![VMware VSHIELD APP 1.0.0 UPDATE 1 - API Скачать руководство пользователя страница 137](http://html1.mh-extra.com/html/vmware/vshield-app-1-0-0-update-1-api/vshield-app-1-0-0-update-1-api_admin-manual_1043350137.webp)
VMware, Inc.
137
Appendix B Troubleshooting
Load-Balancer Throws Error 502 Bad Gateway for HTTP Requests
To determine why the load balancer service on a vShield Edge is throwing a 502 Bad Gateway error
This error occurs when the backend or Internal servers are not responding to requests.
1
Verify that internal server IP addresses are correct.
The current configuration can be seen through the vShield Manager or through the CLI command
show
configuration lb
.
2
Verify that internal server IP addresses are reachable from the vShield Edge internal interface.
3
Verify that internal servers are listening on the IP:Port combination specified at the time of load balancer
configuration.
If no port is specified, then IP:80 must be checked. The internal server must not listen on only 127.0.0.1:80;
either 0.0.0.0:80 or <internal-ip>:80 must be open.
VPN Does Not Work
To determine why VPN does not work on a vShield Edge
1
Verify that the other endpoint of the tunnel is configured correctly. Use the CLI command:
show
configuration ipsec
2
Verify that IPSec service is running on the vShield Edge.
To verify using the CLI command:
show service ipsec
. IPSec service has to be started by issuing the
start
command.
If ipsec is running and any errors have occurred at the time of tunnel establishment, the output of
show
service ipsec
displays relevant information.
3
Verify the configuration at both ends (vShield Edge and remoteEnd), notably the shared keys.
4
Debug MTU or fragmentation related issues by using ping with small and big packet sizes.
ping -s 500 ip-at-end-of-the-tunnel
ping -s 2000 ip-at-end-of-the-tunnel
Troubleshooting vShield Endpoint Issues
Thin Agent Logging
vShield Endpoint thin agent logging is done inside the protected virtual machines. Two registry values are
read at boot time from the windows registry. They are polled again periodically.
There are two registry values,
log_dest
and
log_level
. The two entries are located in the following registry
locations:
HKLM\System\CurrentControlSet\Services\VFileScsiFilter\Parameters\log_dest
HKLM\System\CurrentControlSet\Services\VFileScsiFilter\Parameters\log_level
Both are
DWORD
bit masks that can be any combination of the following values:
log_dest
WINDBLOG
VMWARE_LOG
0x1
0x2
log_level
AUDIT
ERROR
WARN
INFO
DEBUG
0x1
0x2
0x4
0x8
0x10
Содержание VSHIELD APP 1.0.0 UPDATE 1 - API
Страница 9: ...VMware Inc 9 vShield Manager and vShield Zones...
Страница 10: ...vShield Administration Guide 10 VMware Inc...
Страница 14: ...vShield Administration Guide 14 VMware Inc...
Страница 18: ...vShield Administration Guide 18 VMware Inc...
Страница 24: ...vShield Administration Guide 24 VMware Inc...
Страница 34: ...vShield Administration Guide 34 VMware Inc...
Страница 42: ...vShield Administration Guide 42 VMware Inc...
Страница 46: ...vShield Administration Guide 46 VMware Inc...
Страница 47: ...VMware Inc 47 vShield Edge and Port Group Isolation...
Страница 48: ...vShield Administration Guide 48 VMware Inc...
Страница 57: ...VMware Inc 57 vShield App and vShield Endpoint...
Страница 58: ...vShield Administration Guide 58 VMware Inc...
Страница 62: ...vShield Administration Guide 62 VMware Inc...
Страница 68: ...vShield Administration Guide 68 VMware Inc...
Страница 78: ...vShield Administration Guide 78 VMware Inc...
Страница 85: ...VMware Inc 85 Appendixes...
Страница 86: ...vShield Administration Guide 86 VMware Inc...
Страница 130: ...vShield Administration Guide 130 VMware Inc...
Страница 144: ...vShield Administration Guide 144 VMware Inc...