This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cannot set the "preferred primary device"

Good morning,

I have two clusters of XGS 2100 in HA (Active-Passive) running with the firmware version 19.5.0 GA-Build197. As per object, I am not able to set the preferred primary device on both the clusters. The error message is always the same: "Couldn't update HA".

Has someone had the same issue? If yes, how did you solve it?

Thank you and have a nice day!

Best regards,

Leonardo



This thread was automatically locked due to age.
Parents
  • Hello  ,

    Thank you for reaching out to the community, refer the Updating HA devices.

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 

    Log a Support Case | Sophos Service Guide
    Best Practices – Support Case


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Good morning  ,

    thank you for your answer but this is not what I am looking for. It is not about updating the clusters but set the preferred primary node in the HA clusters.

    Best regards,

    Leonardo

  • Hi  In that case we may need to check CSC debug and applog to confirm more during an error time when you are trying to update HA settings. Can you please log a support case to have a further investigation on the same, if a case is already open then please share the case ID for reference here?  

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • Hi  ,

    I already opened a support case with the following ID: 06358412. I will keep you updated.

    Thank you and have a nice day!

    Best regards,

    Leonardo

  • Hi   Thanks for sharing the case ID. let me review the case status and add a note over there.

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • Hi   I have reviewed the collected logs and below is the observations.

    Applog.log

    Mar 23 14:07:20Z apiInterface:entityjson::::::::system::updatehaconfiguration=HASH(0xbaed410)
    Mar 23 14:07:20Z Info:: Transaction will not be rolled back for opcode updateha. If any operation fails, request is part of multiple request :
    Mar 23 14:07:20Z updateha: begin!
    Mar 23 14:07:20Z
    checkPortIsValid called !
    Mar 23 14:07:20Z updateha: updateha failed !!!
    Mar 23 14:07:47Z apiInterface:: Deleting Entity and Event for legacy mode base operation
    Mar 23 14:07:47Z Request type = 1

    postgres.log
    8288 2023-03-23 14:07:20.269 GMTERROR: list_interface:::Invalid ipfamily:<NULL>
    8288 2023-03-23 14:07:20.269 GMTSTATEMENT: select count(*)::INT as count from list_interface($1,false,$2) where ipassigntype in($3,$4) and interface=$5

    CSC Debug logs:

    DEBUG   Mar 23 14:07:20Z [worker:8250]: # OPCODE Called: 'updateha'DEBUG   Mar 23 14:07:20Z [worker:8250]: {"response":{"method":"opcode","name":"updateha","version":"1.14","type":"text","length":46,"data":{ "statusmessage": "failed", "status": "500"

    +++

    DEBUG     Mar 23 14:07:20Z  [updateha:8250]: do_prep_query: PREPSTMT with ARGS: select count(*)::INT as count from list_interface(?,false,?) where ipassigntype in(?,?) and interface=?
    DEBUG     Mar 23 14:07:20Z  [updateha:8250]: get_txid:Transaction ID: 794259
    ERROR     Mar 23 14:07:20Z  [updateha:8250]: get_query_status: DB has returned error code: P0001
    ERROR     Mar 23 14:07:20Z  [updateha:8250]: get_query_status:Query Error: ERROR:  list_interface:::Invalid ipfamily:<NULL>
    CRITICAL  Mar 23 14:07:20Z  [updateha:8250]: csc_prep_query: execute_prepare_query failed for Execute Query.
    ERROR     Mar 23 14:07:20Z  [updateha:8250]: do_prep_query: Failed PREPSTMT: 'select count(*)::INT as count from list_interface(?,false,?) where ipassigntype in(?,?) and interface=?'


    Were there any changes on any settings on any interfaces which are part of HA  after which you started observing this error? 

    Regards,

    Vishal Ranpariya
    Technical Account Manager | Sophos Technical Support

    Sophos Support Videos | Knowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link.

  • can you post an ifconfig and remove sensitive details if needed?

    please mark, which is the HA interface

    collect that from both nodes (login ssh to the other node)

    eventually both nodes have different network settings

  • Hello  ,

    thank you for your answer. I did not make any configuration change anywhere.

    Thank you and have a nice day!

    Best regards,

  • Lately I have not been able to update/change the HA settings until I set an IPv4 address in the "Peer Management Settings".

    Possibly a bug, but after setting the IP it always worked.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Hello  ,

    thank you for your answer! I started to suspect this strange behaviour too; the problem is that I am not currently in the office for mapping the interface on the peer. Tomorrow I will try and I will let you know.

    Thank you and have a nice day!

    Best regards,

    Leonardo

  • You don't configure this on the Aux device, you configure it in the HA settings


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Hello  , setting the "Peer Administration settings" made the trick. This solution has also been confirmed from the Sophos Support. Thank you and have a nice WE!

    Best regards,

    Leonardo Mele

Reply Children
No Data