sk182476 - Security Group Member in a VSX environment is in a boot loop after creating a new Virtual System with a WRP interface or after upgrading jumbo hotfix accumulator

Security Group Member in a VSX environment is in a boot loop after creating a new Virtual System with a WRP interface or after upgrading jumbo hotfix accumulator

Product: Maestro HyperScale Firewall, Scalable Chassis
Version: R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2024-11-20

Symptoms

    Reason:Reboot from unknown reason occurred! Type:unknown
    ```

- The `/var/log/start_bfm.log.dbg` file contains this log:
    Interface wrpjX should have warp vmac, setting mac address to XX:YYYY
    wrpjX mac changed, set reboot needed to 1
    wrp mac changed, reboot
```

Cause

When the "Same VMAC" feature is enabled or disabled, a new kernel parameter is added to the fwkern.conf file: fwha_ch_same_vmac_enabled_os. For more information, see sk165674.

When you add a new VS that is connected to a Virtual Switch (VSW), a WRP interface is created and assigned a MAC address. Because of a possible race condition, a reboot function is called that causes the SGM to get stuck in a boot loop.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, the following workaround is available.

Note: value of the fwha_ch_same_vmac_enabled_os parameter in the fwkern.conf has to be 0 otherwise it will turn off VMAC feature.

  1. Remove fwha_ch_same_vmac_enabled_os=0 entry from fwkern.conf file on all Security Group Members
  2. To enforce change, Security Group Members requires a reboot

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.