# Support and questions about distributed monitoring

**URL:** <https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456>\
**Category:** Icinga 2\
**Created:** [March 19, 2022, 12:49pm UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456 "2022-03-19T12:49:46Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![mainik](https://community.icinga.com/letter_avatar_proxy/v4/letter/m/8baadc/32.png) [@mainik](https://community.icinga.com/u/mainik)\
**Post date:** [March 19, 2022, 12:49pm UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/1 "2022-03-19T12:49:47Z")

</div>

Hello,

I’m quite insecure about the distributed monitoring in my case:

I currently have a OnPrem Master running as a CentOS 8 Virtual Machine in our internal network (Icinga 2.13.2-1, web 2-9-5, director 1.9.0)

In a project we got new external hosted machines (ionos 1and1 monitoring is pretty limited and does not give me needed information)

I already setup an satellite instance of icinga in our DMZ-Network which works flawless in communication to internal network.

Here are my insecuritys are starting about the correct deployment:

I tried to setup the external hosted machine as additional satellite which has his parent to the DMZ satellite Instance (used our firewall to setup some rules that only the IP of the external hosted machine can access port 5665 to the dmz satellite)

After importing the new satellite to the master. I setup a new host which only is accessible from the external hosted machine but the hostalive check doesnt finish and is outstanding.

I didnt find something for stacking satellites, maybe its an design problem from my site. Here is a photo how I thought this design could work?

 ![grafik](https://community.icinga.com/uploads/default/original/2X/b/b0292a6ca38151acde1e53e07052ff687eb9cbeb.png)

zones.conf from master:

```auto
`object Endpoint "dmz-satellite" {
}

object Zone "dmz-satellite" {
        endpoints = ["dmz-satellite"]
        parent = "internal master"
}

object Endpoint "external hosted server" {
}

object Zone "external hosted server" {
        endpoints = ["external hosted server"]
        parent = "dmz-satellite"
}
`

```

Im happy for every input and corrections 🙂

---

<div class="post-metadata">

**Author:** ![ShowMeYourSkil](https://community.icinga.com/user_avatar/community.icinga.com/showmeyourskil/32/4975_2.png) [@ShowMeYourSkil](https://community.icinga.com/u/ShowMeYourSkil)\
**Post date:** [March 19, 2022, 5:32pm UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/3 "2022-03-19T17:32:41Z")

</div>

Hi, I don’t see a problem with your design at the moment. Have you ever tried to query the host via the DMZ satellite? What do the uptime statistics of the satellites say? Have you blocked the interface rolls in the firewall or not released the port in both directions?

---

<div class="post-metadata">

**Author:** ![rsx](https://community.icinga.com/user_avatar/community.icinga.com/rsx/32/2094_2.png) [@rsx](https://community.icinga.com/u/rsx)\
**Post date:** [March 21, 2022, 8:11am UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/4 "2022-03-21T08:11:03Z")

</div>

As you do not share enough details here some general hints. With [cluster-zone](https://icinga.com/docs/icinga-2/latest/doc/10-icinga-template-library/#cluster-zone) you can define checks which informs you whether a zone is connected or not. Second, in `icinga2.log` of all icinga instances you’ll find hints about connection tries and failures.

---

<div class="post-metadata">

**Author:** ![mainik](https://community.icinga.com/letter_avatar_proxy/v4/letter/m/8baadc/32.png) [@mainik](https://community.icinga.com/u/mainik)\
**Post date:** [March 21, 2022, 12:24pm UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/5 "2022-03-21T12:24:23Z")

</div>

Hey, thanks for your message. I think Firewall isnt an issue as I created rules, means:

Internal master connects successfully to DMZ-Satellite and DMZ-Satellite connects to the Internal master successfully.

The DMZ-Satellite connects successfully to the external hosted server and external hosted server connects to the dmz satellite successfully.

---

<div class="post-metadata">

**Author:** ![mainik](https://community.icinga.com/letter_avatar_proxy/v4/letter/m/8baadc/32.png) [@mainik](https://community.icinga.com/u/mainik)\
**Post date:** [March 21, 2022, 12:46pm UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/6 "2022-03-21T12:46:06Z")

</div>

Hello Roland, thanks for the hint about cluster-zone, will look into it. Here are some more Information I have found.

icinga2.log on the DMZ-Satellite:

> Ignoring config update from endpoint ‘Internal Master’ for unknown zone ‘External hosted server’

so there is something wrong in a zones.conf ?

Here is the zones.conf from the DMZ-Satellite:

```auto

object Endpoint "internal master" {
        host = "internal master"
        port = "5665"
}

object Zone "master" {
        endpoints = ["internal master"]
}

object Endpoint "dmz-satellite" {
}

object Zone "dmz-satellite" {
        endpoints = ["dmz-satellite"]
        parent = "master"
}

object Zone "global-templates" {
        global = true
}

object Zone "director-global" {
        global = true
}

```

here is the zones.conf from the external hosted server

```auto

object Endpoint "dmz-satellite" {
        host = "x.x.x.x"
        port = "5665"
}

object Zone "master" {
        endpoints = ["dmz-satellite"]
}

object Endpoint "external hosted server" {
}

object Zone "external hosted server" {
        endpoints = ["external hosted server"]
        parent = "master"
}

object Zone "global-templates" {
        global = true
}

object Zone "director-global" {
        global = true
}

```

If I run icinga2 daemon -C on all servers there are no errors and everything is green…  
Here a Screeshot from th director with the endpoints:

 ![grafik](https://community.icinga.com/uploads/default/original/2X/5/5d8f13fe8967bbf6f73b9f07cb248c0ddbbc246f.png)

---

<div class="post-metadata">

**Author:** ![rsx](https://community.icinga.com/user_avatar/community.icinga.com/rsx/32/2094_2.png) [@rsx](https://community.icinga.com/u/rsx)\
**Post date:** [March 21, 2022, 12:58pm UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/7 "2022-03-21T12:58:10Z")

</div>

You have defined a zone called master with two different endpoints and I’m not sure if this would work. As it is confusing anyway I’d not do it.

---

<div class="post-metadata">

**Author:** ![mainik](https://community.icinga.com/letter_avatar_proxy/v4/letter/m/8baadc/32.png) [@mainik](https://community.icinga.com/u/mainik)\
**Post date:** [March 21, 2022, 1:12pm UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/8 "2022-03-21T13:12:52Z")

</div>

Hello Roland, thanks for your reply! For my understanding I have to set different endpoints?

The endpoint for the external hosted satellite is the dmz-satellite (?)  
The endpoint for the dmz-satellite is the internal master (?)

So that the external hosted satellite uses the dmz-satellite as bridge and that I dont need to forward any ports from the internal master to the WWW (?)

---

<div class="post-metadata">

**Author:** ![rsx](https://community.icinga.com/user_avatar/community.icinga.com/rsx/32/2094_2.png) [@rsx](https://community.icinga.com/u/rsx)\
**Post date:** [March 21, 2022, 1:38pm UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/9 "2022-03-21T13:38:48Z")

</div>

I was talking about this:

> [@](#):
>
> ```auto
> object Zone "master" {
> endpoints = ["internal master"]
> }
> 
> ```

> [@](#):
>
> ```auto
> object Zone "master" {
> endpoints = ["dmz-satellite"]
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![mainik](https://community.icinga.com/letter_avatar_proxy/v4/letter/m/8baadc/32.png) [@mainik](https://community.icinga.com/u/mainik)\
**Post date:** [March 21, 2022, 2:06pm UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/10 "2022-03-21T14:06:00Z")

</div>

Yes, I know that you were reffering to this two distinctions… Is it an mistake like this?

I can not understand how the external hosted satellite should communicate with the internal master without using the dmz-satellite as bridge which means to me that the parent for the external hosted server is the dmz-satellite?

---

<div class="post-metadata">

**Author:** ![9strands](https://community.icinga.com/user_avatar/community.icinga.com/9strands/32/7702_2.png) [@9strands](https://community.icinga.com/u/9strands)\
**Post date:** [March 25, 2022, 1:40am UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/11 "2022-03-25T01:40:20Z")

</div>

> [@rsx](#):
>
> ```auto
> object Zone "master" {
> endpoints = ["dmz-satellite"]
> }
> 
> ```

Wouldn’t you want to define both in the same stanza, like this?

```auto
object Zone "master" {
        endpoints = ["dmz-satellite", "internal master"]
}

```

---

<div class="post-metadata">

**Author:** ![mainik](https://community.icinga.com/letter_avatar_proxy/v4/letter/m/8baadc/32.png) [@mainik](https://community.icinga.com/u/mainik)\
**Post date:** [March 29, 2022, 9:12am UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/12 "2022-03-29T09:12:54Z")

</div>

Hmmm, I changed the zones.conf on the external site like this without success…  
I’m already thinking about making the dmz-satellite to an standalone extra master and configure the external server as satellite, maybe I’m more successfull with this solution

---

<div class="post-metadata">

**Author:** ![rsx](https://community.icinga.com/user_avatar/community.icinga.com/rsx/32/2094_2.png) [@rsx](https://community.icinga.com/u/rsx)\
**Post date:** [March 29, 2022, 12:23pm UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/13 "2022-03-29T12:23:35Z")

</div>

You need something like this

```auto
object Zone "master" {
        endpoints = ["internal master"]
}

object Endpoint "internal master" {
}

object Zone "dmz-satellite" {
        endpoints = ["dmz-satellite"]
        parent = "master"
}

object Endpoint "dmz-satellite" {
}

object Zone "external-satellite" {
        endpoints = ["external-satellite"]
        parent = "dmz-satellite"
}

object Endpoint "external-satellite" {
}

object Zone "external hosted server" {
        endpoints = ["external hosted server"]
        parent = "external-satellite"
}

object Endpoint "external hosted server" {
}

```

Easiest is to have this on every node and add `host` and `port` on those nodes who shall initiate to cluster connection.

---

<div class="post-metadata">

**Author:** ![9strands](https://community.icinga.com/user_avatar/community.icinga.com/9strands/32/7702_2.png) [@9strands](https://community.icinga.com/u/9strands)\
**Post date:** [March 29, 2022, 11:31pm UTC](https://community.icinga.com/t/support-and-questions-about-distributed-monitoring/9456/14 "2022-03-29T23:31:13Z")

</div>

Ah, from your previous configuration, I though that was already supposed to be another master node. If that wasn’t intended, then definitely don’t do what I recommended!
