sk182272 - Policy installation on a Security Gateway running with UPPAK fails with error code 2000240 or 2000267
Policy installation on a Security Gateway running with UPPAK fails with error code 2000240 or 2000267
Product: SecureXL, Security Gateways
Version: R81.20
OS: Gaia
Last Modified: 2024-07-01
Symptoms
Policy installation on a Security Gateway running User Space SecureXL (UPPAK) fails with error code
2000240or2000267.The /var/log/usim_x86.elg contains these messages :
[UPPAK]:m_get: allocation failure [UPPAK]:fwk_snd_alloc_mbuf_for_fw: failed to alloc mbuf for fw, vsid: x, instance: y [UPPAK]:fwk_snd_msg_queue_dequeue_msg: failed to alloc mbuf for fw, vsid: x, instance: yThe output of the
fwaccel statcommand is printed after a long time.The $FWDIR/log/fwk.elg contains this message:
fwmultik_process_entry: no corresponding ipv6 instance for opcode 2, instance 0A traffic outage might occur.
IPv6 traffic arrives at the Security Gateway while IPv6 is disabled.
Cause
A memory leak occurred in UPPAK.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 70.
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.