> Source: [sk43172](https://support.checkpoint.com/results/sk/sk43172)

# sk43172 - Cluster performs fail-overs - detected a problem (cphad) / (fwd)

| Property | Value |
|----------|-------|
| Solution ID | sk43172 |
| Date Created | 2009-11-10 |
| Last Modified | 2016-12-19 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Cluster members perform recurring failovers when the CPU reaches a 100% CPU utilization (in spikes or constant).

* Cluster fails over due to a timeout in FWD pnote or in CPHAD pnote.

* SmartView Tracker shows logs about cluster member being down:

  * `...detected a problem (fwd)`
  * `...detected a problem (cphad)`

## Cause

Both FWD process (monitored by 'FWD' pnote) and CPHAMCSET process (monitored by 'CPHAD' pnote) are running in User Mode.

These processes send life-signs to the kernel on a regular basis (configurable as 'timeout' of the pnote).

When the kernel does not receive the life-signs from these processes for longer than defined in timeout of the corresponding pnote, kernel assumes that monitored process failed. As a result, by design, a 'problem' state is reported on the corresponding pnote, and then, by design, kernel initiates the failover between cluster members.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
