sk182076 - "asg perf" command does not show output when MDPS is enabled on Scalable Platforms
"asg perf" command does not show output when MDPS is enabled on Scalable Platforms
Product: Maestro HyperScale Firewall
Version: R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2025-01-16
Symptoms
- The "
asg perf" command on a Security Group does not show any output - the Gaia OS prompt appears immediately after entering the command and pressing the Enter key. - When running the "
mac_verifier" and other commands on a Security Group, the output may show the error message "mount of /sys failed: device or resource busy". - The "
distutil verify -v" command on a Security Group returns "verification failed". - The "
g_allc "mount -l | grep sysfs"" command on a Security Group shows multiple mounts of "sysfs". - These issues started after enabling the MDPS feature ( sk138672).
Cause
A mounting issue of the filesystem sysfs may occur when enabling the MDPS feature.
Solution
This problem was fixed. The fix is included starting from:
- Check Point Quantum R82
- Jumbo Hotfix Accumulator for R81.20 starting from Take 41
- Jumbo Hotfix Accumulator for R81.10 starting from Take 131
- Jumbo Hotfix Accumulator for R81 starting from Take 99
- Jumbo Hotfix Accumulator for R80.40 starting from Take 211
Important Note - After installing this Jumbo Hotfix, when MDPS plane separation is enabled, in the context of the Management plane, the directory /sys/class/net/ now shows interfaces that belong to the Data plane, although it should show interfaces that belong to the Management plane.
If you choose not to upgrade, this workaround is available:
Important - Schedule a maintenance window.
- Connect to the command line on the Security Group.
- If your default shell is Gaia gClish, go to the Expert mode:
expert
- Back up this file on all Security Group Members:
g_all cp -v /etc/profile.d/mdpsenv.sh{,_BKP}
- Edit this file:
vi /etc/profile.d/mdpsenv.sh
Remove these lines:
/usr/bin/mount sysfs 1>/dev/null 2>&1/usr/bin/umount sysfs 1>/dev/null 2>&1
Save the changes in the file and exit Vi editor.
Copy the modified file to all Security Group Members:
asg_cp2blades /etc/profile.d/mdpsenv.sh
- Reboot all Security Group Members:
reboot -b all
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-03-04
Last Modified: 2025-01-16