We have a client currently that is only connected with LAN. The client is reporting network changes the the firewall every few minutes and generates a new HB session. Causing many interruptins for the user.
The client computer remains connected to the network all the time and ping and voip applications have no outages. eventlog of windows also is not showing network reconnects. anyway the heartbeat agent re-initiates HB against the firewall every few minutes.
I can follow the communication on wireshark - the clients terminates the HB session and sends a FIN to the heartbeat IP and starts a new HB TLS session to the HB IP afterwards. that is regardless a user is logged on or not.
We have ruled out drivers and BIOS - that is all up to date and the issue was also with older versions - only for that client.
Question:
What I need from some skilled Sophos guys is how to debug the heartbeat agent on the client computer so I can see, what causes it to "think" there are network changes.
2023-03-17T11:05:35.453Z [ 5484: 6264] A Sending network status 2023-03-17T11:05:35.454Z [ 5484: 6264] A The network status has changed, the Firewall may disconnect. 2023-03-17T11:05:35.456Z [ 5484: 6264] A Received request to enable enhanced application control 2023-03-17T11:05:35.457Z [ 5484: 6264] A Sending endpoint state list request 2023-03-17T11:05:35.457Z [ 5484: 6264] A Sending login status. 2023-03-17T11:05:35.457Z [ 5484: 6264] A User: 2023-03-17T11:05:35.457Z [ 5484: 6264] A Sending health status: admin=1 health=1 service=1 threat=1 threatService=1 2023-03-17T11:05:35.458Z [ 5484: 6264] A Received response to endpoint state list request, size: 2 2023-03-17T11:08:34.755Z [ 5484: 6264] A Sending network status 2023-03-17T11:08:34.755Z [ 5484: 6264] A The network status has changed, the Firewall may disconnect. 2023-03-17T11:08:34.758Z [ 5484: 6264] A Connection closed (network error). 2023-03-17T11:08:35.810Z [ 5484: 6264] A Connection succeeded. 2023-03-17T11:08:35.810Z [ 5484: 6264] A Connected to 'ed98a5bf-xxxxxxxxxxxxxxxxxxxxx13f1b' at IP address 52.5.76.173 on port 8347 2023-03-17T11:08:35.810Z [ 5484: 6264] A Sending network status 2023-03-17T11:08:35.810Z [ 5484: 6264] A The network status has changed, the Firewall may disconnect. 2023-03-17T11:08:35.862Z [ 5484: 6264] A Received request to enable enhanced application control 2023-03-17T11:08:35.862Z [ 5484: 6264] A Sending endpoint state list request 2023-03-17T11:08:35.863Z [ 5484: 6264] A Sending login status. 2023-03-17T11:08:35.863Z [ 5484: 6264] A User: 2023-03-17T11:08:35.863Z [ 5484: 6264] A Sending health status: admin=1 health=1 service=1 threat=1 threatService=1 2023-03-17T11:08:35.864Z [ 5484: 6264] A Received response to endpoint state list request, size: 2 2023-03-17T11:11:35.089Z [ 5484: 6264] A Sending network status 2023-03-17T11:11:35.089Z [ 5484: 6264] A The network status has changed, the Firewall may disconnect. 2023-03-17T11:11:35.091Z [ 5484: 6264] A Connection closed (network error). 2023-03-17T11:11:36.131Z [ 5484: 6264] A Connection succeeded. 2023-03-17T11:11:36.131Z [ 5484: 6264] A Connected to 'ed98a5bf-xxxxxxxxxxxxxxxxxxxxx13f1b' at IP address 52.5.76.173 on port 8347 2023-03-17T11:11:36.132Z [ 5484: 6264] A Sending network status 2023-03-17T11:11:36.132Z [ 5484: 6264] A The network status has changed, the Firewall may disconnect. 2023-03-17T11:11:36.185Z [ 5484: 6264] A Received request to enable enhanced application control 2023-03-17T11:11:36.186Z [ 5484: 6264] A Sending endpoint state list request 2023-03-17T11:11:36.186Z [ 5484: 6264] A Sending login status. 2023-03-17T11:11:36.186Z [ 5484: 6264] A User: 2023-03-17T11:11:36.187Z [ 5484: 6264] A Sending health status: admin=1 health=1 service=1 threat=1 threatService=1 2023-03-17T11:11:36.188Z [ 5484: 6264] A Received response to endpoint state list request, size: 2
Here A client log together with filtered hblog from firewall below
2023-03-17T11:21:36.167Z [ 5484: 6264] A Sending network status 2023-03-17T11:21:36.167Z [ 5484: 6264] A The network status has changed, the Firewall may disconnect. 2023-03-17T11:21:36.170Z [ 5484: 6264] A Connection closed (network error). 2023-03-17T11:21:37.216Z [ 5484: 6264] A Connection succeeded. 2023-03-17T11:21:37.216Z [ 5484: 6264] A Connected to 'ed98a5bf-xxxxxxxxxxxxxxxxxxxxx13f1b' at IP address 52.5.76.173 on port 8347 2023-03-17T11:21:37.217Z [ 5484: 6264] A Sending network status 2023-03-17T11:21:37.217Z [ 5484: 6264] A The network status has changed, the Firewall may disconnect. 2023-03-17T11:21:37.263Z [ 5484: 6264] A Received request to enable enhanced application control 2023-03-17T11:21:37.263Z [ 5484: 6264] A Sending endpoint state list request 2023-03-17T11:21:37.263Z [ 5484: 6264] A Sending login status. 2023-03-17T11:21:37.263Z [ 5484: 6264] A User: 2023-03-17T11:21:37.263Z [ 5484: 6264] A Sending health status: admin=1 health=1 service=1 threat=1 threatService=1 2023-03-17T11:21:37.265Z [ 5484: 6264] A Received response to endpoint state list request, size: 2
[2023-03-17 11:21:13.309Z] INFO HBSessionHandler.cpp[32722]:125 removeDirtySessions - Number of sessions: 174 [2023-03-17 11:21:13.431Z] INFO HBSessionHandler.cpp[32722]:152 findPinnedEndpointIdentity - Number of sessions: 175 [2023-03-17 11:21:16.102Z] WARN ModuleNetwork.cpp[32722]:62 processNetworkRequest - Network settings changed on endpoint, so disconnect it. [2023-03-17 11:21:16.102Z] ERROR ModuleMessageHub.cpp[32722]:82 onHBMsgReceive - sending no response for unhandled message network [2023-03-17 11:21:17.138Z] INFO HBSessionHandler.cpp[32722]:125 removeDirtySessions - Number of sessions: 174 [2023-03-17 11:21:17.216Z] INFO HBSessionHandler.cpp[32722]:152 findPinnedEndpointIdentity - Number of sessions: 175 [2023-03-17 11:21:36.172Z] WARN ModuleNetwork.cpp[32722]:62 processNetworkRequest - Network settings changed on endpoint, so disconnect it. [2023-03-17 11:21:36.172Z] INFO EndpointStorage.cpp[32722]:110 endpoint_connectivity_cb - Connectivity changed for <6c9d2bxxxxxxxxxxxxxxxxxxxe2462d84a>: <1> -> <5> [2023-03-17 11:21:36.172Z] ERROR ModuleMessageHub.cpp[32722]:82 onHBMsgReceive - sending no response for unhandled message network [2023-03-17 11:21:37.207Z] INFO HBSessionHandler.cpp[32722]:125 removeDirtySessions - Number of sessions: 174 [2023-03-17 11:21:37.221Z] INFO HBSessionHandler.cpp[32722]:152 findPinnedEndpointIdentity - Number of sessions: 175 [2023-03-17 11:21:37.221Z] INFO HBSession.cpp[32722]:504 logNewSession - New Session: [172.xxx.xxx.86]:20977 connected [2023-03-17 11:21:37.222Z] INFO EndpointStorage.cpp[32722]:110 endpoint_connectivity_cb - Connectivity changed for <6c9d2bxxxxxxxxxxxxxxxxxxxe2462d84a>: <5> -> <1> [2023-03-17 11:21:37.222Z] INFO ModuleSacFirst.cpp[32722]:95 sendEacMessage - send EacSwitchRequest to endpoint (IP=172.xxx.xxx.86) [2023-03-17 11:21:37.267Z] INFO EpStateListBroker.cpp[32722]:56 markEndpointForUpdates - Endpoint marked for receiving Stonewall updates: 6c9d2bxxxxxxxxxxxxxxxxxxxe2462d84a(172.xxx.xxx.86) [2023-03-17 11:21:37.269Z] INFO ModuleStatus.cpp[32722]:137 processMessageStatus - Status request received from endpoint: 6c9d2bxxxxxxxxxxxxxxxxxxxe2462d84a (172.xxx.xxx.86) health: 1 [2023-03-17 11:21:46.176Z] WARN ModuleNetwork.cpp[32722]:62 processNetworkRequest - Network settings changed on endpoint, so disconnect it. [2023-03-17 11:21:46.176Z] ERROR ModuleMessageHub.cpp[32722]:82 onHBMsgReceive - sending no response for unhandled message network [2023-03-17 11:21:47.222Z] INFO HBSessionHandler.cpp[32722]:125 removeDirtySessions - Number of sessions: 174 [2023-03-17 11:21:47.298Z] INFO HBSessionHandler.cpp[32722]:152 findPinnedEndpointIdentity - Number of sessions: 175
This thread was automatically locked due to age.