Dragon 7.5.0.95 HIDS client cannot connect to EMS server
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-01-2013 06:48 PM
I have a 7.5.0.95 Dragon EMS server and sensors. One sensor (HIDS running on Linux) shows the Event Channel down in the reporting dashboard, and the management client shows it unable to communicate. The HIDS sensor keeps logging "[net-cfg-client (25650)]: Could not connect: Connection timed out." What should I look at to fix this issue? I've got other sensors working just fine, this is my odd box.
17 REPLIES 17
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-04-2013 09:05 PM
The HIDS sensor does reconnect to port 9111, but I don't see the local high port changing. The netcfgclient.log file continues to log connection timed out error messages too. No other errors in any other log files.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-04-2013 07:19 PM
When the software was restarted, did it establish a connection on 9111? Also if you again for this connection a minute later do you see the local high port changing? This would indicate a constant reconnection taking place. root@snowman:/opt/dragon/bin# netstat -antuv | grep 9111 tcp 0 0 10.58.24.77:50848 10.58.24.88:9111 ESTABLISHED In the above example, 50848, is the local high port. Can you deploy to this sensor at this time? Thanks Jeff
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-04-2013 07:05 PM
Shutdown removed the lock. No problem there. The HIDS sensor is RHEL5.9 32 bit. FWIW, all sensors connect sensor-to-server.
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-04-2013 04:50 PM
Hi Could we shutdown the software on the HIDS? (dragon-shutdown.sh) then check to make sure the .net-cfg-client.lock is removed from the ~/dragon/bin directory. If not, please remove it manually and then restart. The 9111 channel is responsible the configuration pushes so perhaps there is a disconnect between the software and the operating system. What version of Linux is the Host? 64 or 32 bit? Thanks
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎11-04-2013 04:29 PM
I have established connections on 9111 and 9112. I get heartbeats and system health info. In the EMS client, it shows the sensor needs to be deployed, which fails. But, it's listed as working (green checkmark). I've checked to make sure the shared secret is listed as correct too. It all looks connected, but isn't listed as up.
