Troubleshooting Network Quarantine

To collect and send information to Tanium for troubleshooting, collect logs and other relevant information.

Collect logs

The information is saved as a compressed ZIP file that you can download with your browser.

  1. From the Network Quarantine Home page, click Help , then click the Troubleshooting tab.
  2. In the Troubleshooting ZIP File section, Click Download the File.
    A networkquarantine-support.zip file downloads to the local download directory.
  3. Contact Tanium Support to determine the best option to send the ZIP file. For more information, see Contact Tanium Support.

Tanium Network Quarantine maintains logging information in networkquarantineNN.log files in the \Program Files\Tanium\Tanium Module Server\services\networkquarantine-files directory. A new log file gets created each time the file size reaches 1 MB.

Configure log levels

  1. From the Network Quarantine Home page, click Help , then the Troubleshooting tab.
  2. In the Logging Level section, select the log level that you want to enable.

View audit log

The audit log contains all of the quarantine and unquarantine actions that occur on the configured NACs.

  1. From the Network Quarantine menu, click Audit log.
  2. You can filter the log by specific IP or MAC address, action, NAC name, and so on.
  3. Click Export to save the current view of the audit log to a CSV file.

Fix SASLError not-authorized error

Problem

When a client connects to ISE with a certificate, ISE remembers that certificate and pins the certificate to the client. If that client then attempts to connect with a different client certificate, the connection is rejected with a SASL:not-authorized error.

Solution

  1. In the ISE UI, go to Administration > pxGrid Services > All Clients.
  2. Select the user and delete the session.
  3. In Network Quarantine, start the NAC.

Uninstall Network Quarantine

  1. From the Main menu, go to Administration > Configuration > Solutions.
  2. In the Content section, select the Network Quarantine row.
  3. Click Delete Selected and then click Uninstall to complete the process.

Contact Tanium Support

To contact Tanium Support for help, send an email to [email protected].