<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CPU Spike due to &amp;quot;fw_full&amp;quot; and &amp;quot;unknown&amp;quot; top consumer in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197183#M36805</link>
    <description>&lt;P&gt;After checking to ensure debugs aren't enabled (&lt;SPAN&gt;sk172047) I would recommend engaging TAC to review the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;They will request more information from spike detective / cpinfo / cpview / HCP as relevant to isolating the problem further.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Nov 2023 13:00:04 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-11-06T13:00:04Z</dc:date>
    <item>
      <title>CPU Spike due to "fw_full" and "unknown" top consumer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197151#M36794</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have a cluster gateway with R81.20, installed with the latest hotfixes (T26).&lt;/P&gt;&lt;P&gt;Recently I encountered that the CPU usage of the gateways will spike for a period of seconds. From the spike detector logs, we saw that the CPU spike is caused by the top consumer named "fw_full" and "unknown" for 5th and 6th November.&lt;/P&gt;&lt;P&gt;Active Gateway:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-06 155229.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23050iF0C4A18517B29D54/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-06 155229.png" alt="Screenshot 2023-11-06 155229.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Standby Gateway:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-06 155350.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23051iFFFECF856B78B742/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-06 155350.png" alt="Screenshot 2023-11-06 155350.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Anyone has any idea will caused these things happen?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much. Appreciate it.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 07:56:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197151#M36794</guid>
      <dc:creator>BigHec</dc:creator>
      <dc:date>2023-11-06T07:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: CPU Spike due to "fw_full" and "unknown" top consumer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197183#M36805</link>
      <description>&lt;P&gt;After checking to ensure debugs aren't enabled (&lt;SPAN&gt;sk172047) I would recommend engaging TAC to review the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;They will request more information from spike detective / cpinfo / cpview / HCP as relevant to isolating the problem further.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 13:00:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197183#M36805</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-06T13:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: CPU Spike due to "fw_full" and "unknown" top consumer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197199#M36815</link>
      <description>&lt;P&gt;When you open the TAC case, please have this information ready and upload it to the case. It will save time because you will be asked to do so. Do the cpinfos from all devices (Bad gateway, good gateway, management).&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 15:11:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197199#M36815</guid>
      <dc:creator>Jim_Holmes</dc:creator>
      <dc:date>2023-11-06T15:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: CPU Spike due to "fw_full" and "unknown" top consumer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197260#M36834</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1795"&gt;@Jim_Holmes&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the suggestion. Will try to disable the debug first and if the issue still persist then I will open a TAC case for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate it.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 01:45:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197260#M36834</guid>
      <dc:creator>BigHec</dc:creator>
      <dc:date>2023-11-07T01:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: CPU Spike due to "fw_full" and "unknown" top consumer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197277#M36840</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1795"&gt;@Jim_Holmes&lt;/a&gt;&amp;nbsp;&amp;amp;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found out that in the fwd.elg file, there is an update process called "ciu_cmd_kss_commit_set_updater_cur_dir" running every 4 hours and it causes the spike of the CPU utilization. But it does not causes the spike everytime the process run, just sometimes the CPU will spike.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-07 165013.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23077i292F7EAA2F80AE07/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-07 165013.png" alt="Screenshot 2023-11-07 165013.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Do you guys have any idea on this process and what does this process do?&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 08:54:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197277#M36840</guid>
      <dc:creator>BigHec</dc:creator>
      <dc:date>2023-11-07T08:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: CPU Spike due to "fw_full" and "unknown" top consumer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197332#M36868</link>
      <description>&lt;P&gt;Almost certainly this:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk174347" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk174347: Software blade updates may cause single CPU spikes&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 14:45:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/197332#M36868</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-11-07T14:45:48Z</dc:date>
    </item>
    <item>
      <title>Re: CPU Spike due to "fw_full" and "unknown" top consumer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/200191#M37556</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;Im experiencing a similar issue myself with R81.20 Take 26 and random "fw_full" spikes, causing VSX/VS Failover.&lt;BR /&gt;Would be interessting to hear if you were able to solve the issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2023 14:16:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/200191#M37556</guid>
      <dc:creator>PetterD</dc:creator>
      <dc:date>2023-12-11T14:16:41Z</dc:date>
    </item>
    <item>
      <title>Re: CPU Spike due to "fw_full" and "unknown" top consumer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/200260#M37571</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Previously I did opened a TAC case and the TAC is still in progress of investigating this issue. For what they mention is that this is an issue that is happening in the cluster environment of R81.20. In my case is that the CPU will spike every 4 hours, consistently on Standby member and lesser on Active member. For now TAC checked and comeback with only a SK mentioning the update of IPS/Application packages and are normal and expected behaviour for the CPU to spike.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to know why does the Standby member spikes more compared to the Active member when the Active member is also handling the daily traffic.&lt;/P&gt;&lt;P&gt;No fix provided yet at the moment. Still in progress of investigating.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk174347" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk174347&lt;/A&gt;&amp;nbsp;(SK given by TAC)&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 01:09:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/200260#M37571</guid>
      <dc:creator>BigHec</dc:creator>
      <dc:date>2023-12-12T01:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: CPU Spike due to "fw_full" and "unknown" top consumer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/200602#M37676</link>
      <description>&lt;P&gt;I had a similar issue with a customer, but it was never fully confirmed whether this was the root cause of our problem. With this customer, these spikes resulted in downtime. Sometimes the active member would just stall for a short time without triggering a failover, affecting all traffic passing the gateway, other times it would failover but then the standby member would stall for a short time causing the same issue with traffic passing the gateway.&lt;/P&gt;
&lt;P&gt;All debugs pointed to software blade updates, causing the spikes when the stalling occurred. But we did receive a hotfix for it, but the issue continued even with the hotfix applied. Sadly, the troubleshooting with TAC took so long that we reverted from R81.20 to R81.10. The problems were with R81.20 - JHF Take 8, Take 10, Take 14 and Take 24, which was the latest JHF before we decided to revert. The issue has yet to happen on R81.10 for this customer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Difficult to jump to any conclusions based on this. I wouldn't expect R81.10 and R81.20 to behave differently when updating software blades. But there might be other differences within the software, making the installation of this customer have issues when these updates occur when running R81.20 compared to running R81.10. Who knows.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 11:04:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPU-Spike-due-to-quot-fw-full-quot-and-quot-unknown-quot-top/m-p/200602#M37676</guid>
      <dc:creator>RamGuy239</dc:creator>
      <dc:date>2023-12-14T11:04:02Z</dc:date>
    </item>
  </channel>
</rss>

