- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello mates! How are you all?
We're having issues in our FW; perhaps one of you had this problem before.
FW is an open server, Version 81.10 with JHF T130; it has hyperthreading enabled and is running as proxy.
Every working day seen past few weeks, the CPU goes to 100% for several minutes. We checked the process and the temain ted seems to be taking all the stars.
There are a few elephant connections but can't be accelerated because of FW been used as proxy I think.
I've checked the affinity for temain, and seems to be attached to all the CPU available.
But, if I do "tecli show affinity" the result is
Command: root->show->affinity
error: unable to retrieve process affinity
If I check the management to see logs of the IPS blade, there is nothing there, probably because FW its suffering on 100% load.
I've no idea where else to look or what to do here; help would be really appreciate.
Thanks in advanced!
Does cprestart or reboot help?
Andy
Hello Andy,
Thanks for replying.
We did not restart the FW; I could try it tomorrow. After those 20 to 40 minutes of 100% load, goes like "normally".
I know one client who had this problem and went away after they upgraded to R81.20. I cant recall now what jumbo they installed, but this was few months back, probably April or May.
Andy
Ok, it's an option!
We've thought that and it's scheduled to do this weekend; we'll see if it helps!
Thanks!
Im fairly positive it WILL help!
Andy
Hello Andy,
We've upgraded to 81.20 last JHF but the problem still there. Also discover a new ones but that another thread.
I've also checked the hits on urlf with this command fw tab -t urlf_cache_tbl -s and we'e 7335 on #vals conlumns.
Hi @sebasnqn
If we talk about "Elephant Flows" consider to user SecureXL Fast Accelerator"
https://support.checkpoint.com/results/sk/sk156672
It would help a lot.
Akos
Hi Sir,
Thanks for replying.
We've a few rules activated, but no hits on them. I think related to the proxy usage of the firewall.
Thanks though!
That also makes sense to me.
Andy
ted is "Threat Emulation" not IPS.
Traffic cannot be accelerated with SecureXL when the gateway used as an explicit proxy.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
15 | |
12 | |
8 | |
6 | |
6 | |
6 | |
5 | |
5 | |
4 | |
3 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY