- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hello Community,
do someone make someone experience with high memory after upgrade the getaway with R81.10 Take 110?
Model: Check Point 23800
Version: R81.10 Take 110
Only Firewall Blade and PEP/PDP enabled on the firewall. CPU Util looks good.
What are this processes ?
in.aftpd
in.emaild.pop
in.asmtpd
Thanks 
Do you have the DLP or Content Awareness blades enabled? Those features take advantage of the in.aftpd daemon and you seem to have an awful lot of them.
Hi,
no only FW and IA
[Expert@FW]# enabled_blades
fw identityServer
I can't think of any valid reason why those three security server processes (and so many of them) are running on your gateway with only those blades enabled unless you are utilizing legacy User/Client/Session authentication actions in your rulebase which is unlikely. This behavior seems like a bug to me especially since you just updated your HFA level. Probably going to have to get TAC involved, or you could try backing out the HFA.
I would also suggest TAC case for this.
Andy
Best to get the TAC involved here: https://help.checkpoint.com
Can you also send us output of below commands?
cpview (look for memory usage)
ps -auxw
top
free -g
cpwd_admin list
Andy
If this does turn out to be a bug, please let the community know, ideally with a bug id.
Ok, just had a chance to look at it...I find the issue a bit odd, because based on what you sent, appears you have lots of memory free, as a matetr of fact, shows 30 GB free.
Also, cpu seems fine to me. Processes you asked about are related to security servers. Do you have any sort of client auth configured?
Kind regards,
Andy
Recommend upgrading to T113 and above or reviewing the work arounds per sk180505.
T113 has been in 'ongoing' status for a little longer than normal, but I would expect this to be GA very soon.
Thats true, but I would personally not bother until it is marked as recommended.
Andy
 
					
				
				
			
		
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count | 
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 11 | |
| 11 | |
| 7 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | 
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 11:00 AM (EDT)
Tips and Tricks 2025 #15: Become a Threat Exposure Management Power User!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY