Description

The following KB article explains the reasons behind the failure of security traffic logs configured by the Mist Cloud. The logs are showing the following messages:

  • Apr 15 03:30:13 wp-efw RT_SYSTEM: RTLOG_CONN_ERROR: Connection error app_usage Com 8546 abort
  • Apr 15 03:30:13 wp-efw RT_SYSTEM: RTLOG_CONN_ERROR: Connection error app_usage Error code: major 2 minor 2 code 336151570, description:error:14094412:SSL routines:ssl3_read_bytes:sslv3 alert bad certificates
  • Apr 15 03:30:13 wp-efw RT_SYSTEM: RTLOG_CONN_ERROR: Connection error app_usage status: 0, Error code: major 2 minor 2 code 336151570, description:error:14094412:SSL routines:ssl3_read_bytes:sslv3 alert bad certificate

This section provides an overview of the potential causes, symptoms, and troubleshooting steps to address the issue effectively.

Symptoms

The following symptoms have been observed, indicating issues with the security traffic logs:

  • Unmanaged Configuration: The device's configuration is not managed by the Mist Cloud; it is only being monitored.
  • Chassis Cluster Setup: The setup is a chassis cluster in active/active mode, with some Redundancy Groups (RGs) being primary on both nodes.
  • High CPU Usage: The log messages are causing high CPU utilization on the routing engine.
  • CPU Normalization upon Log Disabling: Disabling these traffic logs results in a significant decrease in CPU usage, confirming that the log messages are the source of the high CPU load.

Solution

The traffic logs are generated from the PFE (Packet Forwarding Engine) instead of the RE (Routing Engine). In this particular setup, one node is handling the RE and the other handling the PFE. Therefore, the node generating the traffic logs is unable to send them because the RPD (Routing Protocol Daemon) is running on the other node. The only way to resolve this is to have all RGs (Redundancy Groups) running on the same node.

Modification History

2024-06-03 : Article Created

Related Information

SRX Getting Started - Configure Traffic Logging (Security Policy Logs) for SRX Branch Devices

Chassis Cluster Redundancy Groups