Issues related to the display status of GWLB in the IPS Manager
If the status of GWLB displays Inactive, it means there is a traffic inspection issue. You can follow the below steps to troubleshoot the display error in the Manager:
Login to the AWS console and check if the Sensors are added to the Target Group.
Check the health status of the Sensor. If the Sensor is unhealthy, perform the following:
If a new Sensor is added, you can wait for approximately 15 minutes and recheck the Sensor status.
Check if the Health check protocol is set to TCP. Also, confirm if the Health check port is Override and set to 9001.
Run the CLI
show cloud-gwlb statusand check ifHealthCheckcounters are increasing. If counters are increasing, there is no issue. The status of GWLB will display as Active in a few minutes. Otherwise, it signifies zero traffic flow through the Sensor due to a routing issue.
Note
It is recommended to have an auto-scaling group so that if a Sensor becomes inactive, all other Sensors remain active.
User data issue
You cannot use the same user data as Probe while configuring the GWLB.
If the user data is missing in the Sensor while deploying the Sensor, the Sensor won't be able to connect to the Manager. Therefore, the Manager dashboard fails to display the Sensor details. Hence, log in to the AWS console and update user data in the Sensor.
If incorrect user data is updated, ensure the Traffic Source is configured as GWLB. In such cases, the Manager connects to the Sensor, but not the GWLB, causing a failure in the health check.
For more information related to user data, see Launch the Virtual IPS Sensor AMI instance for AWS GWLB.
Security group issue
To troubleshoot any security group issue between GWLB and the Sensor, you must first verify the inbound and outbound rules. Ensure the configured rules meet the recommended values. For more information, see Requirements to integrate Trellix vIPS with AWS Gateway Load Balancer.
Issues between GWLB and GWLBe
To troubleshoot any issue between GWLB and GWLBe, ensure to meet the required guidelines while deploying GWLB. If the problem persists, please contact the AWS support team. To contact the AWS support team, login to your AWS account. In the title bar, click on
and select Support Center.