cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
475
Views
0
Helpful
11
Replies
Highlighted
Participant

Expressway Cluter failure

Trying to set up a cluster (8.11.2) and I am getting this error when I try setting up the primary.

Certificate: Invalid (No Subject Alternate Names matched)

FQDN- plxpressc01.cscinfo.com

 

Here is the info from the cert:

X509v3 Subject Alternative Name: 
                DNS:plxpressc01.cscinfo.com, DNS:amrs-xpressc-cluster.cscinfo.com, DNS:plxpressc02.cscinfo.com

Any ideas?

Please remember to rate useful posts, click on the stars below.
11 REPLIES 11
Enthusiast

Re: Expressway Cluter failure

Do you have valid certificates installed? both CA and server certificate? 

Does it work when you set TLS Verification Mode to Permissive?

 

Is that output from the certificate? or from the Expressway Core? 

Highlighted
Participant

Re: Expressway Cluter failure

Yes valid cert. Server and Trust are uploaded.

That is the information in the Certificate

 

Please remember to rate useful posts, click on the stars below.
Highlighted
Rising star

Re: Expressway Cluter failure

Jon,

 

So does it work when your are not enforcing TLS on the clustering?

It just fails when you are trying to enforce correct?

Highlighted
Participant

Re: Expressway Cluter failure

So once I saw the cert error I stopped, I am going to push forward today to see if I can get the cluster up .

Please remember to rate useful posts, click on the stars below.
Highlighted
Rising star

Re: Expressway Cluter failure

I am in the middle of a clustering issue my self.  My 2cents get the cluster working without the certs first then come back to the cert issue.

Highlighted
Rising star

Re: Expressway Cluter failure

How did you make out today on your cluster. No mater what I do I can't shake that error I am having. Co worker running 8.11.3 got same error on expressway-c

Highlighted
Rising star

Re: Expressway Cluter failure

https://tools.cisco.com/security/centehttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-vcsdr/content/CiscoSecurityAdvisory/cisco-sa-20181107-vcsd

 

 

Just a heads up they pulled the software images... Probably going to let this be for a little until they fix the images.

Highlighted
Participant

Re: Expressway Cluter failure

Hey sorry I am so late updating.....

Problem was a routing issue, I am using dual interfaces and the cluster communication was going out the external interface not the one towards the Core.

I put static routes in to send the traffic out the correct Lan and cluster came right up.

Please remember to rate useful posts, click on the stars below.
Highlighted
Rising star

Re: Expressway Cluter failure

Yeah read that in the guide for Expressway E for public IPs.
Still having my replication issue on the Expressway -C
Highlighted
Participant

Re: Expressway Cluter failure


@Gregory Brunn wrote:
Yeah read that in the guide for Expressway E for public IPs.
Still having my replication issue on the Expressway -C

What error are you receiving?

Please remember to rate useful posts, click on the stars below.
Highlighted
Rising star

Re: Expressway Cluter failure

It is in tacs hands now. Basically replication failure.
First one was the cosmetic bug (they thought) but now replication is failing.
CreatePlease to create content