メインコンテンツまでスキップ

暗号化変更後のクラスタピアの障害

Views:
4
Visibility:
Public
Votes:
0
Category:
snapmirror<a>2009743198</a>
Specialty:
dp
Last Updated:

環境

  • ONTAP 9.11.1P8
  • 暗号化
  • クラスタ ピアリング

問題

  • クラスタピアの一方のクラスタで暗号化暗号スイートを更新すると、クラスタピアリングが失敗します。
  • cluster peer health show -bypass-cache true を実行すると、ノードへの接続が次のように表示されます。
cluster1::> cluster peer health show -bypass-cache true Node Cluster-Name Node-Name Ping-Status RDB-Health Cluster-Health Availability ---------- --------------------------- --------- --------------- ------------ c1node-01 cluster2 c2node-01 Data: unreachable ICMP: interface_reachable true true false c2node-02 Data: unreachable ICMP: interface_reachable true true false c1node-02 cluster2 c2node-01 Data: unreachable ICMP: interface_reachable true true false c2node-02 Data: unreachable ICMP: interface_reachable true true false 4 entries were displayed.
  • 必要な暗号スイートを両方のクラスタに追加しても問題が解決しない
  • KTLSハンドシェイクアラートが 表示される

ktls.cnxnHandshakeLimit: ONTAP reached the maximum limit of 170 concurrent TLS connection handshakes

 [cluster: ktlsd: ktls.failed:notice]: "The TLS connections have failed several times with remote host 'xx.xx.xx.xxx' in IPspace 'xxxxxxx', for which the latest reason given is: OpenSSL: error:0A000102:SSL routines::unsupported protocol."

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.