Error "connection refused" when accessing Aria Automation VIP on browser when using F5 load balancer.
search cancel

Error "connection refused" when accessing Aria Automation VIP on browser when using F5 load balancer.

book

Article ID: 397986

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • Although all pods on the Aria Automation nodes are in a running state, accessing the Aria Automation Virtual IP (VIP) through a browser results in a “connection refused” error.

Environment

Aria automation 8.x

Cause

The issue occurs due to incorrect or incomplete configuration of the F5 load balancer.

Resolution

This article outlines the steps to properly configure an F5 load balancer for VMware Aria Automation to resolve this issue.

Before configuring your F5 device, it must be deployed in the environment with access to VMware Aria Suite components over a network.

For configuration, the F5 device must meet these requirements:
  • The F5 device can be either physical or virtual.
  • The F5 Local Traffic module (LTM) load balancer can be deployed in either one-arm or multi-arm topologies.
  • The LTM must be configured and licensed as either Nominal, Minimum, or Dedicated. You can configure the LTM by navigating to 
    System > Resource Provisioning.

    Follow below steps to configure F5 load balancer with Aria Automation:

    1. Configure monitors:
      It is required to add monitors for VMware Aria Automation, and for an external Automation Orchestrator (optional).

      A. Log in to the F5 load balancer and navigate to Local Traffic > Monitor.
      B. Click Create and configure the monitor as outlined in this table. Use the default value if nothing is specified.
           
      Configure Monitors
      Name
      Type
      Interval
      Timeout
      Send String.
      Receive String.
      Alias Service Port
      VMware Aria Automation
      HTTP
      3
      10
      GET /health HTTP/1.0\n\n
      HTTP/1\.(0|1) (200)
      8008
      Automation Orchestrator
       Only for external 
      Automation Orchestrator
       instances.
      HTTP
      3
      10
      GET /health HTTP/1.0\n\n
      HTTP/1\.(0|1) (200)
      8008

      The configuration should look similar to this screen.



    2. Configure F5 server pools:
      It is required to configure service pools for VMware Aria Automation, and for an external Automation Orchestrator (optional).

      A. Log in to the F5 load balancer and navigate to Local Traffic > Pools.
      B. Click Create and configure the pool as outlined in this table. Use the default value if nothing is specified.
          
      Configure Server Pools
      Name
      Health Monitors
      Load Balancing Method
      Node Name
      Address
      Service Port
      VMware Aria Automation
      VMware Aria Automation
      Least Connections (member)
      VA1
      VA2
      VA3
      IP Address
      443
      Automation Orchestrator
      Use only for external 
      Automation Orchestrator
       instances.
      Automation Orchestrator
      Least Connections (member)
      VA1
      VA2
      VA3
      IP Address
      443


      C. Enter each pool member as a New Node and add it to the New Members group.

      The configuration should look similar to this screen.



    3. Configure F5 virtual servers:
      It is required to configure virtual servers for VMware Aria Automation, and for an external Automation Orchestrator (optional).

      A. Log in to the F5 load balancer and navigate to Local Traffic > Virtual Servers.
      B. Click Create and configure the virtual server as outlined in this table. Use the default value if nothing is specified.

      Configure Virtual Servers
      Name
      Type
      Destination Address
      Service Port
      Source Address Translation
      Default Pool
      Default Persistence Profile
      VMware Aria Automation
      Performance (Layer 4)
      IP Address
      443
      Auto Map
      VMware Aria Automation
      None
      Automation Orchestrator
      Use only for external 
      Automation Orchestrator
       instances.
      Performance (Layer 4)
      IP Address
      443
      Auto Map
      Automation Orchestrator
      None

      C. For an overall view and the status of the virtual servers, select Local Traffic > Virtual Servers.

      The configuration should look similar to these screens.