sk181354 - Security Gateway deletes the PIM OIF after it sends "Prune-Echo" and enters MRT

Security Gateway deletes the PIM OIF after it sends "Prune-Echo" and enters MRT

Product: Security Gateways
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2025-01-20

Symptoms

Example lines from the /var/log/routed.log file:

task_timer_dispatch: calling PIM_PIM_SM_MRT_MAINTENANCE, late by 0:00.000
<DATE TIME> mfc_del_oif: deleting oif <Interface> > from (<GROUP IP>, <SOURCE IP>)/64
<DATE TIME>     mfc_krt: parent IF <Interface>
<DATE TIME>     mfc_krt: nexthop IF <Interface>

Cause

Incorrect state transition when the Prune Pending Timer expires.

The (S,G) entry on SPT or the (*,G) entry should transition to the "NoInfo" state while the (S,G) entry on RPT should transition to the "Prune" state.

The logic before was that the (S,G) entry on SPT would transition to the "Prune" state, which led to other incorrect state transitions when receiving a "Join".

Example scenario when the issue can occur:

  1. There are multiple downstream PIM neighbors on the same LAN.
  2. PIM neighbor #1 sends a PIM Prune packet to the Security Gateway.
  3. The Security Gateway starts a Prune-Pending Timer on the interface, on which it received this PIM Prune packet.
  4. PIM neighbor #2 sends a PIM-Join packet to the Security Gateway before the Prune-Pending Timer expires.
  5. When the Security Gateway goes to MRT, a timeout function executes.
  6. As a result, the Security Gateway deletes the OIF even though the Security Gateway received a "Join" packet to keep the traffic flowing on that interface.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2023-08-08
Last Modified: 2025-01-20