We got high water mark errors recently on the Celerra NS80. I checked the server logs and I found the below logs. Anybody know what this error means. Please let me know and that helps me a lot.
2010-02-05 04:43:55: VC: 3: 30: Error on CAVA server xxxx: OFFLINE, ntStatus: SUCCESS.
2010-02-05 04:44:05: VC: 3: 30: Error on CAVA server xxxxx OFFLINE, ntStatus: SUCCESS.
I saw the event logs but did not find any errors related to this issue. But, I found below EMC primus solution could be the reason. Our NAS code is 5.6, CAVA version is 3.6.2 and McAfee is 8.0i. In the primus it is saying that we have to at 8.5i patch7. What are you comments?
Thanks,
Bannu.
EMC Knowledgebase
"CAVA has detected termination of the resident Network Associates."
ID:
emc206027
Usage:
7
Date Created:
01/27/2009
Last Modified:
03/16/2009
STATUS:
Approved
Audience:
Customer
Knowledgebase Solution
Environment:
Product: Celerra
Environment:
Feature: Celerra AntiVirus Agent (CAVA) 3.6.2
Environment:
SW EMC: NAS Code 5.5
Environment:
EMC Software: NAS Code 5.6
Environment:
NAI McAfee VirusScan: 8.5i Patch 2 and and later
Problem:
VC: 4:16: Virus Checking STARTED VC: 3: 8: Server 161.228.78.5: AV_NOT_FOUND, RPC program version 3, CAVA release: 3.6.2, AV Engine: Unknown VC: 3: 5: No Virus Checker Server available, STOP VIRUS CHECKING
Problem:
CAVA Event Viewer Application Log shows the following event multiple times:
CAVA has detected the termination of the resident Network Associates. CAVA will no longer process Celerra AV requests until the resident antiviurs software is restarted.
Problem:
McAfee service pauses and restarts for up to 45 seconds at a time, sometimes more. These restarts can be seen in the CAVA Event Logs.
Root Cause:
The timeout between when Network Associates goes down and starts up again sometimes takes too long and CAVA therefore stops.
Fix:
In this case, the McAfee software was upgraded to McAfee 8.5i Patch 7 and the problem was resolved.
We are in the process of upgrading. I am seeing the below entries in the VC log all the day(couple of times).
2010-03-16 00:23:47: VC: 5: 18: The VC server xxx.x.xxxx.x updated the reference time, reference=Tue Mar 16 04:23:46 2010 (GMT-00:00). 2010-03-16 00:31:45: VC: 5: 18: The VC server xxx.x.xxxx.x updated the reference time, reference=Tue Mar 16 04:31:25 2010 (GMT-00:00). 2010-03-16 01:20:45: VC: 5: 18: The VC server xxx.x.xxxx.xupdated the reference time, reference=Tue Mar 16 05:19:51 2010 (GMT-00:00). 2010-03-16 01:26:46: VC: 5: 18: The VC server xxx.x.xxxx.x updated the reference time, reference=Tue Mar 16 05:26:46 2010 (GMT-00:00).
I checked the CAVA server time and DM time which are almost same(may be 3secs diffrence). Is something that goes away after McAfee upgrade?
I have upgrade Mcafee to 8.5 patch8. Now, the server_viruschk ALL output shows the AV servers going offline sometimes and coming back online.
I changed the settings enabled the when reading from disk option also in the Mcafee properties. What else you think? Getting lot of high water errors too!
Support is saying that we should not enable the "Scan on read if access time". Support is saying that means it AV is scanning all the files when any CIFS user is reading from NAS.
Is that correct?
1 File Mask(s): *.* 2 Excluded File(s): PAGEFILE.SYS *.TMP Share :\***** RPC request timeout=25000 milliseconds. RPC retry timeout=5000 milliseconds. High water mark=200. Low water mark=50. Scan all virus checkers every 60 seconds. When all virus checkers are offline: Continue to work with Virus Checking and CIFS. -------------------------- > Scan on read if access Time is less than Fri Mar 19 15:55:46 2010 (GMT-00:00). Panic handler registered for 65 chunks.
EMC support recommended me to disable the scan on first read on all the DMs, because it will impact the CAVA environment and which is not recommended setting, which I disabled on all DMs. No CAVA errors now.
I tried testing the EICAR file on putting one of those DMs (created a CIFS share). When I chose the delete files automatically on the AV server, I can see that EICAR file was deleting automatically. But, when I chose the option deny access to files from the drop down, it should rename the EICAR file to .vir extension and which is not happening(file was sitting there). Any ideas or comments.
Also found this output from one of the DM.
[nasadmin@ccs1 ~]$ server_log server_2 |grep -i VC 2010-03-22 10:39:04: VC: 5: last message repeated 1 times 2010-03-22 10:39:08: VC: 5: last message repeated 1 times 2010-03-22 10:40:10: VC: 5: last message repeated 1 times 2010-03-22 10:40:21: VC: 5: last message repeated 1 times 2010-03-22 10:41:07: VC: 5: last message repeated 1 times 2010-03-22 10:41:21: VC: 5: last message repeated 1 times 2010-03-22 10:41:39: VC: 5: last message repeated 1 times 2010-03-22 10:41:49: VC: 5: last message repeated 1 times 2010-03-22 10:42:24: VC: 5: last message repeated 1 times 2010-03-22 10:42:32: VC: 5: last message repeated 1 times 2010-03-22 10:42:34: VC: 5: last message repeated 1 times 2010-03-22 10:42:39: VC: 5: last message repeated 1 times 2010-03-22 10:42:53: VC: 5: last message repeated 1 times 2010-03-22 10:42:56: VC: 5: last message repeated 1 times [nasadmin@ccs1 ~]$
Screename1
2 Intern
•
99 Posts
1015
0
Posted March 8th, 2010 09:00
Hi Karl,
Thanks for the prompt response!
I saw the event logs but did not find any errors related to this issue. But, I found below EMC primus solution could be the reason. Our NAS code is 5.6, CAVA version is 3.6.2 and McAfee is 8.0i. In the primus it is saying that we have to at 8.5i patch7. What are you comments?
Thanks,
Bannu.
NAI McAfee VirusScan: 8.5i Patch 2 and and later
VC: 3: 8: Server 161.228.78.5: AV_NOT_FOUND, RPC program version 3, CAVA release: 3.6.2, AV Engine: Unknown
VC: 3: 5: No Virus Checker Server available, STOP VIRUS CHECKING
CAVA has detected the termination of the resident Network Associates. CAVA will no longer process Celerra AV requests until the resident antiviurs software is restarted.