07-06-2015 02:43 PM - edited 02-20-2020 09:29 PM
Suddenly started getting this health alert today on a Sourefire module. Evething else is working fine. What should I be looking at?
11-17-2015 12:46 PM
I think I was having the same problem. If it is then most likely the reason for this is because on the other end of the connection (not your network) the IP pool that the Defense Center (DC) was using to connect to the dynamic cloud was modified and your DC was using one of the IPs that was removed during the modification. In order to fix this, you have to restart the process on the DC that is responsible for this connection and then it'll automatically pick a new IP. Keep in mind that I restarted my DC as part of my troubleshooting and it did not fix this issue, I had to specifically restart the process. This is how I did it:
1. SSH into the DC with a terminal application (e.g. putty, SecureCRT, etc.)
2. login with super user credentials
3. pidof stunnel
! notice the process umber
4. pmtool restartbyid stunnel
5. pidof stunnel
! notice the process number is different than the one on step 3. This confirms that the process restarted
This is what took care of my issue although I had to wait 5-10 min. after the restart to stop seeing the alerts (no downtime experienced). Hope this helps.
11-18-2015 12:03 PM
I'm having this issue as well, though I thought I recently fixed it.
pidof stunnel is not returning any results
ps aux | grep stunnel is not returning any results
pmtool restartbyid stunnel does not change anything
I do have reason to believe that the IP pool DC was using did change, so how do I refresh this?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide