Issues related to the display status of the GCP Internal Passthrough Load Balancer in the IPS Manager
If the status of GCP Internal Passthrough Load Balancer displays Inactive, it means there is a traffic inspection issue. You can follow the below steps to troubleshoot the display error in the Manager:
Login to the GCP portal and check if the Sensors are added to the Backend pool.
Check the health status of the Sensor. If the Sensor is unhealthy, perform the following:
If a new Sensor is added, you can wait for approximately 15 minutes and recheck the Sensor status.
Check if the HealthCheck Protocol is set to TCP. Also, confirm if the HealthCheck Port is set to 9001.
Run the CLI
show cloud-gwlb statusand check ifHealthCheckcounters are increasing. If counters are increasing, there is no issue. The status of GWLB will display as Active in a few minutes. Otherwise, it signifies zero traffic flow due to the GWLB settings issue.Run the CLI
show ingress-egress statto verify if the Sensor receives packets from GWLB. If the Sensor fails to receive packets, verify if a validGCP ILB forwarding rule IPis updated in the user data.
Note
It is recommended to have an auto-scaling group so that if a Sensor becomes inactive, all other Sensors remain active.
If the appropriate protocol (VXLAN), type, ports, and identifiers are not configured accurately during the load balancer deployment, you cannot modify these configurations after the deployment. To change the configuration after load balancer deployment, you can delete and reconfigure the backend pool configuration.
User data issue
If the user data is missing in the Sensor while deploying the Sensor, the Sensor won't be able to connect to the Manager. Therefore, the Manager dashboard fails to display the Sensor details. Hence, log in to the GCP portal and update user data in the Sensor.
If incorrect user data is updated (specifically, if Traffic Source is not configured as GCPNSI and an invalid
GCP ILB forwarding rule IPis added), the Manager will connect to the Sensor but fail to connect to the load balancer, leading to a health check failure.
For more information related to user data, see Launch the Virtual IPS Sensor virtual machine.
Firewall rules issue
To troubleshoot any firewall rules issue between the load balancer and the Sensor, you must first verify the inbound and outbound rules.
The firewall rule for the Sensor's traffic inspection must be configured in the NSI In-band firewall, not within the Trellix vIPS VPC firewall.
For all protected VMs, ensure both ingress (inbound) and egress (outbound) rules are specified within the NSI In-band firewall policy.
Ensure the configured rules meet the recommended values. For more information, see Requirements to integrate the internal passthrough load balancer in the GCP environment.