- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi There,
I have a problem - during policy push cvpnd process is going 100% for 30 seconds during which existing or new connections are not served and users get page not displayed error.
I checked debug of cvpnd process and my findings are that 98% of the lines (out of 2 millions) are:
[12609][23 Apr 17:35:12][ROLES] [ROLES (NAC::IS::TD::Events)] NAC::IS::ROLE_MATCHER_API::RangeList::intersect: no intersection
[12609][23 Apr 17:35:12][ROLES] [ROLES (NAC::IS::TD::Events)] NAC::IS::ROLE_MATCHER_API::RangeList::intersect: intersecting: [x.x.x.x.,x.x.x.x] and [x.x..x.x,x.x..x.x.x.]
[12609][23 Apr 17:35:12][ROLES] [ROLES (NAC::IS::TD::Events)] NAC::IS::ROLE_MATCHER_API::RangeList::intersect: no intersection
What is this ROLE_MATCHER_API doing? It seems it is flooding the process hence it is busy with 100% load.
R80.20 latest JHF
We do use identity awareness, but it is enabled on other gateways, but not on this one. However both gateways share the same management server.
The issue is present in R80.20 JHF47 and R80.20 kernel 3.10 Take11
Looks like a new issue that TAC will need to investigate. Even old TAC SRs didn't show similar messages.
Yes, I have TAC ticket also.
It is really strange and I hope that there is a setting which can force to skip matching roles if IA blade is disabled, but TAC is also struggling to understand this issue.
Same problem on R80.20 JHF 47(GA) or JHF87 (ongoing) with or without IA blade.
Someone have news regarding this?
Massimo
Technical support have build a fix for this. Once I try it I'll let you know.
Forgot to give feedback - the fix worked.
In our case the problem was fixed removing all the network objects (groups in particular is a CPU consuming) from all the Roles
Hello,
Can you clarify with an example? So you had access roles and just removed objects which were in "networks" section?
Hello there,
@abihsot__
@Massimo_Manzato
Could you give an example of the solution?
Was it a specific hotfix you installed?
I currently have a FW 9100 R81.20 JHT 92, this firewall ONLY does VPN mobile access, users connect by client and/or browser, when I installed policies, when I finish the installation the CVPND process is elvated between 80% and 85%, this makes the mobile access web portal stop responding and new users can't connect (users that were already connected have no problem).
Currently I've been months with tickets with TAC and they have not been able to solve the incident, I would like to know how they have managed to solve this problem.
Best Regards!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY