Unable to reach one of the appliances in a cluster intermittently
Originally Published: 2009-11-16
Last Modified: 2023-09-25
Article Number
Applies To
RSA Key Manager Appliance 2.5.0.3
BIG-IP F5 Load Balancer
Issue
Load balancer setup in the same subnet as the RKM Appliances marks one of the appliances as inactive, while the other appliance is marked as active.
A Windows box on the same subnet as the RKM Appliances can connect to (/KMS, /rkmawa, /admingui on) one of the appliances without any problem (using its IP, not through the load balancer), but can only intermittently connect to the other appliance (using its real IP) that is also marked as inactive by the Load Balancer.
Other computers on different subnet than the RKM Appliances can consistently connect successfully to both appliances (through their real IP addresses).
Cause
Resolution
Notes
1. Determine MAC address being used by the RKM Appliance Ethernet interface(s):
- Log in as root via ssh
- Type in the command "ifconfig" and make a note of IP address ('inet addr') and the corresponding MAC address for Ethernet/NIC ('HWaddr')
2. Determine MAC address for the RKM Appliance being set on the BIG-IP load balancer:
- Log in to the load balancer admin console via browser
- Go to Main -> Network -> ARP -> Dynamic List
- Confirm whether or not the MAC address listed for the RKM Appliance matches with what you get from #1 above.
- If the MAC address does not match, a temporary workaround is to delete the rogue entry from the Dynamic List and manually add the RKM Appliance IP address with the correct MAC address under Static List
3. Determine MAC address for the RKM Appliance being set on a Windows box on the same subnet:
- Open a command prompt and type in the command "arp -a". If no recent attempt has been made to connect to the RKM Appliance, the list will not show a cached entry for the RKM Appliance IP and a paired up MAC address.
- Open a browser and attempt to connect to either of /KMS, /rkmawa, or /admingui. You may get an error that page can not be displayed.
- Type in the command "arp -a" again, and check the cache entries for the RKM Appliance IP/MAC address against what you get in #1 above.
If the MAC address assigned to the RKM Appliance IP address on either Load Balancer or Windows box do not match up with what you get in step #1 above, it is an indication of a rogue device on the same subnet configured to use the same IP as the RKM Appliance.
Related Articles
Remote Administration failing with one of several listed errors 8Number of Views When approval activities are grouped by category, they auto-complete when one of the items is rejected in RSA Identity Gov… 95Number of Views Error: Principal does not possess one or more authenticators when using RSA SecurID Access Authenticate app tokencode with… 591Number of Views 'One or more attributes used in Join Condition has duplicate values' error during unification in RSA Identity Governance &… 124Number of Views Face ID is not recognized using Android Securid 4.1.6.2 10Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Unable to login to RSA Authentication Manager Security Console as super admin Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x
Don't see what you're looking for?