cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post
Highlighted
TheRealDiZ
Nickel

IPS causing traffic outage due to: 'number of entries in state on conn (8000) has reached maximum"

Hi All,

 

As per sk52101, we're are currently investigating this issue on R77.30 (latest JHFA 345 installed) with also a TAC case.

Unfortunately I'm not able to see which signature/signatures are causing the issue so I have to use kernel debug mentioned in the sk to find them.

Unfortunately as many of you already know.. Is not always possible to investigate issues with a kdebug.

 

So my question to you is:

Is there a way to understand the number of connections that are populating the "sd_conn" table or the table referenced to this Kernel parameter?

My goal is to provide the visibility of the issue and customize the IPS profile to prevent the table from filling up.

 

Let me know guys if anyone already experienced this issue,

 

**RealD!Z**

5 Replies
Admin
Admin

Re: IPS causing traffic outage due to: 'number of entries in state on conn (8000) has reached maximu

We would need to know which IPS signature is triggering the issue, which it should show in the debug.
Even then I'm not sure you could see the relevant table for that signature.
TheRealDiZ
Nickel

Re: IPS causing traffic outage due to: 'number of entries in state on conn (8000) has reached maximu

Hi @PhoneBoy ,

 

Thank you for your reply.

I think it will be helpful to see how many connections are populating that table.

Do you think from command "ips stat" I can understand something relevant about reaching the maximum connections?

Is there any other command that could help me in order to monitor the IPS blade status?

 

BR

Luca

0 Kudos
Admin
Admin

Re: IPS causing traffic outage due to: 'number of entries in state on conn (8000) has reached maximu

ips stat won't tell you much relates to this.
ips pmstats might tell you something, but I don't know for sure.
TheRealDiZ
Nickel

Re: IPS causing traffic outage due to: 'number of entries in state on conn (8000) has reached maximu

Many many thanks PhoneBoy always on point! 🙂
0 Kudos
Employee++
Employee++

Re: IPS causing traffic outage due to: 'number of entries in state on conn (8000) has reached maximu

Please refer to sk52101

'number of entries in state on conn (8000) has reached maximum allowed' error appears repeatedly in /var/log/messages

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

 

Tal

 

0 Kudos