SailPoint Source Unhealthy After IQService Server Migration

During the server migration where the IQService is hosted, the server’s IP address was updated. After the migration and restarting the SailPoint services, the SailPoint Sources are still showing an unhealthy status.

Any insights or recommended fixes would be greatly appreciated. Thanks.

Hello @habibara ,

What is the error you are getting while testing the connections from ISC?

Hi @habibara ,
Is the server is in same domain after migration ? Also it would be helpful if you share the error during test connection.
Thank you.

Hi @arafathabib,

There are couple of things you need to do after migration of the server.

  1. Update the details in the server where the new servers will be added.
  2. Update IQService details if the server migration was related to IQService.
  3. Have a new certificate from the new server and place it in /home/sailpoint/certificate folder.

Please let us know if these steps are done and you are still facing issues.

Hi @habibara ,

Can you try test connection by removing the IQService setting. Post that add IQService details and do test connection once again. Also observe the logs on VA. Also you are using TLS or non TLS port?

Hello @habibara ,

So, its a generic Request Timeout issue.

Following are the things you need to check.

  1. Is this a new WINDOWS Machine you have migrated to? If yes, then, make sure that new Windows Machine Hostname and respetcive IQ Service Port is opened from VA Servers
  2. Login to VA and check the connectivity from VA machines to new IQ Service Host using pin and netstat commands. If o/p is timedout, then, its connectivity issue
  3. If connectivity is OK, then make sure correct hostname and port is update din IQ Service tab of AD source
  4. If those details are correct, then, make sure you are using correct CA signed certificates in new IQ Service machine and that certificate is installed in VA machine as well with ccg service restarted.

Regards,

Rohit Wekhande.

Hi @habibara ,

Adding on to others, please check your configuration of IQ server where

  1. services are up and running and account is updated correctly.

  2. firewall rules for the correct ports are configured.

  3. the settings are updated on Sailpoint ISC page.

This should be able to fix your issue.

1 Like