sk180705 - Traffic stops working after a Security Gateway Member recovers from a failure

Traffic stops working after a Security Gateway Member recovers from a failure

Solution ID: sk180705
Technical Level: Basic
Product: Scalable Chassis
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS)
Last Modified: 2023-08-14

Symptoms

Notes:

  dropped by fwmultik_process_f2p_cookie_inner Reason: connection not found (F2P);
  1. SGM 1_02 handles the traffic.
  2. FWK crashes on SGM 1_02, and the traffic is distributed to SGM 1_03.
  3. SGM 1_03 handles the distributed traffic successfully.
  4. SGM 1_02 recovers from the failure and goes back to an ACTIVE state.
  5. The traffic is distributed back to SGM 1_02 and then stops flowing.
  6. Running 'fw ctl zdebug + drop' on SGM 1_02 shows this drop:
     dropped by fwmultik_process_f2p_cookie_inner Reason: connection not found (F2P);
     ```

Cause

The connection was not removed from the SecureXL connection table when the User Space Firewall experienced a failure, such as when FWK process stops working.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2023-03-13
Last Modified: 2023-08-14