While applying patch 31.1.1-2p2 on the Controllers and Service Engine, the ServiceEngine failed to establish a secure channel after the SwitchandReboot task. As a result, the upgrade was suspended with the error:"SE did not connect on desired version after reboot."
Following this, the ServiceEngine entered a partitioned state.
Error observed on se_supervisor.log
Vcenter
Since the customer migrated from a SaaS environment, the vApp settings of the Service Engine were not updated with the Avi Controller IP address in vCenter. As a result, the Service Engine attempted to establish a Secure Channel with the SaaS Controller FQDN instead.
From the se_supervisor logs, it was observed that the Service Engine was attempting to connect to the SaaS FQDN.
Power off the Service Engine, update the vApp options with the Controller Leader's IP address, and then power it back on. The Service Engine should successfully connect to the Controller.
Ensure port 8443 is open between Avi Controller and ServiceEngine