<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fw_worker_0 using 100% CPU in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13034#M2183</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As the SK from Gunther states, check your fw ctl multik stat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) What version are you running on your gateways? (R77.20/R77.30/R80.10)&lt;/P&gt;&lt;P&gt;2.) Do you have Route based VPN enabled which could cause CoreXL to be disabled (thus pinning all your traffic for VPN to worker_0)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;a.) I had the same issue and the dispatch global parameter did help drop the CPU on worker 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This setting can be made on the fly and then persistent in fwkern.conf. Please note that this only worked for me in R77.20. When I went to R77.30 the dispatch global must now have a check, as I was told by Diamond, their internal notes state that the dispatch global statement (default 0, I set to 1). Can not be equal to or greater than the number of active CPU's when using the command fw multik stat. If you only have 1 active then you cannot use this command in R77.30, the command will take but the parameter will not move off of any setting other than 0.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If CoreXL is enabled you can check your affinity settings (fw ctl affinity -l -v -r) and check where your SND and workers are distributed.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 05 Nov 2018 13:20:52 GMT</pubDate>
    <dc:creator>Mike_A</dc:creator>
    <dc:date>2018-11-05T13:20:52Z</dc:date>
    <item>
      <title>fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13031#M2180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are facing the issue below since 1 week, this looks very difficult for us to troubleshoot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw_worker_0 process is using 100% CPU, this is causing slowness in the connectivity. When checked the SKs, suggests the Application filtering blade is causing the issue. But we did not enable the blade. We have only enabled URL filtering and not Application filtering. Is there any solution to resolve this issue asap.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2018 11:57:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13031#M2180</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2018-11-05T11:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13032#M2181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i would start troubleshooting using&amp;nbsp;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112134&amp;amp;partition=Advanced&amp;amp;product=CoreXL&amp;quot;"&gt;sk112134: How to troubleshoot the issue with CoreXL "&lt;STRONG&gt;fw_worker_0&lt;/STRONG&gt;" consuming &lt;STRONG&gt;CPU&lt;/STRONG&gt; at &lt;STRONG&gt;100%&lt;/STRONG&gt;&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2018 12:38:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13032#M2181</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-11-05T12:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13033#M2182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gateway version and Jumbo HFA level?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2018 13:13:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13033#M2182</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-11-05T13:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13034#M2183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As the SK from Gunther states, check your fw ctl multik stat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.) What version are you running on your gateways? (R77.20/R77.30/R80.10)&lt;/P&gt;&lt;P&gt;2.) Do you have Route based VPN enabled which could cause CoreXL to be disabled (thus pinning all your traffic for VPN to worker_0)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;a.) I had the same issue and the dispatch global parameter did help drop the CPU on worker 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This setting can be made on the fly and then persistent in fwkern.conf. Please note that this only worked for me in R77.20. When I went to R77.30 the dispatch global must now have a check, as I was told by Diamond, their internal notes state that the dispatch global statement (default 0, I set to 1). Can not be equal to or greater than the number of active CPU's when using the command fw multik stat. If you only have 1 active then you cannot use this command in R77.30, the command will take but the parameter will not move off of any setting other than 0.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If CoreXL is enabled you can check your affinity settings (fw ctl affinity -l -v -r) and check where your SND and workers are distributed.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2018 13:20:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13034#M2183</guid>
      <dc:creator>Mike_A</dc:creator>
      <dc:date>2018-11-05T13:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13035#M2184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike, Below is the version we are running on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is Check Point's software version R80.10 - Build 439&lt;BR /&gt;kernel: R80.10 - Build 448&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And CoreXL is not enabled in&amp;nbsp; this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2018 13:26:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13035#M2184</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2018-11-05T13:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13036#M2185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Gunther,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am checking this. Will get back to you if i find something on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2018 13:28:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13036#M2185</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2018-11-05T13:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13037#M2186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Timothy, Below is the version we are on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is Check Point's software version R80.10 - Build 439&lt;BR /&gt;kernel: R80.10 - Build 448&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No HFA is installed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2018 13:29:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13037#M2186</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2018-11-05T13:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13038#M2187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sanjay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a reason you don't have CoreXL enabled? Without CoreXL you are forcing all&amp;nbsp;all processes to be pinned to a single CPU, which, I can only assume, is causing your 100% usage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is an SK (&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105261#Configuration%20R80.10"&gt;sk105261&lt;/A&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;) that references the dynamic dispatcher in R80.10 and how to enable/disable/check and monitor the dispatching across various cores but CoreXL needs to be enabled.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;- Mike&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2018 13:37:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13038#M2187</guid>
      <dc:creator>Mike_A</dc:creator>
      <dc:date>2018-11-05T13:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13039#M2188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No Jumbo installed ? I would not suggest to&amp;nbsp;keep that state...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2018 13:48:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13039#M2188</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-11-05T13:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13040#M2189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have (&lt;SPAN style="text-decoration: underline;"&gt;or had&lt;/SPAN&gt;) you enabled any other blade (besides firewall and url filtering)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a system on R80.20; I turned on IPS; then I turned it off.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, amw remained loaded; one or more fwk_worker processes go up to 100%.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/73178_cpu.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you check whether or not amw is loaded; if it is, just unload it (fw amw unload) and redeploy the policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Nov 2018 15:43:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13040#M2189</guid>
      <dc:creator>Kris_Pellens</dc:creator>
      <dc:date>2018-11-05T15:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13041#M2190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lots of speculation here, but let's cut through it.&amp;nbsp; Please provide outputs from following commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fwaccel stat&lt;BR /&gt;fwaccel stats -s&lt;BR /&gt;grep -c ^processor /proc/cpuinfo&lt;BR /&gt;/sbin/cpuinfo&lt;BR /&gt;fw ctl affinity -l -r&lt;BR /&gt;sim affinity -l&lt;BR /&gt;netstat -ni&lt;BR /&gt;fw ctl multik stat&lt;BR /&gt;cpstat os -f multi_cpu -o 1&lt;BR /&gt;free -m&lt;BR /&gt;enabled_blades&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mentioned initially that you have URLF enabled but not APCL; you almost certainly need to optimize your URLF policy to keep LAN-speed traffic from getting inappropriately inspected in PXL.&amp;nbsp; See my post here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="link-titled" href="https://community.checkpoint.com/message/28972-re-layers-and-the-cleanup-rule?commentID=28972#comment-28972" title="https://community.checkpoint.com/message/28972-re-layers-and-the-cleanup-rule?commentID=28972#comment-28972"&gt;https://community.checkpoint.com/message/28972-re-layers-and-the-cleanup-rule?commentID=28972#comment-28972&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 14:03:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13041#M2190</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-11-06T14:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13042#M2191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for all your replies. Now the CPU looks stable after the below procedure i followed.&lt;/P&gt;&lt;UL style="margin-top: 0in;"&gt;&lt;LI&gt;NAT &amp;amp; Drop Templates are enabled on Secure XL.&lt;/LI&gt;&lt;LI&gt;JHF Take 154 is installed.&lt;/LI&gt;&lt;LI&gt;Enabled CoreXL.&lt;/LI&gt;&lt;LI&gt;Enabled Dynamic Dispatcher.&lt;/LI&gt;&lt;LI&gt;Disabled URL Filtering.&lt;/LI&gt;&lt;LI&gt;Disabled IPS.&lt;/LI&gt;&lt;LI&gt;Optimized rule base and re-arrange few rules.&lt;/LI&gt;&lt;LI&gt;Enabled the IPS Blade.&lt;/LI&gt;&lt;LI&gt;Disabled the ‘Accept outgoing packets originating from Gateway’&lt;/LI&gt;&lt;LI&gt;Disabled IPS and enabled the URL Filtering.&lt;/LI&gt;&lt;LI&gt;Enabled IPS blade again.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So i suspect the issue was with the 'Accept outgoing packets originating from Gateway'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Nov 2018 10:04:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/13042#M2191</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2018-11-26T10:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: fw_worker_0 using 100% CPU</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/56867#M11433</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;maybe you can check out this commands:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;via "top" command u localize the worker process yoz focus on ...&lt;BR /&gt;and then issue this command with the number of the worker ...&lt;BR /&gt;1."echo 1 &amp;gt; /proc/cpkstats/fw_worker_XXX_stats"&lt;BR /&gt;run it for a few seconds, keep it mind this could cause some performance issues ...&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2."cat /proc/cpkstats/fw_worker_XXX_stats"&lt;BR /&gt;it will print you a table with the top F2F SRC and DST pairs … you can search for the most heavy sessions and analyze the traffic …&lt;BR /&gt;so keep in mind it shows only F2F traffic, which is non-accelerated by SecureXL...&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;3."echo 0 &amp;gt; /proc/cpkstats/fw_worker_XXX_stats"&lt;BR /&gt;use this command to finally stop the trace …&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this helped us today to identify a very heavy connection with cause a massive heavy load on a cluster and dropped VPN´s and made work impossible ...&lt;BR /&gt;Check Point TAC showed us this really helpful set of commands!&lt;/P&gt;&lt;P&gt;best regards&lt;BR /&gt;Thomas.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 19:56:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-worker-0-using-100-CPU/m-p/56867#M11433</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2019-06-27T19:56:34Z</dc:date>
    </item>
  </channel>
</rss>

