Добрый день!
Сегодня на работе произошел сбой в работе VPN с г. Самара на криптошлюзе, назовем его vpncc. При этом в Check Point SmartMonitor все VPN-туннели имели статус “Up” , но в журнале SmartView Tracker постоянно шли сообщения вида: "encryption fail reason: Packet is dropped because there is no valid SA".
При анализе системных журналов активного узла кластера vpncс было выявлено большое кол-во записей о системных ошибках в работе libssp:
Oct 9 10:49:21 vpncс libssp[29514]: cpcsp:!CPCAcquireContext!: CPCSPNewHandle failed!
Oct 9 10:49:21 vpncс libssp[29514]: capi10:!CryptGenRandom!() invalid argument(s)!!
Oct 9 10:49:21 vpncс libssp[29514]: cpcsp:!CPCAcquireContext!: CPCSPNewHandle failed!
Oct 9 10:49:21 vpncс libssp[29514]: capi10:!CryptGenRandom!() invalid argument(s)!!
Oct 9 10:49:51 vpncс shell: cmd by admin: less /var/log/messages
Oct 9 10:49:56 vpncс libssp[29514]: cpcsp:!CPCCreateHash!: CPCSPNewHandle failed!
Oct 9 10:49:57 vpncс libssp[29514]: cpcsp:!CPCImportKey!: CPCSPNewHandle failed!
Oct 9 10:49:57 vpncс libssp[29514]: capi10:!CryptDuplicateKey!() invalid argument(s)!!
Oct 9 10:49:57 vpncс libssp[29514]: capi10:!CryptDestroyKey!() invalid argument(s)!!
Oct 9 10:49:57 vpncс libssp[29514]: capi10:!CryptDestroyHash!() invalid argument(s)!!
Oct 9 10:50:00 vpncс libssp[29514]: cpcsp:!CPCImportKey!: CPCSPNewHandle failed!
Oct 9 10:50:00 vpncс libssp[29514]: capi10:!CryptDuplicateKey!() invalid argument(s)!!
Oct 9 10:50:00 vpncс libssp[29514]: capi10:!CryptDestroyKey!() invalid argument(s)!!
Oct 9 10:50:00 vpncс libssp[29514]: capi10:!CryptDestroyHash!() invalid argument(s)!!
Oct 9 10:50:01 vpncс libssp[29514]: cpcsp:!CPCAcquireContext!: CPCSPNewHandle failed!
Oct 9 10:50:01 vpncс libssp[29514]: cpcsp: CPCAcquireContext (pszContainer=\\.\HDIMAGE\3a72da48, dwFlags=0x60). Result=0, Err=0x8009000e. hProv=0.
Oct 9 10:50:02 vpncс shell: cmd by admin: less /var/log/messages
Oct 9 10:50:12 vpncс libssp[29514]: cpcsp:!CPCAcquireContext!: CPCSPNewHandle failed!
Oct 9 10:50:12 vpncс libssp[29514]: capi10:!CryptGenRandom!() invalid argument(s)!!
Oct 9 10:50:21 vpncс libssp[29514]: cpcsp:!CPCAcquireContext!: CPCSPNewHandle failed!
Oct 9 10:50:21 vpncс libssp[29514]: capi10:!CryptGenRandom!() invalid argument(s)!!
Oct 9 10:50:48 vpncс libssp[29514]: cpcsp:!CPCImportKey!: CPCSPNewHandle failed!
Oct 9 10:50:48 vpncс libssp[29514]: capi10:!CryptDuplicateKey!() invalid argument(s)!!
Oct 9 10:50:48 vpncс libssp[29514]: capi10:!CryptDestroyKey!() invalid argument(s)!!
Oct 9 10:50:48 vpncс libssp[29514]: capi10:!CryptDestroyHash!() invalid argument(s)!!
Oct 9 10:50:56 vpncс libssp[29514]: cpcsp:!CPCCreateHash!: CPCSPNewHandle failed!
Oct 9 10:51:02 vpncс libssp[29514]: cpcsp:!CPCImportKey!: CPCSPNewHandle failed!
Oct 9 10:51:02 vpncс libssp[29514]: capi10:!CryptDuplicateKey!() invalid argument(s)!!
Oct 9 10:51:02 vpncс libssp[29514]: capi10:!CryptDestroyKey!() invalid argument(s)!!
Oct 9 10:51:02 vpncс libssp[29514]: capi10:!CryptDestroyHash!() invalid argument(s)!!
Oct 9 10:51:02 vpncс libssp[29514]: cpcsp:!CPCAcquireContext!: CPCSPNewHandle failed!
Oct 9 10:51:02 vpncс libssp[29514]: cpcsp: CPCAcquireContext (pszContainer=\\.\HDIMAGE\3a72da48, dwFlags=0x60). Result=0, Err=0x8009000e. hProv=0.
Oct 9 10:51:21 vpncс libssp[29514]: cpcsp:!CPCAcquireContext!: CPCSPNewHandle failed!
Oct 9 10:51:21 vpncс libssp[29514]: capi10:!CryptGenRandom!() invalid argument(s)!!
Oct 9 10:51:46 vpncс kernel: FW-1: SIM (SecureXL Implementation Module) SecureXL device detected.
Oct 9 10:51:49 vpncс libssp[29514]: cpcsp:!CPCAcquireContext!: CPCSPNewHandle failed!
Oct 9 10:51:49 vpncс libssp[29514]: capi10:!CryptSetProvParam!() invalid argument(s)!!
Oct 9 10:51:49 vpncс libssp[29514]: capi10:!CryptReleaseContext!() invalid argument(s)!!
Oct 9 10:51:49 vpncс libssp[29514]: cpcsp:!CPCGenKey!: CPCSPNewHandle failed!
Oct 9 10:51:51 vpncс libssp[29514]: cpcsp:!CPCGenKey!: CPCSPNewHandle failed!
Oct 9 10:51:54 vpncс libssp[29514]: cpcsp:!CPCCreateHash!: CPCSPNewHandle failed!
Oct 9 10:51:56 vpncс last message repeated 3 times
Oct 9 10:52:25 vpncс libssp[29514]: cpcsp:!CPCImportKey!: CPCSPNewHandle failed!
Oct 9 10:52:44 vpncс last message repeated 3 times
Oct 9 10:52:51 vpncс ntpdate[14105]: adjust time server 10.10.10.10 offset 0.374960 sec
Oct 9 10:54:49 vpncс libssp[29514]: cpcsp:!CPCCreateHash!: CPCSPNewHandle failed!
Oct 9 10:54:49 vpncс libssp[29514]: capi10:!CryptDestroyKey!() invalid argument(s)!!
Oct 9 10:55:49 vpncс shell: cmd by admin: less /var/log/messages
Подскажите, пожалуйста, где копать и в чем может быть причина?
Спасибо.
Отредактировано пользователем 30 ноября 2012 г. 14:18:44(UTC)
| Причина: Не указана