Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ips.log filling up disk

We have XG210 with SFOS 19.5.4. I've noticed ips.log filling up /var partition till there is no free space on disk and it causes device to boot into fail-safe mode. Stopping IPS service stops log file from growing but when I restart IPS service, this issue occurs again. Switching off IPS Protection button from Intrusion Prevention menu or removing IPS polices from all firewall rules does not resolve this issue and only stopping service stops it. Here is the log that reappears again and again in the log file and causes this issue:

2024-03-03T20:42:03.268400Z [28142]:DAQ:INFO:daq_nmsp.c:2342(daq_nmsp_get_pkt)--> jumbogram read failed. jumbo len: 0 rslot 11 rlen 2048

2024-03-03T20:42:03.268402Z [28142]:DAQ:INFO:daq_nmsp.c:2384(daq_nmsp_get_pkt)--> Exit --> DAQ Error -7

I've tried re-imaging SFOS but it didn't solve the problem. Is there anyway to solve this issue without need to stopping IPS?



This thread was automatically locked due to age.
Parents
  • We have exactly the same problem on a XGS3300 HA Cluster (SFOS Version 20.0). 

    Suddenly CPU usage on the primary node goes high, more and more network connections going down and ips.log is filling up with the messages:

    DAQ:INFO:daq_nmsp.c:2342(daq_nmsp_get_pkt)--> jumbogram read failed. jumbo len: 0 rslot 11 rlen 2048

    DAQ:INFO:daq_nmsp.c:2384(daq_nmsp_get_pkt)--> Exit --> DAQ Error -7

    Struggling around with support since Dec. 2023 and no solution yet. 

  • Could you share the Case ID? 

    __________________________________________________________________________________________________________________

  • First Case: 07151744

    Second Case: 07213100

  •   is this 19.5MR4 too? do you also see log rotation not happening for ips.log? what is max size of ips.log you are seeing? 

  • We have ips.log growing issue in 19.5.4 but I'm not sure root cause for it is log rotation. I'll look for result of command that Shirkant gave and update with results.

  • In my oppinion it's not a problem with log rotation. Furthermore it's a problem in the ips /dpi engine.

    As soon as the error occurs the firewall is becoming more and more unstable until all connections are dropped and during this time there are thousands of the messages you mentioned above in the ips.log.

    The ips.log is growing then from 300MB to about 170gb which fills the partition up. All of this happens in just a few minutes.

    The only thing we can do about this is failover to the auxilliary node and clean up the partition on the former primary node.

    We are running into this issue approx. every 2 weeks.

    The cluster is running on SFOS V20.

  •  - Could we get your problem sorted out? 

    __________________________________________________________________________________________________________________

Reply Children