> Source: [sk184083](https://support.checkpoint.com/results/sk/sk184083)

# sk184083 - CPU spikes of 100% and VPN multicast packet drops on Quantum Maestro 

| Property | Value |
|----------|-------|
| Solution ID | sk184083 |
| Date Created | 2025-09-30 |
| Last Modified | 2025-11-27 |
| Technical Level | General |
| Products | Scalable Platforms |
| Versions | R81.20 |
| OS | Gaia |

## Symptoms

- * VPN multicast packets are repeatedly dropped.

* The following drop is observed when running the command `fw ctl zdebug + drop`:

  `dropped by vpnk_multik_forward_vpnxl Reason: failed in packet_tag_handler;`
* `ksoftirqd/1` threads are repeatedly printed in Spike Detective SNDs.

  Note: `ksoftirqd/1`
  is a Linux kernel thread responsible for handling "soft interrupts" (SoftIRQs) on CPU core 1.
* The `spike_detective.log` file contains:

  `
  spike info: type: thread, thread id: X, thread name: ksoftirqd/X, start time: XX/XX/XX`  
  ` XX:XX:XX, spike duration (sec): X, initial cpu usage: XX, average cpu usage: XX, perf `  
  `taken: X`  
  `
  spike info: type: cpu, cpu core: XX, top consumer: system interrupts, start time: XX/XX/XX`  
  ` XX:XX:XX, spike duration (sec): X, initial cpu usage: XX, average cpu usage: XX, perf`  
  ` taken: X`
* `The ``$FWDIR/log/fwk.elg`` file shows this during the time of the incident:`

  `
  ``
  vpn_route_info_from_orig_route_vals: ERROR: my address (X.X.X.X) is not a cluster's address.`  
  ` Address on kbuf: X.X.X.X. Called by: post_sync_orig_route_table. Keeping current address
  `
* `There is a large number of general VPN drops in CPview > Advanced > Network > Drops.`

## Cause

When VPN multicast packets arrive, they are duplicated and forwarded to other Security Group Members via the uplink BMAC. Although packets are decrypted correctly over the synchronization network, the system fails to identify them as properly handled. This loop results in excessive CPU usage on the SNDs and the observed packet drops.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R82](https://support.checkpoint.com/results/sk/sk181127)
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 118

Check Point recommends to always upgrade to the [Recommended version](https://support.checkpoint.com/results/sk/sk95746) ([Security Gateway](https://support.checkpoint.com/product/73) / [VSX](https://support.checkpoint.com/product/359) / [Security Management Server](https://support.checkpoint.com/product/184) / [Multi-Domain Security Management Server](https://support.checkpoint.com/product/166) / [SmartConsole](https://support.checkpoint.com/product/191)).

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
