- Products
- Learn
- Local User Groups
- Partners
- More
Call For Papers
Your Expertise, Our Stage
Ink Dragon: A Major Nation-State Campaign
March 11th @ 5pm CET / 12pm EDT
AI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
Hello Community,
do someone make someone experience with high memory after upgrade the getaway with R81.10 Take 110?
Model: Check Point 23800
Version: R81.10 Take 110
Only Firewall Blade and PEP/PDP enabled on the firewall. CPU Util looks good.
What are this processes ?
in.aftpd
in.emaild.pop
in.asmtpd
Thanks
Do you have the DLP or Content Awareness blades enabled? Those features take advantage of the in.aftpd daemon and you seem to have an awful lot of them.
Hi,
no only FW and IA
[Expert@FW]# enabled_blades
fw identityServer
I can't think of any valid reason why those three security server processes (and so many of them) are running on your gateway with only those blades enabled unless you are utilizing legacy User/Client/Session authentication actions in your rulebase which is unlikely. This behavior seems like a bug to me especially since you just updated your HFA level. Probably going to have to get TAC involved, or you could try backing out the HFA.
I would also suggest TAC case for this.
Andy
Best to get the TAC involved here: https://help.checkpoint.com
Can you also send us output of below commands?
cpview (look for memory usage)
ps -auxw
top
free -g
cpwd_admin list
Andy
If this does turn out to be a bug, please let the community know, ideally with a bug id.
Tx @Kolafer , will check tomorrow after I do my 50k bike ride 🙂
Andy
Ok, just had a chance to look at it...I find the issue a bit odd, because based on what you sent, appears you have lots of memory free, as a matetr of fact, shows 30 GB free.
Also, cpu seems fine to me. Processes you asked about are related to security servers. Do you have any sort of client auth configured?
Kind regards,
Andy
Recommend upgrading to T113 and above or reviewing the work arounds per sk180505.
T113 has been in 'ongoing' status for a little longer than normal, but I would expect this to be GA very soon.
Thats true, but I would personally not bother until it is marked as recommended.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 9 | |
| 8 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Fri 06 Mar 2026 @ 08:00 AM (COT)
Check Point R82 Hands‑On Bootcamp – Comunidad DOJO PanamáThu 12 Mar 2026 @ 05:00 PM (CET)
AI Security Masters Session 5: Powering Prevention: The AI Driving Check Point’s ThreatCloudThu 12 Mar 2026 @ 05:00 PM (CET)
AI Security Masters Session 5: Powering Prevention: The AI Driving Check Point’s ThreatCloudTue 17 Mar 2026 @ 10:00 AM (CET)
Industrial Cybersecurity in Practice: Manufacturing & Utilities - EMEATue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEAFri 06 Mar 2026 @ 08:00 AM (COT)
Check Point R82 Hands‑On Bootcamp – Comunidad DOJO PanamáTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY