SRX Services Gateway
Highlighted
SRX Services Gateway

SRX3600 kmd out of memory error

‎08-27-2015 06:19 AM

Hi,

 

I have a couple of SRX3600 in a cluster configuration, I configured ipsec VPN and I am getting the follwoing error in the kmd logs:

 

Aug 26 21:39:30   (FPC Slot 11, PIC Slot 0) SPC11_PIC0 kmd[181]: IKE negotiation failed with error: Out of memory. IKE Version: 2, VPN

 

 

There is plenty of memory left on the SRX and there is very little configured on it.

 

Software Rel 12.1X44-D40.2

 

 

Any help is appreciated.

 

 

Thank you

Ranwah

 

3 REPLIES 3
Highlighted
SRX Services Gateway

Re: SRX3600 kmd out of memory error

‎08-28-2015 02:40 AM

Hello,

 

Is it specific to one VPN or all VPNs are affected?

What are Phase 1 & Phase 2 lifetimes?

 

Regards,

 

Rushi

Highlighted
SRX Services Gateway

Re: SRX3600 kmd out of memory error

‎08-30-2015 08:02 AM
The reasons for this may include inappropriate configuration settings (such as using the “SA per host” setting with a very large number of hosts) in addition to other considerations (such as hardware specifications).

Not sure , refer to this link :
http://help.stonesoft.com/onlinehelp/StoneGate/SMC/5.3.7/SGAG/SG_FWIPS_LogFieldValues/VPN_Errors.htm

Regards,
A'bed AL-R.
[JNCSP-SEC JNCDA JNCIS-ENT Ingenious Champion|Sec]
https://srxtech.wordpress.com
Highlighted
SRX Services Gateway

Re: SRX3600 kmd out of memory error

‎08-30-2015 10:15 PM

Hello ranwah ,

 

This issue is reported on 12.1X44 version related to IKE memory leak issue and we do have PR open for the same .

The Fix is in place from 12.1X46 version onwards .  If you need more details on this please open a JTAC ticket for RCA .

 

Please let us know if you have any more concerns .


Thanks,
Sam

Please Mark My Solution Accepted if it Helped, Kudos are Appreciated too .....
Feedback