This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cannot set the "preferred primary device"

Good morning,

I have two clusters of XGS 2100 in HA (Active-Passive) running with the firmware version 19.5.0 GA-Build197. As per object, I am not able to set the preferred primary device on both the clusters. The error message is always the same: "Couldn't update HA".

Has someone had the same issue? If yes, how did you solve it?

Thank you and have a nice day!

Best regards,

Leonardo



This thread was automatically locked due to age.
Parents Reply Children
  • Good morning,

    thank you for your answer, I think you misunderstood my problem. My HA clusters are correctly configured and I have no issues related to them.

    The problem I have is just related to a HA preference. In System Services > High Availability > Preferred primary device, I cannot set my masters, in both my clusters, as preferred nodes. If I try to do it, and I click on "Save", the error message that I get is "Couldn't update HA".

    Thank you and have a nice day!

    Best regards,

    Leonardo

  • Hi : I am suspecting the bridge interface has been selected under Peer administration settings in your HA.

    Can you please confirm under "Peer administration settings" any bridge interface has been selected in your current HA settings? If yes then you are as of now impacted by the known issue NC-114932. You may use the mentioned workaround and post that you may update the required settings in HA.

    Reference: doc.sophos.com/.../index.html

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • Hello  ,

    thank you for your answer. Actually, I have no Peer administration settings configured:

    Thank you and have a nice day!

    Best regards,

    Leonardo

  • Hi  In that case we may need to check CSC debug and applog to confirm more during an error time when you are trying to update HA settings. Can you please log a support case to have a further investigation on the same, if a case is already open then please share the case ID for reference here?  

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • Hi  ,

    I already opened a support case with the following ID: 06358412. I will keep you updated.

    Thank you and have a nice day!

    Best regards,

    Leonardo

  • Hi   Thanks for sharing the case ID. let me review the case status and add a note over there.

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • Hi   I have reviewed the collected logs and below is the observations.

    Applog.log

    Mar 23 14:07:20Z apiInterface:entityjson::::::::system::updatehaconfiguration=HASH(0xbaed410)
    Mar 23 14:07:20Z Info:: Transaction will not be rolled back for opcode updateha. If any operation fails, request is part of multiple request :
    Mar 23 14:07:20Z updateha: begin!
    Mar 23 14:07:20Z
    checkPortIsValid called !
    Mar 23 14:07:20Z updateha: updateha failed !!!
    Mar 23 14:07:47Z apiInterface:: Deleting Entity and Event for legacy mode base operation
    Mar 23 14:07:47Z Request type = 1

    postgres.log
    8288 2023-03-23 14:07:20.269 GMTERROR: list_interface:::Invalid ipfamily:<NULL>
    8288 2023-03-23 14:07:20.269 GMTSTATEMENT: select count(*)::INT as count from list_interface($1,false,$2) where ipassigntype in($3,$4) and interface=$5

    CSC Debug logs:

    DEBUG   Mar 23 14:07:20Z [worker:8250]: # OPCODE Called: 'updateha'DEBUG   Mar 23 14:07:20Z [worker:8250]: {"response":{"method":"opcode","name":"updateha","version":"1.14","type":"text","length":46,"data":{ "statusmessage": "failed", "status": "500"

    +++

    DEBUG     Mar 23 14:07:20Z  [updateha:8250]: do_prep_query: PREPSTMT with ARGS: select count(*)::INT as count from list_interface(?,false,?) where ipassigntype in(?,?) and interface=?
    DEBUG     Mar 23 14:07:20Z  [updateha:8250]: get_txid:Transaction ID: 794259
    ERROR     Mar 23 14:07:20Z  [updateha:8250]: get_query_status: DB has returned error code: P0001
    ERROR     Mar 23 14:07:20Z  [updateha:8250]: get_query_status:Query Error: ERROR:  list_interface:::Invalid ipfamily:<NULL>
    CRITICAL  Mar 23 14:07:20Z  [updateha:8250]: csc_prep_query: execute_prepare_query failed for Execute Query.
    ERROR     Mar 23 14:07:20Z  [updateha:8250]: do_prep_query: Failed PREPSTMT: 'select count(*)::INT as count from list_interface(?,false,?) where ipassigntype in(?,?) and interface=?'


    Were there any changes on any settings on any interfaces which are part of HA  after which you started observing this error? 

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • can you post an ifconfig and remove sensitive details if needed?

    please mark, which is the HA interface

    collect that from both nodes (login ssh to the other node)

    eventually both nodes have different network settings

  • Hello  ,

    thank you for your answer. I did not make any configuration change anywhere.

    Thank you and have a nice day!

    Best regards,

  • Lately I have not been able to update/change the HA settings until I set an IPv4 address in the "Peer Management Settings".

    Possibly a bug, but after setting the IP it always worked.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.