- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hello,
I've recently upgraded our CheckPoint 15400 ClusterXL Gateways to R81.20 Take 53. Since the upgrade we have 10-15 minutes of extreme slowness where everything grinds to a halt before performing normally again. This happens once maybe twice per day.
I've checked the cpview history and there doesn't seem to be a correlation with increased traffic, high CPU but from SolarWinds I can see that latency to Google increases to over 10,000ms.
Has anyone else experienced performance issues in R81.20. Any tips for troubleshooting the issue please?
Many Thanks
I have a lot of firewalls on R81.20 with various jumbos including 53. I haven't seen a problem like you describe.
If the issue isn't correlated to high processor usage on the firewall, maybe it's some traffic the firewall drops such as traffic from an internal DNS server out to DNS servers on the public Internet? When DNS misbehaves, so does basically everything else.
Thanks for the suggestion. I've checked DNS and no drops have been detected. I know it could probably be a number of different issues but any more suggestions on possible causes?
Can you check output of fw tab -t connections -s?
Also, does cpview show u top services/connections?
Andy
fw tab -t connections -s
HOST NAME ID #VALS #PEAK #SLINKS
localhost connections 8158 7239 19761 14263
I'm unable to view historical connections in cpview and top connections under the network tab need to be activated. I've uploaded screenshots of real time network and CPU top connections.
Make sure gateway object has connections set to auto setting as well. Please open TAC case, sounds like a pretty serious issue.
Where in the gateway object is the connection auto setting?
Yes, I have raised it with TAC. Just waiting for someone to pick up the ticket.
Thats it, you got the right option selected.
I've been reading through sk167903 to enable data collection for Network --> Protocols / Connections. The article mentions enabling this feature may cause a performance impact.
Do you know how much of an impact this has? Is it likely to cause performance issues?
I can totally see the point @Bob_Zimmerman is making. I had never seen this issue myself, so highly unlikely its code problem.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 13 | |
| 10 | |
| 8 | |
| 8 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Tue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY