v4.38 / Memory Warning / AV Cloud Query Bypass ???

USG_User
USG_User Posts: 374  Master Member
5 Answers First Comment Friend Collector Sixth Anniversary
edited April 2021 in Security
Since we've updated our USG110 from v4.35 to v4.38 on yesterday morning, we've received two Alert Log Warnings for two times:

System remaining 94 MB memory, AV Cloud Query bypass is on

... and 5 min later another warning message:

System remaining 233 MB memory, AV Cloud Query bypass is off

And as said above, this night we got both messages from USG again. What does it mean? Could anybody explain this new 4.38 behaviour? Is our USG running out of memory every day?

Accepted Solution

«13

All Replies

  • Zyxel_Charlie
    Zyxel_Charlie Posts: 1,034  Zyxel Employee
    50 Answers 500 Comments Friend Collector Fourth Anniversary
    @USG_User
    System messages: "System remaining x MB memory, AV Cloud Query bypass is on" means that the memory protection mechanism has been triggered by the decreasing resources, which temporarily disables AV Cloud Query (but it will still be verified by local engine)

  • USG_User
    USG_User Posts: 374  Master Member
    5 Answers First Comment Friend Collector Sixth Anniversary
    edited May 2020
    Thanks Charlie. But why this appeared the first time after installing the v4.38? We never experienced any memory issues before. That's why we're a little bit confused. Does v4.38 consumes more memory? Could it lead to temporarily disabled UTM services?

    From my point of view our system resources are ok.

  • USG_User
    USG_User Posts: 374  Master Member
    5 Answers First Comment Friend Collector Sixth Anniversary
    edited May 2020
    This morning, right before official office hours began (means less traffic for USG), we received the alert message again:
    1  System remaining 46 MB memory, UTM features bypass is on
    2  System remaining 46 MB memory, AV Cloud Query bypass is on

    And 5 min later:
    1  System remaining 209 MB memory, UTM features bypass is off
    2  System remaining 209 MB memory, AV Cloud Query bypass is off

    Why the USG consumes so much resources since v4.38? Or is this kind of "memory management" a normal behaviour since ever and only sending an alert message is new in v4.38? In any case we are concerned about temporarily bypassing of UTM features at a firewall.

    Does nobody else experience these memory alerts?


  • Zyxel_Charlie
    Zyxel_Charlie Posts: 1,034  Zyxel Employee
    50 Answers 500 Comments Friend Collector Fourth Anniversary
    @USG_User
    Regarding to this case,
    When the memory is kept on some usage, the UTM feature’s bypass will be turned on, until memory released. However,  it will still be verified by local engine. The message appeared does not the issue, just let users understand device's current status.
  • WMelonMan
    WMelonMan Posts: 10  Freshman Member
    First Comment Friend Collector First Anniversary
    I have this with one customer's USG 60. After updating to 4.38 a few days ago they receive these memory alerts each night (like 01:36 "System remaining 77 MB memory, AV Cloud Query bypass is on"  and  01:41 "System remaining 257 MB memory, AV Cloud Query bypass is off"). It is always 5 minutes long and starting either 01:36 or 02:36.
    But what I would like to know: what is going on each night to drive memory consumption up - when there is much less traffic than during day time??? Maybe there is something wrong??
  • Zyxel_Charlie
    Zyxel_Charlie Posts: 1,034  Zyxel Employee
    50 Answers 500 Comments Friend Collector Fourth Anniversary

    @WMelonMan
    It could be background daemon progress on non-peak time.
    Also, the memory consumption accumulative reach the threshold of AV cloud query around midnight, therefore the action will be on. The action actually will keep for 5 mins to release memory. 

  • WMelonMan
    WMelonMan Posts: 10  Freshman Member
    First Comment Friend Collector First Anniversary
    @Zyxel_Charlie OK, thanks. Anyway it seems since I changed AV screening from "Streaming" mode to the new "Express" that this memory thing is not happening anymore.
  • USG_User
    USG_User Posts: 374  Master Member
    5 Answers First Comment Friend Collector Sixth Anniversary
    Is there an explanation about the new Express Mode available? The Help functionality within the USG which is calling a website is not yet updated.
  • WMelonMan
    WMelonMan Posts: 10  Freshman Member
    First Comment Friend Collector First Anniversary
    Yeah, I' d like to have some details on Express Mode, too! Didn't find anything online!
  • Zyxel_Charlie
    Zyxel_Charlie Posts: 1,034  Zyxel Employee
    50 Answers 500 Comments Friend Collector Fourth Anniversary

    @USG_User &@WMelonMan

    On USG Series, the Help description is just not updated yet and we will update the content soon


Security Highlight