Tenable 스캐닝 소프트웨어가 포트 9083을 스캔하면 mTLS가 활성화된 PowerPath Remote Management 프로세스가 실패하여 결국 최대 소켓 연결에 도달하고 피어에 의한 연결 재설정 메시지가 기록됩니다.
PPMA GUI에서 연결 해제 상태는 다음 폴링 주기까지 표시되지 않습니다. 폴링 주기가 실행되면 서버는 결국 GUI(빨간색)에서 연결 해제된 것으로 표시됩니다.
## Windows 원격 관리 응용 프로그램 이벤트 로그
07/23/2023 07:05:23 PM Warning HOSTNAME 3 EmcPowerPathManagementComponent EMC PowerPath Warning: Management Component: Warning: Max socket connection limit reached, incoming connection dropped. Remote host: ip=10.x.x.x, hostname=PPMAHOST.DOMAIN.COM. 07/23/2023 07:05:23 PM Information HOSTNAME 2 EmcPowerPathManagementComponent EMC PowerPath Information: Management Component: Info: SSPI decryption failed. InitSSLServerSchannel(): Failed to query the client. 07/23/2023 07:05:19 PM Warning HOSTNAME 3 EmcPowerPathManagementComponent EMC PowerPath Warning: Management Component: Warning: Max socket connection limit reached, incoming connection dropped. Remote host: ip=10.x.x.x, hostname=PPMAHOST.DOMAIN.COM. 07/23/2023 07:05:19 PM Error HOSTNAME 4 EmcPowerPathManagementComponent EMC PowerPath Error: Management Component: Error: Socket library: send - Connection reset by peer. (err=10054). 07/23/2023 07:05:18 PM Warning HOSTNAME 3 EmcPowerPathManagementComponent EMC PowerPath Warning: Management Component: Warning: Max socket connection limit reached, incoming connection dropped. Remote host: ip=10.x.x.x, hostname=PPMAHOST.DOMAIN.COM. 07/23/2023 07:05:18 PM Error HOSTNAME 4 EmcPowerPathManagementComponent EMC PowerPath Error: Management Component: Error: Socket library: send - Connection reset by peer. (err=10054)
## PPMA DataCollector 로그
ERROR 19:16:08.320 [AnonymousIoService-6] c.e.p.d.hosts.impl.HostAgentListener - Internal error occurred in the connection to HOSTNAME.DOMAIN.COM:9083 WARN 19:16:08.321 [AnonymousIoService-6] c.e.p.d.h.impl.HostAgentConnector - java.lang.Exception: Invalid Header Tag ??U? (Hexdump: 15 03 03 00 1A 00 00 00 00 00 00 00 01 99 FB 16 55 98 19 50 B2 E1 87 35 F2 0D 26 E6 F4 A1 6D) org.apache.mina.filter.codec.ProtocolDecoderException: java.lang.Exception: Invalid Header Tag ??U? (Hexdump: 15 03 03 00 1A 00 00 00 00 00 00 00 01 99 FB 16 55 98 19 50 B2 E1 87 35 F2 0D 26 E6 F4 A1 6D) at org.apache.mina.filter.codec.ProtocolCodecFilter.messageReceived(ProtocolCodecFilter.java:165) at org.apache.mina.common.support.AbstractIoFilterChain.callNextMessageReceived(AbstractIoFilterChain.java:299) at org.apache.mina.common.support.AbstractIoFilterChain.access$1100(AbstractIoFilterChain.java:53) at org.apache.mina.common.support.AbstractIoFilterChain$EntryImpl$1.messageReceived(AbstractIoFilterChain.java:648) at org.apache.mina.filter.support.SSLHandler.flushScheduledEvents(SSLHandler.java:275) at org.apache.mina.filter.SSLFilter.messageReceived(SSLFilter.java:427) at org.apache.mina.common.support.AbstractIoFilterChain.callNextMessageReceived(AbstractIoFilterChain.java:299) at org.apache.mina.common.support.AbstractIoFilterChain.access$1100(AbstractIoFilterChain.java:53) at org.apache.mina.common.support.AbstractIoFilterChain$EntryImpl$1.messageReceived(AbstractIoFilterChain.java:648) at org.apache.mina.filter.executor.ExecutorFilter.processEvent(ExecutorFilter.java:220) at org.apache.mina.filter.executor.ExecutorFilter$ProcessEventsRunnable.run(ExecutorFilter.java:264) at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149) at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624) at org.apache.mina.util.NamePreservingRunnable.run(NamePreservingRunnable.java:51) at java.lang.Thread.run(Thread.java:750) Caused by: java.lang.Exception: Invalid Header Tag ??U? at com.emc.powerpath.datacollector.remote.nio.mina.client.codec.AgentResponseDecoder.getExpectedBytes(AgentResponseDecoder.java:64) at com.emc.powerpath.datacollector.remote.nio.mina.client.codec.AgentResponseDecoder.doDecode(AgentResponseDecoder.java:117) at org.apache.mina.filter.codec.CumulativeProtocolDecoder.decode(CumulativeProtocolDecoder.java:133) at org.apache.mina.filter.codec.ProtocolCodecFilter.messageReceived(ProtocolCodecFilter.java:158) ... 14 common frames omitted WARN 19:16:08.325 [AnonymousIoService-14] c.e.p.d.h.impl.HostAgentConnector - Connection reset by peer java.io.IOException: Connection reset by peer at sun.nio.ch.FileDispatcherImpl.read0(Native Method) at sun.nio.ch.SocketDispatcher.read(SocketDispatcher.java:39) at sun.nio.ch.IOUtil.readIntoNativeBuffer(IOUtil.java:223) at sun.nio.ch.IOUtil.read(IOUtil.java:197) at sun.nio.ch.SocketChannelImpl.read(SocketChannelImpl.java:378) at org.apache.mina.transport.socket.nio.SocketIoProcessor.read(SocketIoProcessor.java:218) at org.apache.mina.transport.socket.nio.SocketIoProcessor.process(SocketIoProcessor.java:198) at org.apache.mina.transport.socket.nio.SocketIoProcessor.access$400(SocketIoProcessor.java:45) at org.apache.mina.transport.socket.nio.SocketIoProcessor$Worker.run(SocketIoProcessor.java:485) at org.apache.mina.util.NamePreservingRunnable.run(NamePreservingRunnable.java:51) at java.lang.Thread.run(Thread.java:750) WARN 19:16:08.325 [AnonymousIoService-14] c.e.p.d.h.impl.HostAgentConnector - Broken pipe java.io.IOException: Broken pipe at sun.nio.ch.FileDispatcherImpl.write0(Native Method) at sun.nio.ch.SocketDispatcher.write(SocketDispatcher.java:47) at sun.nio.ch.IOUtil.writeFromNativeBuffer(IOUtil.java:93) at sun.nio.ch.IOUtil.write(IOUtil.java:65) at sun.nio.ch.SocketChannelImpl.write(SocketChannelImpl.java:469) at org.apache.mina.transport.socket.nio.SocketIoProcessor.doFlush(SocketIoProcessor.java:414) at org.apache.mina.transport.socket.nio.SocketIoProcessor.doFlush(SocketIoProcessor.java:332) at org.apache.mina.transport.socket.nio.SocketIoProcessor.access$500(SocketIoProcessor.java:45) at org.apache.mina.transport.socket.nio.SocketIoProcessor$Worker.run(SocketIoProcessor.java:488) at org.apache.mina.util.NamePreservingRunnable.run(NamePreservingRunnable.java:51) at java.lang.Thread.run(Thread.java:750) ERROR 19:16:08.325 [AnonymousIoService-14] c.e.p.d.hosts.impl.HostAgentListener - Connection to HOSTNAME.DOMAIN.COM:9083 has been lost
이는 mTLS가 활성화된 Windows 7.2.X용 PowerPath 원격 관리가 비 PPMA 서버에서의 Winsock 연결을 올바르게 처리하지 못하는 문제입니다.
이 수정 사항은 Windows용 PowerPath의 향후 릴리스에 포함될 예정이지만 현재는 ETA가 없습니다.
해결 방법은 Windows 서비스에서 "EMC PowerPath Remote Management component" 서비스를 재시작하는 것입니다.