> Source: [sk183690](https://support.checkpoint.com/results/sk/sk183690)

# sk183690 - Multiple log entries about LOGIN_NOTIFIER_SERVER on Security Gateways with R81.20 Jumbo Hotfix Accumulator Take 96 or higher

| Property | Value |
|----------|-------|
| Solution ID | sk183690 |
| Date Created | 2025-07-22 |
| Last Modified | 2026-07-23 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20 |
| OS | Gaia |

## Symptoms

- Syslog Servers and `/var/log/messages` on multiple Security Gateways are experiencing excessive log entries from the LOGIN_NOTIFIER_SERVER process.   
These repetitive entries appear as:  
`login_notifier_server: before force_2fa_generation, params: 2fa-check`  
`
login_notifier_server: after force_2fa_generation, params: 2fa-check`

## Cause

The log has many repeated entries caused by the LOGIN_NOTIFIER_SERVER process repeatedly generating Two-Factor Authentication (2FA) check and regeneration messages, even though 2FA is not enabled or enforced for any users or globally on the affected Security Gateways with installed R81.20 Jumbo Hotfix Accumulator Take 96 or higher.  
This behavior results from changes in the code integrated with the 2FA feature in R81.20 Take 96. The system erroneously performs and logs 2FA operations regardless of the actual 2FA configuration status. The issue is not related to any custom configuration or user action.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
