> Source: [sk124593](https://support.checkpoint.com/results/sk/sk124593)

# sk124593 - After a Security Management Server upgrade from R77.30 to R80.10, traffic on Non-Standard HTTP ports is inspected by the Threat Prevention blades

| Property | Value |
|----------|-------|
| Solution ID | sk124593 |
| Date Created | 2018-04-30 |
| Last Modified | 2019-05-14 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, R82.20 |
| OS | Gaia |

## Symptoms

- * After an upgrade from R77.30 to R80.10, the CPU hits 100% and IPS consumes more resources than it did in R77.30.
* CPView shows **CMI_APPS / HTTP_PARSER** is consuming the most CPU, and streaming traffic seems to be the offending traffic. (HTTP Inspection on Non-Standard ports was disabled in R77.x, but is enabled in R80.10 in the **Threat Prevention** tab.)

## Cause

In R77.x, IPS and Threat Prevention were considered different blades, but in R80.10 they were merged into the "Threat Prevention" blade.

If "HTTP inspection on non standard ports" was enabled on **EITHER**blade, it will, by default, be enabled in R80.10, regardless of whether or not either blade was in use, previously.

**As a result, any streaming traffic that is considered HTTP will be inspected by all Threat Prevention blades.**

This could lead to higher CPU load than in R77.30, or unexpected traffic drops due to the increase in inspected traffic.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
