Home > Cloud, Microsoft, System Center, Virtualization > Hyper-V. CSV Volumes pause states 5120‏: Workaround

Hyper-V. CSV Volumes pause states 5120‏: Workaround


Microsoft is aware that after installing KB3126593 (MS16-014) there may be an issue that causes loss of network packets.

This may cause Cluster Shared Volumes (CSV) on the nodes Failover Clusters to going into a paused state with an event ID 5120 in the System event log what indicates “Status c000020c – STATUS_CONNECTION_DISCONNECTED”. 

You will also find that, on the node that owns the CSV volume(s), there will be an event 7031 with the source: “Service Control Manager”, which indicates “The Windows Firewall Service terminated unexpectedly”. 

Troubleshooting Cluster Shared Volume Auto-Pauses – Event 5120. https://blogs.msdn.microsoft.com/clustering/2014/12/08/troubleshooting-cluster-shared-volume-auto-pauses-event-5120/

Microsoft is aware of this problem and are working on a fix. But until it is release here is what you could do to get around this issue:

Option 1: Disable the Firewall LOGGING for all profiles (domain, private, public). (just the logging, not the firewall . You don’t want to be un-protected)

1.  Start the Windows Firewall with Advanced Security management console (wf.msc)

2.  Right-click Windows Firewall with Advanced Security on Local Computer and select Properties

3.  For all profiles (Domain, Private, Public), under Logging, click Customize. Set Log Dropped Packets and Log Successful connections to NO.

Option 2. Uninstall https://support.microsoft.com/en-us/kb/3126593 from the systems.

I will post an update once Microsoft releases the Hotfix.

  1. Rachon Mincey
    November 23, 2016 at 04:03

    HI Alessandro.
    We are experiencing a similar issue. Have you heard back form microsoft regarding a fix?

    • November 24, 2016 at 10:32

      What version are you running? This was fixed by a Windows Update. Is your server up o date?

  2. Abhinav
    October 17, 2017 at 07:56

    Hi Alessandro,

    I am facing this issue since last 2 months and all attempts to fix this issue have been exhausted. Infra is running on a 4 node HyperV cluster 2012R2 and updated with latest patches until Sep2017. We see very frequent cav paused issues and Usually the backups fail when we see these events.

    A funny observation, when we pause one of the nodes and stop the cluster service on them, these events disappear, sometimes for 2-3 weeks. Do you know if there is a hotfix available for this ?

    Appreciate any help on this!

    • October 31, 2017 at 22:20

      Hi Abhinav
      Do you still see CSV volume pauses after applying the updates? What the error log says? What is the error number?

  3. Rahul Jumde
    November 23, 2018 at 13:39

    Do we have fix available now to resolve this issue?


  1. No trackbacks yet.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

%d bloggers like this: