Loading...
Loading...
On the Firewall Management Center (FMC), the Cisco Secure Dynamic Attributes Connector (CSDAC) component fails to start -- either by way of an initial configuration of the component or a restart of the already configured component. In the FMC GUI, the Dynamic Attributes Connector page may show "Enabling integration with Dynamic Attributes Connector" with either a failure at one of the stages or specifically be endlessly running at the "Verifying images" stage. On the GUI of affected FMC, the "Dynamic Attributes Connector Status" health module may show "Could not get status" as a critical alert. In the standard error logs (/var/log/process_stderr.log) on the affected FMC, one may see logs containing the following as an indication that name resolution is not working during the startup of CSDAC... ---- main.go:62: error during command execution: Get "https://public.ecr.aws/v2/": dial tcp: lookup public.ecr.aws: i/o timeout ---- ... with such error messages appearing as frequently as every 60-90 seconds. If a secondary (and, optionally, tertiary) DNS server is configured, name resolution by other components of the FMC (for example, the download of content updates by the FMC) has been confirmed to be properly working (for example, content updates properly download and install).
The FMC runs a software version where CSDAC is a component directly on the FMC -- version 7.4.1 or later. The primary DNS server configured in the management interface settings of the FMC is either completely inaccessible from the FMC (if a DNS server even exists at that IP address) or cannot properly complete name resolution. CSDAC has been activated on the FMC.
Ensure that the DNS server configured as the primary DNS server in the management interface settings of the FMC is one that is accessible by the FMC and can properly complete name resolution. Change the configured primary DNS server as necessary.
If CSDAC has already been configured and has been confirmed to be working, saving the management interface settings in the FMC GUI will restart backend processes for CSDAC. Thus, if one changes the primary DNS server from one that is working to one that does not work and then saves the management interface settings, CSDAC will fail to restart. The problem reported here will happen even if secondary and/or tertiary DNS servers have been configured on the FMC.
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.