Description

With Advanced Anti-Malware (AAMW) policy enabled, intermittent traffic loss may be observed when the system encounters high memory usage due to a large number of files or URLs with unidentified IDs for AAMW. During this condition, the following error message is often logged: "Memory shortage in fail-close mode"

Symptoms

With Advanced Anti-Malware (AAMW) policy configured on all SRX platforms, this issue can arise when there is high memory allocation by AAMW due to a large number of files or URLs with unidentified IDs.

 

When this happens, AAMW traceoptions may log messages such as "memory shortage in fail close mode" and "need file id or crc32"

 

Sample traceoptions:

Jan  8 23:20:00 13:21:08.959838:CID-1:RT:JSF-AAMW: sess XXXXXXXXXXX content decoded offset 0 length 1460 need file id or crc32

Jan  8 13:21:09 13:21:08.862573:CID-1:RT:jsf_aamw_plugin_handle_http_ctxt_info: uri /pr/xxx/xxx/xxx/xxx

 

Above logs indicate that the system is experiencing memory constraints while processing unidentified files or URLs.

Solution

This issue has been observed on SRX Platform running the following versions: 24.4R1, 23.4R2-S4, 22.2R3-S5 & below

 

The fix for this issue is going to be available in 24.4R2, 25.1R1, 25.2R1 and higher releases

 

Please refer PR1851786 for more information on this

 

Workaround:

- Filter URLs or files with unidentified IDs from AAMW scanning.

- Can disable AAMW on specific policy to avoid to scan the files which should avoid the issue occurring

Modification History

2025-02-26 : Article Created