sk180705 - Traffic stops working after a Security Gateway Member recovers from a failure
Traffic stops working after a Security Gateway Member recovers from a failure
Solution ID: sk180705
Technical Level: Basic
Product: Scalable Chassis
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS)
Last Modified: 2023-08-14
Symptoms
- Traffic stops working when a Security Gateway Member (SGM) recovers from a failure.
Notes:
The traffic keeps working after the SGM fails.
User Space Firewall is configured.
The
fw ctl zdebug + dropcommand shows this drop:
dropped by fwmultik_process_f2p_cookie_inner Reason: connection not found (F2P);
- Example scenario:
- SGM 1_02 handles the traffic.
- FWK crashes on SGM 1_02, and the traffic is distributed to SGM 1_03.
- SGM 1_03 handles the distributed traffic successfully.
- SGM 1_02 recovers from the failure and goes back to an ACTIVE state.
- The traffic is distributed back to SGM 1_02 and then stops flowing.
- Running 'fw ctl zdebug + drop' on SGM 1_02 shows this drop:
dropped by fwmultik_process_f2p_cookie_inner Reason: connection not found (F2P); ```
Cause
The connection was not removed from the SecureXL connection table when the User Space Firewall experienced a failure, such as when FWK process stops working.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 26
- Jumbo Hotfix Accumulator for R81.10 starting from Take 110
- Jumbo Hotfix Accumulator for R81 starting from Take 87
- Jumbo Hotfix Accumulator for R80.40 starting from Take 198
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2023-03-13
Last Modified: 2023-08-14