sk184183 - Security Gateway/Cluster member becomes unresponsive and drops traffic

Security Gateway/Cluster member becomes unresponsive and drops traffic

Product: CoreXL, Security Gateways
Version: R81.20, R82
OS: Gaia
Last Modified: 2026-01-06

Symptoms

  [DATE TIME][fw4_1];[vs_0];[HOSTNAME]: State change: ACTIVE! -> DOWN | Reason: Interface Sync is down (Cluster Control Protocol packets are not received)
  [DATE TIME][fwk4];[vs_0];[instance_8];[18143];Warning:cp_timed_blocker_handler: A handler [0x4116e0] blocked for 3 seconds.
  [DATE TIME][fwk4];[vs_0];[instance_8];[18143];Warning:cp_timed_blocker_handler: Handler info: Library [fwk], Function offset [0x116e0].
  [DATE TIME][fwk4];[vs_0];[instance_11];[18146];Warning:cp_timed_blocker_handler: A handler [0x4116e0] blocked for 7 seconds.
  [DATE TIME][fwk4];[vs_0];[instance_11];[18146];Warning:cp_timed_blocker_handler: Handler info: Library [fwk], Function offset [0x116e0].
  [DATE TIME][fwk4];[vs_0];[instance_13];[18148];Warning:cp_timed_blocker_handler: A handler [0x4116e0] blocked for 7 seconds.
  [DATE TIME][fwk4];[vs_0];[instance_13];[18148];Warning:cp_timed_blocker_handler: Handler info: Library [fwk], Function offset [0x116e0].

Cause

The HyperFlow feature (see R82 Performance Tuning Admin Guide > HyperFlow section) is enabled by default on R81.20 and higher versions. It triggers soft lock-ups, causing the Firewall instances to become locked, delaying or failing the processing and forwarding of Cluster Control Protocol (CCP) packets.

This in turn causes cluster-state flapping and failover.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

If you cannot install the hotfix, you can use this workaround:

  1. Disable the Kernel Parameter:

    • Run the command: # fw ctl set -f int mux_dmd_use_on_non_ef_instance 0
    • Re-enable the HyperFlow feature per sk178070
    • Reboot the Security Gateway to apply the changes.
  2. Verify the change:

    • Run: # fw ctl get int mux_dmd_use_on_non_ef_instance
    • The expected output: mux_dmd_use_on_non_ef_instance = 0

Note: This solution restricts HyperFlow to interact only with CPUs handling relevant connections, resolving lock-up and CCP delay issues.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties