ProxySG & Advanced Secure Gateway

 View Only
Expand all | Collapse all

Error peer not authenticated in Content Analysis

Aboonaim Golandaz

Aboonaim GolandazMar 22, 2019 04:07 AM

Kriangkrai.H

Kriangkrai.HMar 22, 2019 04:16 AM

  • 1.  Error peer not authenticated in Content Analysis

    Posted Mar 20, 2019 03:56 AM

    Hi

     

    I have upgraded software version for ASG S400-30 from 6.6.5.13 to 6.7.3.14 and found the error in Content Analysis > Services > AV Patterns at Downloads topic. After I click update, status for Engine and Patterns has been successful update and then change to Not modified status. But then the status change to Error peer not authenticated. I'm not sure what does this mean and I can't find any article mention about this error. 

    I found error log in clp_service.log that have an error like this:

    Mar 20 05:00:42 2019-03-20 05: 00:42,114 [main] ERROR com.bluecoat.clp.auth.LocalRealmAuthenticator- LoginName null does not exist in CDB for the given Realm name local-realm
    Mar 20 05:00:42 2019-03-20 05: 00:42,116 [main] ERROR com.bluecoat.clp.auth.AuthValidator- ClpException raised during CLI login process. : ErrorCode -16106
    Mar 20 05:00:42 localhost.localdomain ErrorCode=-16106: ErrorMessage=Invalid Login.  
    Mar 20 05:00:42 localhost.localdomain     at com.bluecoat.clp.auth.LocalRealmAuthenticator.validateUserInRealm(LocalRealmAuthenticator.java:104)
    Mar 20 05:00:42 localhost.localdomain     at com.bluecoat.clp.auth.LocalRealmAuthenticator.validateLogin(LocalRealmAuthenticator.java:43)
    Mar 20 05:00:42 localhost.localdomain     at com.bluecoat.clp.auth.AuthValidator.main(AuthValidator.java:51)

    Note: I also have experienced the configuration lost in Content Analysis after upgrade from 6.6.5.13 to 6.7.3.14 but I have re-configured it all again.

     

    Any help would appreicated.



  • 2.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 20, 2019 05:43 AM

    Dear Hongthong,

     

    refr this KB article.

     

    https://www.symantec.com/docs/TECH251011



  • 3.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 20, 2019 05:45 AM

    Hi,

                    Normally this is related to Certificate trust. Is your CAS update requests also going through a proxy or does it have direct access? Try to increase the logging level of the "Pattern Updates" and attempt a download. See the log which will give more clarity of the error

     



  • 4.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 21, 2019 04:20 AM

    Hi,

     

    This proxy have 2 interfaces with different gateway. One gateway can direct access to internet (Default gateway) and one gateway is behind firewall. I try to packet capture this connection but I still don't know the exacly destination.



  • 5.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 21, 2019 07:22 AM
    Dear Hongton, Refer this kb article for list of url https://www.symantec.com/docs/TECH245065


  • 6.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 22, 2019 02:29 AM

    Hi

     

    I try to pcap with filter "host subscription.es.bluecoat.com" while I force update CAS. There is an error like "Encrypted Alert" in pcap file. I'm not sure if this is a problem from SSL or something.

    I also try this KB and it still not work.

    https://support.symantec.com/en_US/article.TECH245964.html



  • 7.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 22, 2019 02:37 AM
    Dear Hongton, Yes it is related to ssl error please disable ssl interception for all the bluecoat url on firewall. Also share pcap with me.


  • 8.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 22, 2019 03:01 AM

    Hi

     

    Our firewall is not enable ssl interception and here's full stream of a connection that connect to subscription.es.bluecoat.com



  • 9.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 22, 2019 04:07 AM
    Dear Hongton, Share full pcap


  • 10.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 22, 2019 04:16 AM
      |   view attached

    Hi

     

    Here's in attached file.

    Attachment(s)

    zip
    CAS peer not authen.zip   6 KB 1 version


  • 11.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 22, 2019 06:57 AM

    Dear Hongthon,

     

    Can you check from F5 team if they are doing any SSL Interception on it.

     

    I can see encrypted alert from F5.



  • 12.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 22, 2019 07:03 AM

    Hi

     

    I also take care of F5 and no SSL intercept on it. Just forwarding traffic and do loadbalancing.



  • 13.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 22, 2019 07:55 AM
    Dear Hongton, Try to restart anto virus service from cas and try to download pattern and share the pcap. Also update the ASG default certificate . https://www.symantec.com/docs/TECH244738


  • 14.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 25, 2019 10:50 PM

    Dear Honghton,

     

    Refr this KB article too:

     

    https://support.symantec.com/en_US/article.TECH251011.html



  • 15.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 26, 2019 03:55 AM
      |   view attached

    Hi

     

    I have try these

    - CAS > Utilities > Services > Refresh Antivirus Engines and Signatures

    - CAS > Services > AV Patterns > Force Update All Now

    - Proxy > Configuration > SSL > Appliance Certificates > Request appliance certificate

    #Ref. https://support.symantec.com/en_US/article.TECH244738.html

    Error still show that "Error peer not authenticated" and firewall does not enable SSL interception feature

     

    I have attached pcap while I force update antivirus

    Attachment(s)

    zip
    CAS peer not authen 2.zip   46.66 MB 1 version


  • 16.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 26, 2019 07:41 AM
    Dear Hongton, Still i can see fin packet from F5.Have you check real time logs on firewall for that ip. Sometimes i observed application base rule on firewall also cause the issue. This time i see certificate from different asg S/N.


  • 17.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 26, 2019 10:51 PM

    Hi

     

    I have 2 ASG (one in production env. and one in test env.) which have the same problem. In the pcap file, the one who sent Encrypted Alert is destination ip 46.235.158.204 which you mention that it may be some device next to proxy to the internet cause this problem. So next I'll try pcap packet from the device behind the ISP router and I'll share pcap to you again.

     

    In the meantime, could you please tell me what impact cause from this error? 



  • 18.  RE: Error peer not authenticated in Content Analysis

    Posted Mar 27, 2019 12:09 AM

    Dear Hongthon,

     

    No impact on CAS just make sure to disable ssl intercept to resolve that error.

     

     



  • 19.  RE: Error peer not authenticated in Content Analysis

    Posted Sep 05, 2019 08:08 AM

    What is the solution for this issue, I am also having same "error peer not authenticated"  while updating Symantec Content Analysis Antivirus.

    It is not updating.



  • 20.  RE: Error peer not authenticated in Content Analysis
    Best Answer

    Posted Sep 10, 2019 11:25 PM

    I have reset proxy to the factory default and re-config again. This problem resolved after that.



  • 21.  RE: Error peer not authenticated in Content Analysis

    Posted Apr 29, 2020 01:44 PM
    Hi,

    We had same kind of issue and it was fixed by this article:
    https://knowledge.broadcom.com/external/article?legacyId=TECH245964

    Actually this command was enough to update the certificate:

    CAS# request-appliance-certificate
      ok

    After that, able to activate AV engine and download pattern.