McAfee M4050 Troubleshooting Guide - Page 4

Utilizing the McAfee Knowledge Base, Using the InfoCollector tool - installation

Page 4 highlights

Checking Sensor health ...22 Pinging a Sensor...22 Ensuring that the Sensor is receiving traffic 22 Checking Sensor failover status 23 Cabling failover through a network device 23 Checking whether a signature or software update was successful 24 Checking status of a download or upload 24 Conditions requiring a Sensor reboot 24 Rebooting a Sensor via the Manager 25 Rebooting a Sensor using the reboot command 25 Sensor doesn't boot ...25 Debugging critical Sensor issues 25 Loss of connectivity between the Sensor and Manager 29 How Sensor handles new alerts during connectivity loss 30 Manager connectivity to the database 30 Manager database is full ...31 Error on accessing the Configuration page 31 Sensor response if its throughput is exceeded 31 MySQL issues ...32 How Sensors handle various types of traffic 32 Jumbo Ethernet frames ...32 ISL frames ...32 Sensor failover issues ...33 External fail-open kit issues in connecting to the monitoring port 33 XC cable connection issues for M8000 Sensors 33 Chapter 5 Determining False Positives 34 Reducing false positives...34 Tune your policies ...34 About false positives and "noise 35 Determining a false positive versus noise 36 Chapter 6 System Fault Messages 38 Critical faults...38 Error faults...55 Warning faults ...61 Informational faults ...65 Other faults...76 Chapter 7 Error Messages 77 Error messages for RADIUS servers 77 Error messages for LDAP server 78 Chapter 8 Using the InfoCollector tool 79 Introduction...79 Running the InfoCollector...80 Using InfoCollector ...80 Chapter 9 Automatically restarting a failed Manager with Manager Watchdog ...81 Introduction...81 How the Manager Watchdog Works 81 Installing Manager Watchdog...82 Starting Manager Watchdog...82 Using Manager Watchdog with Manager in an MDR configuration 82 Tracking Manager Watchdog activities 82 Chapter 10 Utilizing the McAfee Knowledge Base 84 Index ...86 iv

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95

iv
Checking Sensor health
..............................................................................................................
22
Pinging a Sensor
..................................................................................................................
22
Ensuring that the Sensor is receiving traffic
................................................................................
22
Checking Sensor failover status
..................................................................................................
23
Cabling failover through a network device
...........................................................................
23
Checking whether a signature or software update was successful
.............................................
24
Checking status of a download or upload
...................................................................................
24
Conditions requiring a Sensor reboot
..........................................................................................
24
Rebooting a Sensor via the Manager
...................................................................................
25
Rebooting a Sensor using the reboot command
..................................................................
25
Sensor doesn’t boot
....................................................................................................................
25
Debugging critical Sensor issues
................................................................................................
25
Loss of connectivity between the Sensor and Manager
..............................................................
29
How Sensor handles new alerts during connectivity loss
....................................................
30
Manager connectivity to the database
.........................................................................................
30
Manager database is full
......................................................................................................
31
Error on accessing the Configuration page
.................................................................................
31
Sensor response if its throughput is exceeded
...........................................................................
31
MySQL issues
.............................................................................................................................
32
How Sensors handle various types of traffic
...............................................................................
32
Jumbo Ethernet frames
........................................................................................................
32
ISL frames
............................................................................................................................
32
Sensor failover issues
.................................................................................................................
33
External fail-open kit issues in connecting to the monitoring port
...............................................
33
XC cable connection issues for M8000 Sensors
.........................................................................
33
Chapter 5 Determining False Positives
....................................................
34
Reducing false positives
..............................................................................................................
34
Tune your policies
.......................................................................................................................
34
About false positives and “noise”
.........................................................................................
35
Determining a false positive versus noise
............................................................................
36
Chapter 6 System Fault Messages
............................................................
38
Critical faults
................................................................................................................................
38
Error faults
...................................................................................................................................
55
Warning faults
.............................................................................................................................
61
Informational faults
......................................................................................................................
65
Other faults
..................................................................................................................................
76
Chapter 7 Error Messages
..........................................................................
77
Error messages for RADIUS servers
..........................................................................................
77
Error messages for LDAP server
................................................................................................
78
Chapter 8 Using the InfoCollector tool
.....................................................
79
Introduction
..................................................................................................................................
79
Running the InfoCollector
............................................................................................................
80
Using InfoCollector
......................................................................................................................
80
Chapter 9 Automatically restarting a failed Manager with Manager
Watchdog
.....................................................................................................
81
Introduction
..................................................................................................................................
81
How the Manager Watchdog Works
............................................................................................
81
Installing Manager Watchdog
......................................................................................................
82
Starting Manager Watchdog
........................................................................................................
82
Using Manager Watchdog with Manager in an MDR configuration
............................................
82
Tracking Manager Watchdog activities
.......................................................................................
82
Chapter 10 Utilizing the McAfee Knowledge Base
..................................
84
Index
.............................................................................................................
86