Network Monitor server goes into unknown state
search cancel

Network Monitor server goes into unknown state

book

Article ID: 252527

calendar_today

Updated On:

Products

Data Loss Prevention Network Monitor Data Loss Prevention

Issue/Introduction

The Network Monitor server goes into an unknown state and does not report to the Enforce Console.
We can see the following errors in the packet capture log:

[PacketDriverNapatechv3.cpp(256)]
10/02/22 08:19:31 [0x7f33b247b700] ERROR PacketDriver - NT_NetRxGet failed [PacketDriverNapatechv3.cpp(278)]
10/02/22 08:19:31 [0x7f33b247b700] ERROR PacketDriver - NT_NetRxGet failed: Error: Host buffer time stamp merge error [PacketDriverNapatechv3.cpp(256)]
10/02/22 08:19:31 [0x7f34d3a488c0] INFO  MonitorReactor - Monitor Reactor is stopped. Id: Napatech Adapter 0 Port 0_0 [MonitorReactor.cpp(104)]

Environment

DLP 15.8, 16.0

Cause

The function in above error NT_NetRxGet gets data from an in-line or capture stream. This function is called to retrieve packets/segments from an in-line or capture stream. The calling process is suspended when no data is immediately available, which means DLP is not receiving any traffic on this NIC. The error also mentions about PacketDriver, so it is mostly caused due to the NIC driver.

Resolution

Update the Napatech NIC drivers after which the Network Monitor detection server should start reporting to the Enforce server and also receive the network traffic.  This issue can also be caused by the NIC simply not receiving traffic from the network in cases where an intermediary load balancer or traffic routing is used.