Avamar:備份失敗,因為 DNS 查詢花費時間過長 - avtar 嚴重 <8941>:嚴重的伺服器連線問題,中止初始化。確認正確的伺服器位址和登入認證。
Summary: 本 KB 文章的目的是說明 avtar 交握失敗,但 ping 可正常運作且所需的 TCP 連接埠號碼也開啟的特殊情況。
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
在這種情況下,我們發現一些用戶端受到影響,而另一些則沒有。
對於受影響的用戶端,Win FS 備份和 VSS 備份都會發生此問題。
從 avtar 記錄中,我們可以看到下列錯誤訊息:
avtar FATAL <8941>: Fatal server connection problem, aborting initialization. Verify correct server address and login credentials. avtar Info <5694>: - Failed initial handshake, trying again avtar Info <5562>: - - Connect: Trying 10.xx.xx.xx:29000 Adding log debugging we can see the extra bit of information in the log:
[avtar] sslcertificate::verify_certificate_ip CN Name='Avamar Server RSA TLS'
[avtar] sslcertificate::verify_cnname Performing CN Name validation for Avamar Server RSA TLS
[avtar] uwrapper::gethostbyaddr DnsQuery(dns) returned (9002) for 10.xx.xx.xx
[avtar] sslcertificate::verify_certificate_ip CN Name='<avamar-server-fqdn>'
[avtar] sslcertificate::verify_cnname Performing CN Name validation for <avamar-server-fqdn>
[avtar] uwrapper::gethostbyaddr DnsQuery(dns) returned (9002) for 10.xx.xx.xx
[avtar] sslcertificate::verify_certificate_ip CN Name field did not match Hostname - Checking SA Names
[avtar] sslcertificate::verify_certificate_ip rawIPAddrLen = 4
[avtar] sslcertificate::verify_certificate_ip Comparing 10.xx.xx.xx with 10.xx.xx.xx
[avtar] sslcertificate::verify_certificate_ip Certificate successfully verified
[avtar] <-- SSL
[avtar] <-- TLS 1.2 Handshake, ServerHelloDone
[avtar] --> SSL
[avtar] --> TLS 1.2 Handshake, ClientKeyExchange
[avtar] --> SSL
[avtar] --> TLS 1.2 ChangeCipherSpec
[avtar] --> SSL
[avtar] --> TLS 1.2 Handshake, Finished
>[avtar] sslsockimpl::open connect failure (setrslt 1) (conrslt 0)
>[avtar] Printing ssl error stack
[avtar] certlock::~certlock() success to remove SSL cert lock 'C:\Program Files\avs\etc\.tmp\.certlock'
[avtar] sslsockimpl::save_server_cert saving cert='C:\Program Files\avs\etc\servercert.pem'
[avtar] sslsockimpl::save_server_cert cipher='AES256-SHA'
>[avtar] sslsockimpl::open failure
> avtar Info <5694>: - Failed initial handshake, trying again
For the troubleshooting purpose we checked and confirmed that the TCP ports 28001, 28002, 27000 and 29000 were all open and within the correct TCP directions as per Avamar security guide, ping and DNS resolution were also working fine.
Cause
此問題是由於 DNS 查詢的回應時間較長,實際上我們可以看到「DnsQuery(dns) return」每次都需要超過 10 秒的時間,請注意握手過程在完全失敗之前會運行多次查詢嘗試。
例如:
例如:
2019/03/05-10:22:41.39299 [avtar] sslcertificate::verify_cnname Performing CN Name validation for Avamar Server RSA TLS 2019/03/05-10:22:53.30100 [avtar] uwrapper::gethostbyaddr DnsQuery(dns) returned (9002) for 10.xx.xx.xx And the entire handshake process would require about 50 seconds to complete and fail:
2019/03/05-10:22:14.89800 [avtar] sslsockimpl::open initclient success .... 2019/03/05-10:23:05.41599 [avtar] sslsockimpl::open failure
For comparison here is an example from a working client where we see that the the "DnsQuery" is returned in less than 1 second:
2019/03/05-11:56:06.97600 [avtar] sslcertificate::verify_cnname Performing CN Name validation for <avamar-server-fqdn> 2019/03/05-11:56:07.79600 [avtar] uwrapper::gethostbyaddr DnsQuery(dns) returned (9002) for 10.xx.xx.xx And the entire handshake process would complete in about 13 seconds:
2019/03/05-11:55:54.12400 [avtar] sslsockimpl::open initclient success ... 2019/03/05-11:56:07.82899 [avtar] sslsockimpl::open initclient success, cipher: AES256-SHA In a summary, the root cause is identified as DnsQuery spent too much time on the affected client machines.
Resolution
為了解決此類問題,系統管理員需要在 DNS 伺服器上採取措施來解決此延遲。
由於此問題超出 Avamar 備份產品的範圍,因此 Sys 管理員必須介入。
由於此問題超出 Avamar 備份產品的範圍,因此 Sys 管理員必須介入。
Additional Information
如果您遇到相同的錯誤,但在您的情況下,DNS 在不到一秒的時間內回應,那麼您可能會遇到不同類型的問題。
請先檢查 Dell EMC 知識庫,看看是否有任何其他 KB 文章可以幫助您解決此問題,否則請聯絡 Avamar 支援小組。
請先檢查 Dell EMC 知識庫,看看是否有任何其他 KB 文章可以幫助您解決此問題,否則請聯絡 Avamar 支援小組。
Affected Products
AvamarProducts
Avamar, Avamar Client for WindowsArticle Properties
Article Number: 000055434
Article Type: Solution
Last Modified: 11 Oct 2024
Version: 3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.