Views:

Symptom

  • Agent communication failures: agents that communicate through the Forward Proxy Service fail to connect; Forward Proxy access logs show DNS resolution failures (e.g. ERR_DNS_FAIL) when contacting Trend Micro cloud/agent endpoints.
  • WRS unavailable: the Smart Protection Server (SPS) module’s WRS becomes unavailable to clients pointed at it (e.g. Apex One clients), either continuously or intermittently.
  • Threat-intelligence / Connected Products sync stalls: a configured threat-intelligence connector (e.g. MISP) stops syncing, and the Connected Products/Servers view shows no connected products for Suspicious Object List, Forward Proxy Service, or Smart Protection Servers within the recent time window — the entries reappear only if the time range is widened (e.g. to the last 7 days).
  • A plain restart of the appliance while it is still running 3.0.31 may appear to restore the affected service, but only briefly (observed to last a few minutes) before it fails again.

Cause

Version 3.0.31 has a packaging defect: the CoreDNS container image was not bundled into the appliance’s installer/upgrade package. On air-gapped appliances — those without direct outbound/internet access to the container image registry — the CoreDNS pod cannot pull that image after the upgrade (or after a subsequent restart), and it never reaches a running state. Appliances with outbound registry access are likely unaffected, since the image pull can succeed live.

Resolution

Trend Micro has identified this as a defect specific to appliance version 3.0.31 and is preparing version 3.0.32 to replace it. Version 3.0.31 has already been removed from the automatic-upgrade channel, so appliances with auto-upgrade enabled will no longer be moved onto 3.0.31.

Upgrade to 3.0.32 once it is available. Appliances with auto-upgrade enabled will upgrade automatically, no action needed; appliances without auto-upgrade enabled should be upgraded to 3.0.32 manually.

If 3.0.32 is not yet available for your appliance, roll back to the version that was running before the 3.0.31 upgrade as a temporary workaround. For VMware-based deployments, see How to Rollback Service Gateway Appliance When the Upgrade Fails in Trend Vision One.

Products and Versions

Product Trend Vision One — Service Gateway (SG)
Affected version 3.0.31 (build 3.0.31.10668)
Not affected Versions prior to 3.0.31 (e.g. 3.0.30, 3.0.23)
Fixed in 3.0.32