ipfw.ReachedMaxStates Due to Excessive TLSv1.3 Connections to StorageGRID
Applies to
- ONTAP 9
- TLSv1.3
- StorageGrid
Issue
- EMS repeatedly logs
ipfw.ReachedMaxStatesfrom ONTAP intercluster LIF IP to StorageGrid IP-
Mon Apr 27 19:45:15 -0400 [node01: OscHighPriThreadPoo: ipfw.ReachedMaxStates:notice]: The ipfw firewall failed to create dynamic "keep-state" entry. Reason: Dynamic entries for 'keep-state' rules allocation failure, current # of entries: 31776. Recent connections reaching this limit:[x.x.x.x]:11090->[y.y.y.y]:10443 (TCP):32768;[x.x.x.x]:11091->[y.y.y.y]:10443 (TCP):32768;[x.x.x.x]:11092->[y.y.y.y]:10443 (TCP):32768;[x.x.x.x]:54768->[y.y.y.y]:10443 (TCP):31776;[x.x.x.x]:11089->[y.y.y.y]:10443 (TCP):32768;
-
