vSAN Skyline Health warning - vSAN Cluster Partition - vSAN Witness Appliance
search cancel

vSAN Skyline Health warning - vSAN Cluster Partition - vSAN Witness Appliance

book

Article ID: 393755

calendar_today

Updated On:

Products

VMware vSphere ESXi VMware vSAN 7.x VMware vSAN 8.x VMware vSAN 6.x

Issue/Introduction

vCenter vSAN Skyline Health Alarm Network Health - vSAN Cluster Partition has triggered.

The alert shows that there is a duplicate entry for the vSAN Witness host.

Entry 1: Shows the Witness Host as part of the vSAN cluster 

Entry 2: Shows the Witness Host isolated in its own separate network partition, disconnected from the vSAN data nodes - as seen in the below screenshot, essentially a split-brained scenario.

 

Environment

VMware vSAN (All Versions)

Cause

This was caused due to required vSAN port 2233 is blocked via a firewall not allowing proper communication between Witness hosts and the Data hosts.

 

Resolution

  • Verify all intervening firewalls and network security filters for dropped UDP traffic between the vSAN data nodes and the Witness Appliance on ports 12321 and 2233
  • Engage your networking team and ensure all required vSAN ports are open bi-directionally so that ESXi data hosts and ESXi Witness host are able to communicate properly.
  • See KB vSAN Witness appliance partitioned from the stretch cluster to help troubleshoot the network connectivity between the vSAN Witness host and the Data hosts.