Hi @Stefano_Cappell
CUT>>>
cerbero1 kernel: [fw4_1];...[ERROR]: malware_res_rep_rad_query: rad_kernel_api_async_get_resource() failed with error: Service is down
And then:
cerbero1 kernel: [fw4_1];CLUS-120202-1: Stopping CUL mode after 80 sec (short CUL timeout), because no member reported CPU usage above the configured threshold (80%) during the last 10 sec.
<<<CUT
I think the RAD service is not available (marked red) and is restarted again and again. Anti-Bot, Anti-Virus, URL Filtering, HTTPs Inspection uses Resource ADvisor (RAD process) to enforce their policies/profiles. RAD forwards the relevant reputation/categorization requests to CP cloud. The request is being made to cws.checkpoint.com.
cws.checkpoint.com resolves to one Akamai servers. The server may change and once it does RAD is not able to recognize it.
Solution:
To identify that this is indeed the issue, do the following:
1) From within the Security Gateway identify the current cws.checkpoint.com IP by either pinging it or resolving it with nslookup.
2) Use 'netstat -nap | grep rad' and see which IP RAD uses at the moment.
If point 1 and 2 do not match, then this is the issue of change
Possible solutions:
1) Install policy.
2) Restart rad process by running 'rad_admin restart'
---
If that is not the problem, I would open a TAC case if the RAD service is not available.
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips