sk182453 - Default filter is loaded on virtual systems after reboot

Default filter is loaded on virtual systems after reboot

Product

VSX (Traditional)

Version

R81.20

OS

Gaia

Last Modified

2025-05-19

Symptoms

ID  | Type & Name             | Access Control Policy | Installed at    | Threat Prevention Policy | SIC Stat
  -----+-------------------------+-----------------------+-----------------+--------------------------+---------
     5 | S                       | defaultfilter         | --------------- |                          | Trust
     6 | S                       | defaultfilter         | --------------- |                          | Trust
[DATE TIME][fwk4];[vs_5];[dev_thread_0];[24402];fwk_dmd_init_shmem_if_needed: fwk_dmd_state is Initialized, shmem was already init
[DATE TIME][fw4_0];[vs_5];fw_dmd_policy_wait_while: timed-out waiting for dmd
[DATE TIME][fw4_0];[vs_5];fw_dmd_policy_wait_till_prepared: Preparing dmd policy failed (status 0) dmd_new_policy=0x7f5308616008
[DATE TIME][fw4_0];[vs_5];fwk_atomic_load_prepare: fw_dmd_policy_wait_till_prepared() failed.
[DATE TIME][fw4_0];[vs_5];pm_policy_cleanup_fw_opq: Freeing shared memory opaque 0x7f53086be008
[DATE TIME][fw4_0];[vs_5];[ERROR]: fwk_install_policy_app_load_prepare: fwk_atomic_load_prepare() failed, error: (-1)
[DATE TIME][fw4_0];[vs_5];[ERROR]: install_policy_mgr_k_load_prepare: load_prepare failed for app: (FW), app_id: (1), app_position: (2)
[DATE TIME][fw4_0];[vs_5];fwmultik_up_local_run_phase: install_policy_mgr_k_load_prepare() failed
[DATE TIME][fw4_0];[vs_5];fwdrv_ioctl_wrapper_do: time violation for cmd 157 [flags 0, instance 0, cmd c0046a9d] - time 11
cp_yshmem_consume: caller pm_job_policy.c:277: failed to open shared memory file: /cp0001f
cp_yshmem_consume: caller kiss_thin_nfa.c:1205: failed to open shared memory file: /cp00013
[DATE TIME: consume_tier1_from_shmem          | !!!] Failed consuming bnfa_start(0x180000135c)
[DATE TIME: consume_tier1_from_shmem_dmd      | !!!] consume_tier1_from_shmem failed
[DATE TIME: pm_policy_prepare                 | !!!] Failed consuming and creating handler for part 0 in context 129
[DATE TIME: wt_policy_prepare                 | !!!] VS 5, type IPv4 policy preparation for module Pattern Matcher engine failed
[DATE TIME: dmd_wt_policy_rollback_internal   | ---] Worker -2 rollbacking policy for VS 5
[DATE TIME: wt_policy_rollback                | !!!] VS ID (5), type (IPv4) policy wasn't prepared
[DATE TIME: dmd_wt_policy_rollback_internal   | ---] Worker -2 rollbacking policy for VS 5
[DATE TIME: wt_policy_rollback                | !!!] VS ID (5), type (IPv4) policy wasn't prepared

Cause

Hyperflow takes too long to initialize during boot, causing a timeout. As a result, the memory for Hyperflow policy preparation and installation is freed, and once Hyperflow initializes, it is unable to install policy as the memory for it was freed. This is causing a firewall policy installation failure, resulting in fetching default filter.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.