Troubleshooting Network Quarantine

To collect and send information to Tanium for troubleshooting, collect logs and other relevant information.

Collect logs

The information is saved as a compressed ZIP file that you can download with your browser.

  1. From the Network Quarantine home page, click Help , then click the Troubleshooting tab.
  2. In the Troubleshooting ZIP File section, Click Download the File.
    A networkquarantine-support.zip file downloads to the local download directory.
  3. Attach the ZIP file to your Tanium Support case form or send it to your TAM.

Tanium Network Quarantine maintains logging information in networkquarantineNN.log files in the \Program Files\Tanium\Tanium Module Server\services\networkquarantine-files directory. A new log file gets created each time the file size reaches 1 MB.

Configure log levels

  1. From the Network Quarantine home page, click Help , then the Troubleshooting tab.
  2. In the Logging Level section, select the log level that you want to enable.

View audit log

The audit log contains all of the quarantine and unquarantine actions that occur on the configured NACs.

  1. From the Network Quarantine menu, click Audit log.
  2. You can filter the log by specific IP or MAC address, action, NAC name, and so on.
  3. Click Export to save the current view of the audit log to a CSV file.

Fix SASLError not-authorized error

Problem

When a client connects to ISE with a certificate, ISE remembers that certificate and pins the certificate to the client. If that client then attempts to connect with a different client certificate, the connection is rejected with a SASL:not-authorized error.

Solution

  1. In the ISE UI, go to Administration > pxGrid Services > All Clients.
  2. Select the user and delete the session.
  3. In Network Quarantine, start the NAC.

Uninstall Network Quarantine

  1. From the Main menu, click Tanium Solutions.
  2. In the Tanium Content section, select the Network Quarantine row.
  3. Click Uninstall. Click Proceed with Uninstall to complete the process.

Last updated: 8/14/2018 12:43 PM | Feedback