We are trying to connect an Icinga for Windows Agent with an ICINGA MASTER.
During the configuration we discovered that the SAtellite cannot communicate with master.
Our network people anser us with this Info:
Following the tests carried out, it emerges that since there is a PAT and not a 1:1 NAT (between MASTER and SATELLITE), it is possible to establish a communication only if this starts from the MASTER. I will try to explain myself better if I try to perform a ping or a telnt start from MASTER this then manages to respond correctly towards the ICINGA Satellite, because the session has already been created by the latter, however if the session is created from SATELLITE towards the ICINGA MASTER the session is not created and the FW drops the connection because that PAT IP is shared with all customers and therefore the FW doesnât know who you are trying to communicate with by dropping the communication.
For this reason the solution would be to review the application logic by trying to have the ICINGA MASTER machine establish the session in order to keep the session up.
Due to this explanation how can I connect the MASTER with satellite and make the monitoring (Icinga for Windows) works fine ?
Is there a procedure to connect a MASTER (starting configuration from master) with a SATELLITE (icinga for windows) ?
THX
If you only have the connection information in the masters zone.conf then the satellite will not try to connect. The relationship/parent of the satellite still needs to be in the satellites zones.conf or it will not accept the connection.
So if you omit, in the zones.conf on the satellite, the host variable in the endpoint of the master node, it will stop trying to establish the connection.
Hi Dominik, i was reading the thread you attached, but i donât understand if in that way is possible to install icinga agent on the client without the requisite that the client have to establish a connection starting from his side.
Thanks
There is the mentioned config file zones.conf and in there the nodes of the cluster are declared.
if no host = Address is stated for the endpoint, the agent with this zones.conf will not try to connect to this cluster node. If the other cluster node has a host = address in his zones.conf for the fist node then it will try to initiate the connection. If both have the host of the other node, the connection can be established faster if no problems like the one of the OP are present.
Hi Dominik.
Unfortunately Iâm not sure to have understood what is the right procedure to configure the IGINGA FOR WINDOWS Agent on this scenario.
We can only start the configuration from MASTRR NODE (traffic is allowed only when start from master to satellite and not viceversa)
Can you details the steps to configure the SATELLITE ?
THX
P.
Just donât put any host = address statements of the master endpoints into the zones.conf files of the satellites.
This will stop the satellites from initiating connections to the master nodes.
to sign the CSR and create your cert.
Then copy the cert back to the agent, restart the service and check both logs (master and agent) if the connection is correctly established
The mentioned settings for the zones.conf files by @rivad are also necessary.
PS: Just for the sake of completeness and for future use of the correct terminology:
Icinga on a windows host is always (and only) an agent. On a Linux host it can be a master, a satellite or an agent.
Agents only check themselves while masters and satellites are also able to check other hosts.
This would be the self-signed cert the agent deploys on installation.
Try using the key and create a CSR on your master:
icinga2 pki new-cert --cn icinga2-master1.localdomain
âkey icinga2-master1.localdomain.key
âcsr icinga2-master1.localdomain.csr
(replace with naming for your agent)
I solved changhing the configuration regarding the CA when Installing the AGENT.
probably I was wront when ASK me for a ca.crt âPATHâ I Insert the folder path - instead of the ca.crt FILE PATH.
THIS Solve my âsignâ master-client problem.
NOw I have another problem but I will open another POST.
THX