<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster AG behind F5 in Dynatrace Managed Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Cluster-AG-behind-F5/m-p/220407#M2746</link>
    <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hello &lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/16821"&gt;@Islam_Zedan&lt;/a&gt; There are probably many reasons why you might get this. I used to have a similar setup with no issues, what I kept in mind is the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Name-mismatch error: &lt;/SPAN&gt;Your certificate is associated with a specific host name. To avoid a name-mismatch error, make sure that the common name (domain name) in the SSL certificate matches the address displayed in the address bar of the browser.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Do not configure the SSL certificate directly on the device. &lt;/SPAN&gt;Do not attempt to configure SSL certificates directly to your Cluster ActiveGate, by uploading them to the device itself. If you do this, the certificate will be overwritten by automatic management performed by Dynatrace. &lt;STRONG&gt;Upload your certificate using the Cluster Management Console or &lt;A class="" title="Learn how to use the Dynatrace API to store cluster SSL certificate." href="https://www.dynatrace.com/support/help/managed-cluster/cluster-api/cluster-api-v1/ssl-certificates-v1/post-cluster-ssl-cert-store-status" target="_blank" rel="noopener"&gt;the Cluster REST API v1&lt;/A&gt;.&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.dynatrace.com/support/help/shortlink/rum-firewall" target="_blank" rel="noopener"&gt;https://www.dynatrace.com/support/help/shortlink/rum-firewall&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Also we used a Ping/Pong dummy server to test just networking configuration without the added complexity of Dynatrace config.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 10 Aug 2023 17:34:58 GMT</pubDate>
    <dc:creator>DanielS</dc:creator>
    <dc:date>2023-08-10T17:34:58Z</dc:date>
    <item>
      <title>Cluster AG behind F5</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Cluster-AG-behind-F5/m-p/220282#M2741</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have a customer who want to deploy 2 CAG behind a F5, they configured an endpoint with a public IP to receive the traffic on port 443 they reroute from the LB to CAGs on port 9999. currently we are getting "&lt;SPAN&gt;OpenSSL SSL_read: SSL_ERROR_SYSCALL, errno 104" error even with certificate applied on both AGs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Anyone faced that before? and what is the recommended configuration for such setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Islam&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2023 12:27:35 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Cluster-AG-behind-F5/m-p/220282#M2741</guid>
      <dc:creator>Islam_Zedan</dc:creator>
      <dc:date>2023-08-09T12:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster AG behind F5</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Cluster-AG-behind-F5/m-p/220407#M2746</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;Hello &lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/16821"&gt;@Islam_Zedan&lt;/a&gt; There are probably many reasons why you might get this. I used to have a similar setup with no issues, what I kept in mind is the following:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Name-mismatch error: &lt;/SPAN&gt;Your certificate is associated with a specific host name. To avoid a name-mismatch error, make sure that the common name (domain name) in the SSL certificate matches the address displayed in the address bar of the browser.&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;Do not configure the SSL certificate directly on the device. &lt;/SPAN&gt;Do not attempt to configure SSL certificates directly to your Cluster ActiveGate, by uploading them to the device itself. If you do this, the certificate will be overwritten by automatic management performed by Dynatrace. &lt;STRONG&gt;Upload your certificate using the Cluster Management Console or &lt;A class="" title="Learn how to use the Dynatrace API to store cluster SSL certificate." href="https://www.dynatrace.com/support/help/managed-cluster/cluster-api/cluster-api-v1/ssl-certificates-v1/post-cluster-ssl-cert-store-status" target="_blank" rel="noopener"&gt;the Cluster REST API v1&lt;/A&gt;.&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://www.dynatrace.com/support/help/shortlink/rum-firewall" target="_blank" rel="noopener"&gt;https://www.dynatrace.com/support/help/shortlink/rum-firewall&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;Also we used a Ping/Pong dummy server to test just networking configuration without the added complexity of Dynatrace config.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 10 Aug 2023 17:34:58 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Cluster-AG-behind-F5/m-p/220407#M2746</guid>
      <dc:creator>DanielS</dc:creator>
      <dc:date>2023-08-10T17:34:58Z</dc:date>
    </item>
  </channel>
</rss>

