Datapathd 4761 firewalldp [ERROR] Memory resource from hugepage exhausted in the firewall service
search cancel

Datapathd 4761 firewalldp [ERROR] Memory resource from hugepage exhausted in the firewall service

book

Article ID: 413441

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Gateway Firewall drops traffic during a burst in activity. There is an Edge Datapath Mempool Alarm around the same time.
  • Virtual machines may have unexplained connection interruptions 
  • Exchange email delivery delays or failures.
  • Dropped DNS traffic on Tier-0 or Tier-1 Gateways.
  • Edge Health Alarm : Edge Datapath Mempool High

Edge syslog (/var/log/syslog)

2025-09-03T15:19:26.084Z ####-edge03.####.com NSX 4761 FIREWALL [nsx@6876 comp="nsx-edge" subcomp="datapathd" s2comp="firewalldp" level="ERROR"]  message repeated 412 times: [Memory resource from hugepage exhausted in the firewall service size=1128(0M)]

2025-09-03T15:19:26.210Z #######-edge03.#####.com ##### #### - -  message repeated 77 times: [ 2025-09-03T15:19:26Z datapathd 4761 firewalldp [ERROR] Memory resource from hugepage exhausted in the firewall service size=1128(0M) ]

2025-09-03T15:19:25.423Z ###-edge03.####.com NSX 4761 FIREWALL [nsx@6876 comp="nsx-edge" subcomp="datapathd" s2comp="firewalldp" level="ERROR"] Dropped 826 log messages in last 23245 seconds (most recently, 23244 seconds ago) due to excessive rate

2025-09-03T15:19:26.002Z #####-edge03.####.com datapath-systemd-helper 4585 - -  2025-09-03T15:19:26Z datapathd 4761 firewalldp [ERROR] Memory resource from hugepage exhausted in the firewall service size=1128(0M)

Environment

VMware NSX

VMWare NSX-T Datacenter

Cause

Memory is exhausted on the Edge Node due to traffic burst.  During these bursts, there is inadequate memory for new flows, causing packets to drop.

In this case there is stateful default firewall enabled on Logical Routers and there appears to be a lot of hits from a burst of traffic that occurs on the Logical Router thus using up all the memory.

Resolution

Fixed in NSX 4.2.4 and higher. See Download Broadcom products, patches and software to download this release.

Workarounds

If an upgrade cannot be performed immediately, use one of the following methods to clear the affected mempools:

  1. Edge Failover and Reboot:

    • Schedule a maintenance window.
    • Fail over the active Edge node to its standby peer.
    • Place the affected Edge into NSX maintenance mode.
    • Reboot the Edge node to clear the memory pools.
    • Exit maintenance mode and repeat for the peer node.
  2. Restart Dataplane Service:

    • Log in to the Edge CLI.
    • Run the command: restart service dataplane. Note: This causes a brief traffic interruption.
  1. Rule Optimization:

    • Evaluate if stateful firewall rules can be replaced with stateless rules to reduce pool consumption for high-volume traffic.
    • If stateful firewall is needed, the Edge Node will need to be resized appropriately to handle the traffic flows.

Additional Information

For collecting and analyzing DPDK Memory Usage open a ticket with Broadcom Support

Install the Python Script in this KB article:  Edge Datapath Stats Collection script for 3.x, 4.0 and 4.1

Upload the dp-stats.log files to your case.