GCP CMEK service_reachability failed during gcp check when using Private Service Connect
- Views:
- 162
- Visibility:
- Public
- Votes:
- 0
- Category:
- cloud-volumes-ontap-cvo
- Specialty:
- google_cloud_platform
- Last Updated:
Applies to
- ONTAP 9
- GCP
- CMEK
- CVO
Issue
Category: service_reachability
Status: FAILED
Details: Google Cloud Key Management Service operation "get" failed. Cryptsoft error: "IO".
Issue (privilege: diag) "security key-manager
external <akv|aws|gcp|ikp> invoke" for more
information.Cause
Internal load balancer not configured for the TCP protocol or Target.
- Working
==============================================================================================
NAME: Netapp-ilb3-nas-vm1-forwardingrule-tcp
REGION: us-central1
IP_ADDRESS: 192.168.1.4
IP_PROTOCOL: TCP
TARGET: us-central1/backendServices/Netapp-ilb3-nas-vm1-backendservice-tcp
NAME: Netapp-ilb3-nas-vm1-forwardingrule-udp
REGION: us-central1
IP_ADDRESS: 192.168.1.4
IP_PROTOCOL: UDP
TARGET: us-central1/backendServices/Netapp-ilb3-nas-vm1-backendservice-udp
==============================================================================================
- Non-working
==============================================================================================
NAME: Netapp-a47803-ilb-nas-vm1-forwardingrule-tcp
REGION: us-central1
IP_ADDRESS: 192.168.1.4
<<<<<<<<<<<<<<<================ Missing IP_PROTOCOL and TARGET
NAME: Netapp-a47803-ilb-nas-vm1-forwardingrule-udp
REGION: us-central1
IP_ADDRESS: 192.168.1.4
IP_PROTOCOL: UDP
TARGET: us-central1/backendServices/Netapp-a47803-ilb-nas-vm1-backendservice-udp
==============================================================================================
Solution
In the GCP console you can use the command "gcloud compute forward-rules list" to view the configuration.
Reach out to GCP for assistance adding the missing configuration.
