sk182220 - Intermittent Unresponsiveness of Identity Awareness (PDP)
Intermittent Unresponsiveness of Identity Awareness (PDP)
Product: Identity Awareness
Version: R81.20
Last Modified: 2024-10-06
Symptoms
The Policy Decision Point (PDP) intermittently becomes unresponsive. The issue can be resolved by restarting the process.
The PDP debug logs display the following events:
T_event_do_del: The socket of type 62 is marked for deletion.T_get_event: Unable to register socket 62 (1024 sockets already registered for in).T_event_do_del: No event found for socket/type: 62/0.
Netstat shows around 1000 or more connections to PDP over port 5908.
Cause
In R81.20, we incorporated multithreading, which introduced a new behavior wherein each thread executes its independent mainloop. Prior to this enhancement, the pdpd daemon functioned within a singular mainloop with no concurrency.
Previously, earlier iterations used epoll as the event handler for the mainloop, as outlined in its API documentation, see epoll(7).
Note - Epoll imposes no constraints on the quantity of file descriptors it can monitor for events.
In R81.20, the mainloop for each thread utilized an API called select as the default event handler, as described in the epoll documentation.
It's important to note that the Select API imposes a limitation on the maximum number of file descriptors it can monitor for events, set at 1024.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 89
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-05-02
Last Modified: 2024-10-06