Checking the connection state
The Teration UI will report either an inactive agent (no longer checking-in), no exported flows (on Agent Workload Profile page under Stats), or failed enforcement. Depending on the error, you can check different logs on the workload to help determine the source of the issue.
Inactive Agent
Windows Log: C:\Program Files\Cisco Tetration\Logs\TetUpdate.exe.log
Linux Log: /usr/local/tet/logs/check_conf_update.log
An HTTP response code of 304 is expected and means there is no configuration change. Error code = 2 is expected as well. Any other HTTP response code will indicate a issue talking to the WSS service on the Secure Workload cluster.
Tue 06/09/2020 17:25:25.08 check_conf_update: "curl did not return 200 code, it's 304,
˓→ exiting"
Tue 06/09/2020 17:25:25.08 check_conf_update: "error code after running check_conf_
˓→update = 2"
-
304 Expected, no config change. Successful check-in
-
401 Registration is not successful, missing Activation Key (TaaS)
-
403 Agent already registered to the cluster with same UUID
-
000 Indicates connection issue with SSL. Either curl could not reach the WSS server or there is a issue with the certificate. See SSL troubleshooting: SSL Troubleshooting
No exported flows
Windows Log: C:\Program Files\Cisco Tetration\Logs\TetSen.exe.log
Linux Log: /usr/local/tet/logs/tet-sensor.log
The following indicates a successful connection to WSS
cfgserver.go:261] config server: StateConnected, wss://<config_server_ip>:443/wss/
˓→<sensor_id>/forensic, proxy:
The following indicates a successful connection to the Collectors
collector.go:258] next collector: StateConnected, ssl://<collector_ip>>:5640
If there are errors connecting to either WSS or the Collectors, check your firewall configuration or verify if any SSL decryption is occurring between the agent and Secure Workload. See: SSL Troubleshooting
Failed to enforce policy
Windows Log: C:\Program Files\Cisco Tetration\Logs\TetEnf.exe.log
Linux Log: /usr/local/tet/logs/tet-enforcer.log
ssl_client.cpp:341] Successfully connected to EFE server
If there are errors connecting to the EFE server, check your firewall configuration or verify if any SSL decryption is occurring between the agent and Secure Workload. See: SSL Troubleshooting