Mailing List Archive

Problems commiting changes to firewall filter
After updating a firewall filter with a new term, i get following error
msg in the syslog:

Jul 18 18:10:48 xxxxx mgd[1041]: UI_COMMIT_QUIT: User 'wds' performed
'commit and-quit'
Jul 18 18:10:49 xxxxx /kernel: BAD_PAGE_FAULT: pid 1052 (dfwc), uid
0: pc 0x804f366 got a read fault at 0xa, x86 fault flags = 0x4
Jul 18 18:10:49 xxxxx /kernel: Trapframe Register Dump:
Jul 18 18:10:49 xxxxx /kernel: eax: 00000001 ecx: 00000010 edx:
00000002 ebx: 00a10000
Jul 18 18:10:49 xxxxx /kernel: esp: bfbff314 ebp: bfbff32c esi:
080610e8 edi: 08084680
Jul 18 18:10:49 xxxxx /kernel: eip: 0804f366 eflags: 00010246
Jul 18 18:10:49 xxxxx /kernel: cs: 001f ss: 002f ds: 002f
es: 002f
Jul 18 18:10:49 xxxxx /kernel: fs: 002f trapno: 0000000c
err: 00000004
Jul 18 18:10:49 xxxxx /kernel: Page table info for pc address
0x804f366: pde = 0x1ca01067, pte = 9dc3425
Jul 18 18:10:49 xxxxx /kernel: Dumping 16 bytes starting at pc
address 0x804f366:
Jul 18 18:10:49 xxxxx /kernel: 8b 42 08 eb 13 90 8b 4a 18 8b 42 14 03
41 08 80
Jul 18 18:10:49 xxxxx dcd[1051]: DCD_FW_COMPILER_EXIT: dfwc exited
with signal 11

Jul 18 18:10:49 xxxxx mgd[1041]: UI_CHILD_EXITED: Child exited: pid
1051, status 1, command '/sbin/dcd'

when i remove the new term, i can commit. I'm sure there is no problem
with the term itself as i applied it in the same filter on another
router.

Any comments are appreciated. We're running JunOS 5.4 on M-20's.

thanks,

--
walter

----- End forwarded message -----
Problems commiting changes to firewall filter [ In reply to ]
After updating a firewall filter with a new term, i get following error
msg in the syslog:

Jul 18 18:10:48 xxxxx mgd[1041]: UI_COMMIT_QUIT: User 'wds' performed
'commit and-quit'
Jul 18 18:10:49 xxxxx /kernel: BAD_PAGE_FAULT: pid 1052 (dfwc), uid
0: pc 0x804f366 got a read fault at 0xa, x86 fault flags = 0x4
Jul 18 18:10:49 xxxxx /kernel: Trapframe Register Dump:
Jul 18 18:10:49 xxxxx /kernel: eax: 00000001 ecx: 00000010 edx:
00000002 ebx: 00a10000
Jul 18 18:10:49 xxxxx /kernel: esp: bfbff314 ebp: bfbff32c esi:
080610e8 edi: 08084680
Jul 18 18:10:49 xxxxx /kernel: eip: 0804f366 eflags: 00010246
Jul 18 18:10:49 xxxxx /kernel: cs: 001f ss: 002f ds: 002f
es: 002f
Jul 18 18:10:49 xxxxx /kernel: fs: 002f trapno: 0000000c
err: 00000004
Jul 18 18:10:49 xxxxx /kernel: Page table info for pc address
0x804f366: pde = 0x1ca01067, pte = 9dc3425
Jul 18 18:10:49 xxxxx /kernel: Dumping 16 bytes starting at pc
address 0x804f366:
Jul 18 18:10:49 xxxxx /kernel: 8b 42 08 eb 13 90 8b 4a 18 8b 42 14 03
41 08 80
Jul 18 18:10:49 xxxxx dcd[1051]: DCD_FW_COMPILER_EXIT: dfwc exited
with signal 11

Jul 18 18:10:49 xxxxx mgd[1041]: UI_CHILD_EXITED: Child exited: pid
1051, status 1, command '/sbin/dcd'

when i remove the new term, i can commit. I'm sure there is no problem
with the term itself as i applied it in the same filter on another
router.

Any comments are appreciated.

thanks,

--
walter
Problems commiting changes to firewall filter [ In reply to ]
Walter De Smedt <wdesmedt@pandora.be> writes:

> After updating a firewall filter with a new term, i get following error
> msg in the syslog:
>
> Jul 18 18:10:48 xxxxx mgd[1041]: UI_COMMIT_QUIT: User 'wds' performed
> 'commit and-quit'
> Jul 18 18:10:49 xxxxx /kernel: BAD_PAGE_FAULT: pid 1052 (dfwc), uid
> 0: pc 0x804f366 got a read fault at 0xa, x86 fault flags = 0x4
> [snip]
> Jul 18 18:10:49 xxxxx dcd[1051]: DCD_FW_COMPILER_EXIT: dfwc exited
> with signal 11

I remeber having the same problem with 5.4R2.4. The problem was
fixed in 5.4R3 and 5.5R2 according to the email I've received
from our Juniper support in November. Unfortunately, I don't have
the PR number of this problem. Also, I don't remeber whether I
was able come up with some workaround.

Cheers,

--
- Matti -