sk181643 - IKED process consumes high CPU and causes VPN outages every hour
IKED process consumes high CPU and causes VPN outages every hour
Product: IPSec VPN, Remote Access VPN, Site-to-Site VPN
Version: R81.20
OS: Gaia
Last Modified: 2025-03-11
Symptoms
The gateway has R81.20 Jumbo Hotfix Accumulator Take 14 or higher installed.
All IKED processes are exit/crash approximately once an hour without creating core dumps or messages.
IKED log files show the following prints:
vDbGbgCol: failed to remove entry from delete database -database file: /opt/CPsuite-R81.20/fw1/database/deldb may be corrupted vDbGbgCol: failed to remove entry from cookie database -database file: /opt/CPsuite-R81.20/fw1/database/cookiedb may be corrupted
Cause
Degradation introduced by R81.20 Jumbo Hotfix Accumulator Take 14 in which all the processes are trying to edit a database file at the same time.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 43
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
Additionally, the following procedure must be performed on the gateway after installation of the fix:
Open the Security Gateway / Cluster object properties > IPSec VPN > VPN Advanced
Under "Restart Options".
Make sure that the checkbox " Perform an organized shutdown of tunnels upon gateway restart" is unchecked.
Click OK and install the policy
After the policy was installed, run these commands (on all cluster members):
mv $FWDIR/database/cookiedb.NDB $FWDIR/database/cookiedb.NDB.backup mv $FWDIR/database/deldb.NDB $FWDIR/database/deldb.NDB.backup
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2023-11-15
Last Modified: 2025-03-11