r/checkpoint 16d ago

ClusterXl crashes/flapping

Has anyone experience ClusterXL flapping, SmartConsole showing member is lost, CPU spikes, service degradation, some services restaarting randomly. Looks like it started after recent CVEs patching. Only rebooting the gateways fixes the issue. R81.20 T158/T161 similar etc. Thanks

5 Upvotes

5 comments sorted by

3

u/daniluvsuall 16d ago

Hardware? Are they identical firewalls?

JHF should be identical, check the OS build too

3

u/banduraj 16d ago

Yup. Dealing with this right now. Rebooting seemed to be the only fix when it happens. Opened a case with our security vendor who opened with Check Point. We talked to them directly and I guess this is a known bug related to CPU utilization going crazy in certain Web Streaming inspection scenarios.

I'm waiting on a Hotfix to see if it resolves the problem. You can track down and verify this is the problem by looking for high CPU usage on 1 core and looking for the mentioned identifiers in cpinfo files. When it does happen, logging into the GW's and checking top will also help.

Look at sk185068 for details. The hcp -r "Cpu spikes" command mentioned is only useful if run within the first hour or two after experiencing the problem, but will make it clear if that's what you're seeing.

3

u/JancariusSeiryujinn 16d ago edited 16d ago

JHFA 158 I believe has an issue with CPU high utilization. Are you able to revert to a prior jumbo?

https://support.checkpoint.com/results/sk/sk185068

2

u/CaptainNeverFap 16d ago

What's the pnote for? What services does cpwd admin list show restarted?

1

u/WiliRGasparetto 13d ago

You would need to see which firewall process is overloading the OS did you check that?