[Amazon FSx] FSx for Windows File Server ํŒŒ์ผ ์‹œ์Šคํ…œ ์ž˜๋ชป ๊ตฌ์„ฑ๋จ ์ƒํƒœ๋กœ ์ธํ•œ ์‹คํŒจ (AD Connectivity, FSx Validation)

2024. 2. 25. 23:59ใ†AWS/troubleshooting

โ˜„๏ธ ํ˜„์ƒ

FSx๊ฐ€ misconfigured ์ƒํƒœ๋กœ ๋ณ€๊ฒฝ๋˜์–ด ์ •์ƒ์ ์œผ๋กœ ์Šคํ† ๋ฆฌ์ง€์— ์ ‘๊ทผ์ด ๋ถˆ๊ฐ€๋Šฅํ•˜์˜€๋‹ค. ์ฝ˜์†”์—์„œ ํ™•์ธํ–ˆ๋˜ ์ƒํƒœ ๊ด€๋ จ ๋กœ๊ทธ๋Š” ์•„๋ž˜์™€ ๊ฐ™๋‹ค.

Amazon FSx is unable to communicate with your Microsoft Active Directory domain controllers. Please allow network traffic between Amazon FSx and your domain controllers as recommended in the Amazon FSx user guide: https://docs.aws.amazon.com/fsx/latest/WindowsGuide/aws-ad-integration-fsxW.html

ํ•ด๋‹น ์‹œ๊ฐ„์— FSx์˜ maintanence window์— ๋ฐœ์ƒํ•œ Patch offline ์ž‘์—…์ด ์žˆ์—ˆ๋‹ค. AWS ํ‹ฐ์ผ“์„ ํ†ตํ•ด ํ™•์ธํ•œ ๊ฒฐ๊ณผ, FSx ํŒŒ์ผ์‹œ์Šคํ…œ์—์„œ ํŒŒ์›Œ์‰˜๋กœ Get-ADComputer ๋ช…๋ น์–ด ์ˆ˜ํ–‰ ์‹œ ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ–ˆ์œผ๋ฉฐ ๋‚ด๋ถ€ ํˆด์—์„œ๋Š” ์•„๋ž˜์™€ ๊ฐ™์€ ์—๋Ÿฌ ๋กœ๊ทธ๊ฐ€ ๋‚จ๊ฒจ์ ธ ์žˆ์—ˆ๋‹ค๊ณ  ํ•œ๋‹ค.

- because file server role cannot be set up due to AD connectivity issue.; caused by Failed to call WSFCAdminService /wsfcadmin/AddClusterFileServerRole2
- ACTIVE_DIRECTORY_INVALID_CREDENTIALS_ON_UPDATE

 

 

๐ŸŒŽ ์„ค์ • ํ™˜๊ฒฝ

  • AWS FSx for Windows File Server
  • ์ž์ฒด ๊ด€๋ฆฌํ˜• AD (Self-managed Microsoft Active Directory)
  • ๋ฐฐํฌ ์œ ํ˜• : Single AZ 2

 


 

๐Ÿ”ซ Trouble Shooting

0. StartMisconfiguredStateRecovery

FSx ์ฝ˜์†”์—์„œ Attempt Recovery ๋ฒ„ํŠผ์„ ํ†ตํ•ด StartMisconfiguredStateRecovery์„ ์ˆ˜ํ–‰ํ•˜์˜€์œผ๋ฉฐ, 40๋ถ„ ํ›„ FSx์˜ ์ƒํƒœ๊ฐ€ Available๋กœ ์ •์ƒ ๋ณต๊ท€๋˜์—ˆ๋‹ค. StartMisconfigureStateRecovery๋Š” ๊ธฐ์กด ๋ณผ๋ฅจ์„ Detach ํ›„, ์‹ ๊ทœ๋กœ ํŒŒ์ผ์‹œ์Šคํ…œ์„ ์žฌ์ƒ์„ฑํ•˜๊ณ  ๊ธฐ์กด ๋ณผ๋ฅจ์„ attach ํ•˜๋Š” ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•œ๋‹ค. FSx๊ฐ€ Single Node์ธ ๊ฒฝ์šฐ์—, path offline ๋ฐ StartMisconfigureStateRecovery ์ž‘์—… ์‹œ FSx ํŒŒ์ผ์‹œ์Šคํ…œ์— ์ ‘๊ทผ์ด ๋ถˆ๊ฐ€๋Šฅํ•  ์ˆ˜ ์žˆ์œผ๋‹ˆ ์ฃผ์˜ํ•˜์ž.

StartMisconfiguredStateRecovery๋ฅผ ํ†ตํ•ด ์ž„์‹œ๋กœ ์ƒํƒœ๋ฅผ ๋ณ€๊ฒฝํ•˜์˜€์œผ๋‚˜ ์˜คํ”„๋ผ์ธ ํŒจ์น˜์—์„œ ์‹คํŒจํ•˜๋Š” ๊ทผ๋ณธ์ ์ธ ์›์ธ์„ ํ•ด๊ฒฐํ•  ์ˆ˜๋Š” ์—†์—ˆ๋‹ค.

1. AD ↔ FSx ๊ฐ„ ํ†ต์‹  ํ™•์ธ

์ฐธ๊ณ : https://docs.aws.amazon.com/fsx/latest/WindowsGuide/fsx-aws-managed-ad.html#rfim-networking-requirements

AD ์„œ๋ฒ„์˜ Windows ๋ฐฉํ™”๋ฒฝ์€ ๋ชจ๋‘ off ๋˜์–ด ์žˆ์—ˆ์œผ๋ฉฐ, ๋„คํŠธ์›Œํฌ ํ†ต์‹  ๊ตฌ๊ฐ„์— ๋ง‰ํ˜€์žˆ๋Š” ๋ฐฉํ™”๋ฒฝ์€ ์—†์—ˆ๋‹ค. FSx์— ์—ฐ๊ฒฐ๋˜์–ด ์žˆ๋Š” Security Group์—์„œ๋„ ํŠน์ด์‚ฌํ•ญ์€ ์—†์—ˆ๋‹ค. 

๐Ÿ’ก ์ฐธ๊ณ  ๐Ÿ’ก
5985๋ฒˆ:  FSx ํŒŒ์ผ์‹œ์Šคํ…œ์„ Remote Session์—์„œ ๊ด€๋ฆฌ์ž๊ฐ€ ์•„๋ž˜์™€ ๊ฐ™์€ ๋ช…๋ น์–ด๋กœ ๊ด€๋ฆฌํ•˜๊ธฐ ์œ„ํ•ด ํ•„์š”ํ•œ Win RM ๊ด€๋ จ ํฌํŠธ.
Get-FSxDedupConfiguration
Get-FSxDedupSchedule
Get-FSxDedupStatus
Get-FSxDedupJob
Get-FsxShadowStorage
Get-FSxShadowCopies
Get-FsxShadowCopySchedule

 

2. FSx Service Account ํ™•์ธ

FSx์— ์—ฐ๊ฒฐ๋œ Service Account (AD ๊ณ„์ •)์˜ ๋ณ€๊ฒฝ ์ด๋ ฅ์€ ์—†์—ˆ๋‹ค.

3. FSx Validation Tool๋กœ AD์™€์˜ ์—ฐ๊ฒฐ์„ฑ ๊ฒ€์ฆ

๐Ÿ’ก FSx Validation Tool์ด๋ž€?
์ž์ฒด ๊ด€๋ฆฌํ˜• AD์™€์˜ ์—ฐ๊ฒฐ์„ฑ์„ ๊ฒ€์ฆํ•˜๊ธฐ ์œ„ํ•œ AWS์—์„œ ์ œ๊ณตํ•˜๋Š” ๋ชจ๋“ˆ๋กœ 2, 3์˜ ๊ณผ์ •๋„ ํฌํ•จ๋˜์–ด ์žˆ๋‹ค. AWS์—์„œ๋Š” FSx Validation Tool์„ ์ฃผ๊ธฐ์ ์œผ๋กœ ๊ฒ€์ฆํ•˜์—ฌ AD ํ™˜๊ฒฝ ๋ณ€ํ™”๊ฐ€ ์žˆ๋Š” ๊ฒฝ์šฐ ํŒจ์น˜ ์˜คํ”„๋ผ์ธ ์‹คํŒจ์˜ ๊ฐ€๋Šฅ์„ฑ์„ ์ค„์ด๋„๋ก ๊ถŒ์žฅํ•œ๋‹ค.

โ‘  FSx์™€ ๊ฐ™์€ ์„œ๋ธŒ๋„ท์— ์ž„์‹œ EC2๋ฅผ ๋งŒ๋“ ๋‹ค.

  • ๋ณด์•ˆ๊ทธ๋ฃน : FSx์— ์—ฐ๊ฒฐ๋˜์–ด ์žˆ๋Š” ๋ณด์•ˆ๊ทธ๋ฃน์„ FSx์™€ ๋™์ผํ•˜๊ฒŒ ์—ฐ๊ฒฐํ•œ๋‹ค.
  • IAM Role: AmazonEC2ReadOnlyAccess Policy ์—ฐ๊ฒฐ

โ‘ก ํ•ด๋‹น ์„œ๋ฒ„์— FSx Validation Tool์„ ๋‹ค์šด๋กœ๋“œํ•œ๋‹ค. : ์ฐธ๊ณ 

โ‘ข ํ•ด๋‹น ์„œ๋ฒ„๋ฅผ AD์— ์กฐ์ธํ•œ๋‹ค.

โ‘ฃ Tool์„ ์ˆ˜ํ–‰ํ•˜๊ธฐ ์œ„ํ•œ ๋ณ€์ˆ˜๋ฅผ ์ค€๋น„ํ•œ๋‹ค. Credential์—๋Š” FSx ํŒŒ์ผ์‹œ์Šคํ…œ์— ์‚ฌ์šฉ๋œ AD ๊ณ„์ • ์ •๋ณด๋ฅผ ์ž…๋ ฅํ•œ๋‹ค.

$FSxADValidationArgs = @{
    # DNS root of ActiveDirectory domain
    DomainDNSRoot = 'DOMAINNAME.COM'

    # IP v4 addresses of DNS servers
    DnsIpAddresses = @('IP_ADDRESS_1', 'IP_ADDRESS_2')

    # Subnet IDs for Amazon FSx file server(s)
    SubnetIds = @('SUBNET_1', 'SUBNET_2')

    Credential = $Credential
}

โ‘ค FSx Validation Tool ์‹คํ–‰

WARNING: Subnet not defined in an Active Directory site: subnet-#################!
WARNING: The following subnet(s) are not defined in an Active Directory site: subnet-#################!
Please ensure all subnets in the VPC associated with your Amazon FSx file system are defined in an Active Directory site.
Skipping Validate connectivity with DNS Servers ...
Skipping Validate FSx service user credentials ...
Skipping Validate 'Create Computer Objects' permission ...
Skipping Validate 'Validated write to DNS host name' permission ...
Skipping Validate 'Validated write to service principal name' permission ...
Skipping Validate 'Reset Password' permission ...
Skipping Validate 'This Organization' list children permission ...
Skipping Validate 'Read and write Account Restrictions' permission ...
Skipping Validate 'Delete Computer Objects' permission ...
9 of 17 tests skipped.
FAILURE - Tests failed. Please see error details below:

Name                         Value
----                         -----
NoAdSubnetForEc2Subnet       {subnet-#################}

 

AD Site์— FSx๊ฐ€ ํฌํ•จ๋œ ๋Œ€์—ญ์ด ์กด์žฌํ•˜์ง€ ์•Š์•„ Validation Tool์—์„œ ๊ฒ€์ฆ์„ ์‹คํŒจํ•˜์˜€๋‹ค. AD ์‚ฌ์ดํŠธ ์ •์˜๋Š” ์•„๋ž˜์™€ ๊ฐ™์ด AWS ๊ณต์‹ ๊ฐ€์ด๋“œ ๋ฌธ์„œ์—์„œ FSx ๊ตฌ์„ฑ ์‹œ ์ˆ˜ํ–‰ํ•ด์•ผ ํ•˜๋Š” ์‚ฌ์ „ ์ค€๋น„ ์‚ฌํ•ญ์ด๋‹ค. 

์ถœ์ฒ˜: https://docs.aws.amazon.com/ko_kr/fsx/latest/WindowsGuide/self-manage-prereqs.html

FSx๊ฐ€ ์˜ค๋ฅ˜ ์—†์ด ๊ตฌ์„ฑ๋˜๊ณ  ์ˆ˜๋…„๊ฐ„ ๋ฌธ์ œ์—†์ด ์šด์˜๋˜์—ˆ๋˜ ๊ฒƒ์ด ์ด์ƒํ•˜์ง€๋งŒ ์ด ๊ณ„๊ธฐ๋กœ FSx๊ฐ€ ์—ฐ๊ฒฐ๋˜์–ด ์žˆ๋Š” AD Subnet์œผ๋กœ FSx ์„œ๋ธŒ๋„ท ๋Œ€์—ญ์„ ์ถ”๊ฐ€ํ•˜์˜€๋‹ค. Subnet ์ถ”๊ฐ€ ์‹œ ์—ฐ๊ฒฐํ•˜๋Š” Site๋Š” FSx๊ฐ€ ์—ฐ๊ฒฐํ•˜๋Š” AD DC๊ฐ€ ํฌํ•จ๋œ Site๋ฅผ ์„ ํƒํ•œ๋‹ค. ์ดํ›„ Validation Tool์„ ์žฌ์ˆ˜ํ–‰ํ–ˆ์„ ๋•Œ ๋ฌธ์ œ์—†์ด ์„ฑ๊ณตํ•˜์˜€๋‹ค. 

AD Subnet์— FSx ๋Œ€์—ญ ์ถ”๊ฐ€ ์ดํ›„ ์˜คํ”„๋ผ์ธ ํŒจ์น˜ ์ž์ฒด๊ฐ€ ์ˆ˜ํ–‰๋˜์ง€ ์•Š์•„ ์™„๋ฒฝํ•˜๊ฒŒ ํ•ด๊ฒฐ๋˜์—ˆ๋Š”์ง€๋Š” ์•Œ ์ˆ˜ ์—†์ง€๋งŒ AD Connectivity๋ฅผ ์›์ธ์œผ๋กœ misconfigured ์ƒํƒœ๋กœ ๋ณ€๊ฒฝ๋  ๊ฐ€๋Šฅ์„ฑ์„ ๋‚ฎ์ถ”์—ˆ๋‹ค.