Hi All,
Bit of a strange one after a staged upgrade of an r80.20 cluster to r80.40 Y77.
We have upgraded one of the nodes and enabled MVC but have hit what appears to be an fwx_alloc issue:
cloningd: Error in delayed connection() 111 - Connection refused
kernel: [fw4_0];fwxlate_allocate_port_from_sync: synced port already exists. Port 10702 (protocol 6) of hide_src ##########, dst ##########.
kernel: [fw4_0];fwxlate_sync_port_allocation: fwxlate_allocate_port_from_sync failed
kernel: [fw4_1];fwxlate_allocate_port_from_sync: synced port already exists. Port 10602 (protocol 6) of hide_src ##########, dst ##########.
kernel: [fw4_1];fwxlate_sync_port_allocation: fwxlate_allocate_port_from_sync failed
kernel: [fw4_4];de_allocate_port: fwx_alloc_global_del failed (second try). <ipp: 6 hide_src: ##########, port: 10637, dest: ##########, dport: 443 (443)>
kernel: [fw4_0];fwxlate_allocate_port_from_sync: synced port already exists. Port 10708 (protocol 6) of hide_src ##########, dst ##########.
kernel: [fw4_0];fwxlate_sync_port_allocation: fwxlate_allocate_port_from_sync failed
kernel: [fw4_0];de_allocate_port: fwx_alloc_global_del failed (second try). <ipp: 6 hide_src: ##########, port: 10404, dest: ##########, dport: 443 (443)>
kernel: [fw4_3];de_allocate_port: fwx_alloc_global_del failed (second try). <ipp: 6 hide_src: ##########, port: 10555, dest: ##########, dport: 443 (443)>
GNAT is set to 1 as its a 6 FW worker appliance.
Have a Ticket open with TAC but suspect next step is create and modify fwkern.conf to 0 as per sk165153.
Anyone come across this ?
UPDATE:
As per sk165153 and sk26202 we set fwx_gnat_enabled to 0 and rebooted the appliances. Fixed the issue.
CCSME, CCTE, CCME, CCVS