sk183438 - Stability issue in Check Point appliances 9300 and 9400

Stability issue in Check Point appliances 9300 and 9400

Product: Check Point Appliances, ClusterXL, Maestro HyperScale Firewall, Security Gateways, VSNext, VSX (Traditional)

Version: R81.20, R82

OS: Gaia

Platform: 9000

Last Modified: 2025-08-04

Symptoms

Cause

We have identified an issue affecting the Quantum Force 9300 and 9400 models due to the unique Intel E-cores / P-cores architecture used in these models. This issue may cause system crashes, particularly in specific configurations.

Solution

You must follow all these steps:

  1. Immediate step to reduce the risk: If the Firewall runs in the Kernel Space (KSFW), then configure it to run in the User Space (USFW). For information about Firewall modes, see sk167052.

    This change will significantly decrease the risk of encountering the issue.

Important Note - If there is a specific reason to run the Firewall in the Kernel Space (KSFW) mode, contact Check Point Support for assistance. The recommended and the default configuration is to the Firewall in the User Space (USFW) mode.

  1. Connect to the command line on the problematic Security Gateway / Cluster Member.

  2. Log in.

  3. If the default shell is Gaia Clish, then go to the Expert mode:

    expert
    
  4. Get the current Firewall mode:

    fwmode -s
    
Command Output Next Step
Firewall is User mode Continue to Step 2 to install the Hotfix.
Firewall is Kernel mode Configure the Firewall to run in the User Space (USFW) mode (see sk167052):
 **Important Note** - Schedule a full maintenance window because this procedure requires a reboot.
 1. Run:
    
    ```
    cpconfig
    ```
 2. Enter the number of the option **Check Point CoreXL**.
 3. Enter the number of the option **Change firewall mode**.
 4. Follow the instructions on the screen.
 5. Exit from the `cpconfig` menu.
 6. Reboot as described below:
    - On a single Security Gateway, run:
      
      ```
      reboot
      ```
    - In a ClusterXL configured in the High Availability mode:
      1. Get the current cluster state:
         
         ```
         cphaprob state
         ```
      2. Reboot all cluster members in the cluster state "Standby" - one cluster member at a time:
         
         ```
         reboot
         ```
      3. Reboot the remaining cluster member:
         
         ```
         reboot
         ```
    - In a ClusterXL configured in the Load Sharing Unicast mode:
      1. Get the current cluster state:
         
         ```
         cphaprob state
         ```
      2. Reboot all cluster members in the cluster state "Non-Pivot":
         
         ```
         reboot
         ```
      3. Reboot the remaining cluster member:
         
         ```
         reboot
         ```
    - In a ClusterXL configured in the Load Sharing Multicast mode:
      Reboot all cluster members - one cluster member at a time.
      
      ```
      reboot
      ```
  1. This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

Important Note - Schedule a full maintenance window because this procedure requires a reboot.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.