> Source: [sk178225](https://support.checkpoint.com/results/sk/sk178225)

# sk178225 - "mux_passive_capture_context: ERROR: Failed to perform capture" errors flood the messages files

| Property | Value |
|----------|-------|
| Solution ID | sk178225 |
| Date Created | 2022-06-29 |
| Last Modified | 2022-07-06 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |

## Symptoms

- * fwk.elg or /var/log/messages files are flooded with these errors:  
  `
  [DATE TIME] Gateway kernel: [fw4_28];psl_capture_forensics_ex: could not allocate forensicsh`  
  `
  [DATE TIME] Gateway kernel: [fw4_28];mux_passive_capture_context: ERROR: Failed to perform capture.`  
  `
  [DATE TIME] Gateway kernel: [fw4_28];mux_handle_capture_context: ERROR: Failed to capture context.`  
  `
  [DATE TIME] Gateway kernel: [fw4_28];mux_perform_capture: ERROR: Failed to handle capture context.`  
  `
  [DATE TIME] Gateway kernel: [fw4_28];advp_mux_read_handler_ex: ERROR: Failed to perform packet capture.`  
  `
  [DATE TIME] Gateway kernel: [fw4_28];forensics_new: failed to send start kmsg`

* acapd.elg is full of the following logs that indicates the source ip of the enormous traffic capture forensics.  
  `
  [acapd PID]@Gateway[DATE TIME] capd_trap_handler: closing file=`  
  `
  /opt/CPsuite-R80.40/fw1/tmp/amw/time1639111546.idb0409710.blade02.cap id=b0409710 user=172.22.22.22_0.0.0.0`

* There are tons of IPS log displayed in the SmartConsole that only contains 'Packet Capture' information. You can only get the traffic details from the Packet Capture file.  

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk178225/IPS_Log_Details202203071656102.png)

* In kernel debug: \[**`# fw ctl debug -m fw + drop conn vm ips log dynlog cmi`** \], you see indication that an exception rule is matched:  

  `@;1979984;DATE TIME;[vs_0];[tid_2];[fw4_2];ips_get_tp_action_by_prot_id: ipspkg prot_id(32bit)=0x96574b79 severity=3 performance=2 confidence=0 flags=0xa;`  
  `
  @;1979984;DATE TIME;[vs_0];[tid_2];[fw4_2];ips_get_tp_action_by_prot_id: rule_id=2 profile=1(Optimized) `**excp=1**` action=1 track=0 ;`  
  `
  @;1979984;DATE TIME;[vs_0];[tid_2];[fw4_2];cmi_handle_action: prot_id(32bit)=0x96574b79 severity=3 performance=3 flags=0xa action=1 `**pcap_enable=1**` `  
  `
  is_silent=0 session_id=0ips_update_dyn_log_args: received log_nargs to: 4;`

## Cause

There is a Threat Prevention exception with Action: **Detect** and Track: **None** configured, and there is much traffic that triggers this exception. The error logs are printed when there is not enough space in the trap buffer for the packet capture forensics because of the high match rate.  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk178225/Exception_Rule202203071653031.png)  

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
