Troubleshoot policy installation failure due to connection timeouts
Resolve problems when policy installation fails because the connection between the Engine and the SMCaaS Application times out.
The Engine is up and running, but policy installation fails when the SMCaaS Application is contacting the nodes. When node-initiated contact is active, the SMCaaS Application might also wait for contact from a node, but the contact never happens.
The connection might time out for the following reasons:
- There is no network-level connectivity.
- The Engine or the SMCaaS Application uses the wrong IP address.
- The Engine and the SMCaaS Application reject each others’ certificates.
Steps
- Check for network problems, such as faulty or loose cables, mismatching speed/duplex settings, IP addresses, and routing.
- Check the Locations and Contact Addresses of the SMCaaS Application, which are required if NAT is applied to these system communications.
- In a cluster, all nodes that the SMCaaS Application tries to contact must be reachable and operational to install a policy on any of the clustered Engines. If you have taken down an Engine for maintenance, temporarily disable it to install the policy on the other cluster members.
- If the problem seems to be related to certificates, you can recertify the Engine to re-establish contact between the Engine and the SMCaaS Application.
- Check the Engine software version (shown in the Info pane when you select the element in the SMCaaS Application).