sk180981 - CloudGuard Controller fails to connect to Cluster with MDPS enabled

CloudGuard Controller fails to connect to Cluster with MDPS enabled

Product

CloudGuard Controller

Version

R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20

OS

Gaia

Platform

All

Last Modified

2024-03-31

Symptoms

[DATE TIME] ERROR datacenter.util.CommandExec [gateway-updater_]: command: [/opt/CPshrd-R81.10/bin/cprid_util, -server, , -timeout, 120, -stdout, /etc/fw/tmp/_vsecUpdate.sh.stdout, -verbose, rexec, -rcmd, /bin/bash, /etc/fw/tmp/_vsecUpdate.sh, , ] failed with exit code: 255

Cause

The default behavior of the CloudGuard Controller is to send the vsecUpdate.sh script to the Cluster VIP. With MDPS enabled, the Management can connect on the Management Plane only. The Cluster VIP resides in the Data Plane, so no connection is possible.

Solution

This problem was fixed. The fix is included in:

Check Point recommends to always upgrade to the Recommended version.

If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect CPinfo files from the Management Server and Security Gateways / Cluster Members involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.


After the Hotfix installation:

  1. Back up and edit the vsec.conf file on the Security Management server.

Locations of the vsec.conf file:

$FWDIR/conf/vsec.conf

$MDSDIR/conf/vsec.conf

  1. Add these lines to the configuration file:
# In version R81.10 with Jumbo HFA Take 95 and higher:
# Send Data Center updates from the CloudGuard Controller to the main IP address of Active member
# on the Management Plane instead of the cluster VIP address on the Data Plane
updateClusterMemberAndNotVip=true
  1. All configuration values are read from the vsec.conf file only when CloudGuard Controller is loaded. If you change one of the parameters, you must restart the CloudGuard Controller with the commands: "vsec stop ; vsec start"

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General Status: Approved by TAC Date Created: 2023-05-29 Last Modified: 2024-03-31