僅限 RecoverPoint Classic:不同 RecoverPoint 系統物件之間的連線問題
Summary: 加密箱問題會導致物件顯示為未知。
Symptoms
RecoverPoint Classic 系統中不同物件之間的連線問題。
這些錯誤與特定的 RecoverPoint 裝置 (RPA) 有關。
系統警示與 CLI get_system_status 顯示不同的連線能力相關問題。
可能會發生以下任何一或多個錯誤:
RPAs:
WARNING: States of all RPAs are unknown WARNING: LAN connection between all RPAs is unknown WARNING: RPA 2 in Site2: LAN network interface status is unknown
磁碟區:
WARNING: States of all devices are unknown WARNING: User volume [VM1_CG, prod, VM2_0_0_scsi] is unknown to RPA x WARNING: Journal volume [VM2_CG, prod, IOFilter_JVOL_00005] is unknown to RPA x
分割器:
WARNING: States of all splitters are unknown ERROR: RP_esxi_cluster-xx.xx.xx.xx1's connection status with RPA x is unknown ERROR: RP_esxi_cluster-xx.xx.xx.xx0's connection status with RPA x is unknown ERROR: RP_esxi_cluster-xx.xx.xx.xx2's connection status with RPA x is unknown ERROR: RP_esxi_cluster-xx.xx.xx.xx3's connection status with RPA x is unknown
WAN 問題:
Items: WARNING: No remote communication between clusters in the system Items: WARNING: Data link status is unknown for RPA 1 between clusters Site2 and Site1, WARNING: Data link status is unknown for RPA 2 between clusters Site2 and Site1
控制記錄中的範例錯誤 (解壓縮*/files/home/kos/control/result.log):
2020/05/08 19:23:03.235 - #2 - 21038/20782 - lockboxSet: fips-security: lockboxSet: inserting to lockbox: name = SiteUID_List value.size() = 18 2020/05/08 19:23:03.236 - #1 - 21038/20782 - Lockbox: The Lockbox contains no entries. 2020/05/08 19:23:03.236 - #2 - 20916/20782 - WatchDogLEPInterface: service manager expects watchdog keep-alive notification messages! 2020/05/08 19:23:03.236 - #1 - 21038/20782 - Lockbox: insert: Can't open lockbox: -35 2020/05/08 19:23:03.236 - #1 - 21038/20782 - ControlCryptoUtils: fips-security: lockboxSet: error updating value in lockbox: -35 2020/05/08 19:23:03.236 - #2 - 21038/20782 - aux::updateLockboxWithKvolTriplet: fips-security: error writing updated site list into lockbox. 2020/05/08 19:23:03.236 - #0 - 20916/20782 - LEP2: errno=0 WatchDog 0 time is low (lease =-39.6798)! RPA might be rebooted. 2020/05/08 19:23:03.237 - #2 - 21034/20782 - BC::handleUpdateLockboxWithKvolTriplet: fips-security: auxAsyncWorker returned error. rc=MRC_LOCKBOX_ACCESS_ERROR 2020/05/11 16:54:53.366 - #1 - 1702/1644 - Lockbox: Lockbox tampering was detected, so it cannot be read. 2020/05/11 16:54:53.366 - #2 - 1702/1644 - lockboxGet: fips-security: error=-60 2020/05/11 16:54:53.366 - #0 - 1702/1644 - BSAFE_FIPS_TLSHandler: errno=2 loadLocalCert: Unable to get server certificate from lockbox 2020/05/11 16:54:53.366 - #0 - 1702/1644 - BSAFE_FIPS_TLSHandler: errno=2 init: Unable to retrieve server certificate 2020/05/11 16:54:53.366 - #0 - 1702/1644 - xTE: errno=2 1762817320: MessageHandler::open()unable to initialize a socket handler!
Cause
RPA 上的加密箱檔案在某些方面已損毀,因此 RPA 無法使用憑證與其他物件通訊。
它可能無法與系統中的任何物件通訊,包括其他 RPA、分割器 (這些分割器下的任何磁碟區)、其他網站等。
加密箱損毀的其中一個可能原因是 RPA 上的檔案系統已滿案例。
Resolution
因應措施:
執行下列指令檔,清除每個受影響 RPA 上的密碼箱問題。
腳本運行時,RPA 有時可能會重新開機。
透過 PuTTY 或 SSH 以 boxmgmt 使用者身分登入,然後選取下列項目:[2] 設定 -> [8] 進階選項 -> [4] 執行指令檔 -> 貼上以下指令檔:
MWRjNmQ3ZGY2YzM2NWI0NWFjNTQ5NmE1MjliYzg2ZjMKdW5saW1pdGVkCm5vdF9yZXN0cmljdGVk ClRoZSBpZCBvZiB0aGUgc2NyaXB0IGlzOgpGaW5kIGFuZCBmaXggbG9ja2JveCBpc3N1ZXMKQXNz aWYgSGFsClZFUlNJT049JChncmVwIHRfd2luSW5zdGFsbFNoaWVsZFZlcnNpb24gL2hvbWUva29z L2tib3gvc3JjL2luaXRpYWxpemF0aW9uL3R3ZWFrX3BhcmFtcy90d2Vhay5wYXJhbXMudmVyc2lv bnxncmVwIC1vICJbMS05XS4qWzAtOV0iKQpNQUpPUlZFUlNJT049IiR7VkVSU0lPTjowOjF9IgpN SU5PUlZFUlNJT049IiR7VkVSU0lPTjoyOjF9IgppZiBbICRNQUpPUlZFUlNJT04gLWd0IDUgXSB8 fCAoWyAkTUFKT1JWRVJTSU9OIC1lcSA1IF0gJiYgWyAkTUlOT1JWRVJTSU9OIC1nZSAzIF0pOyB0 aGVuCglpZiBbWyBgemVncmVwIC1hICJyZXRyaWV2ZTogZmFpbGVkIHRvIHJldHJpZXZlIGl0ZW0u KnByaXZfY3VycnxMb2NrYm94IHRhbXBlcmluZ3xNUkNfTE9DS0JPWF9BQ0NFU1NfRVJST1IiIC9o b21lL2tvcy9jb250cm9sL3Jlc3VsdC5sb2cubGF0ZXN0IC9ob21lL2tvcy9jb250cm9sL3Jlc3Vs dC5sb2cucHJldmlvdXMuZ3p8d2MgLWxgIC1ndCAwIF1dOyB0aGVuCgkJZWNobyAiTG9ja2JveCBp c3N1ZXMgd2VyZSBmb3VuZCwgYnV0IHNpbmNlIHRoaXMgaXMgNS4zLCBQbGVhc2UgY29udGFjdCBh IFJlY292ZXJQb2ludCBTdXBwb3J0IFNNRS4iCgkJZXhpdCAwCgllbHNlCgkJZWNobyAiTm8gaXNz dWVzIGZvdW5kIgoJCWV4aXQgMAoJZmkKZWxzZQoJaWYgW1sgYHplZ3JlcCAtYSAiTG9ja2JveCB0 YW1wZXJpbmd8TVJDX0xPQ0tCT1hfQUNDRVNTX0VSUk9SIiAvaG9tZS9rb3MvY29udHJvbC9yZXN1 bHQubG9nLmxhdGVzdCAvaG9tZS9rb3MvY29udHJvbC9yZXN1bHQubG9nLnByZXZpb3VzLmd6fHdj IC1sYCAtZ3QgMCBdXTsgdGhlbgoJCWVjaG8gIkRldGVjdGVkIGxvY2tib3ggaXNzdWUuIENsZWFy aW5nIGl0IGFuZCByZXN0YXJ0aW5nIGNvbnRyb2wiCgkJcm0gLWYgL2hvbWUva29zL2xvY2tib3gv KgoJCXBraWxsIC05IGNvbnRyb2xfcHJvY2VzcwoJZWxzZQoJCWVjaG8gIk5vIGlzc3VlcyBmb3Vu ZCIKCWZpCmZpCg== #
按下 Enter 鍵,輸入您的名稱以套用指令檔。
主意:
Dell Technologies 工程部門正在調查此問題。永久修正方法仍在進行中。如需技術協助,請聯絡 Dell Technologies 客戶支援中心或您的服務代表,並引用此解決方案 ID。
Additional Information
重要資訊:
此 KB 僅適用於 RecoverPoint Classic,RecoverPoint 適用於 VM 5.2 版及更舊版本。
請勿嘗試在 RecoverPoint 上為 VM 5.3 及更新版本執行因應措施!
若為 VMs 5.3 及更新版本的 RecoverPoint,請使用 VMs 的 RecoverPoint:由於加密箱損毀,遠端叢集之間無法通訊 (需要登入)
針對 RecoverPoint Classic:
以下已簽署指令檔可啟用加密箱偵錯,這可能有助於工程部門瞭解日後密碼箱問題的原因。
如果使用者看到這種情況無緣無故發生,我們可以啟用調試日誌記錄並在再次發生后收集日誌。
啟用偵錯記錄、以 boxmgmt/admin 身分登入每個 RPA,然後執行下列指令檔:
OWFkNmQ5YWEzMWRjZDk0ZWIxZTRiMzQ4ZTFkZTYyNTQKdW5saW1pdGVkCm5vdF9yZXN0cmljdGVk ClRoZSBpZCBvZiB0aGUgc2NyaXB0IGlzOjEwMTAzCkxvY2tib3ggZGVidWcgdHJhY2Ugc2V0CkVF CiMhL2Jpbi9iYXNoCmVjaG8gIlN0YXJ0IGFkZGluZyB0cmFjZSBDU1RfVFJBQ0UsQ0xCX1RSQUNF IGluIGZpbGUgL2V0Yy9yYy5sb2NhbCIKc2VkIC1pICcvbGRjb25maWcvaSBcZXhwb3J0IENTVF9U UkFDRT0iL3Vzci9DU1RfVFJBQ0UuTE9HIicgL2V0Yy9yYy5sb2NhbApzZWQgLWkgJy9sZGNvbmZp Zy9pIFxleHBvcnQgQ0xCX1RSQUNFPSIvdXNyL0NMQl9UUkFDRS5MT0ciJyAvZXRjL3JjLmxvY2Fs CkNTVF9UUkFDRV9DT1VOVD1gZ3JlcCAnZXhwb3J0IENTVF9UUkFDRT0iL3Vzci9DU1RfVFJBQ0Uu TE9HIicgL2V0Yy9yYy5sb2NhbCB8IHdjIC1sYApDTEJfVFJBQ0VfQ09VTlQ9YGdyZXAgJ2V4cG9y dCBDTEJfVFJBQ0U9Ii91c3IvQ0xCX1RSQUNFLkxPRyInIC9ldGMvcmMubG9jYWwgfCB3YyAtbGAK aWYgW1sgKCAiJENTVF9UUkFDRV9DT1VOVCIgLWd0IDAgKSAmJiAoICIkQ0xCX1RSQUNFX0NPVU5U IiAtZ3QgMCApIF1dCnRoZW4KICAgICBlY2hvICJBZGRlZCBib3RoIENTVF9UUkFDRSxDTEJfVFJB Q0Ugc3VjZXNzZnVsbHkiCiAgICAgZWxzZQogICAgICAgICAgZWNobyAiQ291bGQgbm90IGFkZCBD U1RfVFJBQ0UsQ0xCX1RSQUNFIHN1Y2Vzc2Z1bGx5IgogICAgICAgICAgZmkK #
然後重新啟動 RPA 並等待再次發生。