Skip to main content
Waters

Instruments not populating in DHCP; CrowdStrike firewall in place - WKB302033

Article number: 302033

SYMPTOMS

  • Instruments are not populating in the Waters DHCP Server
  • Network interface card and PC are configured correctly
  • Software installed correctly (confirmed via verification tool)

ENVIRONMENT

  • Windows 10
  • P520
  • MassLynx

CAUSE

Firewall is blocking communications (e.g., (abbreviated) "Deny, Inbound, UDP (17) ...\Waters Instruments\WDHCPServerSvc.exe"). In some instances this can occur even when the firewall is configured correctly, due to the way threat analysis is configured.

FIX or WORKAROUND

  1. Remove CrowdStrike to confirm as cause; once removed, communications should be restored (a reboot may be required).
  2. Consult with customer IT to properly configure Firewall and InfoSec Policy in order to avoid communication issues.

ADDITIONAL INFORMATION

CrowdStrike maintains a local Firewall log when installed on a system. The default location can be found within the Windows file system (C:\Windows\System32\drivers\CrowdStrike\hbfw.log). The log is constantly updating and, when reaching a specific size, will create a new file of the same name and rename the previous log as hbfw.log.1, then hbfw.log.2, and so on. This can be opened via Notepad, but performance will be low due to the size of the file, Notepad++ or similar programs would be more appropriate. Formatting of the file is not ergonomic, but the easiest way to check is to search for keywords such as "deny" or "waters".

Not able to find a solution? Click here to request help.