vSphere Health Service - Internet Connectivity Check
search cancel

vSphere Health Service - Internet Connectivity Check

book

Article ID: 317238

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

The health check in Skyline Health (aka vSphere Health) for internet connectivity is yellow.

The following warning alarms may be reported:

Alarm: vSphere Health detected new issues in your environment.

Alarm: Skyline Health has detected issues in your vSphere environment

 

Logs report the below error:

Log File: /var/log/vmware/analytics/analytics.log

YYYY-MM-DDTHH:MM:SS.MS+HH:MM phStageLogDrainerTaskExecutor-1 ERROR ph.phservice.push.telemetry.PhRtsTelemetryService Telemetry request for collector [vpxd.perfmanager] with instance [ph-vpxd-########-####-####-####-############] could not be processed by VMware Analytics Cloud.

YYYY-MM-DDTHH:MM:SS.MS+HH:MM phStageLogDrainerTaskExecutor-1 INFO org.bouncycastle.jsse.provider.ProvTlsClient [client #27198 @4969a79] opening connection to vcsa.vmware.com:443

YYYY-MM-DDTHH:MM:SS.MS+HH:MM pool-5-thread-1108 INFO org.bouncycastle.jsse.provider.ProvTlsClient [client #27199 @159ac7c3] opening connection to vcsa.vmware.com:443

YYYY-MM-DDTHH:MM:SS.MS+HH:MM phStageVcTelemetryLevelMaintainerScheduler-1 INFO org.bouncycastle.jsse.provider.ProvTlsClient [client #27200 @11f45587] opening connection to vcsa.vmware.com:443

YYYY-MM-DDTHH:MM:SS.MS+HH:MM phProdLogDrainerTaskExecutor-3 INFO org.bouncycastle.jsse.provider.ProvTlsClient [client #27201 @5263fc3f] opening connection to vcsa.vmware.com:443

YYYY-MM-DDTHH:MM:SS.MS+HH:MM phProdLogDrainerTaskExecutor-4 ERROR ph.phservice.common.ph.PhRtsClient Failed to execute request. org.apache.http.conn.ConnectTimeoutException: Connect to vcsa.vmware.com:443 [vcsa.vmware.com/###.##.#.###, vcsa.vmware.com/###.###.###.###] failed: Read timed out
        at org.apache.http.impl.conn.DefaultHttpClientConnectionOperator.connect(DefaultHttpClientConnectionOperator.java:151)
        at org.apache.http.impl.conn.PoolingHttpClientConnectionManager.connect(PoolingHttpClientConnectionManager.java:376)
        at org.apache.http.impl.execchain.MainClientExec.establishRoute(MainClientExec.java:393)
        at org.apache.http.impl.execchain.MainClientExec.execute(MainClientExec.java:236)
        at org.apache.http.impl.execchain.ProtocolExec.execute(ProtocolExec.java:186)
        at org.apache.http.impl.execchain.RetryExec.execute(RetryExec.java:89)
        at org.apache.http.impl.execchain.RedirectExec.execute(RedirectExec.java:110)
        at org.apache.http.impl.client.InternalHttpClient.doExecute(InternalHttpClient.java:185)
        at org.apache.http.impl.client.CloseableHttpClient.execute(CloseableHttpClient.java:83)
        at org.apache.http.impl.client.CloseableHttpClient.execute(CloseableHttpClient.java:108)
        at com.vmware.ph.phservice.common.ph.http.execute.OneTimeRequestExecutor.executeRequest(OneTimeRequestExecutor.java:22)
        at com.vmware.ph.phservice.common.ph.PhRtsClient.send(PhRtsClient.java:101)
        at com.vmware.ph.phservice.push.telemetry.PhRtsTelemetryService.processTelemetry(PhRtsTelemetryService.java:68)
        at com.vmware.ph.phservice.push.telemetry.PhRtsTelemetryService.processTelemetry(PhRtsTelemetryService.java:49)
        at com.vmware.ph.phservice.push.telemetry.internal.log.LogTelemetryDrainer.processLog(LogTelemetryDrainer.java:141)
        at com.vmware.ph.phservice.push.telemetry.internal.log.LogTelemetryDrainer.drain(LogTelemetryDrainer.java:90)
        at com.vmware.ph.phservice.push.telemetry.internal.log.LogTelemetryDrainerExecutor$1.run(LogTelemetryDrainerExecutor.java:69)
        at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
        at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
        at java.lang.Thread.run(Thread.java:750)
Caused by: java.net.SocketTimeoutException: Read timed out
        at java.net.SocketInputStream.socketRead0(Native Method)
        at java.net.SocketInputStream.socketRead(SocketInputStream.java:116)
        at java.net.SocketInputStream.read(SocketInputStream.java:171)
        at java.net.SocketInputStream.read(SocketInputStream.java:141)

Environment

VMware vCenter Server 7.0.x
VMware vCenter Server 8.0.x

Cause

Outbound internet connectivity from the vCenter Server is restricted.

Resolution

Verify if vCenter Server can access vcsa.vmware.com via HTTPS/443.

To test if HTTPS Port 443 access is enabled:

  1. Connect to the vCenter Server appliance through SSH or console.
  2. Test the connectivity using command:
    • # curl -v https://<VC FQDN>

A successful connection should show messages similar to "Connected to vcsa.vmware.com...port 443" along with some certificate information.
Please note that the text "403 Forbidden" in the results is also expected in a successful connection. Connecting to https://<VC FQDN> requires authentication parameters that are not passed by curl. Using curl to test connectivity will result in "403 Forbidden" but this still validates that vCenter can reach https://<VC FQDN>/
If result is an "error/connection timed out" message, then HTTPS port 443 access is likely not enabled.
for example :


Note: If a vCenter cannot directly communicate with the internet (e.g., the hosting organization blocks the access to the internet by a firewall), the environment can still use vSphere Health Service as it is not required for the service to function.

As needed, configure vCenter to communicate using a HTTP proxy. Likewise, configure Skyline with a proxy as needed:

  1. Click Configuration.
  2. Click Proxy.
  3. Click Add Proxy.
  4. Enter the Proxy Server's 'IP Address'
  5. Enter the Proxy Server's 'Port'
  6. If needed, enter the Proxy Server 'username'
  7. If needed, enter the Proxy Server 'password' for the user name specified in the previous step.
  8. Click Add Proxy Configuration.

Additional Information

Note: If CEIP is not enabled, the Internet connectivity check is unavailable.


vSphere Health utilizes data collected under the Customer Experience Improvement Program (CEIP). CEIP provides information that enables VMware both to improve VMware products and services and to identify and resolve issues. When configured to participate in CEIP, VMware collects technical information about the use of VMware products and services on a regular basis.

The information collected does not contain identifiable information about an organization.

For additional information on CEIP and the data collected, please see VMware Products in CEIP Program