Scenario
Connectivity issues between the Sensor and Manager
Applicable to Sensor models: NS-series and Virtual IPS Sensors
Sensor software versions: 10.1, 11.1
Problems type to be solved
Sensor is not detected on the Manager.
Trust establishment does not happen between the Sensor and Manager.
Data/Information Collection
Steps:
Execute the following commands on the Sensor:
statusshowshow sbcfgshow mgmtcfgshow doscfgshow mgmtportgetccstatsshow netstatcheckmanagerconnectivity
Collect the Manager infocollector logs. If possible, perform the following:
For Windows-based Manager, enable detailed debugging messages by modifying
<Manager_Install_Dir>\config\log4j2.xmlfile.Note
The default Manager installation directory is
%programfiles%\Trellix\IPS Manager\App.For Linux-based Manager, enable detailed debugging messages by modifying
log4j2.xmlfile. To open the file, executeedit log4j2.xml.Find out and modify the following lines in the
log4j2.xmlfile:<Logger name="iv.core.DiscoveryService" additivity="false" level="debug"> <appender-ref ref="DEVICE_CONFIG_LOG"/> </Logger>
<Logger name="iv.core.SensorConfiguration" additivity="false" level="debug"> <appender-ref ref="DEVICE_CONFIG_LOG"/> </Logger>
The modified logs will be available in
<Manager_Install_Dir>\logs\device_config.logfile.Collect the Sensor trace files.
Collect packet capture at the Manager (for the problematic Sensor).
Network diagrams clearly mentioning where the Sensor and Manager are located.
Troubleshooting Steps
Check if there is any network connectivity issue such as conflicting IP address of the Sensor. This can result in alert/pktlog channel flaps.
Verify that the Management Interface speed and duplex settings are configured correctly on the Manager and Sensor and that they are hard-coded. If this fails, change one link to auto and change the other side's duplex and speed settings until communications are established or combinations are exhausted.
Ping from the Sensor to Manager and Manager to Sensor, and make sure the ping is successful.
Check if the other Sensors connected to the same Manager are also facing this issue.
If yes, it is a Manager issue.
Check the IP address of the system on which the Manager is installed. Make sure the correct IP address is provided in the
set manager ipcommand at Sensor CLI.Try a
deinstalland establish the trust again with the Manager.Check if the Manager machine has multiple NIC cards. If yes, do the following:
For Windows-based Manager, open
<Manager_Install_Dir>\bin\tms.batfile.For Linux-based Manager, open
tms.shfile. To open the file, executeedit tms.sh.
Later, modify the following line to assign the relevant IP address that is also used in the Sensor configuration:
set JAVA_OPTS=%JAVA_OPTS% -Dlumos.fixedManagerSNMPIPaddress=""restart ManagerCheck the Sensor name, which is given on the Manager while adding the Sensor using the Add New Device wizard. Sensor name is case-sensitive. So make sure it exactly matches the one given on the Manager.
Check that the device type is selected as IPS Sensor while adding the Sensor using Add New Device. Selecting incorrect device type can also lead to connectivity issues.
Make sure that firewall is not blocking traffic between the Manager and Sensor for the following ports:
Manager:4167 -> Sensor:8500 (UDP)Sensor:Any -> Manager:8501-8504,8510 (TCP) for 1024-bit trustsSensor:Any -> Manager:8504,8506-8509 (TCP) for 2048-bit trustsIf using the malware policy, check if the file save option is enabled. Make sure firewall is not blocking ports 8509 and 8510, which are used for saving malware files.
Check that UDP port 8500 is open and allows the Manager to Sensor SNMP communication.
Use the
netstat -nacommand to verify that ports 8501 - ,8505 are listening on the Manager. Click Start → Run typecmd, press Enter, then typenetstat -naat the command prompt.Make sure large UDP and/or fragmented UDP packets are not dropped between the Sensor and Manager communication. This can lead to SNMP timeout. Look for the following logs in ems.log:
Ems log******014-06-27 15:47:29,150 INFO [Thread-135] iv.core.SensorConfiguration - M1450 Experience a SNMP error during set/get, Change the STATUS to DISCCONECTED2014-06-27 15:47:29,163 ERROR [Thread-135] iv.core.SensorConfiguration - Fail to process SNMP return node:com.intruvert.ext.sensorconfig.leap.SensorConfigException: Time OutCapture UDP traffic using Wireshark on the Manager. Check if the Manager is receiving UDP response packets from the Sensor.
Sample capture on the Manager:
.png)
Check the time on the Sensor, and if it matches with the Manager system time.
Check if there are any Out Of Memory related logs in the Manager. This can lead to connectivity issues between the Sensor and Manager.
Check if the Manager is an MDR pair. If yes, verify that the IP of primary Manager in the sensor matches the IP of the active Manager. Also check whether the Sensor is treating the standby Manager as the primary Manager. This might lead to connectivity issues.
If the problem still persists, contact Trellix Support for further assistance.