StorageGRID active gateway node is unable to reach the HA Group Virtual IP (VIP)
Applies to
StorageGRID 11.9.0.
Issue
- The active gateway node is unable to reach the HA Group Virtual IP (VIP) address, while the passive gateway node and all other containers in the environment can connect to the VIP without issue.
- Environment topology:
- Public IP is configured as an IRV (Integrated Routing and Bridging) interface on a Mellanox switch.
- Traffic is routed to a Juniper SRX345 firewall, which performs DNAT (port forwarding) for inbound port 443 to the StorageGRID load balancer HA Group VIP.
Troubleshooting performed:
- General internet connectivity verified (ping and curl to external hosts succeed from all hosts).
- DNS resolution happens successfully for the public IP of the router. But all the curl requests to the S3 Port (443) is giving timeouts.
/etc/hostsentry was added on all hosts mapping to the HA Group VIP (local IP). Passive gateway node and all other containers can successfully reach the VIP using the same /etc/hostsentry.
