Issue:
Bad Gateway message when connected to StruxureWare private side device using HTTPS.
Product Line:
StruxureWare Data Center Expert (DCE)
APC devices with Network Management Card
Environment:
StruxureWare Data Center Expert 7.x
APC devices with Network Management Card(NMC) installed or built in HTTPS to devices on DCE private LAN
Cause:
StruxureWare DCE can be configured with devices on it's "Private LAN". This is a separate and distinct LAN from the customer's network or Public LAN. As with devices on the public LAN, you can double click a device in DCE and launch to the web interface of that device. When configured for HTTPS, DCE will attempt to connect using TLS version 1.0 to the private side devices.
Please note: This issue has been found to occur on devices that are not residing on the private LAN of DCE.
If the device on the private LAN is configured for TLS version 1.1 or 1.2, you will receive the following error:
Bad Gateway
The proxy server received an invalid response from an upstream server.
Resolution:
There are 2 ways to resolve this issue:
1: Change the device launch settings in StruxureWare to use http instead of https. Using this option will also require http to be enabled on DCE itself as well as the device's NMC.
2: In the current version of many APC devices, you can configure which version of TLS to use. Change the device to use TLS version 1.0
If you feel that TLS version 1.1 or version 1.2 is necessary on the NMC, you will need to contact APC tech support directly and allow them access to make changes to the server.
Please also note that the old NMC1 and devices that the older NMC1 internally (AP9617, 18, 19, Ap7900, etc) do not support higher versions of TLS and they will not communicate if the version of TLS is changed on the server.
Bad Gateway message when connected to StruxureWare private side device using HTTPS.
Product Line:
StruxureWare Data Center Expert (DCE)
APC devices with Network Management Card
Environment:
StruxureWare Data Center Expert 7.x
APC devices with Network Management Card(NMC) installed or built in HTTPS to devices on DCE private LAN
Cause:
StruxureWare DCE can be configured with devices on it's "Private LAN". This is a separate and distinct LAN from the customer's network or Public LAN. As with devices on the public LAN, you can double click a device in DCE and launch to the web interface of that device. When configured for HTTPS, DCE will attempt to connect using TLS version 1.0 to the private side devices.
Please note: This issue has been found to occur on devices that are not residing on the private LAN of DCE.
If the device on the private LAN is configured for TLS version 1.1 or 1.2, you will receive the following error:
Bad Gateway
The proxy server received an invalid response from an upstream server.
Resolution:
There are 2 ways to resolve this issue:
1: Change the device launch settings in StruxureWare to use http instead of https. Using this option will also require http to be enabled on DCE itself as well as the device's NMC.
2: In the current version of many APC devices, you can configure which version of TLS to use. Change the device to use TLS version 1.0
If you feel that TLS version 1.1 or version 1.2 is necessary on the NMC, you will need to contact APC tech support directly and allow them access to make changes to the server.
Please also note that the old NMC1 and devices that the older NMC1 internally (AP9617, 18, 19, Ap7900, etc) do not support higher versions of TLS and they will not communicate if the version of TLS is changed on the server.