- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
we have an Open Server with Check Point R80.10 ClusterXL (two nodes) with these enabled blades: IPSec VPN, Mobile Access, Application Control, URL Filtering, IPS, Anti-Virus, Identity Awareness, Monitoring. The server has 16 CPUs but was licensed for 3.
Sometimes/randomly it happens the active node freezes; the console (SSH) becomes unavailable. Before resetting it forcibly I managed to launch cpview and take this screenshot from iLO (it is an HPE server):
Now I understand it should be necessary a deep investigation; but what's could be the root cause for all CPUs reaching more than 90% of usage ? Do you think 3 processors license are enough for all enabled blades ?
Thank you,
Luca
Please read last post by Timothy Hall here that likely describes your situation perfectly:
Multiple questions (licensing, number of cores) that starts with:
"Any time the number of licensed cores differs from the number of physical cores on open hardware gateways, watch out for what call I call the licensing "core crunch" in the second edition of my book."
Hello Vladimir,
here the current output of fw ctl affinity -l -r:
The "Core Crunch" behavior doesn't seem to occur here, isn't it ? We have 3 Firewall Worker assigned to each CPU.
Bye,
Luca
You are licensed for 4 cores, not 3 and are using all of them.
Please go with Danny's suggestions to get more info.
Sorry, you are right. My mystake: 4 CPUs licensed.
Could you please show me a screenshot of the main menu of our ccc script running?
Let's find the root cause.
Hello Danny,
this is the screenshot from affected node (now standby):
This is from active node:
I'l will check your other points...
Bye,
Luca
As Danny mentioned, Super Seven outputs would be helpful here. Your screenshot shows cores 1-3 which are all your Firewall Workers getting very busy which indicates a lot of PXL or even F2F path traffic. Some tuning will probably help, but not as much as licensing another 4 cores I would imagine, as the only things cores 4-15 can do is handle generic Gaia/Linux processes.
There is not a "core crunch" present as there is only one Firewall Worker assigned to cores 1-3 each.
--
Second Edition of my "Max Power" Firewall Book
Now Available at http://www.maxpowerfirewalls.com
Firewall Priority Queues in R77.30 / R80.10 and above
Packets could be dropped by Firewall when CPU cores, on which Firewall runs, are fully utilized. Such packet loss might occur regardless of the connection's type (for example, local SSH or connection to Security Management Server server).
To help mitigate the above issue, Firewall Priority Queues feature was introduced in R77.30 Security Gateway.
Firewall R77.30 / R80.10 and above assigns higher priority to control connections than to other connections.
By default, the following services are considered by Firewall R77.30 / R80.10 and above as control connections:
Not all control services get the same priority. Firewall R77.30 / R80.10 and above prioritizes some control services over the other control services.
Hello all,
just an update regarding this issue, so it could be helpful for other users.
After IPS and Anti-Virus rules optimization, overall performances were increased (we still have 4 CPUs but we planned to update to 8 CPUs).
Thank you for your support.
Regards,
Luca
Can you share the data on how many hosts are behind this cluster (approximation), if you are running HTTPS inspection and what is the Internet bandwidth utilization looks like?
I am interested in these data points to be able to size appliances more accurately based on the real world experience.
Thank you,
Vladimir
Hello Vladimir,
here some overall information regarding our Check Point environment:
I think it could be enough.
Bye,
Luca
Thank you for the data!
If I may trouble you some more:
1. what is the average Internet bandwidth consumption you are seeing?
2. were you using "Optimized" IPS profile before encountering high utilization?
3. if you were using customized IPS profiles, were there any particular protections that were found to be responsible for the bulk of the impact on CPU utilization?
Vladimir
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
31 | |
17 | |
4 | |
3 | |
3 | |
3 | |
3 | |
3 | |
2 | |
2 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY