Appendix - Things to Remember
- Qualys Gateway Service detects only one secondary hard disk.
- To retain more logs, you can extend the primary hard disk.
- To retain more patches, you can extend the secondary hard disk.
- Extending any QGS hard disks must be done from your hypervisor console with appropriate permissions with the QGS in question, powered off.
- You can only have a maximum of 5 proxies, QGS appliances, DNS aliases, or Load Balancer VIP entries.
- The direct connection from a cloud agent is attempted after all proxy/QGS/DNS/VIP options have been attempted and works only if the firewall rules allow it.
- You can nest QGS appliances, but only the QGS device that the cloud agent communicates directly with can be used in proxy, cache, or patch mode. Any QGS above the first QGS must be defined as the upstream proxy for the first QGS, using only the proxy port on the second QGS.
- Restart the CAMSD service unit if you see your appliance is inactive on the UI.
The following are the steps to restart the CAMSD service unit to active your appliance on the UI:
- Connect to the appliance Text user interface.
- Go to the Diagnostics and select Units.
- Go to the CAMSD unit and click Restart.
- Wait at least 45 minutes to 1 hour for the appliance to become active on the UI.
- The appliance logs are not immediately available directly on the root location if the diagnostics logs are generated repeatedly on the same appliance. Instead, it can be found in the "/var/diagnostics" location.
Frequently Asked Questions
How do I know whether the appliance is upgraded to the latest services or not?
Go to the appliance's Text User Interface (TUI), click the Info tab and click OK to see the details.
- When the minimum requirement for the primary disk and RAM are not fulfilled, the following message is shown on the appliance TUI under the Info tab.
- A Minimum 16GB of RAM is recommended for CAMS/QGS appliances. A total of 2000 concurrent cloud agent requests are supported by a QGS appliance. In case of more than 2000 agents communicating simultaneously, customers should deploy a new appliance instead of increasing RAM on the existing appliance.
How do I know whether the appliance is upgraded to the latest version or not?
Go to the appliance's Text User Interface (TUI), click the Info tab and click OK to see the appliance is upgraded to the latest version or not.
You can verify that all the latest images are present on the appliances by navigating to
TextUI > Diagnostics > Images. Refer to the following screenshot.
- Also, you can verify the appliance with the latest image version by navigating to the QGS UI > APPLIANCES > clicking the Appliance. As shown in the following screenshot.
How to add POD suffix details for the image version 2.1.0 and above using TextUI?
You can add a POD suffix details for the image version 2.1.0 and above for all supported formats; go to the TextUI > System Settings > POD Suffix.
The POD Suffix option is grayed out after the successful upgrade of the existing appliances deployed with image version 1.1.0.
To know the POD suffixes for corresponding PODs, refer to the POD Suffixes table.
We recommend entering the correct POD suffix because the cloud metadata services always overwrite an incorrectly entered POD suffix.
Go to the Information tab to check the connected status and pod suffix with qagpublic and camspublic. As highlighted in the following screenshot.
To check the connectivity with the backend services; go to the TextUI > Diagnostics > Connectivity.
Select whether to check connectivity for IPv4 or IPv6 protocol.
The connectivity check returns healthy if the screen is displayed as below.
If any of the services from CAMSPM, CAMSREPO, camspublic, and qagpublic is not connected to the appliance, you cannot register the appliance. You can observe the following error shown on the screenshot.
If you use appliance image version 2.1.0 and above, you must provide a POD Suffix as the mandatory field.
If you use appliance image version 1.1.0 -X, the pod suffix option is not be available.
POD Suffixes
To identify the Platform URL Suffix for your subscription, refer to the Platform URL Suffix section of the Qualys Platform Identification.