<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 1100 resource exhaustion after moving to R80.40? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1100-resource-exhaustion-after-moving-to-R80-40/m-p/100426#M4303</link>
    <description>&lt;P&gt;So I wanted to post this to let people know I had a customer experience this after upgrading to R80.40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Starting point:&lt;/P&gt;&lt;P&gt;R80.30 recent jumbo at the time of upgrade&lt;/P&gt;&lt;P&gt;1100 with R77.20.80 in field as a remote office.&amp;nbsp; Centrally managed, only FW, VPN and IPS blades enabled.&amp;nbsp; Tuned IPS for SMB/older firewall versions disabling high cpu impact protections, others to minimize impact.&lt;/P&gt;&lt;P&gt;VPN, local connectivity, remote connectivity all worked to local 1100 appliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Upgraded to R80.40 JHF 77 (may have even been one GA patch earlier).&lt;/P&gt;&lt;P&gt;Started experiencing odd problems including but not limited to:&lt;/P&gt;&lt;P&gt;VPN drops permanently, reboot of box sometimes fixed.&lt;/P&gt;&lt;P&gt;Local connectivity loss including icmp ping, and web management loss.&lt;/P&gt;&lt;P&gt;Inability to login remotely via web.&lt;/P&gt;&lt;P&gt;Inability to login remotely via ssh.&lt;/P&gt;&lt;P&gt;Login, but error about role not assigned to user, then appliance stated that it needed to run initial configuration again.&lt;/P&gt;&lt;P&gt;most command would fail in this state:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;vpn11-test1100 login: admin&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Password:&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Role is not assigned to user&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Role is not assigned to user&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;vpn11-test1100&amp;gt; top&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Unexpected error: /usr/local/share/lua/5.1/sys/permissions.lua:0: attempt to index upvalue '' (a nil value)&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;vpn11-test1100&amp;gt; top&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Unexpected error: /usr/local/share/lua/5.1/sys/permissions.lua:0: attempt to index upvalue '' (a nil value)&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;vpn11-test1100&amp;gt; expert&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Unexpected error: /usr/local/share/lua/5.1/sys/permissions.lua:0: attempt to index upvalue '' (a nil value)&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reboots would sometimes fix the problem, so we limped along.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my initial conclusion after doing some troubleshooting was that maybe this was a hardware issue, so we swapped it with a spare 1100 appliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Initially looked like it was going to work, but within a few hours saw the same issues.&lt;/P&gt;&lt;P&gt;Finally decided to swap (AGAIN?!) for a 1400 series appliance, same policy same network configuration, same blades enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Worked perfectly!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Had customer ship me both boxes to put online locally where I could see serial consoles.&lt;/P&gt;&lt;P&gt;Wiped boxes to factory default with newer firmware, so newer firmware was the factory default.&amp;nbsp; Configured box with basic ip connectivity and connected to the internet.&lt;/P&gt;&lt;P&gt;No issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Connected box to central management, got policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on console started seeing things like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;vpn11-test1100 login: Out of memory: kill process 3263 (fw) score 3475 or a child&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Killed process 3264 (fw)&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Out of memory: kill process 3263 (fw) score 3056 or a child&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Killed process 3263 (fw)&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Out of memory: kill process 1832 (fw) score 1528 or a child&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Killed process 1832 (fw)&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Out of memory: kill process 2256 (fw) score 1528 or a child&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Killed process 2256 (fw)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this time I opened a case with TAC.&amp;nbsp; (I can provide SR if interested).&lt;/P&gt;&lt;P&gt;After some basic diagnostics (do we not have any other tools other them memtest.sh?) it was decided to RMA both boxes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the same time, we also ordered new 1530 appliances to see if they would have the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New boxes arrived, 1530 came up just fine with no issues and have no stability issues so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Plugged in new RMA 1100 box and it experienced the same memory issues.&amp;nbsp; See same memory issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the questions are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Why are there no tools to better diagnose problems on the SMB (sometimes used even in enterprise) firewalls?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Why is there an increase in resource usage on 1100 appliances when centrally managed?&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Is there any reason one should even run the 1100 appliance with R80.40.&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; Is there a way out of this situation?&amp;nbsp; Or is hardware upgrade the only solution?&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; Is there a problem with my testing methodology that I am making?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 28 Oct 2020 19:33:35 GMT</pubDate>
    <dc:creator>Ted_Serreyn</dc:creator>
    <dc:date>2020-10-28T19:33:35Z</dc:date>
    <item>
      <title>1100 resource exhaustion after moving to R80.40?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1100-resource-exhaustion-after-moving-to-R80-40/m-p/100426#M4303</link>
      <description>&lt;P&gt;So I wanted to post this to let people know I had a customer experience this after upgrading to R80.40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Starting point:&lt;/P&gt;&lt;P&gt;R80.30 recent jumbo at the time of upgrade&lt;/P&gt;&lt;P&gt;1100 with R77.20.80 in field as a remote office.&amp;nbsp; Centrally managed, only FW, VPN and IPS blades enabled.&amp;nbsp; Tuned IPS for SMB/older firewall versions disabling high cpu impact protections, others to minimize impact.&lt;/P&gt;&lt;P&gt;VPN, local connectivity, remote connectivity all worked to local 1100 appliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Upgraded to R80.40 JHF 77 (may have even been one GA patch earlier).&lt;/P&gt;&lt;P&gt;Started experiencing odd problems including but not limited to:&lt;/P&gt;&lt;P&gt;VPN drops permanently, reboot of box sometimes fixed.&lt;/P&gt;&lt;P&gt;Local connectivity loss including icmp ping, and web management loss.&lt;/P&gt;&lt;P&gt;Inability to login remotely via web.&lt;/P&gt;&lt;P&gt;Inability to login remotely via ssh.&lt;/P&gt;&lt;P&gt;Login, but error about role not assigned to user, then appliance stated that it needed to run initial configuration again.&lt;/P&gt;&lt;P&gt;most command would fail in this state:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;vpn11-test1100 login: admin&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Password:&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Role is not assigned to user&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Role is not assigned to user&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;vpn11-test1100&amp;gt; top&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Unexpected error: /usr/local/share/lua/5.1/sys/permissions.lua:0: attempt to index upvalue '' (a nil value)&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;vpn11-test1100&amp;gt; top&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Unexpected error: /usr/local/share/lua/5.1/sys/permissions.lua:0: attempt to index upvalue '' (a nil value)&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;vpn11-test1100&amp;gt; expert&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Unexpected error: /usr/local/share/lua/5.1/sys/permissions.lua:0: attempt to index upvalue '' (a nil value)&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reboots would sometimes fix the problem, so we limped along.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So my initial conclusion after doing some troubleshooting was that maybe this was a hardware issue, so we swapped it with a spare 1100 appliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Initially looked like it was going to work, but within a few hours saw the same issues.&lt;/P&gt;&lt;P&gt;Finally decided to swap (AGAIN?!) for a 1400 series appliance, same policy same network configuration, same blades enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Worked perfectly!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Had customer ship me both boxes to put online locally where I could see serial consoles.&lt;/P&gt;&lt;P&gt;Wiped boxes to factory default with newer firmware, so newer firmware was the factory default.&amp;nbsp; Configured box with basic ip connectivity and connected to the internet.&lt;/P&gt;&lt;P&gt;No issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Connected box to central management, got policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on console started seeing things like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;vpn11-test1100 login: Out of memory: kill process 3263 (fw) score 3475 or a child&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Killed process 3264 (fw)&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Out of memory: kill process 3263 (fw) score 3056 or a child&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Killed process 3263 (fw)&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Out of memory: kill process 1832 (fw) score 1528 or a child&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Killed process 1832 (fw)&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Out of memory: kill process 2256 (fw) score 1528 or a child&lt;/P&gt;&lt;P class="p1 lia-indent-padding-left-30px"&gt;Killed process 2256 (fw)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this time I opened a case with TAC.&amp;nbsp; (I can provide SR if interested).&lt;/P&gt;&lt;P&gt;After some basic diagnostics (do we not have any other tools other them memtest.sh?) it was decided to RMA both boxes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the same time, we also ordered new 1530 appliances to see if they would have the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New boxes arrived, 1530 came up just fine with no issues and have no stability issues so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Plugged in new RMA 1100 box and it experienced the same memory issues.&amp;nbsp; See same memory issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the questions are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Why are there no tools to better diagnose problems on the SMB (sometimes used even in enterprise) firewalls?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Why is there an increase in resource usage on 1100 appliances when centrally managed?&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; Is there any reason one should even run the 1100 appliance with R80.40.&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; Is there a way out of this situation?&amp;nbsp; Or is hardware upgrade the only solution?&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; Is there a problem with my testing methodology that I am making?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 19:33:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1100-resource-exhaustion-after-moving-to-R80-40/m-p/100426#M4303</guid>
      <dc:creator>Ted_Serreyn</dc:creator>
      <dc:date>2020-10-28T19:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: 1100 resource exhaustion after moving to R80.40?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1100-resource-exhaustion-after-moving-to-R80-40/m-p/100427#M4304</link>
      <description>&lt;P&gt;One question: did you push policy to the 1100 AFTER upgrading the management to R80.40?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 19:39:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1100-resource-exhaustion-after-moving-to-R80-40/m-p/100427#M4304</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-28T19:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: 1100 resource exhaustion after moving to R80.40?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1100-resource-exhaustion-after-moving-to-R80-40/m-p/100428#M4305</link>
      <description>&lt;P&gt;yes, and that seems to be when the problems start.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 19:41:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1100-resource-exhaustion-after-moving-to-R80-40/m-p/100428#M4305</guid>
      <dc:creator>Ted_Serreyn</dc:creator>
      <dc:date>2020-10-28T19:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: 1100 resource exhaustion after moving to R80.40?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1100-resource-exhaustion-after-moving-to-R80-40/m-p/100460#M4306</link>
      <description>&lt;P&gt;That seems to point to an issue with the policy compiled by the backward compatibility package for R80.40.&lt;BR /&gt;The 1400 and 1500 have a bit more memory than the 1100 series appliances also (and use different BC packages for compilation).&lt;BR /&gt;TAC will definitely have to investigate this.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 23:01:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1100-resource-exhaustion-after-moving-to-R80-40/m-p/100460#M4306</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-28T23:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: 1100 resource exhaustion after moving to R80.40?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1100-resource-exhaustion-after-moving-to-R80-40/m-p/100519#M4307</link>
      <description>&lt;P&gt;1. Why are there no tools to better diagnose problems on the SMB (sometimes used even in enterprise) firewalls?&lt;/P&gt;
&lt;P&gt;There is a variety of SMB tools from monitor/spike scripts to debug firmware !&lt;/P&gt;
&lt;P&gt;2. Why is there an increase in resource usage on 1100 appliances when centrally managed?&lt;/P&gt;
&lt;P&gt;This depends on the rulebase used, kind and number of objects a.o. Locally managed, the rulebase will usually be much less complicated...&lt;/P&gt;
&lt;P&gt;3. Is there any reason one should even run the 1100 appliance with R80.40.&lt;/P&gt;
&lt;P&gt;You can not install R80.40 on SMB - but R80.40 Management should work. You can also stay with R80.30 if you do not need additional features...&lt;/P&gt;
&lt;P&gt;4. Is there a way out of this situation? Or is hardware upgrade the only solution?&lt;/P&gt;
&lt;P&gt;I would try to streamline the rules used on the SMB install targets to save memory - but the 1100 footprint is rather small as it was released in May-20138)&lt;/img&gt;&lt;/P&gt;
&lt;P&gt;Engineerig Support for 1100 ended last June, and in June 22, all Support will end - this is a good reason for a hardware upgrade.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 08:58:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1100-resource-exhaustion-after-moving-to-R80-40/m-p/100519#M4307</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-29T08:58:39Z</dc:date>
    </item>
  </channel>
</rss>

