Resolving Oracle Enterprise Manager
(OEM) on Oracle Cloud Infrastructure (OCI) can sometimes feel like peeling back
layers of an onion. You’ve verified your VCN security lists, confirmed your
ingress rules are wide open, and even checked that firewalld is inactive. Yet,
the OEM console persists with a frustrating “No route to hosts” error on port
3872. If you’ve hit this wall, the culprit isn’t your cloud network – it’s hiding
right underneath the OS hood. Oracle Linux images in OCI frequently carry
pre-configured, low-level kernel packet filters or iptables rule chains that
silently drop traffic on non-standard ports by default, completely bypassing
higher-lelve firewall managers.
The below steps shows how to
resolve “No Rout to Host” error on the OEM console.
1.
Check the ingress rule on the VCN to confirm
that the OEM is allowed access to the VM on port 3872.
2.
Check Low-Level iptables Rules on the target
VM
Run this command as root to see if a hidden drop or reject
rule is intercepting port 3872 traffic:
sudo iptables -L -n -v | grep 3872
If this returns nothing or shows packets being
dropped/rejected, iptables is blocking the connection.
3.
Test telnet from the OMS to the target VM
on port 3872
Test telnet access from the OMS server to the DR server on
port 3872.
The above output shows that the OEM is not able to reach the
target VM on port 3872.
4.
Explicitly Force Open Port 3872 via
iptables
To instantly force the local Linux firewall kernel to accept
connections on port 3872, run:
sudo iptables -I INPUT -p tcp --dport 3872 -j
ACCEPT
5.
Test telnet access again from the OMS server to
the DR server on port 3872.
The output shows that the OEM sever is now able to reach the
target on port 3872.
6.
Add the internal targets and execute the upload agent
command.
7.
The “No Route to Host” error is resolved
and the target is now up.
The metric evaluation error is resolved, and the target is
up on the OEM.
No comments:
Post a Comment