- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
A typical issue is ClusterXL under freeze by policy installation. ClusterXL administrator would like to suppress the messages printed by the Cluster Under Load (CUL) mechanism (see sk92723) in the /var/log/messages file and in the dmesg. I always enable this on the cluster to solve this "under freeze" issue.
1) Open vi and add the following settings
# vi $FWDIR/boot/modules/fwkern.conf
add the Line:
fwha_freeze_state_machine_timeout=0
2) Reboot all Gateways
Is this setting permanet after a reboot?
If you add lines in fwkern.conf, it is permanent after a reboot.
Regards
Heiko
Hi Heiko, Thanks for the great stuff. On doing some research , I did noticed below (sk106576). I'm confused about the statement : "Cluster members do not install policy at the same exact time, and are not aware when the peer members install policy."
Typically, policies are installed @ same time in Clusters. Does this happen under High Load or CPU utilization. Not sure, please assist ![]()

Hi Srinivasan,
over 80% cpu load and 30 sec.
Typical by policy installation.
Regards
Heiko
Hello everybody,
we are having a Cluster of 12600 appliances, having a policy with 800 rules and only very very less traffic (< 100Mbit/s, 5000 concurrent Connections) and very less CPU load.
in the beginning we had 200s configured, then we noticed that secondary was going down when doing policy install. We opened a ticket and Support suggested us to increase timeout.
So we increased from 200 - 300s and then a week later from 300 to 600. Did not solve the Problem.
We did not reboot but we did "fw ctl set int fwha_freeze_state_machine_timeout" to modify it live.
Any suggestions:
- how to measure a usefull freeze_timeout for am policy install?
- which values are usefull to set and which value we should not exceed?
Regards
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY