Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
TrevorB
Explorer

Multiple httpd processes consuming a lot of CPU

We've recently run across an issue with one of our two Maestro environments. The security group on one of them now is  consuming 70-80% of CPU on a regular basis. It appears that there are about 30 httpd processes that are the main culprit. If I stop and start the Usercheck portal (mpclient stop UserCheck and then mpclient start UserCheck) the httpd processes are destroyed but eventually come back. Nothing has changed in our configuration of the unit that would explain this. I have an open case with Checckpoint but given it is a Maestro unit, I find the responses to be slow at best.\

Just curious if anyone has seen anything like this, Maestro or not. Any ideas of what would cause multiple UserCheck portals to spawn? We push about the same amount of web based traffic out of our two different Maestro environments but only one is showing this odd behavior.

I'm just waiting on support in the meantime.

10 Replies
CheckPointerXL
Advisor
Advisor

same problem here

0 Kudos
Chris_Atkinson
Employee Employee
Employee

The last time I saw something like this it was things like hotspot detection in Mozilla Firefox hanging the UserCheck portal waiting for user interactions that of course never eventuate.

This obviously isn't Maestro specific but it might pay to dig deeper into the logs that trigger a redirect/UserCheck action and exclude or properly block requests that aren't user initiated.

CCSM R77/R80/ELITE
0 Kudos
CheckPointerXL
Advisor
Advisor

Hello Chris,

thank you for your feedback. I'm on a simply cluster gateway, please take a look at the attached image.

 

Watching Top command, we can see that a ton of HTTPD process comes up on process list and they disappear after few secs.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Do you use Mobile Access on this cluster and which version & JHF is it?

I'd start with sk85040 and approach TAC from there otherwise.

CCSM R77/R80/ELITE
0 Kudos
CheckPointerXL
Advisor
Advisor

People connecting to gw by Checkpoint mobile, check out attached imaged for full enabled features

Gaia R81 JHF 36

new crazy spike attached 

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Noted, for reference PRJ-24688,
PRHF-16135 for HTTPD process is addressed in JHF T42 and higher.

CCSM R77/R80/ELITE
CheckPointerXL
Advisor
Advisor

just finished remote session with tac

problem seems to be fixed, editet file inside CPcvpn-R81 folder

HeikoAnkenbrand
Champion Champion
Champion

Hi @CheckPointerXL,

Can you describe what exactly has been changed?

THX
Heiko

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips
CheckPointerXL
Advisor
Advisor

Hello Heiko,

TAC informed me that the fix is only authorized for Checkpoint use, so I'm honest with you and i'm very sorry to not share the details .
Anyway inside a file in that folder we changed a value from "unlimited" to a value calculated by the amount of "maximum number of concurrent vpn client connection" estimated on my side, that's all.

0 Kudos
CheckPointerXL
Advisor
Advisor

PS problem seems to be fixed on take 42 and above

0 Kudos