# DLPU process stops working, creating a User Space core dump file on the Security Gateway

## Product
Data Loss Prevention

## Version
R80.40 (EOS), R81.10 (EOS)

## OS
Gaia

## Last Modified
2024-02-01

## Symptoms
- The DLPU process intermittently stops working.
- The `/var/log/dump/usermode` directory on the DLP Security Gateway contains a core dump file for the DLPU process.
- The "`ps aux | grep dlpu`" command shows that the DLPU process consumes memory over time.
- When you run the Memory Monitor tool based on the instructions in [sk163613](https://support.checkpoint.com/results/sk/sk163613), the tool shows that the DLPU process' memory consumption increases.

## Cause
There is an issue with memory allocation when the SMB Protocol is enabled in the Threat Prevention profile (in **Profiles** > **Anti-Virus** > **Protocol**).

## Solution
This problem was fixed. The fix is included in:
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 26  
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 110  
- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 89  
- [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 198

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

### Hotfix installation instructions:
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

The hotfix makes the timeout of dlpu_mngr configurable in minutes based on the "dlp_config" section of $FWDIR/conf/malware_config.

Note: This section does not exist by default

From $FWDIR/conf/malware_config please change "dlpu_mngr_connection_timeout_minutes" to 10 Minutes

```plaintext
dlp_config

dlpu_mngr_connection_timeout_minutes=10
```

Please note: For VSX environment, the configuration of the $FWDIR/conf/malware_config file is VS dependent (Reference:- [sk92224](https://support.checkpoint.com/results/sk/sk92224))

#### NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties
- **Access Level**: General
- **Status**: Approved by TAC
- **Date Created**: 2023-06-04
- **Last Modified**: 2024-02-01
