VMware, Inc. 155
Appendix C Troubleshooting
Load-Balancer Throws Error 502 Bad Gateway for HTTP Requests
To determine why the load balancer service on a vShield Edge is throwing a 502 Bad Gateway error
ThiserroroccurswhenthebackendorInternalserversarenotrespondingtorequests.
1VerifythatinternalserverIPaddressesarecorrect.
ThecurrentconfigurationcanbeseenthroughthevShieldManagerorthroughtheCLIcommandshow
configuration lb.
2VerifythatinternalserverIPaddressesarereachablefromthevShield
Edgeinternalinterface.
3VerifythatinternalserversarelisteningontheIP:Portcombinationspecifiedatthetimeofloadbalancer
configuration.
Ifnoportisspecified,thenIP:80mustbechecked.Theinternalservermustnotlistenononly127.0.0.1:80;
either0.0.0.0:80or<internal‐ip>:80mustbeopen.
VPN Does Not Work
To determine why VPN does not work on a vShield Edge
1Verifythattheotherendpointofthetunnelisconfiguredcorrectly.UsetheCLIcommand:show
configuration ipsec
2VerifythatIPSecserviceisrunningonthevShieldEdge.
ToverifyusingtheCLIcommand:show service ipsec.IPSecservicehastobestartedbyissuingthe
startcommand.
Ifipsecisrunningandany
errorshaveoccurredatthetimeoftunnelestablishment,theoutputofshow
service ipsecdisplaysrelevantinformation.
3Verifytheconfigurationatbothends(vShieldEdgeandremoteEnd),notablythesharedkeys.
4DebugMTUorfragmentationrelatedissuesbyusingpingwithsmallandbigpacketsizes.
ping -s 500 ip-at-end-of-the-tunnel
ping -s 2000 ip-at-end-of-the-tunnel
Troubleshooting vShield Endpoint Issues
Thin Agent Logging
vShieldEndpointthinagentloggingisdoneinsidetheprotectedvirtualmachines.Tworegistryvaluesare
readatboottimefromthewindowsregistry.Theyarepolledagainperiodically.
Therearetworegistryvalues,log_destandlog_level.Thetwoentriesarelocatedinthefollowingregistry
locations:
HKLM\System\CurrentControlSet\Services\VFileScsiFilter\Parameters\log_dest
HKLM\System\CurrentControlSet\Services\VFileScsiFilter\Parameters\log_level
BothareDWORDbitmasksthatcanbeanycombinationofthefollowingvalues:
log_dest WINDBLOG
VMWARE_LOG
0x1
0x2
log_level AUDIT
ERROR
WARN
INFO
DEBUG
0x1
0x2
0x4
0x8
0x10
Comentarios a estos manuales