Inconsistent session recording share behaviour
search cancel

Inconsistent session recording share behaviour

book

Article ID: 280831

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Inconsistent Session Recording behaviour is observed in versions 4.0.X and 4.1.X

These include the following type of behaviours

  • Random outages of the NFS shares for one or several nodes while it is verified that the NFS server is up and running
  • Lack of traffic between the PAM appliances and the NFS server
  • NFS server is shown as mounted but not available
  • NFS goes down and recovers after an unspecified amount of time

Likewise situations may arise as well for CIFS-mounted shares

Environment

CA PAM 4.0.X and 4.0.X (X from 1 to 6)

Cause

The issue was caused by a malformed rule in the internal iptables firewall causing blockage of packets when they contained certain text strings. Since this is a situation which may occur several times during operation of final customers the error occurred randomly.

It is highly advisable that prior to logging a support call or doing further troubleshooting, these hotfixes are deployed to all nodes of the existing clusters experiencing difficulties with Session Recording.

Resolution

There is no fix for versions 4.0.X, which are already EOS as of the time of the writing of this article

For versions 4.1.X please download and apply the following fixes

  • For CA PAM versions 4.1.1 through 4.1.3 please apply generic hotfix CAPAM_4.1.3.16
  • For CA PAM versions 4.1.4 through 4.1.6 please apply generic hotfix CAPAM_4.1.5.05

Both hotfixes may be retrieved from the CA PAM hotfix page. These patches do not require reboot or cluster stop, and they also include the revert counterpart if necessary.

For more information about these hotfixes see the Privileges Access Manager Hotfixes reference manual in CA PAM documentation