Data Loss Prevention

 View Only
  • 1.  On the dlp network monitor server Ceh.exe keeps logging that it is faulting but we are not running email prevent

    Posted Jul 17, 2013 01:57 PM

    We have installed DLP 11.0 recently and I have for the past couple of weeks seen in the event log that the ceh.exe module keeps crashing.  From what I've seen this module is part of the email prevent system so the fact that it keeps popping up is curious.  I'm just wondering if this should be cause for alarm and if there is a way to clean it up.  All that I'm seeing relates to correcting the problem when you have email prevent running.



  • 2.  RE: On the dlp network monitor server Ceh.exe keeps logging that it is faulting but we are not running email prevent

    Trusted Advisor
    Posted Jul 17, 2013 04:20 PM

    The CEH is part of the system and NOT just for Email Prevent.

    It will extract the content from files for inspection.

    I would first of all upgrade to a more current version.
    At least to 11.5.1.

    There are some known bugs that were fixed after 11.1.2

    If this solves your questions please marked as solved.

    Ronak



  • 3.  RE: On the dlp network monitor server Ceh.exe keeps logging that it is faulting but we are not running email prevent

    Posted Jul 17, 2013 04:28 PM

    Sorry it's 11.6.2 not 11.0.  Good to know that it is part of the overall system and not just email prevent though.



  • 4.  RE: On the dlp network monitor server Ceh.exe keeps logging that it is faulting but we are not running email prevent

    Trusted Advisor
    Posted Jul 17, 2013 04:37 PM

    Also I would make sure that you have the right server specs and have tuned the system for 64bit performance (if applicable).

    What kind of DLP server are these errors happening on? (Discover, Monitor etc..)

    If this is happening on a Monitor, you my have some bad or 'dirty' traffic that is causing the issue.

    If this solves your questions please marked as solved.

    Ronak



  • 5.  RE: On the dlp network monitor server Ceh.exe keeps logging that it is faulting but we are not running email prevent

    Posted Jul 18, 2013 11:17 AM

    We had vendor support on the install so I don't think the tuning would be a problem.  However what sort or dirty traffic would we be looking at?  (Yes this is on one of our two monitor servers.)  Is this something that can be cleaned up?



  • 6.  RE: On the dlp network monitor server Ceh.exe keeps logging that it is faulting but we are not running email prevent

    Trusted Advisor
    Posted Jul 18, 2013 05:46 PM

    You would need to look at a couple of things to see if the traffic is dirty and then to clean it up...

    Look at the System > Traffic page and click on the servers and see how many Unprocessable Files there are or other errors that might be happening. If there are a lot, then you may have too much or dirty traffic.

    Also look at the amount of traffic you are seeing on EACH monitor. There is a limit to the amount of traffic they can handle.

    You can also do a WireShark packet capture on the Tap/Span port on the monitor. Then look at the capture, make sure there aren't any duplicate packets and the amount of traffic is manageable.

    If you have dirty traffic, you will need to configure the TAP/span port to not send duplicate traffic or unwanted traffic.

    There are tools that you can get from Symantec to help look at it too.

    I have attached a couple of items that will help with tuning and analyzing the packets.

    If this solves your questions please marked as solved.

    Ronak