sk184340 - Security Gateway working in SecureXL User Mode (UPPAK) crashes because of SND core flapping and USIM_x86 segmentation faults
Security Gateway working in SecureXL User Mode (UPPAK) crashes because of SND core flapping and USIM_x86 segmentation faults
Symptoms
- When working in SecureXL User Mode (UPPAK), Security Gateway crashes with kernel logs showing segmentation faults in the USIM_x86 process.
- The $FWDIR/log/dsd.elg logs show SND core flapping in dynamic balancing concurrent with the segmentation faults:
update_interfaces_uppak: added 2 SNDs for UPPAK
update_interfaces_uppak: removed 2 SNDs for UPPAK
recover_record_runtime_state: Recording runtime state
FWs filtered average: 60.3 | SNDs filtered average: 0.0
```
- The _/var/log/usim_x86.elg_ log shows:
[UPPAK];host_if_msg_ds_update: sent sleep trigger to SND thread on cpu 4, rc = 1
[SIM4];packet_thread: cpu 5 qid 4 going to sleep ...
[UPPAK];host_if_msg_ds_update: sent sleep trigger to SND thread on cpu 5, rc = 1
[SIM4];EAL: Core MIA. Last seen 11999ms ago.
[UPPAK];Worker on CPU 4 is inactive, excusing it from wd trigger
[SIM4];EAL: Core died. Last seen 23999ms ago.
[UPPAK];Threads got STUCK
```
Cause
SND (Secure Network Distributor) core flapping causes segmentation faults in the USIM_x86 process.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 60
- Jumbo Hotfix Accumulator for R81.20 starting from Take 120
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.