This section discusses issues related to fail-open kit in the customer's environment.
Applicable to Sensor models: NS-series
Problem scenarios
Reset the password and all the parameters to factory default.
Passive fail-open does not bypass even though the fail-open kit Sensor is down/Sensor is rebooted.
Passive fail-open does not come up and continuously flaps.
Active fail-open does not come up and continuously flaps.
Active fail-open to Sensor link flaps continuously.
Data/Information Collection
Execute the following commands in the Sensor:
showstatusshow intfport <port>(multiple times)show inlinepktdropstat <port>show sensor-load
Check the following details:
Active fail-open type (model) and configuration
Cables and SFP type
Physical connection details (network topology)
Peer device port configuration
Trace the Sensor files.
Check the infoCollector tool for the logs including the configuration backup (This is optional in case the issue is required to be reproduced locally.)
Following are the troubleshooting steps for the problem scenarios stated above:
Problem 1: Reset the password and all the parameters to factory default
If you have forgotten the password and do not know the correct password, perform the following steps to reset the password and all the other parameters of the Active Fail-Open kit.
On the fail-open switch, press the PB0 push button for three seconds to enter the main menu seen in the display panel.
.png)
Do a short press on the PB0 push button to move to the next submenu in the list.
Note
Perform this step till you move to the
OPsubmenu.Push the PB1 push button with a short press to select and view the options in the
OPsubmenu.Do a short press on the PB0 push button to move to the next option in the
OPsubmenu.Note
Perform this step till you move to the
DEFAULToption.Push the PB1 push button with a short press to select the
DEFAULToption.
When the option DEFAULT is selected, it sets the default factory parameters.
In the display panel, you can view small lines ( _ _ _ _ _ ) which indicates that default factory parameters are successfully set. As a result, the password is also reset to the default password.
Problem 2: Passive fail-open does not bypass even though the fail-open kit Sensor is down/Sensor is rebooted
Check if the Sensor is up and in good state.
In the Physical Ports page of the Manager, check the following configurations:
Port is configured to Inline Fail Open - Passive
Auto-Negotiate is selected.
If peer device port does not support MDIX, use an appropriate cable to bring up the link during the Sensor bypass. If it does not work, check the Passive Fail-Open Kit for any hardware issues.
While using Passive Fail-Open Kit, make sure to disable the STP on the peer device ports to avoid auto renegotiate.
Note
While using Passive Fail-Open Kit, each Sensor port individually negotiates with peer port initially when the Sensor is in inline mode. When the Sensor goes to bypass mode, the peer device port re-negotiates with each other. Make sure to enable
Portfaston peer devices to minimize network outage.
Problem 3: Passive fail-open does not come up and continuously flaps
Check if the Sensor is up and in good state.
In the Physical Ports page of the Manager, check the following configurations:
Port is configured to Inline Fail Open - Passive
Auto-Negotiate is selected.
Appropriate cable is used. The cable type should be Cat5e and above for copper, and for fiber single-mode/multi-mode depending on the SFP used.
Check the control cable connection and the right controller port.
Check if the SFPs are according to Trellix's recommendations.
Check for bad/defective cable and SFPs.
Check if the peer device port is working and if the port settings are set to Auto-Negotiate.
Ensure local port testing (by connecting monitoring ports back to back).
Swap the working SFP and cables from another port pair.
If all the above steps fail, RMA the Sensor.
Problem 4: Active fail-open does not come up and continuously flaps
Check if the Sensor is up and in good state.
Use Trellix recommended transceivers (normal SFP for 1G, SPF+ for 10G, and QSP for 10G ports).
Check the Active Fail-Open Kit monitoring port setting (specifically Auto-Negotiate and speed settings). It should be the same as Sensor monitoring ports and peer device.
Ensure local loopback port testing (by connecting monitoring ports back to back).
Swap the working SFP and cables from another port pair.
Check the load on the Sensor.
If all the above steps fail, RMA the Sensor.
Steps to Configure and Debug active fail-open
When configuring the Active Fail-Open Kit, in case of flapping issues, the configuration on the network peer ports must match with the one on Active Fail-Open Kit-Sensor monitoring port pair.
Ensure the power to the Optical Bypass Switch is on.
Using a DB-9 RS232 programming cable. Connect a PC that is running the HyperTerminal to the Optical Bypass Switch.
Launch a terminal emulation software like HyperTerminal, and set the following communication parameters:
Bits per second: 19200
Stop bit: 1
Data bits: 8
Flow control: None
Parity: None
Click OK. The CLI banner and login prompt are displayed.
Type the default username and password. (The default username and password is Trellix00 and is case-sensitive).
Once you are logged in, use the following commands in the table to configure and troubleshoot the Active Fail-Open Kit:
Command
Description
aSet the timeout value.
To set the Timeout value, do the following:
Type a and press Enter.
TimeOut period (1-254 sec) — Type the number of seconds between each heartbeat (1-254 seconds) and press Enter. Default = 1.
Retry Count (1-254) — Type the number of missed heartbeats allowed before the Bypass Switch enters the On mode. Default = 3.
Note
The Retry Count must be greater than or equal to the Timeout period.
bSet Switch parameters.
To set speed duplex and auto-negotiation, LFD, bypass detect:
1= Turn On.
0 = Turn Off.
Fail Mode Open/Close= 1
Note
The LFD and Bypass detecting mode settings cannot be changed.
cSet TAP mode.
Type c and press Enter.
Type 1 to set the tap mode On, or 0 to set the tap mode Off. Default = Off.
dShow configuration.
Type d and press Enter. The following is displayed:
LFD = On
Timeout Period= 1
Bypass Detect= Off
Retry Count= 3
Fail Mode= Open
Bypass State= Off
TAP Mode= Off
eShow port status.
Type e and press Enter. The following is displayed:
Port A= Up/Down
Port B= Up/Down
Port 1= Up/Down
Port 2= Up/Down
fSet Switch name.
Type f and press Enter.
At the prompt, type the Switch name, which can be 8 characters long.
zReset to Factory Defaults.
Problem 5: Active fail-open to Sensor link flaps continuously
Check if the Sensor is up and in a good state.
Use Trellix recommended transceivers (normal SFP for 1G, SPF+ for 10G, QSFP+ for 40G, and QSP28 for 100G ports).
Check the Active Fail-Open Kit monitoring port setting (specifically Auto-Negotiate and speed settings). It should be the same as Sensor monitoring ports and peer device.
Check the Sensor ports (by connecting monitoring ports back to back).
Swap the working SFPs and cables from the other working port pair.
Swap the working Active Fail-Open Kit to confirm whether a hardware problem exists.
Check the load on the Sensor to make sure that Sitera is dropping the HB packets from the Active Fail-Open Kit. To test if the Sitera is dropping the HB packets, contact Trellix Support for further assistance.