UNSOLVED

Screename1

updated

17 years ago

S

Screename1

2 Intern

99 Posts

0

12568

March 5th, 2010 14:00

Celerra CAVA errors

Hi,

We got high water mark errors recently on the Celerra NS80. I checked the server logs and I found the below logs. Anybody know what this error means. Please let me know and that helps me a lot.

2010-02-05 04:43:55: VC: 3: 30: Error on CAVA server xxxx: OFFLINE, ntStatus: SUCCESS.

2010-02-05 04:44:05: VC: 3: 30: Error on CAVA server xxxxx OFFLINE, ntStatus: SUCCESS.

2010-02-05 04:44:55: VC: 3: 30: Error on CAVA serverxxxxxx: OFFLINE, ntStatus: SUCCESS.

2010-02-05 04:44:55: VC: 5: 29: Server xxxxx is online.

2010-02-05 04:44:57: VC: 5: 29: Server xxxxxx is online.

2010-02-05 05:00:22: VC: 3: 2: high water mark reached

2010-02-05 05:03:08: VC: 4: 3: low water mark reached.

Thanks for your help on advance.

Bannu.

  • Screename1

    2 Intern

    99 Posts

    1015

    0

    Posted March 8th, 2010 09:00

    Hi Karl,

    Thanks for the prompt response!

    I saw the event logs but did not find any errors related to this issue. But, I found below EMC primus solution could be the reason. Our NAS code is 5.6, CAVA version is 3.6.2 and McAfee is 8.0i. In the primus it is saying that we have to at 8.5i patch7. What are you comments?

    Thanks,

    Bannu.

    EMC Knowledgebase
    spacer
    spacer"CAVA has detected termination of the resident Network Associates."
    spacer
    spacerspacerspacer
    ID:emc206027
    Usage:7
    Date Created:01/27/2009
    Last Modified:03/16/2009
    STATUS:Approved
    Audience:Customer
    Knowledgebase Solution

    Environment:Product: Celerra
    Environment:Feature: Celerra AntiVirus Agent (CAVA) 3.6.2
    Environment:SW EMC: NAS Code 5.5
    Environment:EMC Software: NAS Code 5.6
    Environment:

    NAI McAfee VirusScan: 8.5i Patch 2 and and later

    Problem:VC: 4:16:  Virus Checking STARTED
    VC: 3: 8:  Server 161.228.78.5: AV_NOT_FOUND, RPC program version 3, CAVA release: 3.6.2, AV Engine: Unknown
    VC: 3: 5:  No Virus Checker Server available, STOP VIRUS CHECKING
    Problem:CAVA Event Viewer Application Log shows the following event multiple times:

    CAVA has detected the termination of the resident Network Associates.  CAVA will no longer process Celerra AV requests until the resident antiviurs software is restarted.

    Problem:McAfee service pauses and restarts for up to 45 seconds at a time, sometimes more.  These restarts can be seen in the CAVA Event Logs.
    Root Cause:The timeout between when Network Associates goes down and starts up again sometimes takes too long and CAVA therefore stops.
    Fix:In this case, the McAfee software was upgraded to McAfee 8.5i Patch 7 and the problem was resolved.

    spacer

  • Screename1

    2 Intern

    99 Posts

    1015

    0

    Posted March 11th, 2010 08:00

    Hi Karl,

    What are the McAfee upgrade steps:

    Can I stop the viruschecker service on all DMs

    Upgrade the McAfee to 8.5i patch7 and start the VC service? Will it updates the Virusdefinition file. Means will it scans all the files again.

    Could you please let me know.

    Thanks,

    Bannu.

  • Screename1

    2 Intern

    99 Posts

    1015

    0

    Posted March 16th, 2010 11:00

    Hi Karl,

    We are in the process of upgrading. I am seeing the below entries in the VC log all the day(couple of times).

      2010-03-16 00:23:47: VC: 5: 18: The VC server xxx.x.xxxx.x updated the reference time, reference=Tue Mar 16 04:23:46 2010 (GMT-00:00).
    2010-03-16 00:31:45: VC: 5: 18: The VC server xxx.x.xxxx.x updated the reference time, reference=Tue Mar 16 04:31:25 2010 (GMT-00:00).
    2010-03-16 01:20:45: VC: 5: 18: The VC server xxx.x.xxxx.xupdated the reference time, reference=Tue Mar 16 05:19:51 2010 (GMT-00:00).
    2010-03-16 01:26:46: VC: 5: 18: The VC server xxx.x.xxxx.x updated the reference time, reference=Tue Mar 16 05:26:46 2010 (GMT-00:00).

    I checked the CAVA server time and DM time which are almost same(may be 3secs diffrence). Is something that goes away after McAfee upgrade?

    Any comments on the above entries?

    Thanks,

    Bannu.

  • Screename1

    2 Intern

    99 Posts

    1015

    0

    Posted March 16th, 2010 13:00

    Thanks Karl for your quick response!

    We have 4 AV servers having the same Autoupdate time 12AM daily. So, can I keep them 12AM, 1AM, 2AM, 3AM for AV servers. Is this a good idea?

    Thanks again.

    Bannu.

  • Screename1

    2 Intern

    99 Posts

    607

    0

    Posted March 17th, 2010 13:00

    Thankyou very much Karl for your quick response.

    Where can I find  E-lab for CAVA on powerlink.

    Thanks,

    Bannu.

  • Screename1

    2 Intern

    99 Posts

    607

    0

    Posted March 17th, 2010 13:00

    Karl,

    We have 8.5i patch8 with our admins. But according to emc primus206027 we need patch7. Is it OK to apply patch8.

    Thanks,

    Bannu.

  • Screename1

    2 Intern

    99 Posts

    607

    0

    Posted March 17th, 2010 13:00

    Hey Karl,

    Thanks for your help.

    I came to know this 4 CAVA AV servers are VMs. Still the operation and eveything should be same as physical machine right?

    Bannu.

  • Screename1

    2 Intern

    99 Posts

    607

    0

    Posted March 18th, 2010 14:00

    Karl,

    I have upgrade Mcafee to 8.5 patch8. Now, the server_viruschk ALL output shows the AV servers going offline sometimes and coming back online.

      I changed the settings enabled the when reading from disk option also in the Mcafee properties. What else you think? Getting lot of high water errors too!

    Really need your help

    Thanks,

    Bannu.

  • Screename1

    2 Intern

    99 Posts

    607

    0

    Posted March 19th, 2010 09:00

    Karl,

    Below is the output from one DM.

    Support is saying that we should not enable the "Scan on read if access time". Support is saying that means it AV is scanning all the files when any CIFS user is reading from NAS.

    Is that correct?

    1 File Mask(s):
    *.*
    2 Excluded File(s):
    PAGEFILE.SYS *.TMP
    Share :\*****
    RPC request timeout=25000 milliseconds.
    RPC retry timeout=5000 milliseconds.
    High water mark=200.
    Low water mark=50.
    Scan all virus checkers every 60 seconds.
    When all virus checkers are offline:
    Continue to work with Virus Checking and CIFS.
    -------------------------- >        Scan on read if access Time is less than Fri Mar 19 15:55:46 2010 (GMT-00:00).
    Panic handler registered for 65 chunks.

  • Screename1

    2 Intern

    99 Posts

    448

    0

    Posted March 22nd, 2010 07:00

    Hi Karl,

    EMC support recommended me to disable the scan on first read on all the DMs, because it will impact the CAVA environment and which is not recommended setting, which I disabled on all DMs. No CAVA errors now.

    I tried testing the EICAR file on putting one of those DMs (created a CIFS share). When I chose the delete files automatically on the AV server, I can see that EICAR file was deleting automatically. But, when I chose the option deny access to files from the drop down, it should rename the EICAR file to .vir extension and which is not happening(file was sitting there). Any ideas or comments.

    Also found this output from one of the DM.

    [nasadmin@ccs1 ~]$ server_log server_2 |grep -i VC
    2010-03-22 10:39:04: VC: 5: last message repeated 1 times
    2010-03-22 10:39:08: VC: 5: last message repeated 1 times
    2010-03-22 10:40:10: VC: 5: last message repeated 1 times
    2010-03-22 10:40:21: VC: 5: last message repeated 1 times
    2010-03-22 10:41:07: VC: 5: last message repeated 1 times
    2010-03-22 10:41:21: VC: 5: last message repeated 1 times
    2010-03-22 10:41:39: VC: 5: last message repeated 1 times
    2010-03-22 10:41:49: VC: 5: last message repeated 1 times
    2010-03-22 10:42:24: VC: 5: last message repeated 1 times
    2010-03-22 10:42:32: VC: 5: last message repeated 1 times
    2010-03-22 10:42:34: VC: 5: last message repeated 1 times
    2010-03-22 10:42:39: VC: 5: last message repeated 1 times
    2010-03-22 10:42:53: VC: 5: last message repeated 1 times
    2010-03-22 10:42:56: VC: 5: last message repeated 1 times
    [nasadmin@ccs1 ~]$

    Thanks,

    Bannu.