01-09-2017 01:46 AM
Hello I have this message trying to activate centralized quarantine on my 2nd ESA :
"Unable to proceed with Centralized Policy, Virus and Outbreak (PVO) Quarantines configuration as esa2 in ESA has content filters / DLP actions available at a level different from the Machine esa2 level."
Not sure what I Should do ?
01-09-2017 01:55 AM
Hi Clement
Most likely there is an override between the machine/cluster level for the Policy, Virus and Outbreak quarantine(PVO)
From the CLI run the following command clustercheck
Regards
Raed
01-09-2017 01:59 AM
I got this result
"No inconsistencies found on available machines."
01-09-2017 02:19 AM
Check the following article it might be of use
01-09-2017 03:33 AM
Great !
Thank you very much.
So what I did :
- Remove ESA from cluster
- Reconfigure POV quarantine
- Join Cluster again
No more error message but it seems that ESA2 settings are overriding cluster settings.
How to set cluster settings for ESA2 ?
01-09-2017 03:40 AM
Just join the cluster from the second machine CLI > clusterconfig > join over ssh/ccs "based on how you configured things" and after the join the settings should be inhered from the cluster
Regards
Raed
01-09-2017 11:03 AM
Hello,
In order to successfully enable Centralized PVO, any machine-level settings for DLP, Content Filters and PVO itself will need to be deleted. Both ESA1 and ESA2 need to be setup to be using the cluster level settings. You'll need to change the mode to 'machine-level' for ESA1 or ESA2, then delete those settings (make sure nothing at machine-level needs to be copied over to cluster level), save the changes and then confirm that both appliances are now only using the cluster level settings. Then, you should be able to try and enable Centralized PVO.
Also, prior to the above you'll need to make sure you perform the migration step on the SMA via Centralized Services --> PVO Quarantines --> Launch Migration Wizard. (This is assuming you've already added ESA2 to the SMA)
Thanks!
-Dennis M.
05-31-2017 08:29 PM
Hi Libin,
"In order to successfully enable Centralized PVO, any machine-level settings for DLP, Content Filters and PVO itself will need to be deleted."
Did you mean, incoming and outgoing content filters should be delete?
Is there any other settings need to be delete in the clustering mode?
Kindly advise.
06-01-2017 12:09 PM
Only machine level configuration would need to be deleted, nothing needs to be deleted from the cluster.
Please go through the article shared by Raed earlier in the post.
- Libin V
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide