Instruments not populating DHCP, CrowdStrike Firewall - WKB302033
SYMPTOMS
- Instruments are not populating in the Waters DHCP Server
- Network Interface Card & PC configured correctly
- Software installed correctly (confirmed via verification tool)
ENVIRONMENT
- Windows 10
- P520
- MassLynx
CAUSE
Firewall blocking communications (e.g. (abbreviated) "Deny, Inbound, UDP (17) ...\Waters Instruments\WDHCPServerSvc.exe"). In some instances this can occur even when the firewall is configured correctly due to the way threat analysis is configured.
FIX or WORKAROUND
- Remove CrowdStrike to confirm cause; once removed communications should be restored (a reboot may be required).
- Liaise with customer IT to properly configure Firewall and InfoSec Policy in order to avoid communication issues.
ADDITIONAL INFORMATION
CrowdStrike maintains a local Firewall log when installed on a system. The default location can be found within the Windows filesystem (C:\Windows\System32\drivers\CrowdStrike\hbfw.log). The log is constantly updating and once reaching a specific size will create a new file of the same name and rename the previous log as hbfw.log.1, then hbfw.log.2 etc. This can be opened via Notepad but performance will be low due to the size of the file, Notepad++ or other similar programs would be more appropriate. Formatting of the file is not ergonomic however the easiest way to check is to search for keywords e.g. 'deny' or 'waters'
