Hello Wolfgang,
have you checked this SK sk92810
"Unable to open '/vs0/dev/fw0': Connection refused' during boot or cpstart, FWK_WD process is terminated after reboot"
it states that " $FWDIR/boot/modules/fwkern.conf" might be corrupted...
R81.10 manual CP_R81.10_ThreatPrevention_AdminGuide.pdf says on page 262:
Inspection of TLS v1.3 Traffic
From R81, the Check Point Security Gateway can inspect traffic that relies on Transport Layer Security (TLS) v1.3 (see RFC 8446).
From R81.10, this feature is enabled by default for Security Gateways (and Cluster Members) that use the User-Space Firewall Mode (USFW)).
For the list of supported platforms, see sk167052.
Important - In a Cluster, you must configure all the Cluster Members in the same way.
Note - To disable the inspection of the TLS v1.3 traffic for testing purposes, set the value of the global parameter fwtls_enable_tlsio to 0 and reboot.
The HTTPS Inspection feature decrypts traffic for better protection against advanced threats, bots, and other malware.
so you must set "fwtls_enable_tlsio" in fwkern.conf to "1" i suspect ...