# Crowdsec-firewall-bouncer ipset error : exit status 1

**URL:** <https://discourse.crowdsec.net/t/crowdsec-firewall-bouncer-ipset-error-exit-status-1/1900>\
**Category:** crowdsec\
**Created:** [June 30, 2024, 10:56am UTC](https://discourse.crowdsec.net/t/crowdsec-firewall-bouncer-ipset-error-exit-status-1/1900 "2024-06-30T10:56:59Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![kepon](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/kepon/32/919_2.png) [@kepon](https://discourse.crowdsec.net/u/kepon)\
**Post date:** [June 30, 2024, 10:56am UTC](https://discourse.crowdsec.net/t/crowdsec-firewall-bouncer-ipset-error-exit-status-1/1900/1 "2024-06-30T10:56:59Z")

</div>

Good morning,

I get an error “ipset clean-up: /usr/sbin/ipset -exist destroy crowdsec-blacklists” when I try to stop the crowdsec-firewall-bouncer service:

```auto
==> /var/log/crowdsec-firewall-bouncer.log <==
time="30-06-2024 12:42:46" level=info msg="Shutting down backend"
time="30-06-2024 12:42:46" level=info msg="iptables clean-up : /usr/sbin/iptables -D INPUT -m set --match-set crowdsec-blacklists src -j DROP"
time="30-06-2024 12:42:46" level=info msg="ipset clean-up : /usr/sbin/ipset -exist destroy crowdsec-blacklists"
time="30-06-2024 12:42:46" level=error msg="set destroy error : exit status 1 - ipset v7.10: Set cannot be destroyed: it is in use by a kernel component\n"
time="30-06-2024 12:42:46" level=info msg="iptables clean-up : /usr/sbin/ip6tables -D INPUT -m set --match-set crowdsec6-blacklists src -j DROP"
time="30-06-2024 12:42:46" level=info msg="ipset clean-up : /usr/sbin/ipset -exist destroy crowdsec6-blacklists"
time="30-06-2024 12:42:46" level=error msg="set destroy error : exit status 1 - ipset v7.10: Set cannot be destroyed: it is in use by a kernel component\n"
time="30-06-2024 12:42:46" level=fatal msg="process terminated with error: received SIGTERM"

```

And indeed in ipset, crowdsec6-blacklists persists!

However, if I run the command given in the log by hand it works without error / return 1:

```auto
# /usr/sbin/ipset -exist destroy crowdsec6-blacklists
# echo $?
0
# 

```

It’s not harmful because the iptables entry is no longer there, but it shouldn’t be normal either:

```auto
# ipset list crowdsec-blacklists | head
Name: crowdsec-blacklists
Type: hash:net
Revision: 6
Header: family inet hashsize 16384 maxelem 131072 timeout 300
Size in memory: 1361416
References: 0
Number of entries: 29073
Members:
XXXXXXX timeout 563435
XXXXXXXX timeout 577838
# iptables -L | grep crow
DROP all -- anywhere anywhere match-set crowdsec-blacklists sr
# service crowdsec-firewall-bouncer stop
# iptables -L | grep crow
# ipset list crowdsec-blacklists | head
Name: crowdsec-blacklists
Type: hash:net
Revision: 6
Header: family inet hashsize 16384 maxelem 131072 timeout 300
Size in memory: 1361416
References: 0
Number of entries: 29073
Members:
XXXXXXX timeout 563400
XXXXXXXX timeout 577803

```

My Crowdsec :

```auto
# crowdsec --version
version: v1.6.2-debian-pragmatic-amd64-16bfab86
Codename: alphaga
BuildDate: 2024-05-31_09:15:34
GoVersion: 1.22.2
Platform: linux
libre2: C++
User-Agent: crowdsec/v1.6.2-debian-pragmatic-amd64-16bfab86-linux
Constraint_parser: >= 1.0, <= 3.0
Constraint_scenario: >= 1.0, <= 3.0
Constraint_api: v1
Constraint_acquis: >= 1.0, < 2.0

```

I found related topics without an answer to this problem:

- [Error in crowdsec-firewall-bouncer log](https://discourse.crowdsec.net/t/error-in-crowdsec-firewall-bouncer-log/1698)
- [Failed to start The firewall bouncer - #8 by Aukfood](https://discourse.crowdsec.net/t/failed-to-start-the-firewall-bouncer/973/8)

Thank you and thank you for Crowdsec!
