After upgrading DLP to 16.1 detection servers are not communicating incidents
search cancel

After upgrading DLP to 16.1 detection servers are not communicating incidents

book

Article ID: 410599

calendar_today

Updated On:

Products

Data Loss Prevention Core Package

Issue/Introduction

The upgrade to 16.1 has successfully completed and detection servers are online but no incidents can be generated. 

Environment

DLP 16.1

Cause

Neglecting to upgrade to the JRE included in the DLP Platform download can result in servers that show as connected but with limited or no functionality. 
A Warning is present in the logs:

org.jboss.netty.channel.socket.nio.AbstractNioSelector
WARNING: Failed to initialize an accepted socket.
java.lang.IllegalArgumentException: Unsupported ciphersuite TLS_AES_256_GCM_SHA384

Resolution

Ensure that, prior to installation of DLP you are using the correct JRE for that release. Each Release Update(RU) or greater update will have an included JRE packaged with the platform download. This is the minimum version that can be used with this version of DLP. 
After installing the latest JRE you can either uninstall and reinstall the detection server or Update the JRE Using Interactive Mode

See also
How to upgrade JRE (Java Runtime Environment) on DLP Enforce and Detection Servers

Additional Information

With DLP 16.1 DLP switched to using TLS 1.3 by default, so the older java versions will cause this explicit failure if not updated.