Can we place the SDC in Maintenance Mode to avoid the alarm "Secure Domain Connector Lost" when we take the server down for monthly patching?
search cancel

Can we place the SDC in Maintenance Mode to avoid the alarm "Secure Domain Connector Lost" when we take the server down for monthly patching?

book

Article ID: 402153

calendar_today

Updated On:

Products

Network Observability Spectrum

Issue/Introduction

Every month I've got an Alarm "Secure Domain Connector connection lost". It is because VM OS is  patched and rebooted. Is it possible to schedule a Maintenance for SDC during patching process to avoid this alarm?

 

Our SDC is not modeled as a pingable or host device, we only have a SD Connector process model.

Environment

Spectrum ANY

Secure Domain Connector (SDC)

Cause

Placing the SDC in Maintenance Mode will not prevent the "Secure Domain Connector connection lost" alarm from being placed on the SDC model.

Resolution

Spectrum Engineering have provided a workaround to make sure the "Secure Domain Connector connection lost" alarm is not created on the SDC model.

Here are the steps as follows:

 

1) Modeled SDC as Pingable. (Modeltype handle is pingable), change "value when red" attribute to 7 to make it a significant model.
2) Then configured SDC by importing sdm.config. (Modeltype handle is pingable(Not SDConnectorProcess))
3) Added Maintenance Schedule to the SDC model.
4) SDC went into Maintenance mode. (even in this case, device polling is successful if SDC is up)
5) Made SDC down. (SecureDomainStatus is changed to "Lost" but "Secure Domain lost" alarm is NOT generated as it is in maintenance.)
6) Device polling failed as SDC is down and device went in to suppressed state as SDC-FI kicked in.

Additional Information

Observations: 
1) There is no root cause on the suppressed device in SDC maintenance mode case. (Normal case (not maintenance mode), "Secure Domain lost" alarm becomes the root cause of suppressed devices)
2) SDC is in maintenance and it goes down. Now when SDC comes out of maintenance mode, then also "Secure Domain lost" alarm is NOT generated (SDC will be green) as SecureDomainStatus was already set to "Lost" during maintenance.
If the customer just doesn't want "Secure Domain lost" alarm then they can model SDC as pingable first and import sdm.config (check model_handle which should be the same).