values that are commented out # serve to show the default. # If extensions (or modules to document with autodoc) are in another directory, # add these directories to sys.path here. If the directory is relative to the # documentation root, use os.path.abspath to make it absolute, like shown here. # # import os # import sys # sys.path.insert(0, os.path.abspath('.')) import sphinx_rtd_theme #from better import better_theme_path def setup(app): app.add_stylesheet('css/custom.css') app.add_javascript('js/custom.js') app.add_javascript('js/') app.add_javascript('js/marketo-munchkin.js') app.add_javascript('js/drift.js') # -- General configuration ------------------------------------------------ # If your documentation needs a minimal Sphinx version, state it here. # # needs_sphinx = '1.0' # Add any Sphinx extension module names here, as strings. They can be # extensions coming with Sphinx (named 'sphinx.ext.*') or your custom # ones. #extensions = [] extensions = ['sphinxcontrib.disqus'] # Add any paths that contain templates here, relative to this directory. templates_path = ['_templates'] # The suffix(es) of source filenames. # You can specify multiple suffix as a list of string: # # source_suffix = ['.rst', '.md'] source_suffix = '.rst' # The master toctree document. master_doc = 'index' # General information about the project. project = 'aviatrix_docs' copyright = '2018, Aviatrix Systems, Inc' author = 'Aviatrix' # Options for extensions disqus_shortname = 'docs-aviatrix-com' # The version info for the project you're documenting, acts as replacement for # |version| and |release|, also used in various other places throughout the # built documents. # # The short X.Y version. version = '' # The full version, including alpha/beta/rc tags. release = '' # The language for content autogenerated by Sphinx. Refer to documentation # for a list of supported languages. # # This is also used if you do content translation via gettext catalogs. # Usually you set "language" from the command line for these cases. language = None # List of patterns, relative to source directory, that match files and # directories to ignore when looking for source files. # This patterns also effect to html_static_path and html_extra_path exclude_patterns = ['_build', 'Thumbs.db', '.DS_Store'] # The name of the Pygments (syntax highlighting) style to use. pygments_style = 'sphinx' # If true, `todo` and `todoList` produce output, else they produce nothing. todo_include_todos = False # -- Options for HTML output ---------------------------------------------- # The theme to use for HTML and HTML Help pages. See the documentation for # a list of builtin themes. # #html_theme = "nature" #html_theme = "alabaster" #html_theme = "haiku" html_theme = "sphinx_rtd_theme" #html_theme = 'custom' #html_theme_path = [sphinx_rtd_theme.get_html_theme_path()] #html_theme_path = [better_theme_path] #html_theme = 'better' #html_style = 'aviatrix_theme.css' # make sure search results for relative urls link to html_use_opensearch = '' # Theme options are theme-specific and customize the look and feel of a theme # further. For a list of options available for each theme, see the # documentation. # html_theme_options = { 'logo_only': True, 'display_version': False, } # html_logo goes here, lets try this #html_logo = 'logo-aviatrix-new.png' #html_logo = 'aviatrix-logo-final - bold.png' html_logo = 'aviatrix_logo_final_reverse.png' # Add any paths that contain custom static files (such as style sheets) here, # relative to this directory. They are copied after the builtin static files, # so a file named "default.css" will overwrite the builtin "default.css". html_static_path = ['_static'] # -- Options for HTMLHelp output ------------------------------------------ # Output file base name for HTML help builder. htmlhelp_basename = 'aviatrix_docsdoc' # -- Options for LaTeX output --------------------------------------------- latex_elements = { # The paper size ('letterpaper' or 'a4paper'). # # 'papersize': 'letterpaper', # The font size ('10pt', '11pt' or '12pt'). # # 'pointsize': '10pt', # Additional stuff for the LaTeX preamble. # # 'preamble': '', # Latex figure (float) alignment # # 'figure_align': 'htbp', } # Grouping the document tree into LaTeX files. List of tuples # (source start file, target name, title, # author, documentclass [howto, manual, or own class]). latex_documents = [ (master_doc, 'aviatrix_docs.tex', 'aviatrix\\_docs Home', 'Aviatrix Systems', 'manual'), ] # -- Options for manual page output --------------------------------------- # One entry per manual page. List of tuples # (source start file, name, description, authors, manual section). man_pages = [ (master_doc, 'aviatrix_docs', 'aviatrix_docs Home', [author], 1) ] # -- Options for Texinfo output ------------------------------------------- # Grouping the document tree into Texinfo files. List of tuples # (source start file, target name, title, author, # dir menu entry, description, category) texinfo_documents = [ (master_doc, 'aviatrix_docs', 'aviatrix_docs Home', author, 'aviatrix_docs', 'One line description of project.', 'Miscellaneous'), ] ########################################################################### # auto-created specific configuration # ########################################################################### # # The following code was added during an automated build on # It is auto created and injected for every build. The result is based on the # file found in the codebase: # # import importlib import sys import os.path from six import string_types from sphinx import version_info # Get suffix for proper linking to GitHub # This is deprecated in Sphinx 1.3+, # as each page can have its own suffix if globals().get('source_suffix', False): if isinstance(source_suffix, string_types): SUFFIX = source_suffix else: SUFFIX = source_suffix[0] else: SUFFIX = '.rst' # Add RTD Static Path. # Add RTD Static Path. Add to the end because it overwrites previous files.
if not 'html_static_path' in globals():
    html_static_path = []
if os.path.exists('_static'):
    html_static_path.append('_static')

# Add RTD Theme only if they aren't overriding it already
using_rtd_theme = (
    (
        'html_theme' in globals() and
        html_theme in ['default'] and
        # Allow people to bail with a hack of having an html_style
        'html_style' not in globals()
    )
    or 'html_theme' not in globals()
)
if using_rtd_theme:
    theme = importlib.import_module('sphinx_rtd_theme')
    html_theme = 'sphinx_rtd_theme'
    html_style = None
    html_theme_options = {}
    if 'html_theme_path' in globals():
        html_theme_path.append(theme.get_html_theme_path())
    else:
        html_theme_path = [theme.get_html_theme_path()]

if globals().get('websupport2_base_url', False):
    websupport2_base_url = ''
    websupport2_static_url = ''

#Add project information to the template context.
context = {
    'using_theme': using_rtd_theme,
    'html_theme': html_theme,
    'current_version': "latest",
    'version_slug': "latest",
    'MEDIA_URL': "",
    'STATIC_URL': "",
    'PRODUCTION_DOMAIN': "",
    'versions': [
        ("latest", "/en/latest/"),
    ],
    'downloads': [
        ("htmlzip", "//"),
    ],
    'subprojects': [
    ],
    'slug': 'aviatrix-systems-inc-docs',
    'name': u'Docs',
    'rtd_language': u'en',
    'programming_language': u'words',
    'canonical_url': '',
    'analytics_code': 'UA-62571988-1',
    'single_version': False,
    'conf_py_path': '/',
    'api_host': '',
    'github_user': 'AviatrixSystems',
    'github_repo': 'Docs',
    'github_version': 'master',
    'display_github': True,
    'bitbucket_user': 'None',
    'bitbucket_repo': 'None',
    'bitbucket_version': 'master',
    'display_bitbucket': False,
    'gitlab_user': 'None',
    'gitlab_repo': 'None',
    'gitlab_version': 'master',
    'display_gitlab': False,
    'READTHEDOCS': True,
    'using_theme': (html_theme == "default"),
    'new_theme': (html_theme == "sphinx_rtd_theme"),
    'source_suffix': SUFFIX,
    'ad_free': False,
    'user_analytics_code': 'UA-62571988-1',
    'global_analytics_code': 'UA-17997319-2',
    'commit': 'a43bb3d5',
}

if 'html_context' in globals():
    html_context.update(context)
else:
    html_context = context

# Add custom RTD extension
if 'extensions' in globals():
    # Insert at the beginning because it can interfere
    # with other extensions.
    # See
    extensions.insert(0, "readthedocs_ext.readthedocs")
else:
    extensions = ["readthedocs_ext.readthedocs"] Diagnostic Result --------------- /home/docs/checkouts/ ERROR: Malformed table. +-----------------------------+----------------------------------------------------------------+ |**Controller Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "controller": { | | "SumoLogic Collector": "Not running", | | "Database": "Up", | | "logstash-forwarder": "Not running", | | "Rsyslog Status": "Not running", | | "CloudWatch Service": "Not running", | | "splunkd": "Not running", | | "Connectivity": "Up", | | "SSH": { | | "port": { | | "22": "Down" | | }, | | "service": "Up" | | }, | | "datadog-agent": "Not running", | | "Public IP": "Pass", | | "PKI": "Pass", | | "rsyslogd": "Running" | | } | | | +-----------------------------+----------------------------------------------------------------+ |Indicates Controller status. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Netflow Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "Netflow Service": "Not running", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates Netflow service status. | | - Default: Not running | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Utility Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "Files not found": [ | | "/etc/openvpn/", | | ... (the rest is omitted.) | | ], | | | +-----------------------------+----------------------------------------------------------------+ |N/A | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**LogStash Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "logstash-forwarder": "Not running", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates Logstash logging service status. | | - Default: Not running | | - Related Link `LogStash Integration`_. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**DNS Resolution Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "DNS resolution": "Pass", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates if the gateway can resolve public domain names. | | - Expected value: Pass | | | | - If the result is Fail, check whether the DNS resolution is enabled for the VPC where this | | | | for the VPC where this gateway resides, gateway's security group and | | | | VPC inbound and outbound ACL. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Hostname-filter Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "Hostname-filter Report": [ | | "{\n", | | " \"\": {\n", | | " \"ip_list\": [\n", | | " \"\", \n", | | " \"\", \n", | | " \"\", \n", | | " \"\"\n", | | " ], \n", | | " \"thread_state\": \"ALIVE\"\n", | | " }\n", | | "}" | | ], | | | +-----------------------------+----------------------------------------------------------------+ |Indicates the Hostname filter configuration. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Rsyslog Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "Rsyslog Status": "Disabled", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates the Remote Syslog feature is enabled. | | - Related Link `Remote Syslog Integration`_. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**ipset Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "ipset rules": [ | | "Name: avx_hnf_ipset_d_accept\n", | | "Type: hash:ip,port\n", | | "Revision: 5\n", | | "Header: family inet hashsize ... (the rest is omitted.) | | "Size in memory: 4564\n", | | "References: 1\n", | | "Number of entries: 36\n", | | "Members:\n", | | ",tcp:25 comment \"\"\n", | | ",tcp:25 comment \"\"\n", | | ",tcp:25 comment \"\"\n", | | ",tcp:25 comment \"\"\n", | | ",tcp:25 comment \"\"\n" | | ], | | | +-----------------------------+----------------------------------------------------------------+ |N/A | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**SpanPort Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "SpanPort Service": { | | "port": "unknown", | | "service": "Down" | | }, | | | +-----------------------------+----------------------------------------------------------------+ |Currently not used. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**iptables nat Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "iptables nat rules": [ | | "-P PREROUTING ACCEPT\n", | | "-P INPUT ACCEPT\n", | | "-P OUTPUT ACCEPT\n", | | "-P POSTROUTING ACCEPT\n", | | "-N CLOUDN-LOG-natVPN\n", | | "-N CLOUDX-SNAT\n", | | "-A POSTROUTING -s -j CLOUDN-LOG-natVPN\n", | | "-A POSTROUTING -m addrtype --src-type LOCAL -j ACCEPT\n", | | "-A POSTROUTING -m policy --dir out --pol ipsec -j ACCEPT\n", | | "-A POSTROUTING -j CLOUDX-SNAT\n", | | "-A CLOUDN-LOG-natVPN -j LOG --log-prefix \"AviatrixUser: \"\n", | | "-A CLOUDN-LOG-natVPN -j MASQUERADE\n", | | "-A CLOUDX-SNAT -o eth0 -j MASQUERADE\n" | | ], | | | +-----------------------------+----------------------------------------------------------------+ |Indicates NAT configuration. | | - mainly used for debugging | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Hostname-filter Status** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "Hostname-filter Status": [ | | " avx-hostname-filter.service - Aviatrix Hostname Filter\n", | | " Loaded: loaded (/lib/systemd/system/a ... (the rest is omitted.) | | " Active: inactive (dead)\n" | | | +-----------------------------+----------------------------------------------------------------+ |Indicates Hostname-filter service status | | - Default: inactive | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**iptables Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "iptables rules": [ | | "-P INPUT ACCEPT\n", | | "-P FORWARD ACCEPT\n", | | "-P OUTPUT ACCEPT\n", | | "-N AVX-FILTER-BASE-LOG-ACCEPT\n", | | "-N AVX-FILTER-BASE-LOG-DROP\n", | | "-N AVX-FILTER-CHAIN\n", | | "-N AVX-FILTER-MATCH-LOG-ACCEPT\n", | | "-N AVX-FILTER-MATCH-LOG-DROP\n", | | "-N CLOUDN-AVX-NFQ\n", | | "-N RULE-LOG-ACCEPT\n", | | "-N RULE-LOG-DROP\n", | | ... (the rest is omitted.) | | ], | | | +-----------------------------+----------------------------------------------------------------+ |Indicates Stateful firewall configuration | | - mainly used for debugging | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**ifconfig Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "ifconfig display": [ | | "eth0: flags=4163 The maximum size of /usr should be lower than 6G, please contact | | | | if you see abnormal usage in a folder. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**MsgQueue Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "MsgQueue": { | | "ApproximateNumberOfMessagesNotVisible": "0", | | | | "ContentBasedDeduplication": "false", | | "MessageRetentionPeriod": "345600", | | "ApproximateNumberOfMessagesDelayed": "0", | | "MaximumMessageSize": "262144", | | "CreatedTimestamp": "1545101799", | | "ApproximateNumberOfMessages": "0", | | "ReceiveMessageWaitTimeSeconds": "0", | | "DelaySeconds": "0", | | "FifoQueue": "true", | | "VisibilityTimeout": "30", | | "LastModifiedTimestamp": "1545101878", | | "QueueArn": "arn:aws:sqs:us-west-2:xxxxxx:aviatrix-34-xxx-xxx-16.fifo" | | }, | | | +-----------------------------+----------------------------------------------------------------+ |Indicates AWS SQS message queue status. | | - ApproximateNumberOfMessages indicates the number of pending messages | | | | in the queue. | | | | - Expected value is 0. | | | | - If this value is not 0, it means there's issue on the AWS SQS Service, please update | | | | your IAM policy (refer to `IAM Policy`_. and check if the DNS resolution | | | | passed on the gateway.) You may also check if this SQS queue is still in your AWS | | | | SQS Service. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Supervisorctl Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "supervisorctl status": [ | | "gwmon RUNNING pid 2857, uptime 5:25:55\n", | | "local_launch EXITED Dec 18 02:58 AM\n", | | "openvpn RUNNING pid 5430, uptime 5:20:42\n", | | "perfmon RUNNING pid 2876, uptime 5:25:53\n", | | "sw-wdt4perfmon RUNNING pid 2894, uptime 5:25:51\n", | | "time_action RUNNING pid 2816, uptime 5:25:56\n" | | ], | | | +-----------------------------+----------------------------------------------------------------+ |Indicates the supervisor status. | | - All services should be in RUNNING state except local_launch. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**IKE daemon Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "IKE daemon": { | | "port": { | | "500": "Up", | | "4500": "Up" | | }, | | "service": "Up" | | }, | | | +-----------------------------+----------------------------------------------------------------+ |Indicates IKE daemon service and port status | | - Default: Up for all | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**SumoLogic Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "SumoLogic Collector": "Not running", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates SumoLogic logging service status. | | - Default: Not running | | - Related Link `Sumologic Integration`_. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Upload Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "Upload": "Pass", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates that Aviatrix controller is able to upload files to the gateway. | | - Expected value: Pass | | | | - If fail, please check the port 443 is open in both security group and VPC ACL between | | | | controller and the gateway instance in AWS console. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Datadog Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "Datadog Service": "Not running", | | | +-----------------------------+----------------------------------------------------------------+ | Indicates Datadog logging service status. | | - Default: Not running | | - Related Link `Datadog Integratin`_. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**iptables mangle Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "iptables mangle rules": [ | | "-P PREROUTING ACCEPT\n", | | "-P INPUT ACCEPT\n", | | "-P FORWARD ACCEPT\n", | | "-P OUTPUT ACCEPT\n", | | "-P POSTROUTING ACCEPT\n", | | "-N MSSCLAMPING\n", | | "-A FORWARD -j MSSCLAMPING\n", | | "-A MSSCLAMPING -p ... (the rest is omitted.) | | ], | | | +-----------------------------+----------------------------------------------------------------+ |Indicates iptables mangle configuration. | | - For debugging purpose | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**HTTPS Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "HTTPS": { | | "port": { | | | | "443": [ | | "up", | | "reachable" | | ] | | }, | | "service": "Up" | | }, | | | +-----------------------------+----------------------------------------------------------------+ |Indicates the HTTPS status and reachability on the gateway. | | - Expected value: Up and reachable | | | | - If Fail, please make sure the gateway has its security group port 443 open to the | | | | controller's EIP in AWS console. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**HTTPS Get Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "HTTPS GET": "Pass", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates connectivity for HTTPS request from gateway to the controller. | | - Expected value: Pass if GW can communicate with Controller without issue. | | | | When It shows "Fail" please check both Controller and Gateway security group | | | | - If Fail, please make sure the controller has its security group port 443 open to the | | | | gateway's EIP in AWS console. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**CloudWatch Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "CloudWatch Service": "Not running", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates the AWS CloudWatch service status. | | - Default: Not running | | - Related Link `Cloudwatch How To`_. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Top Memory Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "top mem processes": [ | | "20.2 0.1 398548 432 /lib/systemd/systemd-journald\n", | | | | " 4.6 0.0 454976 1761 /usr/sbin/apache2 -k start\n", | | " 4.3 0.1 807656 2857 python -W ... (the rest is omitted.) | | " 2.8 0.0 90920 2876 python -W ... (the rest is omitted.) | | " 2.6 0.0 84700 2816 python -W ... (the rest is omitted.) | | " 2.2 0.0 457688 5299 /usr/sbin/apache2 -k start\n", | | " 2.1 0.0 65268 1992 /usr/bin/p ... (the rest is omitted.) | | " 2.1 0.0 457688 5297 /usr/sbin/apache2 -k start\n", | | " 1.9 0.0 548016 1183 /usr/lib/snapd/snapd\n", | | " 1.8 0.0 457452 5300 /usr/sbin/apache2 -k start\n" | | ], | | | +-----------------------------+----------------------------------------------------------------+ |Indicates the memory and CPU usage of the gateway. | | - The memory usage of processes (first column) is changing dynamiclly and the overall | | | | usage should be lower than 50% | | | | - Mainly used for debugging | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Splunk Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "splunkd": "Not running", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates Splunk logging service status. | | - Default: Not running | | - Related Link `splunk Integration`_. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**VPN Service Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "VPN Service": { | | "port": { | | | | "943": [ | | | | "up", | | "reachable" | | ] | | }, | | "service": "Down" | | }, | | | +-----------------------------+----------------------------------------------------------------+ |Indicates OpenVPN service status. | | - Status is down if the gateway is non SSLVPN gateway | | | | - For SSLVPN gateway with ELB enabled, port 943 should be UP and the gateway's security | | | | group has default port 943 open to to accept remote user connection. | | | | - For SSLVPN gateway with ELB disabled, port 1194 should be UP and the gateway's security | | | | group has default port 1194 open to to accept remote user connection. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**IP Link Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "ip link display": [ | | "1: lo: mtu 150... (the rest is omitted.) | | " link/ether b2:61:0b:3f:69:a3 brd ff:ff:ff:ff:ff:ff\n", | | "13: tun0: The maximum size of /usr should be lower than 6G, please contact | | | | if you see abnormal usage in a folder. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**MsgQueue Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "MsgQueue": { | | "ApproximateNumberOfMessagesNotVisible": "0", | | | | "ContentBasedDeduplication": "false", | | "MessageRetentionPeriod": "345600", | | "ApproximateNumberOfMessagesDelayed": "0", | | "MaximumMessageSize": "262144", | | "CreatedTimestamp": "1545101799", | | "ApproximateNumberOfMessages": "0", | | "ReceiveMessageWaitTimeSeconds": "0", | | "DelaySeconds": "0", | | "FifoQueue": "true", | | "VisibilityTimeout": "30", | | "LastModifiedTimestamp": "1545101878", | | "QueueArn": "arn:aws:sqs:us-west-2:xxxxxx:aviatrix-34-xxx-xxx-16.fifo" | | }, | | | +-----------------------------+----------------------------------------------------------------+ |Indicates AWS SQS message queue status. | | - ApproximateNumberOfMessages indicates the number of pending messages | | | | in the queue. | | | | - Expected value is 0. | | | | - If this value is not 0, it means there's issue on the AWS SQS Service, please update | | | | your IAM policy (refer to `IAM Policy`_. and check if the DNS resolution | | | | passed on the gateway.) You may also check if this SQS queue is still in your AWS | | | | SQS Service. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Supervisorctl Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "supervisorctl status": [ | | "gwmon RUNNING pid 2857, uptime 5:25:55\n", | | "local_launch EXITED Dec 18 02:58 AM\n", | | "openvpn RUNNING pid 5430, uptime 5:20:42\n", | | "perfmon RUNNING pid 2876, uptime 5:25:53\n", | | "sw-wdt4perfmon RUNNING pid 2894, uptime 5:25:51\n", | | "time_action RUNNING pid 2816, uptime 5:25:56\n" | | ], | | | +-----------------------------+----------------------------------------------------------------+ |Indicates the supervisor status. | | - All services should be in RUNNING state except local_launch. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**IKE daemon Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "IKE daemon": { | | "port": { | | "500": "Up", | | "4500": "Up" | | }, | | "service": "Up" | | }, | | | +-----------------------------+----------------------------------------------------------------+ |Indicates IKE daemon service and port status | | - Default: Up for all | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**SumoLogic Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "SumoLogic Collector": "Not running", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates SumoLogic logging service status. | | - Default: Not running | | - Related Link `Sumologic Integration`_. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Upload Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "Upload": "Pass", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates that Aviatrix controller is able to upload files to the gateway. | | - Expected value: Pass | | | | - If fail, please check the port 443 is open in both security group and VPC ACL between | | | | controller and the gateway instance in AWS console. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Datadog Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "Datadog Service": "Not running", | | | +-----------------------------+----------------------------------------------------------------+ | Indicates Datadog logging service status. | | - Default: Not running | | - Related Link `Datadog Integratin`_. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**iptables mangle Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "iptables mangle rules": [ | | "-P PREROUTING ACCEPT\n", | | "-P INPUT ACCEPT\n", | | "-P FORWARD ACCEPT\n", | | "-P OUTPUT ACCEPT\n", | | "-P POSTROUTING ACCEPT\n", | | "-N MSSCLAMPING\n", | | "-A FORWARD -j MSSCLAMPING\n", | | "-A MSSCLAMPING -p ... (the rest is omitted.) | | ], | | | +-----------------------------+----------------------------------------------------------------+ |Indicates iptables mangle configuration. | | - For debugging purpose | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**HTTPS Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "HTTPS": { | | "port": { | | | | "443": [ | | "up", | | "reachable" | | ] | | }, | | "service": "Up" | | }, | | | +-----------------------------+----------------------------------------------------------------+ |Indicates the HTTPS status and reachability on the gateway. | | - Expected value: Up and reachable | | | | - If Fail, please make sure the gateway has its security group port 443 open to the | | | | controller's EIP in AWS console. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**HTTPS Get Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "HTTPS GET": "Pass", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates connectivity for HTTPS request from gateway to the controller. | | - Expected value: Pass if GW can communicate with Controller without issue. | | | | When It shows "Fail" please check both Controller and Gateway security group | | | | - If Fail, please make sure the controller has its security group port 443 open to the | | | | gateway's EIP in AWS console. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**CloudWatch Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "CloudWatch Service": "Not running", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates the AWS CloudWatch service status. | | - Default: Not running | | - Related Link `Cloudwatch How To`_. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Top Memory Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "top mem processes": [ | | "20.2 0.1 398548 432 /lib/systemd/systemd-journald\n", | | | | " 4.6 0.0 454976 1761 /usr/sbin/apache2 -k start\n", | | " 4.3 0.1 807656 2857 python -W ... (the rest is omitted.) | | " 2.8 0.0 90920 2876 python -W ... (the rest is omitted.) | | " 2.6 0.0 84700 2816 python -W ... (the rest is omitted.) | | " 2.2 0.0 457688 5299 /usr/sbin/apache2 -k start\n", | | " 2.1 0.0 65268 1992 /usr/bin/p ... (the rest is omitted.) | | " 2.1 0.0 457688 5297 /usr/sbin/apache2 -k start\n", | | " 1.9 0.0 548016 1183 /usr/lib/snapd/snapd\n", | | " 1.8 0.0 457452 5300 /usr/sbin/apache2 -k start\n" | | ], | | | +-----------------------------+----------------------------------------------------------------+ |Indicates the memory and CPU usage of the gateway. | | - The memory usage of processes (first column) is changing dynamiclly and the overall | | | | usage should be lower than 50% | | | | - Mainly used for debugging | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**Splunk Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "splunkd": "Not running", | | | +-----------------------------+----------------------------------------------------------------+ |Indicates Splunk logging service status. | | - Default: Not running | | - Related Link `splunk Integration`_. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**VPN Service Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "VPN Service": { | | "port": { | | | | "943": [ | | | | "up", | | "reachable" | | ] | | }, | | "service": "Down" | | }, | | | +-----------------------------+----------------------------------------------------------------+ |Indicates OpenVPN service status. | | - Status is down if the gateway is non SSLVPN gateway | | | | - For SSLVPN gateway with ELB enabled, port 943 should be UP and the gateway's security | | | | group has default port 943 open to to accept remote user connection. | | | | - For SSLVPN gateway with ELB disabled, port 1194 should be UP and the gateway's security | | | | group has default port 1194 open to to accept remote user connection. | | | +-----------------------------+----------------------------------------------------------------+ | | +-----------------------------+----------------------------------------------------------------+ |**IP Link Output** | | +-----------------------------+----------------------------------------------------------------+ |:: | | | | "ip link display": [ | | "1: lo: mtu 150... (the rest is omitted.) | | " link/ether b2:61:0b:3f:69:a3 brd ff:ff:ff:ff:ff:ff\n", | | "13: tun0: