Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ESpataro
Contributor
Jump to solution

Sep 13 13:06:56 2022 CORP-FW1 kernel: [fw4_0];fwx_get_original_conn_key_ex: fwconn_chain_is_data_con

We are getting the following error in the /var/log/messages file on our corporate cluster@

Sep 13 13:06:56 2022 CORP-FW1 kernel: [fw4_0];fwx_get_original_conn_key_ex: fwconn_chain_is_data_conn failed

Sep 13 13:06:56 2022 CORP-FW1 kernel: [fw4_0];fwx_get_original_conn_key_ex: fwconn_chain_is_data_conn failed

Has anyone seen this before , cpinfo below


]# cpinfo -y all

 

This is Check Point CPinfo Build 914000227 for GAIA

[MGMT]

HOTFIX_R81_JUMBO_HF_MAIN Take: 69

[IDA]

No hotfixes..

[CPFC]

HOTFIX_TEX_ENGINE_R81_AUTOUPDATE

[FW1]

HOTFIX_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE

HOTFIX_R81_JUMBO_HF_MAIN Take: 69

HOTFIX_TEX_ENGINE_R81_AUTOUPDATE

HOTFIX_GOT_TPCONF_AUTOUPDATE

HOTFIX_R80_40_MAAS_TUNNEL_AUTOUPDATE

 

FW1 build number:

This is Check Point's software version R81 - Build 029

kernel: R81 - Build 029

[SecurePlatform]

HOTFIX_R81_JUMBO_HF_MAIN Take: 69

[CPinfo]

No hotfixes..

[PPACK]

HOTFIX_R81_JUMBO_HF_MAIN Take: 69

[AutoUpdater]

No hotfixes..

[DIAG]

No hotfixes..

[CVPN]

HOTFIX_R81_JUMBO_HF_MAIN Take: 69

[CPDepInst]

No hotfixes..

[CPUpdates]

BUNDLE_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE Take: 18

BUNDLE_CORE_FILE_UPLOADER_AUTOUPDATE Take: 17

BUNDLE_R81_JUMBO_HF_MAIN Take: 69

BUNDLE_TEX_ENGINE_R81_AUTOUPDATE Take: 14

BUNDLE_GOT_TPCONF_AUTOUPDATE Take: 107

BUNDLE_R80_40_MAAS_TUNNEL_AUTOUPDATE Take: 47

BUNDLE_HCP_AUTOUPDATE Take: 57

BUNDLE_GENERAL_AUTOUPDATE Take: 12

BUNDLE_CPSDC_AUTOUPDATE Take: 21

BUNDLE_INFRA_AUTOUPDATE Take: 55

BUNDLE_DEP_INSTALLER_AUTOUPDATE Take: 24

[cpsdc_wrapper]

HOTFIX_CPSDC_AUTOUPDATE

[hcp_wrapper]

HOTFIX_HCP_AUTOUPDATE

[core_uploader]

HOTFIX_CHARON_HF

 

[Expert@CORP-FW1:0]#

 

 

I saw this SK (https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...) that references R81.10, but the same error message.

 

IPS is enabled:

 

[Expert@CORP-FW1:0]# enabled_blades

fw vpn urlf av appi ips identityServer SSL_INSPECT anti_bot mon

[Expert@CORP-FW1:0]#

0 Kudos
1 Solution

Accepted Solutions
Mika
Participant

This issue seems to be fixed with Jumbo HFA Take 141 (PRJ-50804, PRHF-28437)

 

View solution in original post

5 Replies
Tal_Paz-Fridman
Employee
Employee

I think that as the SK suggests, you should contact TAC with the problem and the SK number so that they can see if the hotfix is relevant in this case.

Thomas_Eichelbu
Advisor

Hello, 

Yes sure i see this all over!
on all R81.10 FW´s

May 24 11:33:53 2023 XXXXXXX kernel: [fw4_0];fwx_get_original_conn_key_ex: fwconn_chain_is_data_conn failed
May 24 11:33:54 2023 XXXXXXX kernel: [fw4_0];fwx_get_original_conn_key_ex: fwconn_chain_is_data_conn failed

[Expert@XXXXXX# fwmode -s
Firewall is Kernel mode
[Expert@XXXXXXX# enabled_blades
fw vpn urlf av appi ips SSL_INSPECT anti_bot content_awareness mon

but not on USFW FW ... here i dont see this logs.
[Expert@YYYYYYYYY:0:ACTIVE]# fwmode -s
Firewall is User mode
[Expert@YYYYYYYYY:0:ACTIVE]# enabled_blades
fw vpn urlf av appi ips identityServer SSL_INSPECT anti_bot mon

the question is, does it have any negative impact??? 
and it only affects Kernel Mode FWs?

 

best regards

 

 

0 Kudos
the_rock
Legend
Legend

Have not seen those in R81.10 and R81.20, but have noticed it in R80.40 user mode. I dont recall it having any negative impact.

Andy

0 Kudos
Mika
Participant

This issue seems to be fixed with Jumbo HFA Take 141 (PRJ-50804, PRHF-28437)

 

the_rock
Legend
Legend

Good job!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events