<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CP5600 Memory Exhaustion in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/CP5600-Memory-Exhaustion/m-p/56391#M11362</link>
    <description>&lt;P&gt;We have a couple of CP5600 operating in different locations with very similar configurations.&amp;nbsp; The load is about the same.&amp;nbsp; Each is running r80.10 - T189.&lt;/P&gt;&lt;P&gt;Location B is stable and running without issues, but Location A we have to reboot about once every 45 days due to memory issues.&amp;nbsp; Whatever is happening, affects the dataplane. IE, Fw stops forwarding packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the memory output for location A:&lt;/P&gt;&lt;P&gt;System Capacity Summary:&lt;BR /&gt;Memory used: 77% (4455 MB out of 5731 MB) - below watermark&lt;BR /&gt;Concurrent Connections: 10410 (Unlimited)&lt;BR /&gt;Aggressive Aging is enabled, not active&lt;/P&gt;&lt;P&gt;Hash kernel memory (hmem) statistics:&lt;BR /&gt;Total memory allocated: 3737321472 bytes in 912432 (4096 bytes) blocks using 14 pools&lt;BR /&gt;Initial memory allocated: 599785472 bytes (&lt;FONT color="#FF0000"&gt;Hash memory extended by 3137536000 bytes&lt;/FONT&gt;) - &lt;FONT color="#0000FF"&gt;3.1GB&lt;/FONT&gt;?&lt;BR /&gt;Memory allocation limit: 4806672384 bytes using 512 pools&lt;BR /&gt;Total memory bytes used: 0 unused: 3737321472 (100.00%) peak: 3426386556&lt;BR /&gt;Total memory blocks used: 0 unused: 912432 (100%) peak: 861288&lt;BR /&gt;Allocations: 4163792559 alloc, 0 failed alloc, 4140371486 free&lt;/P&gt;&lt;P&gt;System kernel memory (smem) statistics:&lt;BR /&gt;Total memory bytes used: 4598247500 peak: 4608745920&lt;BR /&gt;Total memory bytes wasted: 3721660&lt;BR /&gt;Blocking memory bytes used: 4784944 peak: 9567848&lt;BR /&gt;Non-Blocking memory bytes used: 4593462556 peak: 4599178072&lt;BR /&gt;Allocations: 13741524 alloc, 0 failed alloc, 13738637 free, 0 failed free&lt;BR /&gt;vmalloc bytes used: 4588389496 expensive: no&lt;/P&gt;&lt;P&gt;Kernel memory (kmem) statistics:&lt;BR /&gt;Total memory bytes used: 4143730832 peak: 4231943656&lt;BR /&gt;Allocations: 4177522403 alloc, 0 failed alloc&lt;BR /&gt;4154099588 free, 0 failed free&lt;BR /&gt;External Allocations: 16896 for packets, 88628453 for SXL&lt;/P&gt;&lt;P&gt;Cookies:&lt;BR /&gt;3778625491 total, 0 alloc, 0 free,&lt;BR /&gt;150073 dup, 300575262 get, 2794359219 put,&lt;BR /&gt;2072999334 len, 2707089222 cached len, 0 chain alloc,&lt;BR /&gt;0 chain free&lt;/P&gt;&lt;P&gt;Connections:&lt;BR /&gt;388319874 total, 136725382 TCP, 231455561 UDP, 19560665 ICMP,&lt;BR /&gt;578266 other, 30721 anticipated, 195046 recovered, 10410 concurrent,&lt;BR /&gt;159214 peak concurrent&lt;/P&gt;&lt;P&gt;Fragments:&lt;BR /&gt;1118953332 fragments, 2706956154 packets, 3456 expired, 0 short,&lt;BR /&gt;0 large, 0 duplicates, 848 failures&lt;/P&gt;&lt;P&gt;NAT:&lt;BR /&gt;67013/0 forw, 52962/0 bckw, 982 tcpudp,&lt;BR /&gt;0 icmp, 5906-17579 alloc&lt;/P&gt;&lt;P&gt;Sync: off&lt;/P&gt;&lt;P&gt;[Expert@LocationA:0]# free -m&lt;BR /&gt;total used free shared buffers cached&lt;BR /&gt;Mem: 7744 7580 164 0 333 1837&lt;BR /&gt;-/+ buffers/cache: 5409 2334&lt;BR /&gt;Swap: 18394 0 18394&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is Location B:&lt;/P&gt;&lt;P&gt;System Capacity Summary:&lt;BR /&gt;Memory used: 9% (539 MB out of 5731 MB) - below watermark&lt;BR /&gt;Concurrent Connections: 8560 (Unlimited)&lt;BR /&gt;Aggressive Aging is enabled, not active&lt;/P&gt;&lt;P&gt;Hash kernel memory (hmem) statistics:&lt;BR /&gt;Total memory allocated: 599785472 bytes in 146432 (4096 bytes) blocks using 1 pool&lt;BR /&gt;Total memory bytes used: 0 unused: 599785472 (100.00%) peak: 27427 7488&lt;BR /&gt;Total memory blocks used: 0 unused: 146432 (100%) peak: 69627&lt;BR /&gt;Allocations: 1607331344 alloc, 0 failed alloc, 1607117916 free&lt;/P&gt;&lt;P&gt;System kernel memory (smem) statistics:&lt;BR /&gt;Total memory bytes used: 967638752 peak: 986044552&lt;BR /&gt;Total memory bytes wasted: 4180014&lt;BR /&gt;Blocking memory bytes used: 5820820 peak: 14955252&lt;BR /&gt;Non-Blocking memory bytes used: 961817932 peak: 971089300&lt;BR /&gt;Allocations: 151132250 alloc, 0 failed alloc, 151129180 free, 0 failed free&lt;BR /&gt;vmalloc bytes used: 956763424 expensive: no&lt;/P&gt;&lt;P&gt;Kernel memory (kmem) statistics:&lt;BR /&gt;Total memory bytes used: 401812380 peak: 640749756&lt;BR /&gt;Allocations: 1758439658 alloc, 0 failed alloc&lt;BR /&gt;1758224295 free, 0 failed free&lt;BR /&gt;External Allocations: 76032 for packets, 89765022 for SXL&lt;/P&gt;&lt;P&gt;Cookies:&lt;BR /&gt;1450833429 total, 836424 alloc, 836424 free,&lt;BR /&gt;251 dup, 433718314 get, 2695578081 put,&lt;BR /&gt;2263227759 len, 2298121504 cached len, 0 chain alloc,&lt;BR /&gt;0 chain free&lt;/P&gt;&lt;P&gt;Connections:&lt;BR /&gt;1628040697 total, 660800638 TCP, 927853823 UDP, 39386225 ICMP,&lt;BR /&gt;11 other, 288832 anticipated, 441738 recovered, 8560 concurrent,&lt;BR /&gt;161987 peak concurrent&lt;/P&gt;&lt;P&gt;Fragments:&lt;BR /&gt;302418965 fragments, 2297426537 packets, 2476610 expired, 0 short,&lt;BR /&gt;0 large, 0 duplicates, 1969 failures&lt;/P&gt;&lt;P&gt;NAT:&lt;BR /&gt;0/0 forw, 0/0 bckw, 0 tcpudp,&lt;BR /&gt;0 icmp, 0-27257 alloc&lt;/P&gt;&lt;P&gt;Sync: off&lt;/P&gt;&lt;P&gt;[Expert@locationB:0]# free -m&lt;BR /&gt;total used free shared buffers cached&lt;BR /&gt;Mem: 7744 7555 189 0 419 4896&lt;BR /&gt;-/+ buffers/cache: 2239 5504&lt;BR /&gt;Swap: 18394 0 18394&lt;/P&gt;&lt;P&gt;The only difference I can find between the two is that Location A is using Extended memory hash tables, but I don't know what would cause this behavior?&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jun 2019 14:16:50 GMT</pubDate>
    <dc:creator>Chris_Sanduliak</dc:creator>
    <dc:date>2019-06-21T14:16:50Z</dc:date>
    <item>
      <title>CP5600 Memory Exhaustion</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP5600-Memory-Exhaustion/m-p/56391#M11362</link>
      <description>&lt;P&gt;We have a couple of CP5600 operating in different locations with very similar configurations.&amp;nbsp; The load is about the same.&amp;nbsp; Each is running r80.10 - T189.&lt;/P&gt;&lt;P&gt;Location B is stable and running without issues, but Location A we have to reboot about once every 45 days due to memory issues.&amp;nbsp; Whatever is happening, affects the dataplane. IE, Fw stops forwarding packets.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the memory output for location A:&lt;/P&gt;&lt;P&gt;System Capacity Summary:&lt;BR /&gt;Memory used: 77% (4455 MB out of 5731 MB) - below watermark&lt;BR /&gt;Concurrent Connections: 10410 (Unlimited)&lt;BR /&gt;Aggressive Aging is enabled, not active&lt;/P&gt;&lt;P&gt;Hash kernel memory (hmem) statistics:&lt;BR /&gt;Total memory allocated: 3737321472 bytes in 912432 (4096 bytes) blocks using 14 pools&lt;BR /&gt;Initial memory allocated: 599785472 bytes (&lt;FONT color="#FF0000"&gt;Hash memory extended by 3137536000 bytes&lt;/FONT&gt;) - &lt;FONT color="#0000FF"&gt;3.1GB&lt;/FONT&gt;?&lt;BR /&gt;Memory allocation limit: 4806672384 bytes using 512 pools&lt;BR /&gt;Total memory bytes used: 0 unused: 3737321472 (100.00%) peak: 3426386556&lt;BR /&gt;Total memory blocks used: 0 unused: 912432 (100%) peak: 861288&lt;BR /&gt;Allocations: 4163792559 alloc, 0 failed alloc, 4140371486 free&lt;/P&gt;&lt;P&gt;System kernel memory (smem) statistics:&lt;BR /&gt;Total memory bytes used: 4598247500 peak: 4608745920&lt;BR /&gt;Total memory bytes wasted: 3721660&lt;BR /&gt;Blocking memory bytes used: 4784944 peak: 9567848&lt;BR /&gt;Non-Blocking memory bytes used: 4593462556 peak: 4599178072&lt;BR /&gt;Allocations: 13741524 alloc, 0 failed alloc, 13738637 free, 0 failed free&lt;BR /&gt;vmalloc bytes used: 4588389496 expensive: no&lt;/P&gt;&lt;P&gt;Kernel memory (kmem) statistics:&lt;BR /&gt;Total memory bytes used: 4143730832 peak: 4231943656&lt;BR /&gt;Allocations: 4177522403 alloc, 0 failed alloc&lt;BR /&gt;4154099588 free, 0 failed free&lt;BR /&gt;External Allocations: 16896 for packets, 88628453 for SXL&lt;/P&gt;&lt;P&gt;Cookies:&lt;BR /&gt;3778625491 total, 0 alloc, 0 free,&lt;BR /&gt;150073 dup, 300575262 get, 2794359219 put,&lt;BR /&gt;2072999334 len, 2707089222 cached len, 0 chain alloc,&lt;BR /&gt;0 chain free&lt;/P&gt;&lt;P&gt;Connections:&lt;BR /&gt;388319874 total, 136725382 TCP, 231455561 UDP, 19560665 ICMP,&lt;BR /&gt;578266 other, 30721 anticipated, 195046 recovered, 10410 concurrent,&lt;BR /&gt;159214 peak concurrent&lt;/P&gt;&lt;P&gt;Fragments:&lt;BR /&gt;1118953332 fragments, 2706956154 packets, 3456 expired, 0 short,&lt;BR /&gt;0 large, 0 duplicates, 848 failures&lt;/P&gt;&lt;P&gt;NAT:&lt;BR /&gt;67013/0 forw, 52962/0 bckw, 982 tcpudp,&lt;BR /&gt;0 icmp, 5906-17579 alloc&lt;/P&gt;&lt;P&gt;Sync: off&lt;/P&gt;&lt;P&gt;[Expert@LocationA:0]# free -m&lt;BR /&gt;total used free shared buffers cached&lt;BR /&gt;Mem: 7744 7580 164 0 333 1837&lt;BR /&gt;-/+ buffers/cache: 5409 2334&lt;BR /&gt;Swap: 18394 0 18394&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is Location B:&lt;/P&gt;&lt;P&gt;System Capacity Summary:&lt;BR /&gt;Memory used: 9% (539 MB out of 5731 MB) - below watermark&lt;BR /&gt;Concurrent Connections: 8560 (Unlimited)&lt;BR /&gt;Aggressive Aging is enabled, not active&lt;/P&gt;&lt;P&gt;Hash kernel memory (hmem) statistics:&lt;BR /&gt;Total memory allocated: 599785472 bytes in 146432 (4096 bytes) blocks using 1 pool&lt;BR /&gt;Total memory bytes used: 0 unused: 599785472 (100.00%) peak: 27427 7488&lt;BR /&gt;Total memory blocks used: 0 unused: 146432 (100%) peak: 69627&lt;BR /&gt;Allocations: 1607331344 alloc, 0 failed alloc, 1607117916 free&lt;/P&gt;&lt;P&gt;System kernel memory (smem) statistics:&lt;BR /&gt;Total memory bytes used: 967638752 peak: 986044552&lt;BR /&gt;Total memory bytes wasted: 4180014&lt;BR /&gt;Blocking memory bytes used: 5820820 peak: 14955252&lt;BR /&gt;Non-Blocking memory bytes used: 961817932 peak: 971089300&lt;BR /&gt;Allocations: 151132250 alloc, 0 failed alloc, 151129180 free, 0 failed free&lt;BR /&gt;vmalloc bytes used: 956763424 expensive: no&lt;/P&gt;&lt;P&gt;Kernel memory (kmem) statistics:&lt;BR /&gt;Total memory bytes used: 401812380 peak: 640749756&lt;BR /&gt;Allocations: 1758439658 alloc, 0 failed alloc&lt;BR /&gt;1758224295 free, 0 failed free&lt;BR /&gt;External Allocations: 76032 for packets, 89765022 for SXL&lt;/P&gt;&lt;P&gt;Cookies:&lt;BR /&gt;1450833429 total, 836424 alloc, 836424 free,&lt;BR /&gt;251 dup, 433718314 get, 2695578081 put,&lt;BR /&gt;2263227759 len, 2298121504 cached len, 0 chain alloc,&lt;BR /&gt;0 chain free&lt;/P&gt;&lt;P&gt;Connections:&lt;BR /&gt;1628040697 total, 660800638 TCP, 927853823 UDP, 39386225 ICMP,&lt;BR /&gt;11 other, 288832 anticipated, 441738 recovered, 8560 concurrent,&lt;BR /&gt;161987 peak concurrent&lt;/P&gt;&lt;P&gt;Fragments:&lt;BR /&gt;302418965 fragments, 2297426537 packets, 2476610 expired, 0 short,&lt;BR /&gt;0 large, 0 duplicates, 1969 failures&lt;/P&gt;&lt;P&gt;NAT:&lt;BR /&gt;0/0 forw, 0/0 bckw, 0 tcpudp,&lt;BR /&gt;0 icmp, 0-27257 alloc&lt;/P&gt;&lt;P&gt;Sync: off&lt;/P&gt;&lt;P&gt;[Expert@locationB:0]# free -m&lt;BR /&gt;total used free shared buffers cached&lt;BR /&gt;Mem: 7744 7555 189 0 419 4896&lt;BR /&gt;-/+ buffers/cache: 2239 5504&lt;BR /&gt;Swap: 18394 0 18394&lt;/P&gt;&lt;P&gt;The only difference I can find between the two is that Location A is using Extended memory hash tables, but I don't know what would cause this behavior?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2019 14:16:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP5600-Memory-Exhaustion/m-p/56391#M11362</guid>
      <dc:creator>Chris_Sanduliak</dc:creator>
      <dc:date>2019-06-21T14:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: CP5600 Memory Exhaustion</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP5600-Memory-Exhaustion/m-p/56408#M11364</link>
      <description>&lt;P&gt;One thing that caught my eye is you have an absolute crapload of fragmented traffic at Site A as compared to Site B.&amp;nbsp; For the process of virtual reassembly, a table called frag_table is employed which is part of your hash memory allocation and could be what is causing your hash memory allocation to balloon like that.&amp;nbsp; Run &lt;STRONG&gt;fw tab -t frag_table -s&lt;/STRONG&gt;, what is the size of that table?&amp;nbsp; My guess is it is very large.&amp;nbsp; Fragmented traffic is a problem since it can't be accelerated at all by SecureXL in R80.10 and earlier, run this command to show all fragments coming into the firewall in real time:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;tcpdump -eni any '((ip[6:2] &amp;gt; 0) and (not ip[6] = 64))'&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Where are the frags coming from?&amp;nbsp; If they come from networks you control, you have an MTU consistency problem in your network.&amp;nbsp; For more info see here:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113992&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk113992: How to configure timeout for fragmented packets on Security Gateway with disabled IPS blade&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2019 01:07:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP5600-Memory-Exhaustion/m-p/56408#M11364</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-06-22T01:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: CP5600 Memory Exhaustion</title>
      <link>https://community.checkpoint.com/t5/General-Topics/CP5600-Memory-Exhaustion/m-p/56411#M11365</link>
      <description>&lt;P&gt;Thank you Timothy&lt;/P&gt;&lt;P&gt;I ran the following "fw tab -t frag_table -s"&amp;nbsp;on Site A:&lt;/P&gt;&lt;P&gt;[Expert@LocationA:0]# fw tab -t frag_table -s&lt;BR /&gt;HOST&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NAME&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ID&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#VALS&amp;nbsp; &amp;nbsp; PEAK&amp;nbsp; &amp;nbsp; &amp;nbsp;#SLINKS&lt;BR /&gt;localhost&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; frag_table&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8184&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;11&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&lt;/P&gt;&lt;P&gt;This was from SiteB:&lt;/P&gt;&lt;P&gt;[Expert@LocationB:0]# fw tab -t frag_table -s&lt;BR /&gt;HOST NAME ID #VALS #PEAK #SLINKS&lt;BR /&gt;localhost frag_table&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;8184&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;196&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0&lt;/P&gt;&lt;P&gt;I don't know if this was the output expected but I really appreciate the help.&lt;/P&gt;&lt;P&gt;I'll definitely be filing that tcpdump command away for later.&amp;nbsp; There is one host in particular that I can see generating a lot of fragmented traffic and it is something we might be able to control.&amp;nbsp; Is it possible for a few hosts to balloon the memory hash tables like this?&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2019 05:22:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/CP5600-Memory-Exhaustion/m-p/56411#M11365</guid>
      <dc:creator>Chris_Sanduliak</dc:creator>
      <dc:date>2019-06-22T05:22:20Z</dc:date>
    </item>
  </channel>
</rss>

