Skip to content

Agents and Software VPN Solutions

If you plan to install PerformanceGuard agents on computers that connect to your network using a software VPN solution, be aware that PerformanceGuard and certain software VPN solutions can’t coexist without problems. The problems are:

  • Network connectivity is lost
  • Windows crashes (on older versions of Windows)

The problems are usually due to a non-conforming implementation of the NDIS interface in the VPN low-level driver.

Software VPN implementations that are known to cause problems

Section titled “Software VPN implementations that are known to cause problems”

These software VPN clients are known to cause problems when used together with the PerformanceGuard agent:

  • Check Point VPN-1 Secure Client (network interface name: cp_scvna Check Point Virtual Network Adapter)
  • VPN solutions based on Microsoft Whale driver (network interface name: Whale Network Connector)
  • Cisco VPN Client

The agent doesn’t capture traffic on network adapters in the List of Excluded Network Adapters setting of its agent configuration group. By default, the list contains:

  • Check Point VPN virtual adapters (adapter name containing cp_scvna)
  • Whale VPN Network Connector (adapter name containing Whale)
  • Microsoft’s SSL VPN Network Connector (adapter name containing SSL Network Tunneling)

On an excluded adapter, PerformanceGuard doesn’t make any measurements that rely on passive network data capture, such as TCP and UDP statistics and HTTP transaction filters. The agent error log then contains the message Adapter in exclude list. Cannot bind to ….

If another VPN adapter causes problems, add it to the list. Each entry has the form <"part of the adapter name"; "description">, and entries are separated by commas. You find the setting under Network Report in Agent Configuration Group Settings.

If you suspect that there’s a software VPN conflict

Section titled “If you suspect that there’s a software VPN conflict”

If you experience problems on a computer with a software VPN client running when you install the PerformanceGuard agent:

  • Verify that the problem only occurs when the PerformanceGuard agent and the VPN solution run at the same time.
  • Use the PerformanceGuard agent web interface to get the name of the network adapter: On the computer that has the agent installed, open a browser and connect to http://localhost:4007. In the agent information window that opens, select View > Adapters. Make sure that you do this with the VPN client connected to the VPN server.

The agent web interface’s network adapter list with IP address, speed, MAC address and name of each adapter

  • Check the PerformanceGuard agent error log (View > Errors), and pay special attention to information from the E2ETcp module.

The agent web interface’s error log filtered on the E2ETcp location

  • Collect the information from the two last steps and send it to CapaSystems support, together with details on the VPN solution.