These are the error faults for a Sensor device.
| Fault | Severity | Description/Cause | Action |
|---|---|---|---|
| Firewall Filter Application Error | Error | Error applying firewall filter "{0}." An attempt to apply this firewall filter from the device to the firewall has failed. Failure reason: {1}. | Check your firewall configuration. If possible, increase the maximum number of available filters. Ensure connectivity between the device and the firewall. |
| NMS User Authentication Key Decryption Failure | Error | NMS user authentication key decryption failed for {0} | Delete and re-add the NMS user. |
| NMS User Privacy Key Decryption Failure | Error | NMS user privacy key decryption failed for {0} | Delete and re-add the NMS user. |
| SSL Decryption Engine Down | Error | The SSL decryption service is down on the device {0}. HTTPS traffic cannot be inspected. | Check the device logs for additional details and contact Trellix Technical Support if it persists. |
| SSL Decryption Update Error | Error | The SSL decryption configuration update failed for component {0} | Check the device status using the "status" CLI command and re-attempt to deploy the changes from the Manager. |
| Internal Packet Drop Error | Error | The device is dropping packets due to high traffic load. | Review the number and duration of performance-related faults for this device and refer its performance charts to determine if high usage is an on-going occurrence. If yes, a model with a higher system capacity should be considered. (Tip: Multiple capacities are supported on some models with a license change to increase the capacity) |
| IPS to NTBA Communication Error | Error | The IPS device cannot communicate with its NTBA appliance. Reason: {0} | This problem may exist for a few minutes after the initial connection but is cleared once complete. If the problem persists, check for interference from external devices, such as a firewall that may be dropping the traffic. |
| Cannot Start Control Channel Service | Error | Cannot obtain the Manager certificate (Size {0}). | Database tuning may fix the problem. Else, a database restore is required. |
| Cannot Start Control Channel Service | Error | Unable to load the Manager key store. | Database tuning may fix this problem. Else, a database restore is required. |
| Failed to Create Command Channel Association | Error | Command channel association creation failed for device {0}. A secure connection could not be established between the Manager and the device. This could be caused due to loss of time during synchronization between the Manager and device, or when the device is not completely online after a reboot. | Restart the Manager and/or check the device status to ensure that the device is connected to the Manager and in good health. |
| {0} Discovery Failure | Error | {0}, {1} failed to discover configuration information. The device is not initialized properly and may not be displayed in the Manager UI. This error is typically due to incompatible software versions between the device and the Manager. | Check the Trellix Download Server to ensure you are running compatible Manager and device software versions. If required, upgrade the device software via SCP or TFTP. |
| Peer DoS Profile Retrieval Failure | Error | Peer DoS profile retrieval request from device {0} failed. No DoS profile for peer {1} is available. The Manager cannot obtain the requested profile from the peer device, nor can it obtain a valid saved profile. | Consult the system log for details. |
| Peer DoS Profile Retrieval Failure | Error | Peer DoS profile retrieval request from device {0} failed as the profile cannot be pushed from the Manager to the device that requested it. | Consult the system log for details. |
| Peer IBAC user info file retrieval failure | Error | Peer IBAC user info file retrieval request from device {0} failed. No IBAC user info file for peer {1} is available. The Manager cannot obtain the requested file from the peer device, nor can it obtain a saved valid file. | Consult the system log for details. |
| Invalid Internal Web Server Certificate Detected | Error | An invalid internal web server certificate ({0}) has been detected on device {1} and needs to be re-imported. Reason: {2} | Re-import the internal web server certificate. |
| Device Discovery Failure | Error | The Manager could not obtain configuration details for device {0}. The device is not properly initialized and may not be displayed in the Manager UI. This error is typically due to incompatible software versions between the device and the Manager. | Check the Trellix Download Server to ensure you are running compatible Manager and device software versions. If required, upgrade the device software via SCP or TFTP. |
| Alert Channel Down | Error | The Manager cannot communicate with the device {0} over the channel on which it receives alerts. Reason: {1}. | Check the device status using the status CLI command. Disconnect and re-connect the channel using the disconnectalertandpktlogchannels and reconnectalertandpktlogchannels CLI commands. |
| Packet Capture Channel Down | Error | The Manager cannot communicate with the device {0} over the channel on which it receives the attack packet captures. Reason: {1}. | Check the device status using the status CLI command. Disconnect and re-connect the channel using the disconnectalertandpktlogchannels and reconnectalertandpktlogchannels CLI commands. |
| Packet Capture Channel Down | Error | The packet capture channel for the device {0} is down, but the physical link is up. Details: {1} | The device normally auto recovers from this issue. If your device is otherwise functioning normally, you can ignore this message. |
| Out-of-Range Configuration | Error | Device {0} has detected an out-of-range SNMP configuration value. | If the problem persists, contact Trellix Technical Support. |
| License Required for SSL Proxy Decryption | Error | Sensor {0} was added to admin domain {1}, which has SSL proxy decryption enabled, yet there is no SSL proxy decryption license available for its model type {2}. Inheritance and the feature have therefore been disabled on Sensor {0}. | Add the missing license and re-enable SSL proxy decryption on the Sensor. |
| NTBA {0} | Error | {0} | Check the NTBA storage configuration. |
| Trust Establishment Error | Error | Device {0} could not be added to the Manager as there is mismatch in the shared secret defined in the Manager. | Make sure the shared secret entered on the device CLI matches exactly with the one defined within the Manager GUI. (Tip: You can edit the one in the GUI if needed) |
| Trust Establishment Error | Error | Device {0} is attempting to establish a trust with the Manager, but it has not been defined on the Manager. | Make sure the device you would like to add to the Manager has been defined within the Manager GUI before trying to add it via the device CLI. Tip: The Manager definition is case sensitive, so make sure the device name and shared secret key match exactly. |
| SSL Decryption Certificate File Update Error | Error | The SSL certificate with key ID "{0}" error in "{1}". | Re-deploy the certificate file. |
| Suricata Rule Load Failure | Error | Device "{0}" failed to load one or more Suricata Snort rule. A log for this has been created in: INSTALL_DIR/App/temp/ftpin/{0}/{1}. | Consult the log for failure details. |
| Packet Capture Error | Error | The device detected an error connecting to the SCP server while attempting to transfer a packet capture file. | The device will attempt to recover automatically. Confirm the packet capture configuration. |
| GAM Engine Process Failure | Error | Device {0} has detected a failure in the GAM engine process, which may impact GAM file analysis. | Run the
status CLI command.
If the system health status is good, the device has likely recovered on its own. If the system health status is bad, a reboot may be required to recover from the failure. Also consult the layer 2 status and auto-recovery settings because repeated failures may cause the device to move into bypass mode or reboot automatically (as configured). |
| Malware Server Process Failure | Error | Device {0} has detected a failure in the malware server process, which may impact all advanced malware file analysis. | Run the
status CLI command.
If the system health status is good, the device has likely recovered on its own. If the system health status is bad, a reboot may be required to recover from the failure. Also consult the layer 2 status and auto-recovery settings because repeated failures may cause the device to move into bypass mode or reboot automatically (as configured). |
| GTI malware file reputation lookup Process Failure | Error | Device {0} has detected a failure in the GTI file reputation lookup process, which may impact GTI file analysis. | Run the
status CLI command.
If the system health status is good, the device has likely recovered on its own. If the system health status is bad, a reboot may be required to recover from the failure. Also consult the layer 2 status and auto-recovery settings because repeated failures may cause the device to move into bypass mode or reboot automatically (as configured). |
| Datapath Process Failure | Error | Device {0} has detected a failure in the datapath process, which may impact datapath inspection. | Run the
status CLI command.
If the system health status is good, the device has likely recovered on its own. If the system health status is bad, a reboot may be required to recover from the failure. Also consult the layer 2 status and auto-recovery settings because repeated failures may cause the device to move into bypass mode or reboot automatically (as configured). |
| Front end Process Failure | Error | Device {0} has detected a failure in the frontend datapath process, which may impact datapath inspection. | Run the
status CLI command.
If the system health status is good, the device has likely recovered on its own. If the system health status is bad, a reboot may be required to recover from the failure. Also consult the layer 2 status and auto-recovery settings because repeated failures may cause the device to move into bypass mode or reboot automatically (as configured). |
| GAM Engine Update Status | Error | Sensor {0} has a status of: {1}. | Please check the connectivity of the Trellix IPS sensor with external network. If connection is fine, please attempt a manual GAM update from the Trellix IPS Manager. If the issue still persists, please contact the support team. |
| PKCS cert processing error | Error | Device {0} faced an error while processing the pkcs cert store. |
Consult the system logs for details. Re-push the configuration to the Sensor. if the error occurs again reach out to the support team. |