Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
TheRealDiZ
Collaborator

IPS causing traffic outage due to: 'number of entries in state on conn (8000) has reached maximum"

Hi All,

 

As per sk52101, we're are currently investigating this issue on R77.30 (latest JHFA 345 installed) with also a TAC case.

Unfortunately I'm not able to see which signature/signatures are causing the issue so I have to use kernel debug mentioned in the sk to find them.

Unfortunately as many of you already know.. Is not always possible to investigate issues with a kdebug.

 

So my question to you is:

Is there a way to understand the number of connections that are populating the "sd_conn" table or the table referenced to this Kernel parameter?

My goal is to provide the visibility of the issue and customize the IPS profile to prevent the table from filling up.

 

Let me know guys if anyone already experienced this issue,

 

**RealD!Z**

5 Replies
PhoneBoy
Admin
Admin

We would need to know which IPS signature is triggering the issue, which it should show in the debug.
Even then I'm not sure you could see the relevant table for that signature.
TheRealDiZ
Collaborator

Hi @PhoneBoy ,

 

Thank you for your reply.

I think it will be helpful to see how many connections are populating that table.

Do you think from command "ips stat" I can understand something relevant about reaching the maximum connections?

Is there any other command that could help me in order to monitor the IPS blade status?

 

BR

Luca

0 Kudos
PhoneBoy
Admin
Admin

ips stat won't tell you much relates to this.
ips pmstats might tell you something, but I don't know for sure.
TheRealDiZ
Collaborator

Many many thanks PhoneBoy always on point! 🙂
0 Kudos
Tal_Paz-Fridman
Employee
Employee

Please refer to sk52101

'number of entries in state on conn (8000) has reached maximum allowed' error appears repeatedly in /var/log/messages

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

 

Tal

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events