Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG330 with Firmware Version SFOS 18.0.3 MR-3 rebooting randomly with intervals of a couple of houres

Hi Everyone,

Our XG330 with Firmware Version SFOS 18.0.3 MR-3 rebooting randomly with intervals of a couple of hours. I have raised the request with the Sophos team and provided all the necessary logs to them and now they said they will investigate it provide an update by the 20th Nov which almost a week away. We are facing this issue for the past three days and our entire production is down.

we are getting below error. Is anyone aware of the temporary workaround then please advise? I have already checked firewall-acceleration is disabled.

BUG: unable to handle kernel paging request at fffffffffffffff8



This thread was automatically locked due to age.
Parents
  • Hello Ranjeet,

    Thank you for contacting the Sophos Community!

    If you have a case open with Support could you please share the Case ID with me, so I can follow-up, if you haven't please open one and share the Case ID with me.

    Can you please submit the following files:

    csc.log, applog.log, syslog.log, msync.log and networkd.log
    If possible, memory and CPU graph and all this detail with exact date and time when issue observed.

    If you have any log under /var/cores, please submit the output of the command.

    Also the output of this command:  grep 'NMI\|backtrace' /log/syslog.log

    Additionally please run the following command, to disable Firewall-Acceleration and monitor if the issue happens again.

    console> system firewall-acceleration disable

    To see if the Firewall Acceleration is enabled, please run

    console> system firewall-acceleration show

    Regards,

  • Hello Emmanuel,

    We are also facing hte same issue, XG330 - Standalone, 3 year old device. was working fine till SFOS17.5.9. upgraded it to SFOS18.0.1 and firewall started rebooting intermittently every few hours. Raised case with Support, had device on console, upgraded to SFOS 18.0.3-MR3, done Disk Analysis , Memory Test still no luck.  We had a spare XG330 - we were planning to go for HA - with SFOS18, replaced it and in stand alone mode, it is also r4estarting.

    Firewall Accelration is disabled on both devices. had PSMON logged and support team didn't find anything. 

    I feel there is some bug in the SFOS that is making firewall restart especially XG330, We have XG 106 /115 and a 230 installed in our envirnment all those are working fine without any issue (fingers crossed).

    The case is still open with Support Team.

  • Hello Ajay,

    Thank you for reaching out!

    Could you please share the Case ID with me.

    Regards,

  • Hello Emmanuel,

    Case ID: 03237950

  • Hello Ajay,

    Thank you for the Case ID.

    Seems like the L2 engineer has asked you to connect a Serial Cable to get some output, in case the device reboots again, if this happens.

    Regards,

  • Yes he had asked me to connect Serial Cable, the device reboot again and I've submitted the serial logs awaiting response from the Engineer.

  • Hello Ajay,

    Thank you for the follow-up!

    I can see your ticket is now escalated to Development and being investigated under NC-64917

    Regards,

  • Yeah, today the DEV team ran a debug patch and the Firewall is under observation with Serial Console connected and taking psmon logs.

    Hoping for some stable solution for the problem.

  • Hello Ajay,

    Thank you for the update.

    Regards,

  • Hi Emmanuel,

    Till now the Firewall restarted exactly 9 times in last 27Hrs- means every 3 hours on an average - applying the Debug Patch yesterday.

    I've shared the Console logs and I'm told the DEV team have gathered the syslog.log, they are digging the logs to find the Root cause and a way to rectify the issue.

    This is a serious issue, please help us get over it.

  • Hi Ajay,

    Same thing happened to us when GES applied the binary patch. I connected him again and reverted the patch and surprisingly no reboot after reverting the binary patch, almost 50+ hours.

  • Hello Ajay,

    Thank you for the follow-up!

    I can see the engineer brought this to the attention of DEV, he is waiting to hear back from them at the moment, seems they are working with a different binary at the moment.

    Regards,

Reply Children
  • The Debug Patch removed, Firewall is still rebooting intermittently but yes the number of times is reduced, about every 24-36 Hrs.

    Been told that DEV collected samples from other similar cases and trying to create the same to debug the Root Cause.

    Its apparent that this issue would be solved only after a patch or update release, as it is a Kernel Bug.

  • Agreeing with your comment. We are also still facing the same issue even after replacing our old xg330 with new xg550. I am not sure how long DEV team will take to provide patch for permanent fix.

  • Will the replaced XG330 still reboot when running completely disconnected from all LAN with your config?

    So if yes, Sophos should be able to easily debug it when loading your config on one of their machines.

    This is also interessting for us. I'd like to avoid running into this when upgrading our XG430 and maybe disconnect the HA peer from the cluster and upgrade it as isolated stand-alone machine, then let it run in this state for a week or so.