# HA Configuration Issue

**URL:** <https://forums.suse.com/t/ha-configuration-issue/30090>\
**Category:** SLES High Availability Extension\
**Created:** [July 26, 2017, 8:45am UTC](https://forums.suse.com/t/ha-configuration-issue/30090 "2017-07-26T08:45:04Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![raju7258](https://avatars.discourse-cdn.com/v4/letter/r/9de053/32.png) [@raju7258](https://forums.suse.com/u/raju7258)\
**Post date:** [July 26, 2017, 8:45am UTC](https://forums.suse.com/t/ha-configuration-issue/30090/1 "2017-07-26T08:45:04Z")

</div>

Hi,

I am facing issue with HA cluster. I have 2 nodes. I am able to see one node online in each server respectively.

## NODE 1

SRVPHN85:~ # crm status  
Stack: corosync  
Current DC: SRVPHN85 (version 1.1.15-19.15-e174ec8) - partition WITHOUT quorum  
Last updated: Tue Jul 25 15:39:36 2017  
Last change: Tue Jul 25 14:04:02 2017 by root via cibadmin on SRVPHN85

1 node configured  
1 resource configured

Online: [SRVPHN85]

Full list of resources:

admin\_addr (ocf:💓IPaddr2): Stopped

* * *

## NODE 2

SRVPHN87:~ # crm status  
Stack: corosync  
Current DC: SRVPHN87 (version 1.1.15-21.1-e174ec8) - partition WITHOUT quorum  
Last updated: Tue Jul 25 15:35:00 2017  
Last change: Tue Jul 25 15:05:57 2017 by root via cibadmin on SRVPHN87

1 node configured  
0 resources configured

Online: [SRVPHN87]

Full list of resources:

* * *

Need to resolved the issue. Need help.

---

<div class="post-metadata">

**Author:** ![arunabha\_banerjee](https://avatars.discourse-cdn.com/v4/letter/a/e480ec/32.png) [@arunabha\_banerjee](https://forums.suse.com/u/arunabha_banerjee)\
**Post date:** [July 26, 2017, 10:10am UTC](https://forums.suse.com/t/ha-configuration-issue/30090/2 "2017-07-26T10:10:42Z")

</div>

Hi Raju,

Could you please share “crm configure show” output? I am suspecting there is some problem with network communication (multicast) between the nodes. Please change it to unicast and try to join the second node again.

Thanks

---

<div class="post-metadata">

**Author:** ![raju7258](https://avatars.discourse-cdn.com/v4/letter/r/9de053/32.png) [@raju7258](https://forums.suse.com/u/raju7258)\
**Post date:** [July 26, 2017, 10:56am UTC](https://forums.suse.com/t/ha-configuration-issue/30090/3 "2017-07-26T10:56:14Z")

</div>

Hi,

Thanks for the reply. I think ports 5404 and 5405 are blocked between nodes. Will there be any issue due to this.

SRVPHN85:~ # crm configure show  
node 184357468: SRVPHN85  
property cib-bootstrap-options: \  
have-watchdog=false \  
dc-version=1.1.15-21.1-e174ec8 \  
cluster-infrastructure=corosync \  
cluster-name=hacluster \  
show \  
stonith-enabled=false

* * *

SRVPHN87:~ # crm configure show  
node 184357468: SRVPHN87  
property cib-bootstrap-options: \  
have-watchdog=false \  
dc-version=1.1.15-21.1-e174ec8 \  
cluster-infrastructure=corosync \  
cluster-name=hacluster \  
show \  
stonith-enabled=false

* * *

---

<div class="post-metadata">

**Author:** ![raju7258](https://avatars.discourse-cdn.com/v4/letter/r/9de053/32.png) [@raju7258](https://forums.suse.com/u/raju7258)\
**Post date:** [July 26, 2017, 11:39am UTC](https://forums.suse.com/t/ha-configuration-issue/30090/4 "2017-07-26T11:39:45Z")

</div>

Sorry mistake.

SRVPHN85:~ # crm configure show  
node 184357467: SRVPHN85 \  
attributes standby=off  
primitive admin\_addr IPaddr2 \  
params ip=xx.xx.xx.xx \  
op monitor interval=10 timeout=20 \  
meta target-role=Started  
property cib-bootstrap-options: \  
have-watchdog=false \  
dc-version=1.1.15-19.15-e174ec8 \  
cluster-infrastructure=corosync \  
cluster-name=hacluster \  
stonith-enabled=false \  
placement-strategy=balanced  
rsc\_defaults rsc-options: \  
resource-stickiness=1 \  
migration-threshold=3  
op\_defaults op-options: \  
timeout=600 \  
record-pending=true

* * *

SRVPHN87:~ # crm configure show  
node 184357468: SRVPHN87  
property cib-bootstrap-options: \  
have-watchdog=false \  
dc-version=1.1.15-21.1-e174ec8 \  
cluster-infrastructure=corosync \  
cluster-name=hacluster \  
show \  
stonith-enabled=false

---

<div class="post-metadata">

**Author:** ![arunabha\_banerjee](https://avatars.discourse-cdn.com/v4/letter/a/e480ec/32.png) [@arunabha\_banerjee](https://forums.suse.com/u/arunabha_banerjee)\
**Post date:** [July 26, 2017, 5:10pm UTC](https://forums.suse.com/t/ha-configuration-issue/30090/5 "2017-07-26T17:10:15Z")

</div>

Please share “/etc/corosync/corosync.conf” file.

---

<div class="post-metadata">

**Author:** ![raju7258](https://avatars.discourse-cdn.com/v4/letter/r/9de053/32.png) [@raju7258](https://forums.suse.com/u/raju7258)\
**Post date:** [July 26, 2017, 5:35pm UTC](https://forums.suse.com/t/ha-configuration-issue/30090/6 "2017-07-26T17:35:08Z")

</div>

## NODE 1

# Please read the corosync.conf.5 manual page

totem {  
version: 2  
secauth: on  
crypto\_hash: sha1  
crypto\_cipher: aes256  
cluster\_name: hacluster  
clear\_node\_high\_bit: yes

```
token: 5000
token_retransmits_before_loss_const: 10
join: 60
consensus:	6000
max_messages:	20

interface {
	ringnumber:	0
	bindnetaddr:	xx.xx.xx.xx
	mcastaddr:	239.108.147.175
	mcastport:	5405
	ttl: 1
}

```

}  
logging {  
fileline: off  
to\_stderr: no  
to\_logfile: no  
logfile: /var/log/cluster/corosync.log  
to\_syslog: yes  
debug: off  
timestamp: on  
logger\_subsys {  
subsys: QUORUM  
debug: off  
}  
}  
quorum {  
# Enable and configure quorum subsystem (default: off)  
# see also corosync.conf.5 and votequorum.5  
provider: corosync\_votequorum  
expected\_votes: 3  
two\_node: 0  
}

## NODE 2

# Please read the corosync.conf.5 manual page

totem {  
version: 2  
secauth: on  
crypto\_hash: sha1  
crypto\_cipher: aes256  
cluster\_name: hacluster  
clear\_node\_high\_bit: yes

```
token: 5000
token_retransmits_before_loss_const: 10
join: 60
consensus:	6000
max_messages:	20

interface {
	ringnumber:	0
	bindnetaddr:	xx.xx.xx.xx
	mcastaddr:	239.108.147.175
	mcastport:	5405
	ttl: 1
}

```

}  
logging {  
fileline: off  
to\_stderr: no  
to\_logfile: no  
logfile: /var/log/cluster/corosync.log  
to\_syslog: yes  
debug: off  
timestamp: on  
logger\_subsys {  
subsys: QUORUM  
debug: off  
}  
}  
quorum {  
# Enable and configure quorum subsystem (default: off)  
# see also corosync.conf.5 and votequorum.5  
provider: corosync\_votequorum  
expected\_votes: 3  
two\_node: 0  
}

---

<div class="post-metadata">

**Author:** ![arunabha\_banerjee](https://avatars.discourse-cdn.com/v4/letter/a/e480ec/32.png) [@arunabha\_banerjee](https://forums.suse.com/u/arunabha_banerjee)\
**Post date:** [July 26, 2017, 5:56pm UTC](https://forums.suse.com/t/ha-configuration-issue/30090/7 "2017-07-26T17:56:39Z")

</div>

You have to change few things.

1. Change network communication ===\> udpu

[CODE]totem {  
version: 2  
secauth: on  
crypto\_hash: sha1  
crypto\_cipher: aes256  
cluster\_name: hacluster  
clear\_node\_high\_bit: yes  
token: 5000  
token\_retransmits\_before\_loss\_const: 10  
join: 60  
consensus: 6000  
max\_messages: 20  
interface {  
ringnumber: 0  
bindnetaddr: 192.168.220.0  
mcastport: 5405  
ttl: 1  
}

```
    transport: udpu

```

}  
[/CODE]

1. Change quorum section (For two nodes)

[CODE]quorum {

```
    # Enable and configure quorum subsystem (default: off)
    # see also corosync.conf.5 and votequorum.5
    provider: corosync_votequorum
    expected_votes: 2
    two_node: 1

```

}

[/CODE]

1. Set proper cib-bootstrap option (For two nodes)

`property cib-bootstrap-options: \\
        stonith-enabled=true \\
        placement-strategy=balanced \\
        no-quorum-policy=ignore \\
        stonith-action=reboot \\
        startup-fencing=false \\
        stonith-timeout=150 \\
`

---

<div class="post-metadata">

**Author:** ![raju7258](https://avatars.discourse-cdn.com/v4/letter/r/9de053/32.png) [@raju7258](https://forums.suse.com/u/raju7258)\
**Post date:** [July 27, 2017, 8:13am UTC](https://forums.suse.com/t/ha-configuration-issue/30090/8 "2017-07-27T08:13:46Z")

</div>

[QUOTE=arunabha\_banerjee;38879]You have to change few things.

1. Change network communication ===\> udpu

[CODE]totem {  
version: 2  
secauth: on  
crypto\_hash: sha1  
crypto\_cipher: aes256  
cluster\_name: hacluster  
clear\_node\_high\_bit: yes  
token: 5000  
token\_retransmits\_before\_loss\_const: 10  
join: 60  
consensus: 6000  
max\_messages: 20  
interface {  
ringnumber: 0  
bindnetaddr: 192.168.220.0  
mcastport: 5405  
ttl: 1  
}

```
    transport: udpu

```

}  
[/CODE]

1. Change quorum section (For two nodes)

[CODE]quorum {

```
    # Enable and configure quorum subsystem (default: off)
    # see also corosync.conf.5 and votequorum.5
    provider: corosync_votequorum
    expected_votes: 2
    two_node: 1

```

}

[/CODE]

1. Set proper cib-bootstrap option (For two nodes)

`property cib-bootstrap-options: \\
        stonith-enabled=true \\
        placement-strategy=balanced \\
        no-quorum-policy=ignore \\
        stonith-action=reboot \\
        startup-fencing=false \\
        stonith-timeout=150 \\
`[/QUOTE]

* * *

how can i remove the cluster from both nodes and start installing from first?

---

<div class="post-metadata">

**Author:** ![rajeshsamineni](https://avatars.discourse-cdn.com/v4/letter/r/3d9bf3/32.png) [@rajeshsamineni](https://forums.suse.com/u/rajeshsamineni)\
**Post date:** [September 24, 2018, 11:26am UTC](https://forums.suse.com/t/ha-configuration-issue/30090/9 "2018-09-24T11:26:36Z")

</div>

Seems both nodes are behaving like individual nodes, please use sleha-join -c to resolve the issue.

[QUOTE=raju7258;38869]Hi,

I am facing issue with HA cluster. I have 2 nodes. I am able to see one node online in each server respectively.

## NODE 1

SRVPHN85:~ # crm status  
Stack: corosync  
Current DC: SRVPHN85 (version 1.1.15-19.15-e174ec8) - partition WITHOUT quorum  
Last updated: Tue Jul 25 15:39:36 2017  
Last change: Tue Jul 25 14:04:02 2017 by root via cibadmin on SRVPHN85

1 node configured  
1 resource configured

Online: [SRVPHN85]

Full list of resources:

admin\_addr (ocf:💓IPaddr2): Stopped

* * *

## NODE 2

SRVPHN87:~ # crm status  
Stack: corosync  
Current DC: SRVPHN87 (version 1.1.15-21.1-e174ec8) - partition WITHOUT quorum  
Last updated: Tue Jul 25 15:35:00 2017  
Last change: Tue Jul 25 15:05:57 2017 by root via cibadmin on SRVPHN87

1 node configured  
0 resources configured

Online: [SRVPHN87]

Full list of resources:

* * *

Need to resolved the issue. Need help.[/QUOTE]

---

<div class="post-metadata">

**Author:** ![nnikalje](https://avatars.discourse-cdn.com/v4/letter/n/b9e5f3/32.png) [@nnikalje](https://forums.suse.com/u/nnikalje)\
**Post date:** [March 20, 2019, 1:14pm UTC](https://forums.suse.com/t/ha-configuration-issue/30090/10 "2019-03-20T13:14:02Z")

</div>

[QUOTE=raju7258;38869]Hi,

I am facing issue with HA cluster. I have 2 nodes. I am able to see one node online in each server respectively.

## NODE 1

SRVPHN85:~ # crm status  
Stack: corosync  
Current DC: SRVPHN85 (version 1.1.15-19.15-e174ec8) - partition WITHOUT quorum  
Last updated: Tue Jul 25 15:39:36 2017  
Last change: Tue Jul 25 14:04:02 2017 by root via cibadmin on SRVPHN85

1 node configured  
1 resource configured

Online: [SRVPHN85]

Full list of resources:

admin\_addr (ocf:💓IPaddr2): Stopped

* * *

## NODE 2

SRVPHN87:~ # crm status  
Stack: corosync  
Current DC: SRVPHN87 (version 1.1.15-21.1-e174ec8) - partition WITHOUT quorum  
Last updated: Tue Jul 25 15:35:00 2017  
Last change: Tue Jul 25 15:05:57 2017 by root via cibadmin on SRVPHN87

1 node configured  
0 resources configured

Online: [SRVPHN87]

Full list of resources:

* * *

Need to resolved the issue. Need help.[/QUOTE]

* * *

“Please check the servers are syncing time with NTP properly”

-Nitiratna Nikalje

---

<div class="post-metadata">

**Author:** ![strahil](https://avatars.discourse-cdn.com/v4/letter/s/b5ac83/32.png) [@strahil](https://forums.suse.com/u/strahil)\
**Post date:** [June 24, 2019, 11:19am UTC](https://forums.suse.com/t/ha-configuration-issue/30090/11 "2019-06-24T11:19:06Z")

</div>

Have you checked the firewall ports are opened?  
I have seen such behaviour when the nodes cannot communicate with each other.

As you haven’t mentioned which verison of SLES you are using - I assume SLES 15.  
It’s using firewalld by default and that doesn’t have a firewall service by default.

On my test openSUSE 15.1 I am using the following:

[CODE]# cat /etc/firewalld/services/high-availability.xml

\<?xml version="1.0" encoding="utf-8"?\> Custom High Availability Service This allows you to use the High Availability . Ports are opened for corosync, pacemaker\_remote, dlm , hawk and corosync-qnetd. [/CODE]
