sk183441 - Security Gateway drops HTTP/2 traffic and generates a core dump file for the FWK daemon

Security Gateway drops HTTP/2 traffic and generates a core dump file for the FWK daemon

Product: HTTPS Inspection, Scalable Chassis, Security Gateways, VSX (Traditional)

Version: R81.10 (EOS), R81.20, R82
OS: Gaia
Last Modified: 2025-06-23

Symptoms

Cause

A rare issue in HTTP/2 multiplexing may lead to traffic disruption.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect these files:

  1. CPinfo file from the Management Server involved in the case.
  2. CPinfo file from the Security Gateway / each Cluster Member involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.


This workaround is also available:

You can disable HTTP/2 support on the Security Gateway, which will cause all web traffic to fall back to HTTP/1.

To disable HTTP/2:

  1. #ckp_regedit -a SOFTWARE\\CheckPoint\\FW1 IGNORE_ALPN_EXTENSION 1
  2. #fw fetch local
  3. #cpstop
  4. #cpstart

To re-enable HTTP/2:

  1. #ckp_regedit -a SOFTWARE\\CheckPoint\\FW1 IGNORE_ALPN_EXTENSION 0
  2. #fw fetch local
  3. #cpstop
  4. #cpstart

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2025-05-08
Last Modified: 2025-06-23