Cloud Proxies become non-functional one week after deployment
search cancel

Cloud Proxies become non-functional one week after deployment

book

Article ID: 450316

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

One week after initial deployment, the Cloud Proxy ceases to function and loses connectivity. This issue occurs because the Cloud Proxy attempts to request a new license or certificate, but the communication fails silently without registering a clear error in the product user interface. 

Environment

  • VMware Aria Automation

  • Cloud Proxies

  • Network firewalls with active Deep Packet Inspection (DPI)

Cause

Exactly one week after deployment, the Cloud Proxy triggers an automated request to renew its license and certificate. If the network security environment enforces Deep Packet Inspection (DPI), this renewal traffic is quietly dropped by the firewall or security appliance, breaking the proxy's functionality. 

Resolution

To resolve this environmental issue, you must work with your network security team to adjust your firewall or gateway settings:

  1. Identify the network path and firewall rules governing the outbound traffic from the Cloud Proxy.

  2. Configure a Deep Packet Inspection (DPI) bypass or exclusion rule for the Cloud Proxy traffic to ensure the renewal requests are not intercepted or dropped.

  3. Verify that the Cloud Proxy can successfully communicate externally to renew its license and certificate.

Additional Information

Subscribe to this knowledge article to get updates on this issue.