When you have Deep Security Agent (DSA) with activated firewall feature, it may cause an issue on the Microsoft cluster communication.
To resolve the issue:
- On the Deep Security console, go to Policies > IP Lists.
- Create a new IP list for the related cluster IPs.
- Go to Policies > Port Lists.
- Create a new port list and enter 3343 and 49152-65535. Make sure to put one port or port range per line.
- Create a customized firewall rule that allows incoming TCP/UDP port listed on 3343 and 49152-65535.
- Apply the newly customized firewall rule to the target cluster IP list.
For more information, refer to this Microsoft article: Service overview and network port requirements for Windows.