator::notify_imp(smdb_cdb_iterator::operation)] operation: [modify], policy: [3]
-
EMS-LOG-FILE.GZ
:
Sun Feb 12 23:53:45 +0200 [<node_name>]: fpolicy: fpolicy.server.connectError:error]: Node failed to establish a connection with the FPolicy server "<CS_Agent IP>" (reason: "TCP Connection to FPolicy server failed.").