sk180981 - CloudGuard Controller fails to connect to Cluster with MDPS enabled
CloudGuard Controller fails to connect to Cluster with MDPS enabled
Product
CloudGuard Controller
Version
R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS
Gaia
Platform
All
Last Modified
2024-03-31
Symptoms
- CloudGuard Controller fails to connect to Cluster with Management Data Plane Separation (MDPS) enabled.
- In the $FWDIR/log/cloud_proxy.elg file on the Security Management server you can see that an error occurs when the Management sends the vsecUpdate.sh file to the Security Gateway, with exit code 255. For example:
[DATE TIME] ERROR datacenter.util.CommandExec [gateway-updater_]: command: [/opt/CPshrd-R81.10/bin/cprid_util, -server, , -timeout, 120, -stdout, /etc/fw/tmp/_vsecUpdate.sh.stdout, -verbose, rexec, -rcmd, /bin/bash, /etc/fw/tmp/_vsecUpdate.sh, , ] failed with exit code: 255
Cause
The default behavior of the CloudGuard Controller is to send the vsecUpdate.sh script to the Cluster VIP. With MDPS enabled, the Management can connect on the Management Plane only. The Cluster VIP resides in the Data Plane, so no connection is possible.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.10 starting from Take 95
- Jumbo Hotfix Accumulator for R81.20 starting from Take 26
Check Point recommends to always upgrade to the Recommended version.
If you choose not to upgrade, contact Check Point Support to get a Hotfix for your version.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect CPinfo files from the Management Server and Security Gateways / Cluster Members involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
After the Hotfix installation:
- Back up and edit the vsec.conf file on the Security Management server.
Locations of the vsec.conf file:
- On a Security Management Server :
$FWDIR/conf/vsec.conf
- On a Multi-Domain Management Server :
$MDSDIR/conf/vsec.conf
- Add these lines to the configuration file:
# In version R81.10 with Jumbo HFA Take 95 and higher:
# Send Data Center updates from the CloudGuard Controller to the main IP address of Active member
# on the Management Plane instead of the cluster VIP address on the Data Plane
updateClusterMemberAndNotVip=true
- All configuration values are read from the vsec.conf file only when CloudGuard Controller is loaded. If you change one of the parameters, you must restart the CloudGuard Controller with the commands: "
vsec stop ; vsec start"
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General Status: Approved by TAC Date Created: 2023-05-29 Last Modified: 2024-03-31