メインコンテンツまでスキップ

SSLが有効になっていないため、SVMはFPolicyサーバに接続できません

環境

  • ONTAP 9
  • FPolicy
  • CIFS
  • SSL

問題

  • SVMがFPolicy サーバに接続できない
  • EMSで次のエラーが表示されます:
    • fpolicy: fpolicy.server.disconnect:error]: Connection to the FPolicy server "10.10.10.75" is broken ( reason: "Read returned error while reading message from FPolicy server." ).
    • fpolicy: fpolicy.server.disconnect:error]: Connection to the FPolicy server "10.10.10.75" is broken ( reason: "Send request to FPolicy server failed." ).
    • Connection to the FPolicy server "10.10.10.75" is broken ( reason: "Error encountered while sending a message to FPolicy to FPolicy server." ).
    • fpolicy.server.connectError: Node failed to establish a connection with the FPolicy server "xx.xx.xx.xx" of policy "Varonis" for Vserver SVM1 (reason: "Select Timed out."). 
  • apache-error.gzエラー:
    • [ssl:warn] [pid 12024:tid 34376559360] [client 10.10.10.75:52449] [vserver 1] SSL is not configured for this vserver
  • パケットトレース:
    • FPolicy サーバ側から接続の試行が開始されると 、NetAppはFPolicyサーバからのTLS Helloに応答せず、TCP接続の終了を要求します。SSLが有効になっていないため、SVMがFPolicyサーバに接続できない

    • NetApp側から接続の試行が開始されると、FPolicyサーバはFPolicyネゴシエート応答の送信後にTCP接続をリセットします。

FPolicyサーバがTCP接続をリセットする

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.