<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ongoing issue: high CPU load fw_workers + rad in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257917#M43488</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thank you for the reply. This gateway runs kernel mode (open server).&lt;/P&gt;
&lt;P&gt;AV is indeed off and I suspect URL filtering as you state. Below the info &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;fwaccel stat&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|0 |KPPAK |enabled |eth,eth,et,eth,eth,|Acceleration,Cryptography |&lt;BR /&gt;| | | |eth,eth,eth,eth | |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,3DES,DES,AES-128,AES-256,|&lt;BR /&gt;| | | | |ESP,LinkSelection,DynamicVPN, |&lt;BR /&gt;| | | | |NatTraversal,AES-XCBC,SHA256, |&lt;BR /&gt;| | | | |SHA384,SHA512 |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;/P&gt;
&lt;P&gt;Accept Templates : enabled&lt;BR /&gt;Drop Templates : enabled&lt;BR /&gt;NAT Templates : enabled&lt;BR /&gt;LightSpeed Accel : disabled&lt;/P&gt;
&lt;P&gt;fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 56744/159331 (35%)&lt;BR /&gt;LightSpeed conns/Total conns : 0/159331 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 7073015862/7843049171 (90%)&lt;BR /&gt;LightSpeed pkts/Total pkts : 0/7843049171 (0%)&lt;BR /&gt;F2Fed pkts/Total pkts : 770033309/7843049171 (9%)&lt;BR /&gt;F2V pkts/Total pkts : 46691949/7843049171 (0%)&lt;BR /&gt;CPASXL pkts/Total pkts : 0/7843049171 (0%)&lt;BR /&gt;PSLXL pkts/Total pkts : 4516731459/7843049171 (57%)&lt;BR /&gt;CPAS pipeline pkts/Total pkts : 0/7843049171 (0%)&lt;BR /&gt;PSL pipeline pkts/Total pkts : 0/7843049171 (0%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/7843049171 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/7843049171 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/7843049171 (0%)&lt;/P&gt;
&lt;P&gt;enabled_blades&lt;BR /&gt;fw urlf appi SSL_INSPECT anti_bot mon&lt;/P&gt;
&lt;H6&gt;netstat -ni&lt;BR /&gt;Kernel Interface table&lt;BR /&gt;Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg&lt;BR /&gt;bond0 1500 0 5062275688 0 40121615 0 2126175119 0 0 0 BMmRU&lt;BR /&gt;bond1 1500 0 2152513947 0 56495 0 4760528963 0 0 0 BMmRU&lt;BR /&gt;bond1. 1500 0 1677398087 0 0 0 3790216944 0 0 0 BMRU&lt;BR /&gt;bond1. 1500 0 78383194 0 0 0 57714744 0 0 0 BMRU&lt;BR /&gt;bond1. 1500 0 396567854 0 0 0 912479637 0 0 0 BMRU&lt;BR /&gt;bond1. 1500 0 162360 0 0 0 121385 0 0 0 BMRU&lt;BR /&gt;bond 1500 0 614958571 0 9384 0 292962839 0 0 0 BMmRU&lt;BR /&gt;bond. 1500 0 122325 0 0 0 92217 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 148628996 0 0 0 149600414 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 139513 0 0 0 64590 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 2370242 0 0 0 645866 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 892143 0 0 0 658440 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 337976 0 0 0 283213 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 2201586 0 0 0 3536011 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 136321 0 0 0 71281 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 57390 0 0 0 1128 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 2297341 0 0 0 2832088 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37220 0 0 0 916 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 16648876 0 0 0 6172715 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 405374 0 0 0 182786 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 217043683 0 0 0 24524361 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 220033 0 0 0 461297 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 79231 0 0 0 26952 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 137994 0 0 0 67416 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 1668621 0 0 0 756463 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37037 0 0 0 493 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 401068 0 0 0 1324006 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 10312912 0 0 0 6584546 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 98212 0 0 0 40187 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37427 0 0 0 1357 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 236101 0 0 0 123601 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 530658 0 0 0 166934 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 228858 0 0 0 134749 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37100 0 0 0 640 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 175716 0 0 0 106860 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 16603109 0 0 0 15064450 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 59945 0 0 0 12711 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 6823638 0 0 0 7417717 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37037 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 82447 0 0 0 28684 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 130923 0 0 0 63626 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37607 0 0 0 1531 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37223 0 0 0 949 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 155458468 0 0 0 41252481 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 55405 0 0 0 973 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 299659 0 0 0 251380 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 142547 0 0 0 68426 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 200022 0 0 0 134207 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 114065 0 0 0 74458 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 138096 0 0 0 76497 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 121315 0 0 0 52825 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 697260 0 0 0 299303 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 439440 0 0 0 424124 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 157129 0 0 0 89365 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37037 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37037 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37130 0 0 0 790 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 374450 0 0 0 358326 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 361316 0 0 0 505759 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 212428 0 0 0 141488 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 197000 0 0 0 88029 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 51423 0 0 0 32713 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37037 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 101164 0 0 0 7108444 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 2732141 0 0 0 2648311 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 130902 0 0 0 80956 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 11641791 0 0 0 5568622 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 158895 0 0 0 105245 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 157470 0 0 0 106759 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 10197392 0 0 0 12422460 0 0 0 BMRU&lt;BR /&gt;bond3 1500 0 19429548 0 0 0 34003635 0 0 0 BMmRU&lt;BR /&gt;eth 1500 0 1585842395 0 42069 0 2466758424 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 566670978 0 14426 0 2293763935 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 314549649 0 5632 0 138402512 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 300402150 0 3752 0 154560077 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 2605246905 0 20795131 0 1111371041 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 2457032749 0 19326484 0 1014805116 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 17752963 0 0 0 14078407 0 0 0 BMRU&lt;BR /&gt;eth 1500 0 11090635 0 0 0 16358918 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 8338913 0 0 0 17644717 0 0 0 BMsRU&lt;BR /&gt;lo 65536 0 690832 0 0 0 690832 0 0 0 ALdRU&lt;/H6&gt;</description>
    <pubDate>Mon, 22 Sep 2025 14:50:27 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2025-09-22T14:50:27Z</dc:date>
    <item>
      <title>Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257882#M43480</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;At the moment I have an ongoing issue with a customer. Symptoms are as following:&lt;/P&gt;
&lt;P&gt;High CPU load:&lt;/P&gt;
&lt;P&gt;top - 12:50:06 up 9:41, 3 users, load average: 24.71, 12.38, 6.78&lt;BR /&gt;Tasks: 347 total, 30 running, 317 sleeping, 0 stopped, 0 zombie&lt;BR /&gt;%Cpu(s): 2.4 us, 81.9 sy, 0.0 ni, 0.0 id, 0.0 wa, 0.3 hi, 15.4 si, 0.0 st&lt;BR /&gt;KiB Mem : 98087944 total, 69572780 free, 15522848 used, 12992316 buff/cache&lt;BR /&gt;KiB Swap: 67108860 total, 67108860 free, 0 used. 81122528 avail Mem&lt;/P&gt;
&lt;P&gt;PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND &lt;BR /&gt;20460 admin 20 0 216456 103184 25532 R 64.4 0.1 32:58.43 rad &lt;BR /&gt;11626 admin 20 0 0 0 0 R 55.8 0.0 72:38.48 fw_worker_7 &lt;BR /&gt;11628 admin 20 0 0 0 0 R 54.6 0.0 70:53.74 fw_worker_9 &lt;BR /&gt;11623 admin 20 0 0 0 0 R 49.5 0.0 74:40.62 fw_worker_4 &lt;BR /&gt;11624 admin 20 0 0 0 0 R 44.8 0.0 71:14.27 fw_worker_5 &lt;BR /&gt;11627 admin 20 0 0 0 0 R 41.3 0.0 71:24.60 fw_worker_8 &lt;BR /&gt;11625 admin 20 0 0 0 0 R 40.7 0.0 70:17.07 fw_worker_6 &lt;BR /&gt;11622 admin 20 0 0 0 0 R 38.5 0.0 72:11.25 fw_worker_3 &lt;BR /&gt;11619 admin 20 0 0 0 0 R 37.5 0.0 74:28.74 fw_worker_0 &lt;BR /&gt;11620 admin 20 0 0 0 0 R 37.2 0.0 73:07.65 fw_worker_1 &lt;BR /&gt;19952 admin 20 0 940080 353524 49376 R 31.5 0.4 110:26.24 fw_full&lt;/P&gt;
&lt;P&gt;We can see slowly the load increase on the workers and later the RAD daemon.&lt;/P&gt;
&lt;P&gt;RAD shows no errors in the rad dir and SmartConsole. CPU spike log is empty.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Only fix now is to failover to the other member and it starts over. At the moment I have to do failover every 10-15 min.&lt;/P&gt;
&lt;P&gt;TAC case is going on as we speak. Wanted to reach out to the community to have a second check, maybe share some ideas.&lt;/P&gt;
&lt;P&gt;We also upgraded the setup yesterday from take 113 to 115 R81.20 no improvement . Disabled blades: av ips etc same result.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 10:57:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257882#M43480</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-09-22T10:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257901#M43482</link>
      <description>&lt;P&gt;Please provide the output of the following commands, ideally taken while the issue is occurring, prior to failing over:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fwaccel stat&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fwaccel stats -s&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;enabled_blades&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Any chance you are on a Quantum Force 3900/9XXX/19XXX/29XXX or Lightspeed appliance?&amp;nbsp; UPPAK is in play there.&lt;/P&gt;
&lt;P&gt;If URLF is enabled, this could be the URL categorization cache thrashing because you have far more than 1,000 surfing users behind the firewall.&amp;nbsp; This cache is not synced between cluster members, so a failover would fix the issue temporarily.&amp;nbsp; It could also be the AV anti-malware cache thrashing, but it sounds like you tried turning off AV, and the issue persisted.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The only other thing a failover would do is dump all connections out of the Medium Path into the fastpath upon failover by default, which would significantly reduce the CPU load on your firewall worker instances temporarily.&amp;nbsp; This effect upon failover was discussed in my &lt;A href="https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/member-exclusives/881/2/Be%20Your%20Own%20TAC2_2025_thall_FINAL2.pdf" target="_self"&gt;CPX Presentation&lt;/A&gt; which you may want to review.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 13:06:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257901#M43482</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-09-22T13:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257902#M43483</link>
      <description>&lt;P&gt;Apart from what Tim asked for, maybe send us below as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;************&lt;/P&gt;
&lt;P&gt;fw tab -t connections -s&lt;/P&gt;
&lt;P&gt;fw ctl multik print_heavy_conn&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 13:18:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257902#M43483</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-22T13:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257910#M43484</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;in&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/URL-filtering-blade-RAD-process-causing-high-CPU-tip/m-p/246430#M48026" target="_blank" rel="noopener"&gt;&amp;nbsp;URL-filtering-blade-RAD-process-causing-high-CPU-tip&lt;/A&gt;&amp;nbsp;we discussed a few RAD issues.&lt;BR /&gt;In our case with high CPU+RAD we had to disable the RAD autodebug option with&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182859" target="_blank" rel="noopener"&gt;sk182859&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 13:59:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257910#M43484</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2025-09-22T13:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257911#M43485</link>
      <description>&lt;P&gt;Good call&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17503"&gt;@D_W&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 14:03:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257911#M43485</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-22T14:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257915#M43486</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thanks for the tip, autodebug is already disabled &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;We see loads of the following RAD error.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FlowError=RAD request exceeded maximum handing time&lt;/P&gt;
&lt;P&gt;On the other hand, CPU issue is still there and there can be 0 RAD errors at the moment. They have been gone all done and just popped up:&lt;/P&gt;
&lt;P&gt;grep "FlowError=" $FWDIR/log/rad_events/Errors/* | grep -oP '(?&amp;lt;=FlowError=).*' | sort | uniq -c | sort -nr&lt;BR /&gt;483 RAD request exceeded maximum handing time&lt;BR /&gt;15 Failed to fetch Check Point resources. Timeout was reached&lt;BR /&gt;14 Failed to fetch Check Point resources. Couldn't resolve host name&lt;BR /&gt;1 Failed to fetch Check Point resources. Couldn't connect to server&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 14:39:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257915#M43486</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-09-22T14:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257916#M43487</link>
      <description>&lt;P&gt;That error is about connectivity issues. What is using CPu now, RAD or FW workers?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 14:42:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257916#M43487</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-09-22T14:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257917#M43488</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thank you for the reply. This gateway runs kernel mode (open server).&lt;/P&gt;
&lt;P&gt;AV is indeed off and I suspect URL filtering as you state. Below the info &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;fwaccel stat&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|0 |KPPAK |enabled |eth,eth,et,eth,eth,|Acceleration,Cryptography |&lt;BR /&gt;| | | |eth,eth,eth,eth | |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,3DES,DES,AES-128,AES-256,|&lt;BR /&gt;| | | | |ESP,LinkSelection,DynamicVPN, |&lt;BR /&gt;| | | | |NatTraversal,AES-XCBC,SHA256, |&lt;BR /&gt;| | | | |SHA384,SHA512 |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;/P&gt;
&lt;P&gt;Accept Templates : enabled&lt;BR /&gt;Drop Templates : enabled&lt;BR /&gt;NAT Templates : enabled&lt;BR /&gt;LightSpeed Accel : disabled&lt;/P&gt;
&lt;P&gt;fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 56744/159331 (35%)&lt;BR /&gt;LightSpeed conns/Total conns : 0/159331 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 7073015862/7843049171 (90%)&lt;BR /&gt;LightSpeed pkts/Total pkts : 0/7843049171 (0%)&lt;BR /&gt;F2Fed pkts/Total pkts : 770033309/7843049171 (9%)&lt;BR /&gt;F2V pkts/Total pkts : 46691949/7843049171 (0%)&lt;BR /&gt;CPASXL pkts/Total pkts : 0/7843049171 (0%)&lt;BR /&gt;PSLXL pkts/Total pkts : 4516731459/7843049171 (57%)&lt;BR /&gt;CPAS pipeline pkts/Total pkts : 0/7843049171 (0%)&lt;BR /&gt;PSL pipeline pkts/Total pkts : 0/7843049171 (0%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/7843049171 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/7843049171 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/7843049171 (0%)&lt;/P&gt;
&lt;P&gt;enabled_blades&lt;BR /&gt;fw urlf appi SSL_INSPECT anti_bot mon&lt;/P&gt;
&lt;H6&gt;netstat -ni&lt;BR /&gt;Kernel Interface table&lt;BR /&gt;Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg&lt;BR /&gt;bond0 1500 0 5062275688 0 40121615 0 2126175119 0 0 0 BMmRU&lt;BR /&gt;bond1 1500 0 2152513947 0 56495 0 4760528963 0 0 0 BMmRU&lt;BR /&gt;bond1. 1500 0 1677398087 0 0 0 3790216944 0 0 0 BMRU&lt;BR /&gt;bond1. 1500 0 78383194 0 0 0 57714744 0 0 0 BMRU&lt;BR /&gt;bond1. 1500 0 396567854 0 0 0 912479637 0 0 0 BMRU&lt;BR /&gt;bond1. 1500 0 162360 0 0 0 121385 0 0 0 BMRU&lt;BR /&gt;bond 1500 0 614958571 0 9384 0 292962839 0 0 0 BMmRU&lt;BR /&gt;bond. 1500 0 122325 0 0 0 92217 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 148628996 0 0 0 149600414 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 139513 0 0 0 64590 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 2370242 0 0 0 645866 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 892143 0 0 0 658440 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 337976 0 0 0 283213 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 2201586 0 0 0 3536011 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 136321 0 0 0 71281 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 57390 0 0 0 1128 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 2297341 0 0 0 2832088 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37220 0 0 0 916 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 16648876 0 0 0 6172715 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 405374 0 0 0 182786 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 217043683 0 0 0 24524361 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 220033 0 0 0 461297 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 79231 0 0 0 26952 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 137994 0 0 0 67416 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 1668621 0 0 0 756463 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37037 0 0 0 493 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 401068 0 0 0 1324006 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 10312912 0 0 0 6584546 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 98212 0 0 0 40187 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37427 0 0 0 1357 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 236101 0 0 0 123601 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 530658 0 0 0 166934 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 228858 0 0 0 134749 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37100 0 0 0 640 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 175716 0 0 0 106860 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 16603109 0 0 0 15064450 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 59945 0 0 0 12711 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 6823638 0 0 0 7417717 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37037 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 82447 0 0 0 28684 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 130923 0 0 0 63626 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37607 0 0 0 1531 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37223 0 0 0 949 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 155458468 0 0 0 41252481 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 55405 0 0 0 973 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 299659 0 0 0 251380 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 142547 0 0 0 68426 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 200022 0 0 0 134207 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 114065 0 0 0 74458 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 138096 0 0 0 76497 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 121315 0 0 0 52825 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 697260 0 0 0 299303 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 439440 0 0 0 424124 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 157129 0 0 0 89365 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37037 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37037 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37130 0 0 0 790 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 374450 0 0 0 358326 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 361316 0 0 0 505759 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 212428 0 0 0 141488 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 197000 0 0 0 88029 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 51423 0 0 0 32713 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37037 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 101164 0 0 0 7108444 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 2732141 0 0 0 2648311 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 130902 0 0 0 80956 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 11641791 0 0 0 5568622 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 158895 0 0 0 105245 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 157470 0 0 0 106759 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 37034 0 0 0 469 0 0 0 BMRU&lt;BR /&gt;bond. 1500 0 10197392 0 0 0 12422460 0 0 0 BMRU&lt;BR /&gt;bond3 1500 0 19429548 0 0 0 34003635 0 0 0 BMmRU&lt;BR /&gt;eth 1500 0 1585842395 0 42069 0 2466758424 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 566670978 0 14426 0 2293763935 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 314549649 0 5632 0 138402512 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 300402150 0 3752 0 154560077 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 2605246905 0 20795131 0 1111371041 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 2457032749 0 19326484 0 1014805116 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 17752963 0 0 0 14078407 0 0 0 BMRU&lt;BR /&gt;eth 1500 0 11090635 0 0 0 16358918 0 0 0 BMsRU&lt;BR /&gt;eth 1500 0 8338913 0 0 0 17644717 0 0 0 BMsRU&lt;BR /&gt;lo 65536 0 690832 0 0 0 690832 0 0 0 ALdRU&lt;/H6&gt;</description>
      <pubDate>Mon, 22 Sep 2025 14:50:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257917#M43488</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-09-22T14:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257919#M43489</link>
      <description>&lt;P&gt;Do you use external DNS servers like 9.9.9.9? They will eventually block the requests due to too many requests/minute.&lt;BR /&gt;Or maybe you hit a limit at&amp;nbsp;&lt;/P&gt;
&lt;P&gt;$FWDIR/conf/rad_conf.C:&lt;/P&gt;
&lt;P&gt;:max_flows (1000)&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 15:02:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257919#M43489</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2025-09-22T15:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257923#M43491</link>
      <description>&lt;P&gt;Hi Val,&lt;/P&gt;
&lt;P&gt;First we see increased load on the fw_workers, shortly after RAD joins aswell with high load.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RAD errors have been clear most of the day today. We experienced high load without any RAD errors in de relevant folder.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is how it looks '''mid'' issue. Customer notice issues around load average of 25&lt;/P&gt;
&lt;P&gt;top - 17:36:03 up 14:27, 4 users, load average: &lt;STRONG&gt;10.60&lt;/STRONG&gt;, 7.64, 7.45&lt;BR /&gt;Tasks: 350 total, 19 running, 331 sleeping, 0 stopped, 0 zombie&lt;BR /&gt;%Cpu(s): 4.0 us, 78.1 sy, 0.0 ni, 11.4 id, 0.0 wa, 0.5 hi, 6.0 si, 0.0 st&lt;BR /&gt;KiB Mem : 98087944 total, 49163212 free, 15571648 used, 33353084 buff/cache&lt;BR /&gt;KiB Swap: 67108860 total, 67108860 free, 0 used. 81177276 avail Mem&lt;/P&gt;
&lt;P&gt;PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND &lt;BR /&gt;19952 admin 20 0 962644 374820 49380 R 86.5 0.4 200:43.26 fw_full &lt;BR /&gt;11622 admin 20 0 0 0 0 R 69.4 0.0 133:56.11 fw_worker_3 &lt;BR /&gt;11619 admin 20 0 0 0 0 R 62.3 0.0 137:19.11 fw_worker_0 &lt;BR /&gt;11625 admin 20 0 0 0 0 R 61.6 0.0 130:51.28 fw_worker_6 &lt;BR /&gt;11624 admin 20 0 0 0 0 R 60.0 0.0 133:16.94 fw_worker_5 &lt;BR /&gt;11626 admin 20 0 0 0 0 R 57.4 0.0 134:03.56 fw_worker_7 &lt;BR /&gt;11623 admin 20 0 0 0 0 R 57.1 0.0 136:49.37 fw_worker_4 &lt;BR /&gt;11621 admin 20 0 0 0 0 R 56.5 0.0 133:35.66 fw_worker_2 &lt;BR /&gt;11628 admin 20 0 0 0 0 R 54.2 0.0 131:37.48 fw_worker_9 &lt;BR /&gt;11627 admin 20 0 0 0 0 R 53.5 0.0 132:21.71 fw_worker_8 &lt;BR /&gt;20460 admin 20 0 220916 111744 28284 R 53.2 0.1 60:11.37 rad &lt;BR /&gt;11620 admin 20 0 0 0 0 R 44.5 0.0 134:50.44 fw_worker_1&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 15:36:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257923#M43491</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-09-22T15:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257925#M43492</link>
      <description>&lt;P&gt;The CSV file did not displayed max flows today, only this morning. TAC noticed that we reached the cap but was not needed to increase the max flow value. FW's connect towards internal infoblox server. After that I am unaware, could ask if important &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 15:39:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257925#M43492</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-09-22T15:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257933#M43493</link>
      <description>&lt;P&gt;All those outputs look OK, pretty sure this is a cache thrash issue caused by AB and/or URLF, see the last two paragraphs on the second page, which is quoted from the most recent edition of my &lt;A href="https://shadowpeak.com/check-point-training" target="_self"&gt;Gateway Performance Course&lt;/A&gt;:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rad11.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31508i00972D993AABC279/image-size/large?v=v2&amp;amp;px=999" role="button" title="rad11.png" alt="rad11.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rad12.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31509i9B229BD3EC864F2A/image-size/large?v=v2&amp;amp;px=999" role="button" title="rad12.png" alt="rad12.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 16:06:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/257933#M43493</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-09-22T16:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/258205#M43567</link>
      <description>&lt;P&gt;Update: we suspect customer was under attack. I noticed following logs:&lt;/P&gt;
&lt;P&gt;SYN Defender: activated &amp;lt;interface&amp;gt;. Number of not established connections is 5017&lt;/P&gt;
&lt;P&gt;After 5000 Syn defender kicks in and does the following (copied from SK):&lt;/P&gt;
&lt;P&gt;When the Gateway decides that a server is under attack, it switches to SYN Relay Defense. SYN Relay counters the attack by making sure that the three-way handshake is complete before sending a SYN packet to the connection's destination.&lt;/P&gt;
&lt;P&gt;Even if the destination server is not listening on that port, the Gateway will respond with a SYN-ACK to make sure that the client completes the three-way handshake with an ACK; it does this to determine the legitimacy of the connection. After the Gateway has determined that the connection is legitimate, it forwards the packet to the firewall layer and eventually to the destination server&lt;/P&gt;
&lt;P&gt;--------------&lt;/P&gt;
&lt;P&gt;So after i disabled this protection load went down. Customer was still under attack and firewall dropped still traffic. But the above protection is a critical performance one. Load went down and fw went stable after this. We blocked the attack(before the fw) and enabled protection again.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see loads of host / port scans. If firewall is gonna reply to them due above protection I can imagine it struggles with it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 14:28:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/258205#M43567</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-09-25T14:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing issue: high CPU load fw_workers + rad</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/258225#M43569</link>
      <description>&lt;P&gt;Enable the SecureXL penalty box feature which will help a lot.&amp;nbsp; It should be enabled by default as far as I am concerned.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 16:26:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ongoing-issue-high-CPU-load-fw-workers-rad/m-p/258225#M43569</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-09-25T16:26:04Z</dc:date>
    </item>
  </channel>
</rss>

