IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: Bad Rule Causing Mass Blocks / Systems to not start

App Control: Bad Rule Causing Mass Blocks / Systems to not start

Environment

  • App Control: All Supported Versions
  • Microsoft SQL Server: All Supported Versions

Symptoms

  • Systems unable to start due to a rule blocking action
  • End-users seeing mass blocks
  • Previously approved software is now blocked

Cause

A bad or unsatisfactory block rule was created or modified

Resolution

If the App Control Server/Database is down:
  1. Boot server(s) into safe mode
  2. Go to Start > Run > services.msc
  3. Set App Control agent service to disabled
  4. Start Windows normally
  5. Open an admin CMD promt
  6. Run command:
    fltmc unload paritydriver
  7. Remove the offending rule in the next section, then pick up again on step 8 of "correcting agents" section

Removing the offending rule:
  1. Login to the App Control console
  2. Determine which rule is causing the block:
  3. Disable the offending rule.
  4. Navigate to Assets > Computers
  5. Confirm agents match "Current CL Version" for the server

Options to correct agents that are unable to boot or receive configlist updates:
  1. Uninstall/Reinstall the agent
  2. Update the CL of Effected Machines:
    1. Boot effected machines(s) into safe mode
    2. Go to Start > Run > services.msc
    3. Set CB Protection agent service to disabled
    4. Start Windows normally 
    5. Open an admin CMD promt
    6. Run command:
      fltmc unload paritydriver
    7. Go to Start > Run > services.msc 
    8. Set App Control agent service to automatic startup 
    9. Start App Control agent service 
    10. In command prompt, run commands:
      cd c:\program files (x86)\bit9\parity agent 
      dascli status 
      Under "Server Information", wait for confliglist line to say <CLINumber> of <CLINumber> 100% (or higher than value found in "Removing the Rule" ) 
      
    11. Restart Device
    12. Confirm device is checking back into CB Console

Additional Notes

  • Uninstalling/reinstalling agents will cause them to go through initialization. Please refer to user guide

Related Content


Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎09-09-2020
Views:
1061