> Source: [sk180860](https://support.checkpoint.com/results/sk/sk180860)

# sk180860 - IDAFServerHostService uses high CPU/Policies fail to update

| Property | Value |
|----------|-------|
| Solution ID | sk180860 |
| Date Created | 2023-04-21 |
| Last Modified | 2023-05-04 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, R82.10, R82, R81.20 |
| OS | Windows |

## Symptoms

- * CPU.Main symptom Client policies are outdated and not relevant or the old default and when customer tried to update policy, it will fail
* Logs in *\\DA\\Files\\ProgramData\\CheckPoint\\Endpoint Security\\Common\\Storage\\Common* contain many messages related to SID52 policies.
* Logs in *\\DA\\Files\\ProgramData\\CheckPoint\\Endpoint Security\\Common\\Storage\\Common* contain more than four files for each policy type.
* Another common but not mandatory symptom is the Check Point Device Auxiliary Framework Service (IDAFServerHostService.exe) process consumes high
* idafserver.log: cppsm \[error\] DecryptData failed. can't read policy. \[PolicyStorageUtils::ReadSAFromFile\] cppsm \[error\] Trying to delete corrupted policy files. \[PolicyStorageUtils::ReadSAFromFile\] ppsm \[error\] Could not delete corrupted policy files. \[PolicyStorageUtils::ReadSAFromFile\] cppsm \[error\] Exiting, Failed getting stored policies from Common \[CPolicyStorageModule::GetStoredPolicies\]

## Cause

During the processing of an HB (heartbeat) request, the ID of Device Settings policy (type 52 or a policy with four or more entries) undergoes changes, regardless of whether the policy itself has been modified. At the end of the processing of the HB request, the Server checks whether synchronization is required. As the policy identifier has changed, the Server considers the policy to have been updated and sends an HB result of 128 (sync is needed).  

Endpoint client sends synchronization updates every minute and stores all policy versions locally.  

The error in the server code appears when the client requests new policies and the Server responds with "*Yes, we have a new policy with enforcement_type = X*". In this case, the most common policy type is 52, but it can be others if there are more than four entries. Despite the new policy identifier, the policy content remains the same.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
