Website Migration Notice: SafePoint is now operated by CyberServal.Learn more →
DiscussionSLA

Safeline 3.1.0 – Intermittent Full Freeze

Published 4 months ago

# SafeLine WAF
# ❓ question

Published 4 months ago

profile_photo

kekw

Updated 4 months ago

0

Hi everyone,
we’ve experienced two complete Safeline freezes over the past two weeks and wanted to share some relevant observations and logs in case this is helpful for further investigation.


Observed Symptoms
• No traffic passes through Safeline
• Management UI becomes completely unreachable
• All containers remain running (no crash / no restart)
• No OOM events
• No file descriptor exhaustion
• Restarting the stack immediately restores functionality

Environment:
• Safeline 3.1.0
• Docker on VM
• 6 vCPU / 16 GB RAM


safeline-dector

flush T1K packet error: Broken pipe (os error 32)
failed to send web log: client error (Connect)

safeline-mgt

read udp 127.0.0.1:xxxxx -> 127.0.0.11:53: i/o timeout
failed to get website
failed to get log webs

safeline-fvm

read udp 127.0.0.1:xxxxx -> 127.0.0.11:53: i/o timeout

Observations
• During the freeze, multiple Safeline components appear unable to reach internal services
• Several log entries show repeated timeouts when communicating via UDP/53
• After a restart, everything recovers immediately without configuration changes

We’re currently reviewing all logs in more detail, but wanted to share this early in case it correlates with known issues or ongoing internal investigations.


Question

Could this behavior potentially be:
• a known issue in Safeline 3.1.0, or
• something that could be investigated internally (e.g. internal service communication, DNS handling, or error recovery)?

Happy to provide:
• full logs
• timestamps
• docker-compose setup

profile_photo

kekw

Updated 4 months ago

0

Additional context:

  • We are running Safeline with a relatively large number of rule groups and custom rules
  • Bot Protection is enabled and actively in use

Are there any known limits, scaling considerations, or best practices regarding:

  • number of rule groups / rules
  • Bot Protection under sustained or high traffic
  • internal queues, workers, or resource thresholds

We’d like to understand if configuration size or rule complexity could contribute to this behavior.

profile_photo

Carrie

Updated 4 months ago

0

This version is quite old, so unexpected issues are possible, and it’s difficult for us to troubleshoot.
But the newer versions are currently running stably, and no customers have reported similar problems.
Would you consider upgrading to a newer version?

profile_photo

kekw

Updated 4 months ago

0

Safeline 9.3.1 – Intermittent Full Freeze

profile_photo

kekw

Updated 4 months ago

0

Hi Carrie,
We are using version 9.3.1 - I had a typo..

profile_photo

Carrie

Updated 4 months ago

0

Our technician said it currently appears to be an issue with network fluctuations or DNS cache timeouts on your side. WAF’s rules and configurations do not affect this DNS resolution functionality.

Safeline 3.1.0 – Intermittent Full Freeze | CyberServal | CyberServal