IBM Support

QRadar on Cloud: Tunnel fails and interface does not exist

Troubleshooting


Problem

Tunnel fails when your adding QRadar on Cloud data gateway to deployment and interface does not exist.

Resolving The Problem

  1. Check the recent entries in /var/log/openvpn.log for errors:
    less +G /var/log/openvpn.log
  2. If the recent errors look similar to the following, it indicates the allowlisted public IP is not getting through the firewall and establishing a connection:
    us=601809 Attempting to establish TCP connection with [AF_INET]y.y.y.y.y:443 [nonblock]
    This TCP connection error can be resolved by checking the public IP of your data gateway and allowlist.
  3.  If the recent errors look similar to the following, it indicates you are able to connect, but the VPN tunnel cannot be established:
    us=601809 Attempting to establish TCP connection with [AF_INET]y.y.y.y.y:443 [nonblock]
    us=602264 TCP connection established with [AF_INET]y.y.y.y:443
    us=602439 TCP_CLIENT link local: (not bound)
    us=602497 TCP_CLIENT link remote: [AF_INET]y.y.y.y:443
    us=659543 Connection reset, restarting [0]
    us=659838 TCP/UDP: Closing socket
    us=660086 SIGUSR1[soft,connection-reset] received, process restarting
    This error indicates the connection gets reset and the socket is closed before the VPN tunnel is established. It is important to note we do not send resets, we simply drop the traffic. Some firewalls block at an application level and further block connections even if TCP 443 is allowed.
  4. Check the firewall at your site to ensure it is not filtering VPN.
  5. Once the VPN is allowed to connect and you get the correct output from ifconfig tun0, rerun the host add script by using a slightly different command:
    /opt/qradar/bin/setup_qradar_host.py mh_setup interactive –r

Document Location

Worldwide

[{"Type":"MASTER","Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSKMKU","label":"IBM QRadar on Cloud"},"ARM Category":[{"code":"a8m0z000000cwtNAAQ","label":"Deployment"},{"code":"a8m0z000000cwszAAA","label":"Install"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Versions"}]

Document Information

Modified date:
11 November 2022

UID

ibm16838833