sk183293 - CVPND process fails to start on a newly created Virtual System
CVPND process fails to start on a newly created Virtual System
Symptoms
The CVPND process does not start on a newly created Virtual System, and the Mobile Access portal is down.
The output of command "cpwd_admin list" indicates that the CVPND process is terminated, for example:
[Expert@HostName]# cpwd_admin list | grep CVPND
CVPND 3 0 T 1 [23:45:18] 26/3/2025 N cvpnd /opt/CPcvpn-R81.20/CTX/CTX00003/log/cvpnd.elg /opt/CPcvpn-R81.20/CTX/CTX00003/conf/cvpnd.C
Attempting to access the Mobile Access Portal results in a "ERR_CONNECTION_RESET" error in the browser.
Attempting to start or restart the Mobile Access services with the commands "
cvpnstart" or "cvpnrestart", this error appears: Mobile Access: Failed to start cvpnd daemon. Look under /opt/CPcvpn-R81.20/CTX/CTX00006/log/cvpnd.elg for more info. Mobile Access: Failed to start cvpn service.The $CVPNDIR/log/cvpnd.elg file logs this error:
[DATETIME] Exception: SetDataReader::getField: Could not obtain the requested field - field name is: snxIpAddressToConnectTo - CVPND aborting
Cause
The snxIpAddressToConnectTo parameter is missing from the $CVPNDIR/conf/cvpnd.C file on the new Virtual System, preventing the CVPND from starting.
This parameter was introduced starting from these versions (Ref: PMTR-95099)
- Jumbo Hotfix Accumulator for R81.20 starting from Take 70
- Jumbo Hotfix Accumulator for R81.10 starting from Take 152
- Jumbo Hotfix Accumulator for R81 starting from Take 99
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 103
- Jumbo Hotfix Accumulator for R82.10 starting from Take 6
If you choose not to upgrade, follow these steps:
Run this procedure on the applicable Virtual System to manually add the missing snxIpAddressToConnectTo parameter:
Connect to the command line on the VSX Security Gateway / each VSX Cluster Member.
Log in to the Expert mode and switch to the affected Virtual System environment.
# vsenv <VSID>Back up the current
cvpnd.Cfile.
[Expert@HostName:VSID]# cp -v $CVPNDIR/conf/cvpnd.C{,_BACKUP}
- Add the missing
snxIpAddressToConnectToparameter:
[Expert@HostName:VSID]# cvpnd_settings $CVPNDIR/conf/cvpnd.C add snxIpAddressToConnectTo "" nobackup
Example output:
Successfully created snxIpAddressToConnectTo with an empty value.
If you are in a cluster environment - you must make the same changes on each member.
You must restart the services by running cvpnrestart for the changes to take effect.
- Restart the Mobile Access services to apply the changes:
[Expert@HostName:VSID]# cvpnrestart
- Make sure that the
CVPNDis running properly:
[Expert@HostName:VSID]# cpwd_admin list | grep CVPND
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2025-03-27
Last Modified: 2026-05-26