Avi Controller status Shows "Not Ready" in Avi Operations (SSP) After IP Address Change
search cancel

Avi Controller status Shows "Not Ready" in Avi Operations (SSP) After IP Address Change

book

Article ID: 451969

calendar_today

Updated On:

Products

VMware vDefend Firewall VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

When an Avi Controller onboarded to Avi Operations (SSP) via FQDN undergoes an IP address change, its status in the Avi Operations portal changes to Not Ready and fails to reconnect automatically, despite the FQDN remaining unchanged.

Environment

SSP 5.2.0 AVI operations 

Cause

The AVI Oprations → AVI Controller, integration currently utilizes the IP address as the primary identity for the integration, rather than the FQDN. This behavior is by design.

Even when an Avi controller is onboarded using an FQDN, the system resolves and stores the underlying IP address to manage the connection. Consequently, if the IP address of a Avi deployment is changed, the integration loses connectivity because it continues attempting to route traffic to the original IP address.

Resolution

If the IP address of a  Avi controller changes, the workflow to restore connectivity is:

  1. Force Offboard the affected site from AVI Operations
  2. Re-onboard the AVI Controller using the new IP address (or the FQDN, which will now resolve to the new IP).