> Source: [sk180437](https://support.checkpoint.com/results/sk/sk180437)

# sk180437 - Unexpected traffic latency or outage on a Security Gateway / Cluster after policy installation 

| Property | Value |
|----------|-------|
| Solution ID | sk180437 |
| Date Created | 2022-12-22 |
| Last Modified | 2026-06-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * Unexpected traffic latency or outages on a Security Gateway / Cluster when the Firewall is configured to work in the User Space (USFW, see [sk167052](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk167052)).

* Usually, the issue starts after a policy installation or a signature load.

* During the time of the incident, the output of the "`top`" / "`ps`" command shows that the "`fwk_wd`" process consumes the CPU at high level.

  <br />

* During the time of the incident, the */var/log/messages* file on the Security Gateway contains these three messages repeatedly:


  `kernel: [SIM<ID>];cpaq_cbuf_send: cpaq_cbuf_call_api_end_ex failed
  `  
  `kernel: [SIM<ID>];cpaq_cbuf_send_buffer: send chunk num 0 failed
  `  
  `kernel: [SIM<ID>];sim_cphwd_stats_cb: failed to create cpaq buffer
  `  
* During the time of the incident, the */var/log/thread_blocker_device64.log* file on the Security Gateway contains soft lockups.

  <br />

* During the time of the incident, the *$FWDIR/log/fwk_wd.elg* file on the Security Gateway contains these messages, repeatedly:


  `thread_blocker_monitor_periodic_timeout_exp_check: tid ` exceeded its timeout(10000)   
  thread_blocker_monitor_periodic_timeout_exp_check: cur_time: reporting_time:

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
