<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Weird 10Gb interface hangup in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/114516#M16019</link>
    <description>&lt;P&gt;Hi, it would be interesting to understand if you have checked DMESG after the issue occurs and can confirm if your seeing a VETO bit message just after the ixgbe interfaces being taken offline. I had an opportunity to look at something similar and was fortunate enough to also capture an "error level 5" message from the PCIE drivers also being captured (effectively stating they we're going to sleep). Subsequently, I found that either a reboot or reloading the ixgbe driver (this reloads all ixgbe interfaces so take care) brings it back into service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you ever find a resolution?&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Ju&lt;/P&gt;</description>
    <pubDate>Wed, 24 Mar 2021 19:35:08 GMT</pubDate>
    <dc:creator>bad_joojoo</dc:creator>
    <dc:date>2021-03-24T19:35:08Z</dc:date>
    <item>
      <title>Weird 10Gb interface hangup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/34846#M2822</link>
      <description>&lt;P&gt;This more of a "friday" post for fun. Although problem was real - in one of our 5900 clusters running R80.10 the standby member out of blue produced some obscure errors on one of the 10Gb bond trunks (eth1-04)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="line-numbers language-none"&gt;&lt;CODE&gt;Jun 27 19:29:19 2018 fwf2 kernel: ixgbe 0000:06:00.1: eth1-04: Detected Tx Unit Hang
Jun 27 19:29:19 2018 fwf2 kernel: Tx Queue &amp;lt;0&amp;gt;
Jun 27 19:29:19 2018 fwf2 kernel: TDH, TDT &amp;lt;37a&amp;gt;, &amp;lt;124&amp;gt;
Jun 27 19:29:19 2018 fwf2 kernel: next_to_use &amp;lt;124&amp;gt;
Jun 27 19:29:19 2018 fwf2 kernel: next_to_clean &amp;lt;37a&amp;gt;
Jun 27 19:29:19 2018 fwf2 kernel: ixgbe 0000:06:00.1: eth1-04: tx_buffer_info[next_to_clean]
Jun 27 19:29:19 2018 fwf2 kernel: time_stamp &amp;lt;2a1b97a3e&amp;gt;
Jun 27 19:29:19 2018 fwf2 kernel: jiffies &amp;lt;2a1b98956&amp;gt;
Jun 27 19:29:19 2018 fwf2 kernel: ixgbe 0000:06:00.1: eth1-04: tx hang 1 detected on queue 0, resetting adapter
Jun 27 19:29:19 2018 fwf2 kernel: ixgbe 0000:06:00.1: eth1-04: Reset adapter
Jun 27 19:29:19 2018 fwf2 kernel: ixgbe 0000:06:00.1: eth1-04: RXDCTL.ENABLE on Rx queue 0 not cleared within the polling period
Jun 27 19:29:19 2018 fwf2 kernel: bonding: bond0: link status down for idle interface eth1-04, disabling it in 200 ms.
Jun 27 19:29:19 2018 fwf2 kernel: ixgbe: eth1-04: ixgbe_setup_mrqc: configure Symmetric RSS
Jun 27 19:29:19 2018 fwf2 kernel: ixgbe: eth1-04: ixgbe_up_complete: Double vlan mode is not set
Jun 27 19:29:19 2018 fwf2 kernel: ixgbe 0000:06:00.1: eth1-04: detected SFP+: 6‍‍‍‍‍‍‍‍‍‍‍‍‍‍‍&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And then few seconds later all interfaces in the expansion slot started reporting continuously&lt;/P&gt;
&lt;PRE class="line-numbers language-none"&gt;&lt;CODE&gt;Jun 27 19:30:55 2018 fwf2 kernel: ixgbe 0000:05:00.0: eth1-01: -1 Spoofed packets detected
Jun 27 19:30:55 2018 fwf2 kernel: ixgbe 0000:06:00.1: eth1-04: -1 Spoofed packets detected
Jun 27 19:30:55 2018 fwf2 kernel: ixgbe 0000:06:00.0: eth1-03: -1 Spoofed packets detected
Jun 27 19:30:55 2018 fwf2 kernel: ixgbe 0000:05:00.1: eth1-02: -1 Spoofed packets detected‍‍‍‍‍‍‍‍&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It was resolved by node reboot. The only relevant SK I found was this&amp;nbsp;&lt;A class="link-titled" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102969" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk102969" target="_blank"&gt;Intermittent outages of TCP traffic on 10GbE interfaces in IP Appliances running Gaia OS&lt;/A&gt;&amp;nbsp;but it's not applicable to R80.10 nor 5900 and offload is definitely disabled on interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here's the best part - the display on the appliance at the time showed this&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66788_pastedImage_100.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this mean firewall needs to go to toilet?? P-p-p-peee....&amp;nbsp;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/cool.png" border="0" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 07:28:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/34846#M2822</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2021-04-14T07:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Weird 10Gb interface hangup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/34847#M2823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like the NIC hardware is what went into the toilet, the display was telling you that the "stream" of outbound packets was no longer getting handled by the NIC, and that the firewall's bladder was too full which can certainly be uncomfortable to say the least.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 15:44:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/34847#M2823</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-06-28T15:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Weird 10Gb interface hangup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/34848#M2824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess some things never change...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="66824" alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66824_check_symbols.gif" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I used a wrong ISO file that time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2018 19:37:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/34848#M2824</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-06-28T19:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Weird 10Gb interface hangup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/34849#M2825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/laugh.png" /&gt;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/laugh.png" /&gt;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/laugh.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jun 2018 07:43:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/34849#M2825</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-06-29T07:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Weird 10Gb interface hangup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/50164#M3735</link>
      <description>&lt;P&gt;Sorry to bring an old post back to live, but I'm having a similar error on a 10Gb interface on a 5900.&amp;nbsp; A reboot initially fixed the issue, but it came back, and again required a reboot (not to mention a disk check on each reboot).&lt;/P&gt;&lt;P&gt;Did you have any more problems with your 5900 after your reboot?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 15:01:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/50164#M3735</guid>
      <dc:creator>Mike_Jones</dc:creator>
      <dc:date>2019-04-08T15:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Weird 10Gb interface hangup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/50193#M3736</link>
      <description>&lt;P&gt;What code version is the firewall using?&amp;nbsp; Make sure you have the latest GA Jumbo HFA applied as updated NIC driver versions are sometimes bundled in Jumbo HFAs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 19:31:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/50193#M3736</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-04-08T19:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: Weird 10Gb interface hangup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/50216#M3739</link>
      <description>&lt;P&gt;Product version Check Point Gaia R80.10&lt;BR /&gt;OS build 479&lt;BR /&gt;OS kernel version 2.6.18-92cpx86_64&lt;BR /&gt;OS edition 64-bit&lt;/P&gt;&lt;P&gt;Using GA Jumbo HFA Take 169&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 21:40:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/50216#M3739</guid>
      <dc:creator>Mike_Jones</dc:creator>
      <dc:date>2019-04-08T21:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: Weird 10Gb interface hangup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/79870#M6130</link>
      <description>Well bringing back this old one again.&lt;BR /&gt;Last weekend we had a 5900 with a 10GB bond (2 interfaces), part of a VSX cluster, with exactly the same problem, a messages files completely filled with anti-spoofing messages. Older messages file was no longer available.&lt;BR /&gt;Code running R80.20 with jumbo 118</description>
      <pubDate>Thu, 26 Mar 2020 21:57:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/79870#M6130</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-26T21:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: Weird 10Gb interface hangup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/79960#M6138</link>
      <description>&lt;P&gt;Sorry I should have posted back with details on this.&amp;nbsp; This was a confirmed by CP to be a nic manufacturer hardware issue.&amp;nbsp; The 5900 was affected, and I think maybe a couple of other models?&amp;nbsp; However, it isn't always an issue on these models.&amp;nbsp; There are some checks you can do to see if you have the issue, but unfortunately, I moved out of the firewall world, and don't have access to check the details.&amp;nbsp; In short, contact CP support.&lt;/P&gt;&lt;P&gt;Found another detail from the past - affected 4 port cards, but not 2 port cards.&amp;nbsp; This went to R&amp;amp;D for investigation and they confirmed is was not software/driver related,but rather HW design.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 13:12:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/79960#M6138</guid>
      <dc:creator>Mike_Jones</dc:creator>
      <dc:date>2020-03-27T13:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: Weird 10Gb interface hangup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/79966#M6139</link>
      <description>Thanks Mike, we will check with TAC.</description>
      <pubDate>Fri, 27 Mar 2020 14:08:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/79966#M6139</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-27T14:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: Weird 10Gb interface hangup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/79972#M6140</link>
      <description>&lt;P&gt;Thanks for the followup, trying to distinguish NIC hardware problems from NIC driver problems can be pretty tough.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 14:13:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/79972#M6140</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-03-27T14:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: Weird 10Gb interface hangup</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/114516#M16019</link>
      <description>&lt;P&gt;Hi, it would be interesting to understand if you have checked DMESG after the issue occurs and can confirm if your seeing a VETO bit message just after the ixgbe interfaces being taken offline. I had an opportunity to look at something similar and was fortunate enough to also capture an "error level 5" message from the PCIE drivers also being captured (effectively stating they we're going to sleep). Subsequently, I found that either a reboot or reloading the ixgbe driver (this reloads all ixgbe interfaces so take care) brings it back into service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you ever find a resolution?&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Ju&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 19:35:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Weird-10Gb-interface-hangup/m-p/114516#M16019</guid>
      <dc:creator>bad_joojoo</dc:creator>
      <dc:date>2021-03-24T19:35:08Z</dc:date>
    </item>
  </channel>
</rss>

