Vscan timed-out due to privileged user mismatch with ONTAP
Applies to
- ONTAP 9
- SMB/CIFS Antivirus (Vscan) Integration
- Trellix (formerly McAfee)
- AV Connector 1.0.4.0
Issue
Vscan scan requests are timing out with the following log messages:
Nblade.vscanBadUserPrivAccess: For Vserver "<vserver>", the attempt to connect to the privileged ONTAP_ADMIN$ share by the client "<ip-address>" is rejected because its logged-in user "<domain\computer-machine account$>" is not configured in any of the Vserver active scanner pools
Nblade.vscanExcessiveTOs: Vscan timed-out scanning events exceeded 2000 in the last 30 minutes for Vscan server (IP: ip-address) in SVM 'vserver'.
- Scanner pool configured privileged user: Domain\\domain-account
- Vscan server attempts authentication as: Domain\\computer-machine account$
- AV Connector version: 1.0.4.0
- Trellix Endpoint Security version: 10.7 (not a supported version)