Creating GSLB Pool Members Fails for TACACS Users after upgrade to 31.2.3 or 32.1.2
search cancel

Creating GSLB Pool Members Fails for TACACS Users after upgrade to 31.2.3 or 32.1.2

book

Article ID: 451636

calendar_today

Updated On:

Products

VMware Avi Load Balancer

Issue/Introduction

  • When using the user interface (UI), remote users who have authenticated via TACACS may be unexpectedly logged out.
  • This issue occurs specifically when attempting to create a Global Server Load Balancing (GSLB) Pool member of type VS and selecting a follower GSLB site. The operation will fail, and the user will be unauthenticated.

Environment

Affected Avi version: 31.2.3 and any version <=32.1.2-2p1

Cause

Due to a recent change to enhance security for GSLB site to site communication, the above operation which involves the GSLB leader authenticating to the follower site encounters a bug for a TACACS user causing the user to be unauthenticated and to be logged out.

Resolution

Alternate Options/Workaround: 

You can successfully create the GSLB Pool member by using any of the following alternative methods:

  • Use a Different Interface: This issue only affects the UI. You can perform the same action successfully using the command-line interface (CLI) or the API.
  • Use a Different Authentication Method: The issue is isolated to TACACS. If your environment is configured for them, you can use other remote authentication types like LDAP or SAML.
  • Use a Local User Account: The issue does not affect local users. Log in with a local user account to create the pool member through the UI.

For fix: Consider subscribing to the article to be updated on fix status. (Reference: https://knowledge.broadcom.com/external/article/275360

Additional Information

We are working on a fix in the upcoming release.