sk181026 - DLPU process stops working, creating a User Space core dump file on the Security Gateway
DLPU process stops working, creating a User Space core dump file on the Security Gateway
Product
Data Loss Prevention
Version
R80.40 (EOS), R81.10 (EOS)
OS
Gaia
Last Modified
2024-02-01
Symptoms
- The DLPU process intermittently stops working.
- The
/var/log/dump/usermodedirectory on the DLP Security Gateway contains a core dump file for the DLPU process. - The "
ps aux | grep dlpu" command shows that the DLPU process consumes memory over time. - When you run the Memory Monitor tool based on the instructions in sk163613, the tool shows that the DLPU process' memory consumption increases.
Cause
There is an issue with memory allocation when the SMB Protocol is enabled in the Threat Prevention profile (in Profiles > Anti-Virus > Protocol).
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 26
- Jumbo Hotfix Accumulator for R81.10 starting from Take 110
- Jumbo Hotfix Accumulator for R81 starting from Take 89
- Jumbo Hotfix Accumulator for R80.40 starting from Take 198
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
The hotfix makes the timeout of dlpu_mngr configurable in minutes based on the "dlp_config" section of $FWDIR/conf/malware_config.
Note: This section does not exist by default
From $FWDIR/conf/malware_config please change "dlpu_mngr_connection_timeout_minutes" to 10 Minutes
dlp_config
dlpu_mngr_connection_timeout_minutes=10
Please note: For VSX environment, the configuration of the $FWDIR/conf/malware_config file is VS dependent (Reference:- sk92224)
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
- Access Level: General
- Status: Approved by TAC
- Date Created: 2023-06-04
- Last Modified: 2024-02-01