Skip to main content
NetApp Knowledge Base

Varonis FPolicy disconnecting repeatedly

Views:
2,063
Visibility:
Public
Votes:
1
Category:
ontap-9
Specialty:
cifs
Last Updated:

Applies to

  • ONTAP 9
  • Clustered Data ONTAP

Symptom

The controller EMS/Event log will display the following sequence of messages often:

Mon Jan 04 12:09:45 EST [example: fpolicy: fpolicy.server.connectError:error]: Node failed to establish a connection with the FPolicy server '10.1.1.101' (reason: 'Connection to FPolicy server is broken(EPIPE) received.').
Mon Jan 04 12:09:45 EST [example: fpolicy: fpolicy.server.disconnect:warning]: Connection to the Fpolicy server '10.1.1.101' is broken ( reason: 'FPolicy server is removed from external engine.' ).
Mon Jan 04 13:06:11 EST [example: fpolicy: fpolicy.server.disconnect:warning]: Connection to the Fpolicy server '10.1.1.101' is broken ( reason: 'FPolicy server is removed from external engine.' ).
Mon Jan 04 13:06:36 EST [example: fpolicy: fpolicy.server.connectError:error]: Node failed to establish a connection with the FPolicy server '10.1.1.101' (reason: 'Select Timed out.').


A packet trace between SVM and FPolicy server will reveal that the FPolicy server is abruptly ending TCP connections.  For some issues, this may be after the connection is established and the TCP connnection is reset by the FPolicy server, as can be observed when using the filter tcp.flags.reset == 1.  For other issues, this may be after the initial FPolicy Negotiation Request is sent by the SVM, and the FPolicy server is not seen to responding as expected due to the issue, and it terminates the TCP connection by sending a TCP FIN,ACK, which can be observed with the filter tcp.flags.fin == 1

 

 

 

 

 

CUSTOMER EXCLUSIVE CONTENT

Registered NetApp customers get unlimited access to our dynamic Knowledge Base.

New authoritative content is published and updated each day by our team of experts.

Current Customer or Partner?

Sign In for unlimited access

New to NetApp?

Learn more about our award-winning Support