sk180437 - Unexpected traffic latency or outage on a Security Gateway / Cluster after policy installation
Unexpected traffic latency or outage on a Security Gateway / Cluster after policy installation
Product: Security Gateways
Version: R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2026-06-16
Symptoms
Unexpected traffic latency or outages on a Security Gateway / Cluster when the Firewall is configured to work in the User Space (USFW, see sk167052).
Usually, the issue starts after a policy installation or a signature load.
During the time of the incident, the output of the "
top" / "ps" command shows that the "fwk_wd" process consumes the CPU at high level.During the time of the incident, the /var/log/messages file on the Security Gateway contains these three messages repeatedly:
kernel: [SIM<ID>];cpaq_cbuf_send: cpaq_cbuf_call_api_end_ex failed kernel: [SIM<ID>];cpaq_cbuf_send_buffer: send chunk num 0 failed kernel: [SIM<ID>];sim_cphwd_stats_cb: failed to create cpaq bufferDuring the time of the incident, the /var/log/thread_blocker_device64.log file on the Security Gateway contains soft lockups.
During the time of the incident, the $FWDIR/log/fwk_wd.elg file on the Security Gateway contains these messages, repeatedly:
thread_blocker_monitor_periodic_timeout_exp_check: tid exceeded its timeout(10000) thread_blocker_monitor_periodic_timeout_exp_check: cur_time: reporting_time:
Solution
We're here for you
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: Advanced
Status: Approved by TAC
Date Created: 2022-12-22
Last Modified: 2026-06-16