> Source: [sk180299](https://support.checkpoint.com/results/sk/sk180299)

# sk180299 - Linux commands report a high CPU load average when SecureXL operates in the User Space (UPPAK) mode

| Property | Value |
|----------|-------|
| Solution ID | sk180299 |
| Date Created | 2022-11-21 |
| Last Modified | 2026-08-26 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * Linux commands (`uptime`, `ps`, `top`, `htop`) report high CPU Load Average when SecureXL operates in the User Space (UPPAK) mode.

* SNMP query for the OID 1.3.6.1.2.1.25.3.3.1.2 returns significantly higher CPU utilization compared to the CPView output.

* The reported high utilization of SND core(s) can also be seen on the Standby member of a ClusterXL cluster.

## Cause

In [R82.10](https://support.checkpoint.com/results/sk/sk183506), [R82](https://support.checkpoint.com/results/sk/sk181127), in the [R81.20 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) (Take 38), and in the [R81.10 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) (Take 81), Check Point added support for the SecureXL User Space (UPPAK) mode operation on specific Check Point appliances. The SecureXL UPPAK mode increases performance and unlocks more advanced features in SecureXL.

As part of this change, Check Point changed the traditional kernel network drivers to Poll Mode Drivers (PMD), which operate in the User Space.

### CPU Load Average ("`uptime`", "`ps`")

> Load Average shows how many processes are waiting for CPU cores. In Linux-based Operating Systems, the Load Average includes the average number of tasks in the running state (marked as "`R`") or uninterruptible sleep state (marked as "`D`"). This is not directly correlated with the real CPU usage, and may initially confuse users.
>
> You can see the Load Average numbers in the output of the "`uptime`" and "`top`" commands.
>
> Example output of the "`uptime`" command:
>
> `14:06:29 up 36 min, 2 users, load average: 16.05, 16.13, 14.63`
>
> When SecureXL operates in the User Space (UPPAK) mode, a User Space packet thread runs in the poll mode on each CPU core that works as a CoreXL SND Instance. These packet threads are in the running state ("`R`") state. For each CoreXL SND, there is in addition a kernel thread running ("`cpfifo1_<X>`") to facilitate communication between the user configuration and SecureXL UPPAK.
>
> Example output of the "`ps -e -o pid,user,pri,stat,psr,cpu,cmd | grep -E 'PID|cpfifo1'`" command:
>
> ` PID USER PRI STAT PSR %CPU COMMAND`  
> `33412 admin 0 D< 0 0.0 cpfifo1_0`  
> `33413 admin 0 D< 1 0.0 cpfifo1_1`  
> `33421 admin 0 D< 28 0.0 cpfifo1_28`  
> `33423 admin 0 D< 29 0.0 cpfifo1_29`  
> `33430 admin 0 D< 56 0.0 cpfifo1_56`  
> `33431 admin 0 D< 57 0.0 cpfifo1_57`  
> `33438 admin 0 D< 84 0.0 cpfifo1_84`  
> `33439 admin 0 D< 85 0.0 cpfifo1_85`
>
> These kernel threads are in the uninterruptible sleep state ("`D`") and only "wake up" when necessary.
>
> This means that the User Space packet threads together with the kernel threads can result in an elevated CPU Load Average, but it does **not**reflect an actual increase in the CPU usage.

### Per-Process CPU Utilization reported by the Kernel ("`top`" "`htop`" and more)

> When SecureXL works in the User Space (UPPAK) mode, Linux-based tools such as "`top`" report higher CPU utilization by the UPPAK-related processes such as "`usim_x86`" or "`pkt_thread_`".
>
> Example output of the "`top`" command:
>
> `top - 16:54:49 up 8 min, 1 user, load average: 4.04, 3.71, 2.01`  
> `top - 16:58:19 up 12 min, 1 user, load average: 4.18, 3.91, 2.43`  
> `Tasks: 260 total, 2 running, 258 sleeping, 0 stopped, 0 zombie`  
> `%Cpu(s): 25.1 us, 0.2 sy, 0.0 ni, 74.6 id, 0.0 wa, 0.1 hi, 0.0 si, 0.0 s`  
> `KiB Mem : 16178816 total, 5628948 free, 6755476 used, 3794392 buff/cache`  
> `KiB Swap: 8385924 total, 8385924 free, 0 used. 8598196 avail Mem`  
> ` PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND`  
> ` 9490 admin 20 0 16.823g 442052 60508 R `199.0` 2.7 23:51.51 `usim_x86  
> `10467 admin 0 -20 4902684 2.337g 313236 S 1.3 15.1 0:31.75 fwk0_dev+`  
> ` 9 admin 20 0 0 0 0 S 0.3 0.0 0:00.53 rcu_sched`  
> `10033 admin 20 0 51496 15332 10064 S 0.3 0.1 0:00.58 confd`  
> `13177 admin 20 0 258236 41488 24776 S 0.3 0.3 0:01.38 vpnd`  
> `17609 admin 20 0 3752 1540 1068 R 0.3 0.0 0:00.02 top`  
> ` 1 admin 20 0 2628 708 604 S 0.0 0.0 0:00.44 init `
>
> The "`top`" command reports high CPU utilization because of the combination of the User Space and kernel threads. However, this situation does not reflect an issue that prevents higher traffic flow through the SecureXL processes. This type of Linux-based tool does not accurately assess the CPU utilization when SecureXL operates in the UPPAK mode.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
