sk184183 - Security Gateway/Cluster member becomes unresponsive and drops traffic
Security Gateway/Cluster member becomes unresponsive and drops traffic
Product: CoreXL, Security Gateways
Version: R81.20, R82
OS: Gaia
Last Modified: 2026-01-06
Symptoms
- Security Gateway/Cluster member becomes unresponsive and drops traffic.
- Frequent and random status changes and failovers occur in a ClusterXL, VSX, or Scalable Platform environments when HyperFlow is enabled, resulting in outages and loss of connectivity.
- Logs in the /var/log/messages file show the Active Cluster member state changing to Down because no CCP packets are received, for example:
[DATE TIME][fw4_1];[vs_0];[HOSTNAME]: State change: ACTIVE! -> DOWN | Reason: Interface Sync is down (Cluster Control Protocol packets are not received)
- The $FWDIR/log/fwk.elg file logs show lock-up messages on Firewall instances, but the CPU utilization remains low, for example:
[DATE TIME][fwk4];[vs_0];[instance_8];[18143];Warning:cp_timed_blocker_handler: A handler [0x4116e0] blocked for 3 seconds.
[DATE TIME][fwk4];[vs_0];[instance_8];[18143];Warning:cp_timed_blocker_handler: Handler info: Library [fwk], Function offset [0x116e0].
[DATE TIME][fwk4];[vs_0];[instance_11];[18146];Warning:cp_timed_blocker_handler: A handler [0x4116e0] blocked for 7 seconds.
[DATE TIME][fwk4];[vs_0];[instance_11];[18146];Warning:cp_timed_blocker_handler: Handler info: Library [fwk], Function offset [0x116e0].
[DATE TIME][fwk4];[vs_0];[instance_13];[18148];Warning:cp_timed_blocker_handler: A handler [0x4116e0] blocked for 7 seconds.
[DATE TIME][fwk4];[vs_0];[instance_13];[18148];Warning:cp_timed_blocker_handler: Handler info: Library [fwk], Function offset [0x116e0].
Cause
The HyperFlow feature (see R82 Performance Tuning Admin Guide > HyperFlow section) is enabled by default on R81.20 and higher versions. It triggers soft lock-ups, causing the Firewall instances to become locked, delaying or failing the processing and forwarding of Cluster Control Protocol (CCP) packets.
This in turn causes cluster-state flapping and failover.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 44
- Jumbo Hotfix Accumulator for R81.20 starting from Take 119
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
If you cannot install the hotfix, you can use this workaround:
Disable the Kernel Parameter:
- Run the command:
# fw ctl set -f int mux_dmd_use_on_non_ef_instance 0 - Re-enable the HyperFlow feature per sk178070
- Reboot the Security Gateway to apply the changes.
- Run the command:
Verify the change:
- Run:
# fw ctl get int mux_dmd_use_on_non_ef_instance - The expected output:
mux_dmd_use_on_non_ef_instance = 0
- Run:
Note: This solution restricts HyperFlow to interact only with CPUs handling relevant connections, resolving lock-up and CCP delay issues.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
- Access Level: General
- Status: Approved by TAC
- Date Created: 2025-10-16
- Last Modified: 2026-01-06