McAfee M4050 Troubleshooting Guide - Page 64

Error faults, Fault, Severity, Description/Cause, Action

Page 64 highlights

McAfee® Network Security Platform 6.0 System Fault Messages Fault VIDS creation failure NTBA is unreachable Severity Critical Description/Cause This fault generally occurs in situations where the port in question is configured incorrectly. For example, a pair of ports is configured to be in different operating modes (1A is in-line while 1B is in SPAN). Action Check the configuration of the port pair to see if there is an inconsistency, and make the port pair run in the same operating mode. Critical Indicates that the NTBA cannot communicate with the Manager. The connection between the NTBA and the Manager is down, or the NTBA has been administratively disconnected. Check that a connection route exists between the Manager and the NTBA. Check the NTBA's status using the status command in the NTBA command line interface, or ping the NTBA or the NTBA gateway to ensure connectivity to the NTBA. This fault clears when the Manager detects the NTBA again. Error faults The faults listed in the following table have a severity of Error. Fault Alert channel is down Severity Error Description/Cause Indicates a failure to communicate with the Sensor via the channel on which the Manager listens for Sensor alerts. Action This fault clears when the alert channel is back up. Approaching alert Error capacity threshold Displays the percentage of space occupied by alerts in the database. As available space decreases, this message will continue to appear- at 50%, 70%, 90% and 100%. Once you've exceeded this threshold, an 'Exceeding' fault will appear. Please perform maintenance operations to clean the database. Delete unnecessary alerts, such as alerts older than a specific number of days. Incident update Error failed Internal packet Error drop error The Manager is unable to accept more incidents. You have reached the maximum number of incidents that can be accepted by the Manager. Delete old incidents to provide room for incoming incidents. The fault clears when the Manager can accept incoming incidents. Sensor is dropping packets due to extreme traffic load. Reduce the amount of traffic passing through the Sensor as this fault indicates oversubscription of traffic on the Sensor 55

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95

McAfee® Network Security Platform 6.0
System Fault Messages
55
Fault
Severity
Description/Cause
Action
VIDS creation
failure
Critical
This fault generally occurs in
situations where the port in
question is configured
incorrectly. For example, a pair
of ports is configured to be in
different operating modes (1A is
in-line while 1B is in SPAN).
Check the configuration of the
port pair to see if there is an
inconsistency, and make the
port pair run in the same
operating mode.
NTBA is
unreachable
Critical
Indicates that the NTBA cannot
communicate with the Manager.
The connection between the
NTBA and the Manager is down,
or the NTBA has been
administratively disconnected.
Check that a connection route
exists between the Manager
and the NTBA.
Check the NTBA’s status
using the status command in
the NTBA command line
interface, or ping the NTBA or
the NTBA gateway to ensure
connectivity to the NTBA. This
fault clears when the Manager
detects the NTBA again.
Error faults
The faults listed in the following table have a severity of
Error
.
Fault
Severity
Description/Cause
Action
Alert channel is
down
Error
Indicates a failure to communicate
with the Sensor via the channel on
which the Manager listens for
Sensor alerts.
This fault clears when the
alert channel is back up.
Approaching alert
capacity
threshold
Error
Displays the percentage of space
occupied by alerts in the database.
As available space decreases, this
message will continue to appear—
at 50%, 70%, 90% and 100%.
Once you’ve exceeded this
threshold, an ‘Exceeding’ fault will
appear.
Please perform maintenance
operations to clean the
database. Delete
unnecessary alerts, such as
alerts older than a specific
number of days.
Incident update
failed
Error
The Manager is unable to accept
more incidents. You have reached
the maximum number of incidents
that can be accepted by the
Manager.
Delete old incidents to
provide room for incoming
incidents. The fault clears
when the Manager can
accept incoming incidents.
Internal packet
drop error
Error
Sensor is dropping packets due to
extreme traffic load.
Reduce the amount of traffic
passing through the Sensor
as this fault indicates
oversubscription of traffic on
the Sensor