Skip to content

Commit 1e0cce6

Browse files
committed
Add TSG for network validation errors
1 parent aa6cf23 commit 1e0cce6

File tree

2 files changed

+36
-0
lines changed

2 files changed

+36
-0
lines changed

AKS-Arc/TOC.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -181,6 +181,8 @@
181181
href: check-vm-sku.md
182182
- name: Connectivity issues with MetalLB
183183
href: load-balancer-issues.md
184+
- name: Troubleshoot general network validation errors
185+
href: network-validation-errors.md
184186
- name: Network validation error due to .local domain
185187
href: network-validation-error-local.md
186188
- name: Reference

AKS-Arc/network-validation-errors.md

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
---
2+
title: Troubleshoot network validation errors
3+
description: Learn how to troubleshoot general network validation errors in AKS Arc.
4+
author: sethmanheim
5+
ms.author: sethm
6+
ms.topic: troubleshooting
7+
ms.date: 05/06/2025
8+
ms.reviewer: pradwivedi
9+
ms.lastreviewed: 05/06/2025
10+
11+
---
12+
13+
# Troubleshoot network validation errors
14+
15+
This article provides guidance on identifying and resolving various network validation errors encountered during cluster creation, emphasizing the importance of pre-checks for early issue detection. These errors are detected by pre-checks designed to highlight issues early, allowing for easier resolution before the cluster is created.
16+
17+
## General network validation errors
18+
19+
The following table summarizes the error codes, possible causes of the errors, and mitigation steps.
20+
21+
| Error | Description | Causes of failure | Mitigation recommendation |
22+
|---|---|---|---|
23+
| **CloudAgentConnectivityError** <br/> Error: Network validation failed during cluster creation. Detailed message: `Not able to connect to http://cloudagent.contoso.local:50000. Error returned: action failed after 5 attempts: Get "http://cloudagent.contoso.local:50000": dial tcp: lookup http://cloudagent.contoso.local: Temporary failure in name resolution` | MOC cloud agent is created using one of the IP addresses from the [Management IP pool](/azure/azure-local/plan/cloud-deployment-network-considerations#management-ip-pool) on port 5500 and the control plane node VM is given IP addresses from the Arc VM logical network. This error occurs when the MOC cloud agent is not reachable from the control plane VM, or DNS servers specified in AKS Arc logical network are unable to resolve the MOC cloud agent FQDN. | Logical network IP addresses can't connect to management IP pool addresses due to:<br/> - Incorrect DNS server resolution.<br/> - Firewall rules.<br/> - The logical network is in a different vlan than the management IP pool and there's no cross-vlan connectivity. | - Make sure that the DNS servers specified in the AKS Arc logical network can resolve the MOC cloud agent FQDN.<br/> - Make sure that the logical network IP addresses can connect to all the management IP pool addresses on the required ports. Check the [AKS network port and cross vlan requirements](aks-hci-network-system-requirements.md#network-port-and-cross-vlan-requirements) for a detailed list of ports that need to be opened. |
24+
| **InternetConnectivityError** <br/> Error: Network validation failed during cluster creation. Detailed message: `Not able to connect to https://mcr.microsoft.com. Error returned: action failed after 5 attempts: Get "https://mcr.microsoft.com": dial tcp: lookup mcr.microsoft.com on <>: read udp <>: i/o timeout` | This error indicates that the required URLs are not reachable from the AKS cluster control plane node VM. | - Control plane node VM has no outbound internet access.<br/> - Required URLs aren't allowed through the firewall. | Ensure that the logical network IP addresses have outbound internet access. If there's a firewall, ensure that the [AKS required URLs](aks-hci-network-system-requirements.md#firewall-url-exceptions) are accessible from the Arc VM logical network. |
25+
| **VMNotReachableError** <br/> Error: Network validation failed during cluster creation. Detailed message: `VM IP : <> is not reachable from management cluster` | This error indicates that the AKS cluster control plane VM is not reachable from the Arc Resource Bridge (ARB). | The AKS Arc logical network is not reachable from management IP pool addresses. | - Make sure that the management IP pool addresses can reach the logical network IP addresses. <br/> - Check the [AKS network port and cross vlan requirements](aks-hci-network-system-requirements.md#network-port-and-cross-vlan-requirements) for a detailed list of ports that need to be opened. |
26+
| **DNSResolutionError** | This error occurs when DNS servers specified in the AKS Arc logical network can't resolve the MOC cloud FQDN or the required URLs. | DNS servers specified in logical network can't resolve the MOC cloud FQDN or the required URLs. | - Check the DNS servers specified in the logical network so that they can resolve the MOC cloud FQDN or the required URLs. |
27+
28+
## Contact Microsoft Support
29+
30+
If the problem persists, [collect AKS cluster logs](get-on-demand-logs.md) before you [create the support request](aks-troubleshoot.md#open-a-support-request).
31+
32+
## Next steps
33+
34+
- [Troubleshoot issues in AKS enabled by Azure Arc](aks-troubleshoot.md)

0 commit comments

Comments
 (0)