Central Management appliance cannot communicate with Helix

Prev Next

Problem

The managing Helix Enterprise-enabled Central Management System appliance cannot communicate with Helix Enterprise.

Reason

The following are probable reasons for the problem:

  • The Central Management System appliance is not configured to use DTI connection settings, such as HTTP proxy settings.

  • The alert ingestion URI is not allowed.

  • The Central Management System appliance is behind a Network Address Translation (NAT) device that managed appliances cannot reach.

  • The Central Management System appliance is using SSL decryption on the connection to Helix Enterprise and a Web proxy gateway such as Blue Coat does not allow access to the alert ingestion URI.

  • The alert ingestion URI has not been registered correctly.

Action

To correct the problem:

  • Run the show fenotify integ helix command and verify that the apply-fenet-settings field is true. If it is not, run the fenotify integ helix apply-fenet-config enable command.

  • Add the alert ingestion URI described in Network requirements to an allowed list.

  • If your Central Management System appliance is behind a NAT device or a Web proxy gateway, allow access to the alert ingestion URI described in Network requirements.

  • If the other actions do not solve the problem, contact Trellix Technical Support to manually set the alert ingestion URI.