Sun System Handbook - ISO 3.4 June 2011 Internal/Partner Edition | |||
|
|
Solution Type Sun Alert Sure Solution 1000658.1 : Sun Fire 12K/15K/20K/25K System Controller Management (scman) Networks May Fail After Applying Patch 122608-01 through 122608-03
PreviouslyPublishedAs 200868 Product Sun Fire 12K Server Solaris Security Toolkit 4.2 Sun Fire E20K Server Sun Fire 15K Server Sun Fire E25K Server Bug Id <SUNBUG: 6537623> Date of Resolved Release 20-JUN-2007 Impact Sun Fire 12K/15K/20K/25K System Controller Management Networks May Fail After Applying Patch 122608-03. As a result, any or all of the following conditions may occur: 1. Dynamic Reconfiguration (DR) operations may time-out. 2. Domain console(1M) may be in the (slower) IOSRAM mode, not the (faster) network mode. 3. Propagation of failover files to the spare System Controller may use the (slower) IOSRAM mode, not the (faster) network mode. Failover will still be functional. 4. TCP/IP communication using the virtual System Controller Management (scman) networks (to the other System Controller (SC) or from the SC to a domain) may fail. This means NTP and ssh(1), for example, will time-out on the scman networks. Contributing Factors This issue can occur on the following platforms:
This issue only occurs if all of the following conditions are true:
Symptoms If the described issue occurs, the following symptoms may be seen: 1. On the System Controller, the showfailover(1M) command output shows "Private I2 Network" in a state other than "Good" 2. Dynamic Reconfiguration operations time out. DR commands are cfgadm(1M) on the domain, or addboard(1M), deleteboard(1M), moveboard(1M), and rcfgadm(1M) on the System Controller. 3. TCP/IP operations (such as ping(1M) or ssh(1) on the scman0 or scman1 network fail. Workaround To work around the described issue, disable the "ipfilter" service in Solaris if the output of "svcs ipfilter" shows "ipfilter" is enabled: # svcs ipfilter STATE STIME FMRI online 16:34:54 svc:/network/ipfilter:default # svcadm disable ipfilter # svcs ipfilter STATE STIME FMRI disabled 7:42:05 svc:/network/ipfilter:default It is not necessary to reboot the system (but you may do so for other reasons). Resolution This issue is addressed in the following releases:
Note: If Solaris Security Toolkit 4.2 was run in "apply" mode since patch 122608-01, 122608-02, or 122608-03 was applied, run SST apply again: /opt/SUNWjass/bin/jass-execute -d sunfire_15k_sc-secure.driver and reboot the System Controller. If it is not known if Solaris Security Toolkit was run in apply mode since one of the patch versions mentioned above was present, apply SST again. No harm will occur by running SST "apply" multiple times. References<SUNPATCH: 122608-04>Previously Published As 102975 Internal Comments Internal Contributor/submitter [email protected] Internal Eng Business Unit Group SSG ES (Enterprise Systems) Internal Eng Responsible Engineer [email protected] Internal Services Knowledge Engineer [email protected] Internal Resolution Patches 122608-04 Internal Sun Alert Kasp Legacy ID 102975 Internal Sun Alert & FAB Admin Info Critical Category: Availability ==> Regression Significant Change Date: 2007-06-20 Avoidance: Patch, Workaround Responsible Manager: [email protected] Original Admin Info: [WF 20-Jun-2007, Jeff Folla: Sent for release.] [WF 19-Jun-2007, Jeff Folla: Sent for 24hr. review.] Product_uuid 077fd4c5-df8f-4320-ad69-7d01603a674d|Sun Fire 12K Server 0f04fae6-6043-11d9-a841-080020a9ed93|Solaris Security Toolkit 4.2 1404a2d3-059a-11d8-84cb-080020a9ed93|Sun Fire E20K Server 29e4659c-0a18-11d6-9fa1-e67bbc033df8|Sun Fire 15K Server d842dd03-059b-11d8-84cb-080020a9ed93|Sun Fire E25K Server ReferencesSUNPATCH:122608-04Attachments This solution has no attachment |
||||||||||||
|