Enforce Console showing all detectors status Unknown during a network outage
search cancel

Enforce Console showing all detectors status Unknown during a network outage

book

Article ID: 264556

calendar_today

Updated On:

Products

Data Loss Prevention Core Package

Issue/Introduction

A subset of detectors, on a network segment that is offline, is showing unknown.

After restarting the Symantec DLP Detection Server Controller Service, all on-premise detectors display an unknown status.

 

Environment

Release : 16.0

Cause

When detectors are configured with short names (NetBios names), Enforce needs to resolve those names to an ip address.

If the domain/dns server that houses those host (a) records is offline, Enforce may display all detectors as unknown until the domain services are available.

Resolution

Workaround to disable DNS lookup for hosts that reside in an offline domain or a downed network segment.

Set the HOSTS file with names of servers that are offline, and provide a dead IP address for Enforce to fail on.

Once the failure to reach a resolved host has occurred, Enforce will continue attempting to connect to other detection servers.