some robots under a hub are unreachable due to firewall restrictions
search cancel

some robots under a hub are unreachable due to firewall restrictions

book

Article ID: 453791

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

A large number of robots beneath a specific hub appear to be functioning normally (submitting alarms and metrics, probes appear green), but they cannot be directly communicated with. Attempting to retrieve information about the robot in the Admin Console (AC) or Infrastructure Manager (IM) results in an error, probes cannot be opened and configuration/Raw Configure cannot be retrieved.

Symptoms:

  • Probes on the robot show as green/active.
  • Alarms and metrics are being received by the primary hub.
  • Direct communication from the IM/AC client to the robot fails.
  • Error message appears in AC above the robot details: "Information about the robot could not be retrieved."

Environment

Product: DX Unified Infrastructure Management (UIM) - Any Version
hubs configured without hub-to-hub SSL tunnels

 

Cause

The robots may be located behind firewalls and are only configured to communicate with their local secondary hub. The IM client is attempting to communicate with the robots directly, but is being blocked by network firewall policies.

When a hub is connected to another hub (e.g. the primary hub) via a "Name Services" entry, then that hub is assumed to be local (on the same LAN) and additionally all its robots are also considered local.

This means that the IM Client, or the Admin Console app on the primary hub, will try to reach out to the robots directly on their IP address at port 48000.

A firewall restricting access to this port from external sources will block this communication and cause errors.

Resolution

To resolve this issue, you must configure hub-to-hub SSL tunnels between the secondary hubs and the primary hub to ensure that all management traffic is proxied correctly.  When tunnels are present, all communication intended for robots flows through their hubs, and the hub sends the communication to the robot instead of trying to establish a direct path.

Steps to configure tunnels:

  1. Access the Infrastructure Manager or Admin Console.
  2. Locate the primary hub and the secondary hubs hosting the affected robots.
  3. Configure a Tunnel connection between the secondary hub and the primary hub.
  4. Ensure the configuration is set so that the primary hub acts as the client for the tunnel connection.
  5. Once the tunnel is established, all management traffic from the IM/AC client will funnel through the hub (IM ->
  6. Tunnel -> Robot) instead of attempting a direct connection to the robot.
  7. Verify connectivity by attempting to retrieve the robot information again in the Admin Console.

Additional Information

How to create tunnels between two hubs in DX UIM

IM tries to connect to remote robots directly even though there is a Tunnel Hub