This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG HA: SFOS 18.0.0 GA-Build379.HF050620.1 Kernel Panic after switching to Auxiliary device

Dedicated HA Port 4: directly connected.

 

After switching to Auxiliary Device. The old Master ist in Boot loop

 

Select Menu Number [0-7]: [ 106.190755] BUG: unable to handle kernel NULL pointer dereference at (null)
[ 106.214245] IP: (null)
[ 106.223986] PGD 80000003a67ff067 P4D 80000003a67ff067 PUD 0
[ 106.240966] Oops: 0010 [#1] SMP PTI
[ 106.251441] Modules linked in: nf_conntrack_ipslb nfnetmap_queue(O) xt_nat xt_xfrmpolicy ah4 xt_addrtype xt_CT nf_nat_ftp nf_conntrack_ftp arpt_arpreq_proxy arpt_arpreply_proxy ebt_vlan ebt_arp ebtable_filter ebtable_nat ebtables ip6t_MASQUERADE xt_muser xt_conntrack xt_l4proto xt_auxtoprim_send xt_RCV_SYN_DATA ip6t_ADVERTISEMENT ip6t_SOLICITATION xt_LBS ip6table_filter iptable_filter xt_DNAT xt_SNAT nf_nat_masquerade_ipv6 xt_nat_lookup xt_UST xt_ust xt_firewall nat_rules sfos_rules_framework firewall ip_set_hash_mlmwsticky ip_set_hash_sslvpn iptable_mangle ip_set_hash_mac ip_set_hash_bw nf_conntrack_dns nf_nat_sip nf_conntrack_sip nf_nat_irc nf_conntrack_irc nf_nat_tftp nf_conntrack_tftp nf_nat_h323 nf_conntrack_h323 nf_nat_pptp nf_conntrack_pptp cfg80211 usbhid hid_generic hid ohci_pci ohci_hcd
[ 106.462861] xhci_pci xhci_hcd uhci_hcd ehci_pci ehci_hcd fw_handle_ngfw_notification fp2sp_api fp_notifier bonding lzo lzo_compress lzo_decompress cifs red red2 appdev nf_conntrack_netlink nf_nat_proto_gre nf_conntrack_proto_gre set_sessiontbl sessiontbl ip_gre gre ipcomp xfrm_ipcomp esp4 xfrm4_mode_transport xfrm4_mode_tunnel xfrm4_tunnel xfrm_user af_key xfrm_algo aesni_intel glue_helper aes_x86_64 crypto_simd cryptd cls_u32 act_mirred sch_ingress ifb sch_hfsc sch_leafprio sch_headprio sch_sfq sch_htb xt_MULTISET xt_MLM xt_SRCNETMAP xt_MARKROUTE xt_CONTINUE xt_LOGDROP xt_ULOG xt_TCPMSS xt_REDIRECT nf_nat_redirect ipt_MASQUERADE nf_nat_masquerade_ipv4 xt_OUT_OUTDEV ip6t_rpfilter ipt_rpfilter ebt_nflog ebt_pkttype xt_serviceset xt_appset xt_hostset xt_pkttype xt_recent xt_state xt_status xt_cet
[ 106.674120] xt_OUTDEV xt_iprange xt_limit xt_hashlimit xt_tcpudp xt_multiport nf_conntrack_relate xt_IPMACFILTER xt_RANGENAT xt_VHDNAT ip_set_bitmap_vhost xt_FWSET xt_set ip_set_hash_maciface_fp ip_set_hash_ipiface_fp ip_set_bitmap_hotspotuser ip_set_hash_hotspotmac ip_set_bitmap_tlsrule ip_set_bitmap_appset ip_set_bitmap_fwrule ip_set_bitmap_ctrxss ip_set_bitmap_user sp2fp_api ip_set_bitmap_userpolicy ip_set_hash_ipuser ip_set_bitmap_service ip_set_bitmap_host ip_set_hash_ipmaciface ip_set_hash_l2mac ip_set_hash_ipmac ip_set_hash_ip ip_set arptable_filter arp_tables caswell_bpgen3(O) network_bypass(O) e1000e_nm(O) igb_nm(O) i2c_algo_bit ixgbe_nm(O) i40e_nm(O) vxlan udp_tunnel ip6_udp_tunnel ptp pps_core mdio i2c_i801 i2c_dev i2c_core netmap(O) ip6table_nat nf_nat_ipv6 ip6table_mangle ip6table_raw
[ 106.886275] iptable_nat iptable_raw nf_nat_ipv4 xt_dscp nf_nat ip6_tables ip_tables tun af_packet 8021q nf_conntrack_ipv6 nf_defrag_ipv6 nf_conntrack_ipv4 ip6_tunnel tunnel6 sit ip_tunnel tunnel4 ppdev parport_pc parport nf_conntrack lineartable bitmap_api br_netfilter bridge nf_defrag_ipv4 ipv6 stp llc x_tables nfnetlink button evdev [last unloaded: nfnetmap_queue]
[ 106.983741] CPU: 5 PID: 8969 Comm: winbindd Tainted: G O 4.14.38 #2
[ 107.005967] Hardware name: Sophos XG/XG, BIOS 5.11 07/20/2018
[ 107.023217] task: ffff8803b1678000 task.stack: ffffc90003944000
[ 107.041025] RIP: 0010: (null)
[ 107.052305] RSP: 0000:ffff88046dd43e18 EFLAGS: 00010202
[ 107.068040] RAX: ffffffffa0851700 RBX: ffff8804454cb680 RCX: ffff88040328bc00
[ 107.089466] RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff8804454cb680
[ 107.110901] RBP: ffff88040328bc50 R08: 0000000000000001 R09: 0000000000000001
[ 107.132341] R10: 0000000000000000 R11: ffffc90003947bf0 R12: ffff880454538000
[ 107.153763] R13: ffff880454538078 R14: ffff8804545380a0 R15: 0000000000000008
[ 107.175188] FS: 0000000000000000(0000) GS:ffff88046dd40000(0063) knlGS:00000000f6b2ee40
[ 107.199538] CS: 0010 DS: 002b ES: 002b CR0: 0000000080050033
[ 107.216813] CR2: 0000000000000000 CR3: 00000003a67b0004 CR4: 00000000001606e0
[ 107.238264] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000
[ 107.259687] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400
[ 107.281138] Call Trace:
[ 107.288541] <IRQ>
[ 107.294626] ? ip_rcv+0x316/0x4c0
[ 107.304611] ? ip_local_deliver_finish+0x1d0/0x1d0
[ 107.319017] ? __netif_receive_skb_core+0x3ec/0xac0
[ 107.333709] ? enqueue_task_fair+0x320/0x440
[ 107.346629] ? process_backlog+0x86/0x120
[ 107.358691] ? process_backlog+0x86/0x120
[ 107.370756] ? net_rx_action+0xcc/0x270
[ 107.382300] ? __do_softirq+0xc5/0x1ec
[ 107.393634] ? do_softirq_own_stack+0x2a/0x40
[ 107.406738] </IRQ>
[ 107.413080] ? do_softirq.part.2+0x3c/0x40
[ 107.425407] ? netif_rx_ni+0x1d/0x30
[ 107.436172] ? dev_loopback_xmit+0xa3/0xc0
[ 107.448507] ? ip_mc_output+0x176/0x240
[ 107.460066] ? ip_finish_output2+0x3b0/0x3b0
[ 107.472910] ? ip_send_skb+0x10/0x40
[ 107.483674] ? udp_send_skb+0x94/0x240
[ 107.494958] ? udp_sendmsg+0x2f8/0x8c0
[ 107.506241] ? release_sock+0x3b/0x90
[ 107.517292] ? sock_sendmsg+0xe/0x20
[ 107.528062] ? SyS_sendto+0xad/0x150
[ 107.538847] ? ep_poll_wakeup_proc+0x20/0x20
[ 107.551691] ? compat_SyS_socketcall+0x12c/0x210
[ 107.565575] ? do_int80_syscall_32+0x58/0x110
[ 107.578696] ? entry_INT80_compat+0x48/0x50
[ 107.591262] Code: Bad RIP value.
[ 107.601242] RIP: (null) RSP: ffff88046dd43e18
[ 107.616950] CR2: 0000000000000000
[ 107.626934] ---[ end trace ddee8a5a26163576 ]---
[ 107.640819] Kernel panic - not syncing: Fatal exception in interrupt
[ 107.659906] Kernel Offset: disabled
[ 107.670405] Rebooting in 3 seconds..
[ 110.702252] ACPI MEMORY or I/O RESET_REG.

 

jemand ne idee, vom support warte ich seit einer Woche auf Antwort. Hardware-Defekt kann man fast ausschließen, da sich die 2. Hardware genauso verhält



This thread was automatically locked due to age.
Parents
  • Hi  

    1)Since when you observed this issue?

    2)Was this issue getting observed with V17 as well?

    3)Is there any re creation steps which can trigger issue all the time with your backup ? If yes then if it possible to share backup with us then message me backup with re creation steps.

    4)Can you please confirm any system NAT command applied on XG CLI? Please share the sh advance firewall output.

    console> sh advanced-firewall 

    Please also share the support case ID.

  • Hi,

    1) New Installation, appears since the beginning

    2) i started with Version 18, no config set on v17, directly updated to 18. I have also tested a new clean installation of v18

    3) yes. I configured HA with quick mode. When this ist finished, i switch to auiliary device, then i've got the failure.

    4) Strict Policy : on
    FtpBounce Prevention : control
    Tcp Conn. Establishment Idle Timeout : 21600
    UDP Timeout :
    UDP Timeout Stream : 60
    Fragmented Traffic Policy : allow
    Midstream Connection Pickup : off
    TCP Seq Checking : on
    TCP Window Scaling : on
    TCP Appropriate Byte Count : on
    TCP Selective Acknowledgements : on
    TCP Forward RTO-Recovery[F-RTO] : off
    TCP TIMESTAMPS : off
    Strict ICMP Tracking : off
    ICMP Error Message : allow
    IPv6 Unknown Extension Header : deny


    Bypass Stateful Firewall
    ------------------------
    Source Genmask Destination Genmask


    NAT policy for system originated traffic
    ---------------------
    Destination Network Destination Netmask Interface SNAT IP 

     

    Support Case ID: 9875735

    of course you can get a backup

     

  • Hi  

    Thanks for sharing the required information. We will update on support case with further information.

  • Hi,

    another, 4 days without an answer. We got Enhanced plus support but no one cares!

  • Hi  

    Sorry for the inconvenience caused to you. 

    I checked and discussed the logs with Internal team and based on that we would like you to confirm below steps.

    If Firewall acceleration is on then can you please disable the same via below command and check the issue status.

    console: system firewall-acceleration disable

  • Hi,

    thx for your reply.

    system firewall-acceleration was disabled

    console> system firewall-acceleration show
    Firewall Acceleration is Disabled.

Reply Children
No Data