> Source: [sk185272](https://support.checkpoint.com/results/sk/sk185272)

# sk185272 - Security Gateway memory consumption unexpectedly increases 

| Property | Value |
|----------|-------|
| Solution ID | sk185272 |
| Date Created | 2026-08-13 |
| Last Modified | 2026-08-17 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * The affected Security Gateway or ClusterXL environment shows steadily increasing virtual memory, physical memory, or kernel memory utilization over time.
* Both ClusterXL members may show similar connection growth patterns and increased synchronization traffic.   
  The total number of Global Connection (gconn) entries is significantly higher than the actual number of concurrent connections.
* The Global Connection table exceeds the expected ratio of approximately 2:1 to 4:1 compared to concurrent connections.
* The Security Gateway may become unstable or experience resource exhaustion due to excessive memory consumption.
* Memory is released only after a Security Gateway reboot.
* SMEM output may show a large alloc_gconn_ent value.
* The `fw ctl multik gconn -p` command may show many `gconn` entries with:  
  `Hold_ref = 4294967295`
* The Security Gateway may display: `alloc_gconn_ent: Failed to allocate entry`
* A very large Global Connection table may cause performance degradation and increase ClusterXL synchronization traffic.  

  Example observed values:  
  Concurrent connections: approximately 57,000  
  Global Connection table entries: approximately 50,000,000  

  Example Global Connection table growth:  
  July 27: 36,460,508 entries  
  July 30: 49,577,334 entries
* Memory utilization increases following connection spikes and does not return to previous levels after connection counts decrease.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 36
* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 118
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 158

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).  

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
