> Source: [sk159972](https://support.checkpoint.com/results/sk/sk159972)

# sk159972 - "Table kbufs - Invalid handle xxxxxxxx (bad entry)" errors are filling the /var/log/messages file

| Property | Value |
|----------|-------|
| Solution ID | sk159972 |
| Date Created | 2019-08-07 |
| Last Modified | 2021-01-09 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * The following logs fill up /var/log/messages files:  

  `
  [DATE TIME] gateway kernel: [fw4_24];fwhandle_get(cphwd_crypt.c:2145): Table kbufs - Invalid handle b5b28000 (bad entry) `  
  `
  [DATE TIME] gateway kernel: [fw4_24];Assertion 0 failed in kiss_handles.c:482 `  
  `
  [DATE TIME] gateway kernel: [fw4_24];fwhandle_get: Invalid handle `

* The ClusterXL is in HA mode. When there is a fail-over, the customer lose S2S VPN connectivity randomly.

* Running kernel debug ("fw ctl zdebug drop") the following logs are seen:  

  `
  ;[cpu_8];[fw4_0];fw_log_drop_conn: Packet < dir 1, x.x.x.x:80 - > y.y.y.y:53818 IPP 6 >, dropped by do_outbound, Reason: encryption failed;`

## Solution

**This problem was fixed. The fix is included in:**

* **[Check point R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122485)**
* **[Check Point R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk144293)**

**Check Point recommends to always upgrade to the most recent version ([IPSec VPN](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=446) / [ClusterXL](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=428))**.

If you do not wish to upgrade, [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue. A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix. For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.

**Hotfix installation instructions:**

1. Hotfix has to be installed on ***Security Gateway / each cluster member and on Security Management Server / Multi-Domain Security Management Server***.

   **Note:** In cluster environment, this procedure must be performed on *all* members of the cluster.   
   **Note:** In Management HA environment, this procedure must be performed on *both* Management Servers.
2. Procedure:

   * Using CPUSE - On Security Gateway / Management Server running Gaia OS:

     Make sure to install the [latest build of the CPUSE Agent](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest build of CPUSE and What's New).

     Refer to [sk92449: CPUSE - Gaia Software Updates (including Gaia Software Updates Agent)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE):
     * Section "[(4-A-c)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE - How to download and import a CPUSE package - Import instructions for Offline procedure - Gaia Portal)" / "[(4-A-d)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE - How to download and import a CPUSE package - Import instructions for Offline procedure - Gaia Clish)" - refer to import instructions for *Offline procedure*
     * Section "[(4-B-a)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE - How to install a CPUSE package - Installing a Hotfix package / Minor Version package)" - refer to installation instructions for *Hotfixes*

     You can also use the [sk111158 - Central Deployment Tool (CDT)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111158) to install this hotfix on Security Gateways.

     **Note:** Reboot is required.
   * Using Legacy CLI - On VSX Gateway running Gaia OS R77.30 and lower; On Security Gateway / Management Server running SecurePlatform/Linux/IPSO OS:

     Note: You must be connected either over Console, or LOM card (SSH session could be disconnected). On VSX versions R77.30 and lower, the Gaia CPUSE does not support installation of hotfixes (refer to [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#System requirements and limitations) - section "(2)" - "VSX Gateways").
     1. Transfer the hotfix package to the machine (into some directory, e.g., */some_path_to_fix/*).

     2. Unpack and install the hotfix package:

        ***\[Expert@HostName\]# cd /some_path_to_fix/***   
        ***\[Expert@HostName\]# tar -zxvf fw1_wrapper_\<HOTFIX_NAME\>.tgz***   
        ***\[Expert@HostName\]# ./fw1_wrapper_\<HOTFIX_NAME\>***
        **Note:** The script will stop all of Check Point services (*cpstop*) - read the output on the screen.
     3. Reboot the machine.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
