> Source: [sk97638](https://support.checkpoint.com/results/sk/sk97638)

# sk97638 - Check Point Processes and Daemons

| Property | Value |
|----------|-------|
| Solution ID | sk97638 |
| Date Created | 2013-12-11 |
| Last Modified | 2026-09-24 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Scalable Platforms |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R81 (EOS), R82.10, R82, R81.20, R81.10 (EOS), R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

**Table of Contents:**

* **Gaia Processes and Daemons**
* **Infrastructure Processes**
* **Security Gateway Software Blades and Features**

  |------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------|
  | * Firewall Blade * IPSec VPN Blade * Mobile Access Blade * Identity Awareness Blade * DLP Blade and Content Awareness Blade * Threat Emulation Blade * Threat Extraction Blade * Zero Phishing Blade | * Threat Prevention * IPS Blade * URL Filtering Blade * Application Control Blade * Anti-Bot Blade * Anti-Virus Blade * Anti-Spam Blade | * Monitoring Blade * HTTPS Inspection * HTTP/HTTPS Proxy * ClusterXL * SecureXL * CoreXL * VSX * SD-WAN |

* **Security Management Software Blades and Features**

  |------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------|---------------------------------------------------------------------------|
  | * Network Policy Management Blade * Endpoint Policy Management Blade * Monitoring Blade * Provisioning Blade * SmartReporter Blade | * SmartEvent Blade * Logging \& Status Blade * Management Portal * SmartLog | * Internal CA * Compliance Blade * SofaWare Management Server * OPSEC LEA |

* **Scalable Platforms**
* **Quantum Spark Appliances**
* **Endpoint Security Client**
* **Additional Processes**
* **Related solutions**

**Important** - Unless stated otherwise, you must run the commands in the Expert mode.

Gaia Processes and Daemons {#Gaia Processes and Daemons}
--------------------------------------------------------

All Gaia processes and daemons run by default, other than `snmpd` and `dhcpd`.

Enter the string you are searching for in this table:   

|----------------|--------------|---------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Daemon         | Child daemon | Section                   | Information                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | -            | Description               | Gaia OS Process Manager (`/bin/pm`). Controls other processes and daemons.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| pm             | -            | Path                      | `/bin/pm`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| pm             | -            | Log File                  | `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pm             | -            | To Stop                   | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| pm             | -            | To Start                  | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| pm             | confd        | Description               | Database and configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | confd        | Path                      | `/bin/confd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| pm             | confd        | Important Note            | Maintenance window is required to restart this daemon: * When `confd` daemon is starting, by design, it restarts any currently running `routed` daemons (by sending a TERM signal). It is done to avoid possible issues in Gaia Clish (e.g., returning invalid results for routing-related commands like "`show route`"). * Since `routed` daemon is responsible for all the routing in Gaia OS, short traffic outage will occur while `routed` daemon is being restarted. * Since `routed` daemon is a Critical Device in Check Point cluster (since R76), cluster fail-over might occur while `routed` daemon is being restarted (refer to [sk92878](https://support.checkpoint.com/results/sk/sk92878)). * In a VSX environment, restarting the routed process owned by VS0 restarts routed for all Virtual Systems. Contact [Check Point support](https://www.checkpoint.com/support-services/contact-support/) for assistance. |
| pm             | confd        | Log File                  | `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pm             | confd        | To Stop                   | `tellpm process:confd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| pm             | confd        | To Start                  | `tellpm process:confd t`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| pm             | confd        | Debug                     | Examine `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | searchd      | Description               | Search indexing daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| pm             | searchd      | Log File                  | `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pm             | searchd      | Path                      | `/bin/searchd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| pm             | searchd      | To Stop                   | `tellpm process:searchd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| pm             | searchd      | To Start                  | `tellpm process:searchd t`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| pm             | searchd      | Debug                     | Examine `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | clishd       | Description               | Gaia Clish CLI interface process - general information for all Gaia Clish sessions.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pm             | clishd       | Path                      | `/bin/clishd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| pm             | clishd       | Log File                  | `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pm             | clishd       | To Stop                   | `tellpm process:clishd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| pm             | clishd       | To Start                  | `tellpm process:clishd t`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| pm             | clishd       | Debug                     | Examine `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | clish        | Description               | Gaia Clish CLI interface process - Clish process per session.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| pm             | clish        | Path                      | `/bin/clish`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| pm             | clish        | Log File                  | `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pm             | clish        | To Stop                   | `tellpm process:clish`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| pm             | clish        | To Start                  | `tellpm process:clish t`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| pm             | clish        | Debug                     | Refer to [sk106938](https://support.checkpoint.com/results/sk/sk106938)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| pm             | routed       | Description               | Routing daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| pm             | routed       | Path                      | `/bin/routed`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| pm             | routed       | Important Note            | Maintenance window is required to restart this daemon: * Since `routed` daemon is responsible for all the routing in Gaia OS, short traffic outage will occur while `routed` daemon is being restarted. * Since `routed` daemon is a Critical Device in Check Point cluster (since R76), cluster fail-over might occur while `routed` daemon is being restarted (refer to [sk92878](https://support.checkpoint.com/results/sk/sk92878)).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| pm             | routed       | Log File                  | * `/var/log/routed.log` * `/var/log/routed_messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| pm             | routed       | Configuration File        | `/etc/routed.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| pm             | routed       | To Stop                   | `tellpm process:routed`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| pm             | routed       | To Start                  | `tellpm process:routed t`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| pm             | routed       | Debug                     | Refer to: * [sk84520 - How to debug OSPF and RouteD daemon on Gaia](https://support.checkpoint.com/results/sk/sk84520) * [sk101399 - How to debug BGP and RouteD daemon on Gaia](https://support.checkpoint.com/results/sk/sk101399) * [sk92598 - How to debug PIM and Multicast on Gaia](https://support.checkpoint.com/results/sk/sk92598)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| pm             | httpd2       | Description               | Web server daemon (Gaia Portal).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| pm             | httpd2       | Path                      | `/web/cpshared/web/Apache/2.2.0/bin/httpd2`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | httpd2       | Log File                  | * `/var/log/httpd2_error_log` * `/var/log/httpd2_access_log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| pm             | httpd2       | Configuration File        | `/web/conf/httpd2.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| pm             | httpd2       | To Stop                   | `tellpm process:httpd2`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| pm             | httpd2       | To Start                  | `tellpm process:httpd2 t`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| pm             | httpd2       | Debug                     | Refer to [sk84561](https://support.checkpoint.com/results/sk/sk84561)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| pm             | monitord     | Description               | Hardware monitoring daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | monitord     | Path                      | `/bin/monitord`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| pm             | monitord     | Log File                  | `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pm             | monitord     | To Stop                   | `tellpm process:monitord`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| pm             | monitord     | To Start                  | `tellpm process:monitord t`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | monitord     | Debug                     | Examine `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | rconfd       | Description               | Provisioning daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| pm             | rconfd       | Path                      | `/bin/rconfd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| pm             | rconfd       | Log File                  | `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pm             | rconfd       | To Stop                   | `tellpm process:rconfd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| pm             | rconfd       | To Start                  | `tellpm process:rconfd t`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| pm             | rconfd       | Debug                     | Examine `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | cloningd     | Description               | Gaia Cloning Groups daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | cloningd     | Path                      | `/bin/cloningd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| pm             | cloningd     | Log File                  | `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pm             | cloningd     | To Stop                   | `tellpm process:cloningd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| pm             | cloningd     | To Start                  | `tellpm process:cloningd t`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | cloningd     | Debug                     | Examine `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | dhcpd        | Description               | DHCP server daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pm             | dhcpd        | Path                      | `/usr/sbin/dhcpd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| pm             | dhcpd        | Log File                  | `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pm             | dhcpd        | Configuration File        | [/etc/dhcpd.conf](http://linux.die.net/man/5/dhcpd.conf)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| pm             | dhcpd        | To Stop                   | * In Gaia Clish: `set dhcp server disable` * In Gaia Portal: "Network Management" section - "DHCP Server" pane                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| pm             | dhcpd        | To Start                  | * In Gaia Clish: `set dhcp server enable` * In Gaia Portal: "Network Management" section - "DHCP Server" pane                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| pm             | dhcpd        | Debug                     | Examine `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pm             | snmpd        | Description               | SNMP (Linux) daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| pm             | snmpd        | Path                      | `/usr/sbin/snmpd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| pm             | snmpd        | Log File                  | `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pm             | snmpd        | Configuration File        | [/etc/snmp/snmpd.conf](http://linux.die.net/man/5/snmpd.conf)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| pm             | snmpd        | To Stop                   | * In Gaia Clish: `set snmp agent off` * In Gaia Portal:"System Management" section - "SNMP" pane                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| pm             | snmpd        | To Start                  | * In Gaia Clish: `set snmp agent on` * In Gaia Portal: "System Management" section - "SNMP" pane                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| pm             | snmpd        | Debug                     | Refer to [sk56783](https://support.checkpoint.com/results/sk/sk56783)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| xpand          | -            | Description               | Configuration daemon that processes and validates all user configuration requests, updates the system configuration database, and calls other utilities to carry out the request.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| xpand          | -            | Path                      | `/bin/confd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| xpand          | -            | Log File                  | `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| xpand          | -            | To Stop                   | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| xpand          | -            | To Start                  | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| xpand          | -            | Debug                     | Examine `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| sshd           | -            | Description               | SSH daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| sshd           | -            | Path                      | `/usr/sbin/sshd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| sshd           | -            | Log File                  | * `/var/log/secure` * `/var/log/auth/` * `/var/log/messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| sshd           | -            | Configuration File        | * R81 higher versions, R80.40 Jumbo Hotfix Take 83 and higher: 1. Back up and edit: `/etc/ssh/templates/sshd_config.templ` 2. Run : `/bin/sshd_template_xlate < /config/active` * In lower versions: [/etc/ssh/sshd_config](http://linux.die.net/man/5/sshd_config)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| sshd           | -            | To Stop                   | `service sshd stop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| sshd           | -            | To Start                  | `service sshd start`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| sshd           | -            | Debug                     | 1. Edit the applicable "`sshd_config`" file (see above): 1. Change the "`LogLevel`" line: from: `#LogLevel INFO` to: `LogLevel DEBUG3` 2. Save the changes in the file 3. Load the updated configuration (in R81 and higher versions, and in R80.40 Jumbo Hotfix Take 83 and higher): `/bin/sshd_template_xlate < /config/active` 2. Start SSHD under debug to run in background (copy the PID): `/usr/sbin/sshd -ddd 1>> /var/log/sshd.debug.txt 2>> /var/log/sshd.debug.txt &` 3. Replicate the issue (connect over SSH). 4. Stop the SSHD: `kill -TERM <PID>` `kill -KILL <PID>` 5. Revert the changes in the applicable "`sshd_config`" file 6. Load the updated configuration (in R81 and higher versions, R80.40 Jumbo Hotfix Take 83 and higher): `/bin/sshd_template_xlate < /config/active` 7. Analyze: `/var/log/sshd.debug.txt`                                                                                          |
| syslogd        | -            | Description               | Syslog (Linux) daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| syslogd        | -            | Path                      | `/sbin/syslogd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| syslogd        | -            | Log File                  | * `/var/log/messages` * `/var/log/dmesg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| syslogd        | -            | Configuration File        | * `/etc/syslog.conf` * `/var/run/syslog.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| syslogd        | -            | To Stop                   | `service syslog stop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| syslogd        | -            | To Start                  | `service syslog start`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| syslogd        | -            | Debug                     | Refer to [sk108421](https://support.checkpoint.com/results/sk/sk108421)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| DAService      | -            | Description               | Check Point Upgrade Service Engine (CPUSE) - former 'Gaia Software Updates' service (refer to [sk92449](https://support.checkpoint.com/results/sk/sk92449)).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| DAService      | -            | Path                      | `$DADIR/bin/DAService`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| DAService      | -            | Log File                  | * `/opt/CPInstLog/DeploymentAgent.log` * `/opt/CPInstLog/DA_UI.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| DAService      | -            | Notes                     | The "`cpwd_admin list`" command shows the process as "`DASERVICE`" (command is "`$DADIR/bin/DAService_script`" - this is a watchdog script that starts the `$DADIR/bin/DAService`, if it is not running).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| DAService      | -            | To See the Current Status | `cpwd_admin list | grep -E "APP|DASERVICE"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| DAService      | -            | To Stop                   | 1. `$DADIR/bin/dastop` 2. `dbget installer:stop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| DAService      | -            | To Start                  | 1. `$DADIR/bin/dastart` 2. `dbget installer:start`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| DAService      | -            | Debug                     | Refer to [sk92449](https://support.checkpoint.com/results/sk/sk92449): 1. Create the configuration file: `touch $DADIR/bin/DAconf` 2. Add the following line (case-sensitive; spaces are not allowed): `PING_TRACE=1` 3. Save the changes 4. Re-load the new configuration: `DAClient conf` 5. As soon as possible: 1. Replicate the issue 2. Delete the `$DADIR/bin/DAconf` file 3. Re-load the configuration with `DAClient conf` command 6. Analyze: `/opt/CPInstLog/DeploymentAgent.log`                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| AutoUpdater    | -            | Description               | AutoUpdater - responsible for automatic updates in: * R80.40 and higher * R80.30 Jumbo Take 71 (and higher) * R80.20 Jumbo Take 117 (and higher) * R80.10 Jumbo Take 245 (and higher)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| AutoUpdater    | -            | Path                      | `$AUTOUPDATERDIR/latest/bin/AutoUpdater`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| AutoUpdater    | -            | Log File                  | `$AUTOUPDATERDIR/AutoUpdater.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| AutoUpdater    | -            | To See the Current Status | `cpwd_admin list | grep -E "APP|AUTOUPDATER"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| AutoUpdater    | -            | To Stop                   | `AutoUpdaterWDUnReg.sh ; autoupdatercli stop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| AutoUpdater    | -            | To Start                  | `AutoUpdaterWDReg.sh`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| AutoUpdater    | -            | Debug                     | `autoupdatercli debug DEBUG`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| dynamic_server | -            | Description               | Dynamic Server daemon for the Gaia Dynamic CLI feature - [sk144112](https://support.checkpoint.com/results/sk/sk144112)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dynamic_server | -            | Path                      | `/usr/bin/dynamic_server`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dynamic_server | -            | Log File                  | `/var/log/dynamicCli.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dynamic_server | -            | To See the Current Status | In the Expert mode: `ps auxw | grep -v grep | grep 'dynamic_server'`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dynamic_server | -            | To Stop                   | In the Expert mode: `tellpm process:dynamic_server`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| dynamic_server | -            | To Start                  | In the Expert mode: `tellpm process:dynamic_server t`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| dynamic_server | -            | Debug                     | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

{#Filter_1Table}

**Note: Other Gaia OS daemons can be stopped in Expert mode, but it is not recommended.**

Infrastructure Processes {#Infrastructure Processes}
----------------------------------------------------

Enter the string you are searching for in this table:

|----------|---------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Daemon   | Section                   | Information                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cpwd     | Description               | WatchDog is a process that launches and monitors critical processes such as Check Point daemons on the local machine, and attempts to restart them if they fail. Among the processes monitored by Watchdog are `cpd`, `fwd`, and `fwm`. Watchdog is controlled by the `cpwd_admin` utility. To learn how to start and stop various daemons, run the `cpwd_admin` command.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cpwd     | Path                      | `$CPDIR/bin/cpwd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| cpwd     | Log File                  | `$CPDIR/log/cpwd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cpwd     | To Stop                   | `cpwd_admin kill` or `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cpwd     | To Start                  | `$CPDIR/bin/cpwd >& /dev/null` or `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cpwd     | Debug                     | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| cpd      | Description               | * Port 18191 - Generic process (add-ons container) for many Check Point services, such as installing and fetching policy, and online updates * Port 18211 - SIC push certificate (from Internal CA) * Inter-process communication between Check Point daemons (starting in R82, this task was moved to the MSGD daemon)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cpd      | Path                      | `$CPDIR/bin/cpd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| cpd      | Log File                  | `$CPDIR/log/cpd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| cpd      | Notes                     | The "`cpwd_admin list`" command shows the process as "`CPD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cpd      | To See the Current Status | `cpwd_admin list | grep -E "APP|CPD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cpd      | To Stop                   | * Management Server / Security Gateway: `cpwd_admin stop -name CPD -path "$CPDIR/bin/cpd_admin" -command "cpd_admin stop"` or `cpstop` * Domain Management Server on a Multi-Domain Security Management Server: `mdsstop_customer <IP Address of Domain Management Server>` * VSX Gateway: `[Expert@HostName:0]# vsenv <VSID>` `[Expert@HostName:<VSID>]# cpwd_admin stop -name CPD -path "$CPDIR/bin/cpd_admin" -command "cpd_admin stop" -ctx <VSID> -env inherit` or `[Expert@HostName:0]# cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cpd      | To Start                  | * Management Server / Security Gateway: `cpwd_admin start -name CPD -path "$CPDIR/bin/cpd" -command "cpd"` or `cpstart` * Domain Management Server on a Multi-Domain Security Management Server: `mdsstart_customer <IP Address of Domain Management Server>` * VSX Gateway: `[Expert@HostName:0]# vsenv <VSID>` `[Expert@HostName:<VSID>]# cpwd_admin start -name CPD -path "$CPDIR/bin/cpd" -command "cpd" -ctx <VSID> -env inherit` or `[Expert@HostName:0]# cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cpd      | Debug                     | "`cpd_admin debug`" - refer to [sk86320](https://support.checkpoint.com/results/sk/sk86320)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| msgd     | Description               | This process exists starting from the R82 version. Dedicated daemon for the Check Point inter-process communication (the processing of inter-process communication was moved from the CPD daemon to the MSGD daemon). This daemon listens on 127.0.0.1:8989. **Important** - If this daemon is stopped, then all Check Point inter-process communication fails. As a result, multiple tasks would fail - policy installation, license installation, and so on.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| msgd     | Path                      | `$CPDIR/bin/msgd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| msgd     | Log File                  | `$CPDIR/log/msgd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| msgd     | Notes                     | The "`cpwd_admin list`" command shows the process as "`MSGD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| msgd     | To See the Current Status | `cpwd_admin list | grep -E "APP|MSGD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| msgd     | To Stop                   | * Management Server / Security Gateway: `cpwd_admin stop -name MSGD -path ${CPDIR}/bin/msgd -command "msg_admin stop"` or `msg_admin stop` * Domain Management Server on a Multi-Domain Security Management Server: `mdsstop_customer <IP Address of Domain Management Server>` * VSX Gateway: `[Expert@HostName:0]# vsenv <VSID>` `[Expert@HostName:<VSID>]# cpwd_admin stop -name MSGD -path ${CPDIR}/bin/msgd -command "msg_admin stop" -ctx <VSID -env inherit` or `[Expert@HostName:0]# cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| msgd     | To Start                  | * Management Server / Security Gateway: `cpd"cpwd_admin start -name MSGD -path ${CPDIR}/bin/msgd -command msgd` or `cpstart` * Domain Management Server on a Multi-Domain Security Management Server: `mdsstart_customer <IP Address of Domain Management Server>` * VSX Gateway: `[Expert@HostName:0]# vsenv <VSID>` `[Expert@HostName:<VSID>]# cpwd_admin start -name MSGD -path ${CPDIR}/bin/msgd -command msgd -ctx <VSID> -env inherit` or `[Expert@HostName:0]# cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| msgd     | Debug                     | Run: 1. `msg_admin -h` 2. `msg_admin debug on <Environment Setting>` 3. `msg_admin debug off`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| fwd      | Description               | * On a Security Gateway - Sending the Security Logs to a Management Server / Log Server * On a Security Gateway - Spawning child processes (e.g., `vpnd, fwk_forker, cpd, rad, pdpd, pepd, cpviewd, cpview_services, cpview_api_service,spike_detective, etc`) * On a Security Gateway - Full Synchronization between ClusterXL members in versions R80.40 and lower. (To perform a Full Sync with a peer cluster member, the FWD daemon on a cluster member connects to the TCP port 256 on the peer cluster member. In versions R81 and higher, the CXLD daemon on a cluster member connects to the TCP port 263.) * On a Security Gateway - Policy installation (notifies applicable daemons, e.g., Security Servers) * On a Security Gateway - IPS packet capture * On a Security Gateway - Update of the Application Control and URL Filtering database * On a Security Gateway - Handling connections from a Management Server to instantly block suspicious connections that are not restricted by the currently enforced security policy using the Suspicious Activity Rules feature in SmartView Monitor ('Tools' menu) * On a Security Gateway - Download of VPN Topology and of Public Key to SecureClient / SecuRemote clients * On a Security Gateway - Handling connections the OPSEC Suspicious Activity Monitor (SAM) connections from GX / LTE SAM clients * On a Management Server - Handling connections from a SmartEvent Server * On a Management Server - Handling connections for exporting FireWall logs using OPSEC Log Export API (LEA) products * On a Management Server - Handling FireWall logs sent by OPSEC products (ELA) * On a Management Server - Exchange of CA-keys and DH-keys between Management Servers (SKIP, FWZ (4.x)) |
| fwd      | Path                      | `$FWDIR/bin/fwd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| fwd      | Log File                  | `$FWDIR/log/fwd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| fwd      | Notes                     | * The "`cpwd_admin list`" command shows the process as "`FWD`". * The "`top`" and "`ps`" commands might also show "`fw`" process and/or "`fw_full`" process, which are just wrappers for the "`fwd`" process.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| fwd      | To See the Current Status | `cpwd_admin list | grep -E "APP|FWD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| fwd      | To Stop                   | * Management Server / Security Gateway: `cpwd_admin stop -name FWD -path "$FWDIR/bin/fwd" -command "fw kill fwd"` or `cpstop` * Domain Management Server on a Multi-Domain Security Management Server: `mdsstop_customer <IP Address of Domain Management Server>` * VSX Gateway: `[Expert@HostName:0]# vsenv <VSID>` `[Expert@HostName:<VSID>]# cpwd_admin stop -name FWD -path "$FWDIR/bin/fwd" -command "fw kill fwd" -ctx <VSID> -env inherit` or `[Expert@HostName:0]# cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| fwd      | To Start                  | * Management Server / Security Gateway: `cpwd_admin start -name FWD -path "$FWDIR/bin/fwd" -command "fwd"` or `cpstart` * Domain Management Server on a Multi-Domain Security Management Server: `mdsstart_customer <IP Address of Domain Management Server>` * VSX Gateway: `[Expert@HostName:0]# vsenv <VSID>` `[Expert@HostName:<VSID>]# cpwd_admin start -name FWD -path "$FWDIR/bin/fwd" -command "fwd" -ctx <VSID> -env inherit` or `[Expert@HostName:0]# cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| fwd      | Debug                     | Refer to [sk86321](https://support.checkpoint.com/results/sk/sk86321): 1. Start debug: `fw debug fwd on TDERROR_ALL_ALL=5` `fw debug fwd on OPSEC_DEBUG_LEVEL=3` 2. Replicate the issue 3. Stop debug: `fw debug fwd off TDERROR_ALL_ALL=0` `fw debug fwd off OPSEC_DEBUG_LEVEL=0` 4. Analyze: `$FWDIR/log/fwd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| msgd     | Description               | This process exists starting from the R82 version. This process is responsible for communication between Check Point processes (to see the list of the registered processes, run the "`msg_admin reg`" command).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| msgd     | Path                      | `$CPDIR/bin/msgd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| msgd     | Log File                  | `$CPDIR/log/msgd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| msgd     | To Stop                   | `cpwd_admin stop -name MSGD -path "$CPDIR/bin/msg_admin" -command "msg_admin stop"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| msgd     | To Start                  | `cpwd_admin start -name MSGD -path "$CPDIR/bin/msgd" -command "msgd"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| msgd     | Debug                     | 1. Start debug: `msg_admin debug on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `msg_admin debug off` 4. Analyze: `$CPDIR/log/msgd.elg*` [](https://support.checkpoint.com/results/sk/sk41793)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cprid    | Description               | Check Point Remote Installation Daemon - distribution of packages from SmartUpdate to managed Gateways.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cprid    | Path                      | `$CPDIR/bin/cprid`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| cprid    | Log File                  | `$CPDIR/log/cprid.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| cprid    | To Stop                   | `$CPDIR/bin/cpridstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| cprid    | To Start                  | `$CPDIR/bin/cpridstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cprid    | Debug                     | Refer to [sk41793](https://support.checkpoint.com/results/sk/sk41793)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cprid_wd | Description               | WatchDog for Check Point Remote Installation Daemon "`cprid`".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cprid_wd | Path                      | `$CPDIR/bin/cprid_wd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cprid_wd | Log File                  | `$CPDIR/log/cprid_wd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cprid_wd | To Stop                   | `$CPDIR/bin/cpridstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| cprid_wd | To Start                  | `$CPDIR/bin/cpridstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cprid_wd | Debug                     | Standard CSH script debugging (`csh -x -v $CPDIR/bin/cprid_wd`)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| kissd    | Description               | KISS - used for kernel memory management.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| kissd    | Path                      | None - created by the kernel code (`drv_init`).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| kissd    | Log File                  | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| kissd    | To Stop                   | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| kissd    | To Start                  | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| kissd    | Debug                     | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |

{#Filter_2Table}

Security Gateway Software Blades and Features {#Security Gateway Software Blades and Features}
----------------------------------------------------------------------------------------------

Enter the string you are searching for in this table:

{#Security Gateway Software Blades and Features - Firewall Blade}{#Security Gateway Software Blades and Features - IPSec VPN Blade}{#Security Gateway Software Blades and Features - Mobile Access Blade}{#Security Gateway Software Blades and Features - Identity Awareness Blade}{#Security Gateway Software Blades and Features - DLP Blade}{#Security Gateway Software Blades and Features - Threat Emulation Blade}{#Security Gateway Software Blades and Features - Threat Extraction Blade}{#Security Gateway Software Blades and Features - Zero Phishing Blade}{#Security Gateway Software Blades and Features - Infinity Threat Prevention Blade}{#Security Gateway Software Blades and Features - IPS Blade}{#Security Gateway Software Blades and Features - URL Filtering Blade}{#Security Gateway Software Blades and Features - Application Control Blade}{#Security Gateway Software Blades and Features - Anti-Bot Blade}{#Security Gateway Software Blades and Features - Anti-Virus Blade}{#Security Gateway Software Blades and Features - Anti-Spam Blade}{#Security Gateway Software Blades and Features - Monitoring Blade}{#Security Gateway Software Blades and Features - HTTPS Inspection}{#Security Gateway Software Blades and Features - HTTP/HTTPS Proxy}{#Security Gateway Software Blades and Features - ClusterXL}{#Security Gateway Software Blades and Features - SecureXL}{#Security Gateway Software Blades and Features - CoreXL}{#Security Gateway Software Blades and Features - VSX}{#Security Gateway Software Blades and Features - SD-WAN}

|------------------------|---------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Daemon                 | Section                   | Information                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Firewall Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
| fwd                    | Description               | * Logging * Spawning child processes (e.g., `vpnd`)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| fwd                    | Path                      | `$FWDIR/bin/fwd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| fwd                    | Log File                  | `$FWDIR/log/fwd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| fwd                    | Notes                     | * The "`cpwd_admin list`" command shows the process as "`FWD`". * The "`top`" and "`ps`" commands might also show "`fw`" process and/or "`fw_full`" process, which are just wrappers for the "`fwd`" process.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| fwd                    | To See the Current Status | `cpwd_admin list | grep -E "APP|FWD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| fwd                    | To Stop                   | * Security Gateway: `cpwd_admin stop -name FWD -path "$FWDIR/bin/fw" -command "fw kill fwd"` or `cpstop` * VSX Gateway: `[Expert@HostName:0]# vsenv <VSID>` `[Expert@HostName:<VSID>]# cpwd_admin stop -name FWD -path "$FWDIR/bin/fw" -command "fw kill fwd" -ctx <VSID> -env inherit` or `[Expert@HostName:0]# cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| fwd                    | To Start                  | * Security Gateway: `cpwd_admin start -name FWD -path "$FWDIR/bin/fwd" -command "fwd"` or `cpstart` * VSX Gateway: `[Expert@HostName:0]# vsenv <VSID>` `[Expert@HostName:<VSID>]# cpwd_admin start -name FWD -path "$FWDIR/bin/fwd" -command "fwd" -ctx <VSID> -env inherit` or `[Expert@HostName:0]# cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| fwd                    | Debug                     | Refer to [sk86321](https://support.checkpoint.com/results/sk/sk86321): 1. Start debug: `fw debug fwd on TDERROR_ALL_ALL=5` `fw debug fwd on OPSEC_DEBUG_LEVEL=3` 2. Replicate the issue 3. Stop debug: `fw debug fwd off TDERROR_ALL_ALL=0` `fw debug fwd off OPSEC_DEBUG_LEVEL=0` 4. Analyze: `$FWDIR/log/fwd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| uprd                   | Description               | This process exists starting from the R82 version. Unified Policy Report Daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| uprd                   | Path                      | `$FWDIR/bin/uprd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| uprd                   | Log File                  | `$FWDIR/log/uprd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| uprd                   | Notes                     | The "`cpwd_admin list`" command shows the process as "`UPRD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| uprd                   | To See the Current Status | `cpwd_admin list | grep -E "APP|UPRD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| uprd                   | To Stop                   | `$CPDIR/bin/cpwd_admin stop -name UPRD` or `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| uprd                   | To Start                  | `$CPDIR/bin/cpwd_admin start -name UPRD -path "$FWDIR/bin/uprd" -command "uprd"` or `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| IPSec VPN Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
| vpnd                   | Description               | R81.10 and higher: * The single `vpnd` daemon handles these VPN connections: * All connections from non-IKE Remote Access clients (SSL Network Extender, Capsule VPN). * Multi-Portal (SSL/TLS) traffic. R81 and lower: * The single `vpnd` daemon handles these VPN connections: * IKE (UDP/TCP) * NAT-T * Tunnel Test * Reliable Datagram Protocol (RDP) * Topology Update for SecureClient * SSL Network Extender (SNX) * SSL Network Extender (SNX) Portal * Remote Access Client configuration * Visitor Mode * L2TP                                                                                                                                                                                                                                                                                                                                                                                     |
| vpnd                   | Path                      | `$FWDIR/bin/vpn`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| vpnd                   | Log File                  | R81.20 and higher: * `$FWDIR/log/vpnd.elg*` * `$FWDIR/log/vpnd.ikev1trace*` * `$FWDIR/log/vpnd.ikev2trace*` R81.10: * `$FWDIR/log/vpnd.elg*` * `$FWDIR/log/legacy_ike.elg*` * `$FWDIR/log/legacy_ikev2.xml*` R81 and R80.40: * `$FWDIR/log/vpnd.elg*` * `$FWDIR/log/ike.elg*` * `$FWDIR/log/ikev2.xmll*` R80.30 and lower: * `$FWDIR/log/vpnd.elg*` * `$FWDIR/log/ike.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| vpnd                   | Notes                     | * This daemon is not monitored by Check Point WatchDog ("`cpwd_admin list`") * This daemon is spawned by the FWD daemon                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| vpnd                   | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| vpnd                   | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| vpnd                   | Debug                     | Refer to: * For R80.10 and higher versions: [sk180488](https://support.checkpoint.com/results/sk/sk180488) * For R77.30 and lower versions: [sk89940](https://support.checkpoint.com/results/sk/sk89940)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| iked                   | Description               | This process exists starting from the R81.10 version. R81.20 and higher: * The multiple `iked` daemons (`iked0`, `iked1`, and so on) handle these VPN connections: * All connections from IKE Remote Access clients (for example, Endpoint clients). * All IKE Site-to-Site connections from peer Security Gateways, and Large Scale VPN (LSV) connections. * All connections from SmartLSM ROBO gateways. * All connections from Security Gateways with a Dynamically Assigned IP Address (DAIP). R81.10: * The single `iked` daemon handles these VPN connections: * All connections from IKE Remote Access clients (for example, Endpoint clients). * All IKE Site-to-Site connections from peer Security Gateways, and Large Scale VPN (LSV) connections. * All connections from SmartLSM ROBO gateways. * All connections from Security Gateways with a Dynamically Assigned IP Address (DAIP).          |
| iked                   | Path                      | `$FWDIR/bin/ike`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| iked                   | Log File                  | R81.20 and higher: * `$FWDIR/log/iked*.elg*` * `$FWDIR/log/iked*.ikev1trace*` * `$FWDIR/log/iked*.ikev2trace*` R81.10: * `$FWDIR/log/ike.elg*` * `$FWDIR/log/iked.elg*` * `$FWDIR/log/ikev2.xml*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| iked                   | Notes                     | This process is not monitored by Check Point WatchDog ("`cpwd_admin list`")                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| iked                   | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| iked                   | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| iked                   | Debug                     | Refer to: * For R80.10 and higher versions: [sk180488](https://support.checkpoint.com/results/sk/sk180488) * For R77.30 and lower versions: [sk89940](https://support.checkpoint.com/results/sk/sk89940)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cccd                   | Description               | This process exists starting from the R81.10 version. The single `cccd` daemon is responsible for the Client Communication Channel (CCC) protocol, while: * IKE for the same clients runs in the IKE daemons `iked`. * The TLS layer of the CCC protocol for the same clients runs in the VPN daemon `vpnd`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| cccd                   | Path                      | `$FWDIR/bin/ccc`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| cccd                   | Log File                  | `$FWDIR/log/cccd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cccd                   | Notes                     | This process is not monitored by Check Point WatchDog ("`cpwd_admin list`")                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cccd                   | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cccd                   | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cccd                   | Debug                     | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| probemond              | Description               | This process exists starting from the R82 version. Advanced monitoring of VPN tunnels using HTTP, HTTPS, or ICMP probing of the configured destinations. To see the available CLI options, run: `probemon help`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| probemond              | Path                      | `$FWDIR/bin/probemond`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| probemond              | Log File                  | * `$FWDIR/log/probemond.elg` * `/var/tmp/probemon_event.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| probemond              | Configuration File        | `$FWDIR/conf/probemond.C`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| probemond              | Notes                     | * The "`cpwd_admin list`" command shows the process as "`PROBEMOND`". * This process listens on port 9877 for other processes. * For details, refer to [sk181994 - How to monitor the status of VPN Network Probes](https://support.checkpoint.com/results/sk/sk181994).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| probemond              | To See the Current Status | `probemon status` or `cpwd_admin list | grep -E "APP|PROBEMOND"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| probemond              | To Stop                   | `probemon stop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| probemond              | To Start                  | `probemon start`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| probemond              | Debug                     | 1. Start debug: `probemon debug trunc` 2. Replicate the issue 3. Stop debug: `probemon debug off` 4. Analyze: `$FWDIR/log/probemond.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Mobile Access Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |||
| cvpnd                  | Description               | Back-end daemon of the Mobile Access Software Blade.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cvpnd                  | Path                      | `$CVPNDIR/bin/cvpnd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cvpnd                  | Log File                  | `$CVPNDIR/log/cvpnd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cvpnd                  | Configuration File        | `$CVPNDIR/conf/cvpnd.C`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cvpnd                  | Notes                     | The "`cpwd_admin list`" command shows the process as "`CVPND`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| cvpnd                  | To See the Current Status | `cpwd_admin list | grep -E "APP|CVPND"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cvpnd                  | To Stop                   | `cvpnstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cvpnd                  | To Start                  | `cvpnstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cvpnd                  | Debug                     | "`cvpnd_admin debug`" - refer to [sk104577](https://support.checkpoint.com/results/sk/sk104577), [sk99053](https://support.checkpoint.com/results/sk/sk99053)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| dbwriter               | Description               | Offloads database commands from `cvpnd` (to prevent locks) and synchronize with other members.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dbwriter               | Path                      | `$CVPNDIR/bin/dbwriter`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| dbwriter               | Log File                  | `$CVPNDIR/log/dbwriter.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| dbwriter               | Configuration File        | `$CVPNDIR/conf/dbwriter.C`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| dbwriter               | Notes                     | The "`cpwd_admin list`" command shows the process as "`DBWRITER`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dbwriter               | To See the Current Status | `cpwd_admin list | grep -E "APP|DBWRITER"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| dbwriter               | To Stop                   | `cvpnstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| dbwriter               | To Start                  | `cvpnstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cvpnproc               | Description               | Offloads blocking commands from `cvpnd` (to prevent locks). Example: Sending DynamicID.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cvpnproc               | Path                      | `$CVPNDIR/bin/cvpnproc`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cvpnproc               | Log File                  | `$CVPNDIR/log/cvpnproc.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cvpnproc               | Configuration File        | `$CVPNDIR/conf/cvpnproc.C`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cvpnproc               | Notes                     | The "`cpwd_admin list`" command shows the process as "`CVPNPROC`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cvpnproc               | To See the Current Status | `cpwd_admin list | grep -E "APP|CVPNPROC"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cvpnproc               | To Stop                   | `cvpnstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cvpnproc               | To Start                  | `cvpnstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cvpnproc               | Debug                     | Refer to [sk104577](https://support.checkpoint.com/results/sk/sk104577): 1. Stop Mobile Access: `cvpnstop` 2. Verify that `cvpnproc` process is not running: `ps aux | grep cvpnproc` 3. If the `cvpnproc` process is still running, then kill it: `kill -KILL $(pidof cvpnproc)` 4. Start `cvpnproc` process under debug to run in background (by running these 2 commands): `export TDERROR_ALL_ALL=5` `$CVPNDIR/bin/cvpnproc $CVPNDIR/log/cvpnproc.elg $CVPNDIR/conf/cvpnproc.C &` 5. Start Mobile Access: `cvpnstart` 6. Replicate the issue 7. Stop debug: `unset TDERROR_ALL_ALL` 8. Stop Mobile Access: `cvpnstop` 9. Kill `cvpnproc` process: `kill -TERM $(pidof cvpnproc)` `kill -KILL $(pidof cvpnproc)` 10. Start Mobile Access: `cvpnstart` 11. Analyze: `$CVPNDIR/log/cvpnproc.elg*`                                                                                                            |
| MoveFileServer         | Description               | Move files between cluster members to perform database synchronization.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| MoveFileServer         | Path                      | `$CVPNDIR/bin/MoveFileServer`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| MoveFileServer         | Log File                  | `$CVPNDIR/log/MFServer.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| MoveFileServer         | Configuration File        | `$CVPNDIR/conf/mfserver.C`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| MoveFileServer         | Notes                     | The "`cpwd_admin list`" command shows the process: * In R77.30 and higher: as "`MFSERVER`" * In R77.20 and lower: as "`MOVEFILESERVER`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| MoveFileServer         | To See the Current Status | `cpwd_admin list | grep -E "APP|MFSERVER"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| MoveFileServer         | To Stop                   | `cvpnstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| MoveFileServer         | To Start                  | `cvpnstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| MoveFileDemuxer        | Description               | Related to `MoveFileServer` process (moving files between cluster members to perform database synchronization).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| MoveFileDemuxer        | Path                      | `$CVPNDIR/bin/MoveFileDemuxer`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| MoveFileDemuxer        | Log File                  | `$CVPNDIR/log/MFDemux.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| MoveFileDemuxer        | Configuration File        | `$CVPNDIR/conf/mfdemuxer.C`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| MoveFileDemuxer        | Notes                     | The "`cpwd_admin list`" command shows the process: * In R77.30 and higher: as "`MFDEMUXER`" * In R77.20 and lower: as "`MOVEFILEDEMUXER`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| MoveFileDemuxer        | To See the Current Status | `cpwd_admin list | grep -E "APP|MFDEMUXER"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| MoveFileDemuxer        | To Stop                   | `cvpnstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| MoveFileDemuxer        | To Start                  | `cvpnstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Pinger                 | Description               | Reduces the number of `httpd` processes that perform ActiveSync.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Pinger                 | Path                      | `$CVPNDIR/bin/Pinger`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Pinger                 | Log File                  | `$CVPNDIR/log/Pinger.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| Pinger                 | Configuration File        | `$CVPNDIR/conf/Pinger.C`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Pinger                 | Notes                     | The "`cpwd_admin list`" command shows the process as "`PINGER`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Pinger                 | To See the Current Status | `cpwd_admin list | grep -E "APP|PINGER"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Pinger                 | To Stop                   | `cvpnstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Pinger                 | To Start                  | `cvpnstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| Pinger                 | Debug                     | Refer to [sk104577](https://support.checkpoint.com/results/sk/sk104577): 1. Verify that `Pinger` process is running: `ps aux | grep Pinger` 2. Enable debug for relevant users: `PingerAdmin debug users <user1>,<user2>,<user3>` 3. Set the debug level: `PingerAdmin debug set TDERROR_ALL_Pinger=3` or `PingerAdmin debug set TDERROR_ALL_ALL=5` 4. Set the debug type: `PingerAdmin debug type All` 5. Delete all files from `$CVPNDIR/log/trace_log/` directory: Note: Do NOT delete the directory itself! `cd $CVPNDIR/log/trace_log/` `rm -i *` 6. Enable trace log: Warning: This might print passwords to local files! `PingerAdmin debug trace on` 7. Start debug: `PingerAdmin debug on` 8. Replicate the issue 9. Stop debug: `PingerAdmin debug off` 10. Disable trace log: `PingerAdmin debug trace off` 11. Reset the debug: `PingerAdmin debug reset` 12. Analyze: `$CVPNDIR/log/Pinger.log*` |
| CvpnUMD                | Description               | Reports SNMP connected users to AMON.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| CvpnUMD                | Path                      | `$CVPNDIR/bin/CvpnUMD`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| CvpnUMD                | Log File                  | `$CVPNDIR/log/CvpnUMD.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| CvpnUMD                | Notes                     | The "`cpwd_admin list`" command shows the process as "`CVPNUMD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| CvpnUMD                | To See the Current Status | `cpwd_admin list | grep -E "APP|CVPNUMD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| CvpnUMD                | To Stop                   | `cvpnstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| CvpnUMD                | To Start                  | `cvpnstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| httpd                  | Description               | Front-end daemon of the Mobile Access Software Blade (multi-processes).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| httpd                  | Path                      | `$CPDIR/web/Apache/2.2.0/bin/httpd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| httpd                  | Log File                  | `$CVPNDIR/log/httpd.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| httpd                  | Configuration File        | `$CVPNDIR/conf/httpd.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| httpd                  | To Stop                   | `cvpnstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| httpd                  | To Start                  | `cvpnstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| httpd                  | Debug                     | Refer to [sk104577](https://support.checkpoint.com/results/sk/sk104577), [sk99053](https://support.checkpoint.com/results/sk/sk99053)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| fwpushd                | Description               | Mobile Access Push Notifications daemon that is controlled by "`fwpush`" command. It is a child of the `fwd` daemon (in R77.10 and higher).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| fwpushd                | Path                      | `$FWDIR/bin/fwpushd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| fwpushd                | Log File                  | `$FWDIR/log/fwpushd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| fwpushd                | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| fwpushd                | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| fwpushd                | Debug                     | 1. Enable debug: `fwpush debug on` 2. Set the debug options: `fwpush debug set all all` 3. Check the debug state: `fwpush debug stat` 4. Replicate the issue 5. Reset the debug options: `fwpush debug reset` 6. Disable debug: `fwpush debug off` 7. Check the debug state: `fwpush debug stat` 8. Analyze: `$FWDIR/log/fwpushd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| postgres               | Description               | PostgreSQL server. Used by Remote Access Session Visibility and Management Utility.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| postgres               | Path                      | `$CPDIR/database/postgresql/bin/postgres`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| postgres               | Configuration File        | The path depends on the software version. Your server may not contain all the files listed below: * `$CPDIR/conf/postgresql/postgresql.conf` * `$CPDIR/database/postgresql/data/postgresql.conf` or using another env variable: `$PGDATA/postgresql.conf` * `/var/log$FWDIR/datadir/postgres/sessions/postgresql.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| postgres               | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| postgres               | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| postgres               | Debug                     | "`su cp_postgres -c "$CPDIR/database/postgresql/bin/pg_ctl -D $RTDIR/events_db/data start`" Also refer to [sk93970](https://support.checkpoint.com/results/sk/sk93970)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Identity Awareness Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
| pepd                   | Description               | Policy Enforcement Point (PEP) daemon: * Receiving identities via identity sharing * Redirecting users to Captive Portal                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| pepd                   | Path                      | `$FWDIR/bin/pep`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| pepd                   | Log File                  | `$FWDIR/log/pepd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pepd                   | Notes                     | The "`cpwd_admin list`" command shows the process as "`PEPD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pepd                   | To See the Current Status | `cpwd_admin list | grep -E "APP|PEPD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| pepd                   | To Stop                   | `cpstop (this will stop entire Gateway), find PID for pepd (ps -ef |grep pepd) and kill <PID>. FWD will restart process.`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| pepd                   | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| pepd                   | Debug                     | "`pep debug`" - refer to the [Identity Awareness Administration Guide](https://support.checkpoint.com/product/436) for your version                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| pdpd                   | Description               | Policy Decision Point (PDP) daemon: * Acquiring identities from identity sources * Sharing identities with other Security Gateways                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| pdpd                   | Path                      | `$FWDIR/bin/pdpd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| pdpd                   | Log File                  | `$FWDIR/log/pdpd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| pdpd                   | Notes                     | The "`cpwd_admin list`" command shows the process as "`PDPD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| pdpd                   | To See the Current Status | `cpwd_admin list | grep -E "APP|PDPD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| pdpd                   | To Stop                   | `cpstop (this will stop entire Gateway), find PID for pdpd (ps -ef |grep pdpd) and kill <PID>. FWD will restart process.`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| pdpd                   | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| pdpd                   | Debug                     | "`pdp debug`" - refer to the [Identity Awareness Administration Guide](https://support.checkpoint.com/product/436) for your version                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| DLP Blade and Content Awareness Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
| fwdlp                  | Description               | In the DLP Blade, this is the DLP core engine that performs the scanning / inspection.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| fwdlp                  | Path                      | `$FWDIR/bin/fwdlp`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| fwdlp                  | Log File                  | * `$FWDIR/log/fwdlp.elg` * `$DLPDIR/log/dlpe.log` (refer to [sk60387](https://support.checkpoint.com/results/sk/sk60387)) * `$DLPDIR/log/dlpe_msg.log` (refer to [sk73660](https://support.checkpoint.com/results/sk/sk73660)) * `$DLPDIR/log/dlpe_files_error.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| fwdlp                  | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| fwdlp                  | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| fwdlp                  | Debug                     | Refer to [sk73660](https://support.checkpoint.com/results/sk/sk73660), [sk60388](https://support.checkpoint.com/results/sk/sk60388): 1. Start debug: `for PROC in $(pidof fwdlp) ; do fw debug $PROC on TDERROR_ALL_ALL=5 ; done` 2. Replicate the issue 3. Stop debug: `for PROC in $(pidof fwdlp) ; do fw debug $PROC off TDERROR_ALL_ALL=0 ; done` 4. Analyze: `$FWDIR/log/fwdlp.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cp_file_convert        | Description               | In the DLP Blade and in the Content Awareness Blade, converts various file formats to simple textual format for scanning by the DLP engine and by the Content Awareness engine.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| cp_file_convert        | Path                      | `$FWDIR/bin/cp_file_convert`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| cp_file_convert        | Log File                  | `$FWDIR/log/cp_file_convertd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cp_file_convert        | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cp_file_convert        | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cp_file_convert        | Debug                     | Refer to [sk73660](https://support.checkpoint.com/results/sk/sk73660): 1. Start debug: `for PROC in $(pgrep cp_file_convert) ; do fw debug $PROC on TDERROR_ALL_ALL=5 ; done` 2. Replicate the issue 3. Stop debug: `fw debug cp_file_convert off TDERROR_ALL_ALL=0` 4. Analyze: * `/var/log/jail/$FWDIR/log/cp_file_convertd.elg*` * `$FWDIR/log/cp_file_convertd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| dlp_fingerprint        | Description               | In the DLP Blade, identifies the data according to a unique signature known as a fingerprint stored in your repository.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| dlp_fingerprint        | Path                      | `$FWDIR/bin/dlp_fingerprint`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| dlp_fingerprint        | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| dlp_fingerprint        | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cserver                | Description               | In the DLP Blade, this Check Server either stops or processes the e-mail.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cserver                | Path                      | `$FWDIR/bin/cserver`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cserver                | Log File                  | `$FWDIR/log/cserver.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cserver                | Notes                     | The "`cpwd_admin list`" command shows the process as "`DLP_WS`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| cserver                | To See the Current Status | `cpwd_admin list | grep -E "APP|DLP_WS"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cserver                | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cserver                | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cserver                | Debug                     | Refer to [sk73660](https://support.checkpoint.com/results/sk/sk73660): 1. Start debug: `fw debug cserver on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug cserver off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/cserver.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| dlpu                   | Description               | In the DLP Blade and in the Content Awareness Blade, receives data from the Check Point kernel.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| dlpu                   | Path                      | `$FWDIR/bin/dlpu`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dlpu                   | Log File                  | `$FWDIR/log/dlpu.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| dlpu                   | Notes                     | The "`cpwd_admin list`" command shows the process as "`DLPU_<N>`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dlpu                   | To See the Current Status | `cpwd_admin list | grep -E "APP|DLPU_"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| dlpu                   | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| dlpu                   | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| dlpu                   | Debug                     | Refer to [sk73660](https://support.checkpoint.com/results/sk/sk73660): 1. Start debug: `for PROC in $(pidof dlpu) ; do fw debug $PROC on TDERROR_ALL_ALL=5 ; done` 2. Replicate the issue 3. Stop debug: `for PROC in $(pidof dlpu) ; do fw debug $PROC off TDERROR_ALL_ALL=0 ; done` 4. Analyze: `$FWDIR/log/dlpu.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| fwucd                  | Description               | In the DLP Blade, this is the UserCheck back-end daemon that sends approval / disapproval requests to user.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| fwucd                  | Path                      | `$FWDIR/bin/fwucd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| fwucd                  | Log File                  | `$FWDIR/log/fwucd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| fwucd                  | Notes                     | The "`cpwd_admin list`" command shows the process as "`FWUCD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| fwucd                  | To See the Current Status | `cpwd_admin list | grep -E "APP|FWUCD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| fwucd                  | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| fwucd                  | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| fwucd                  | Debug                     | Refer to [sk73660](https://support.checkpoint.com/results/sk/sk73660), [sk60388](https://support.checkpoint.com/results/sk/sk60388): 1. Start debug: `fw debug fwucd on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug fwucd off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/fwucd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| usrchkd                | Description               | In the DLP Blade, this is the main UserCheck daemon, which deals with UserCheck requests (from CLI / from the user) that are sent from the UserCheck Web Portal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| usrchkd                | Path                      | `$FWDIR/bin/usrchkd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| usrchkd                | Log File                  | `$FWDIR/log/usrchkd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usrchkd                | Configuration File        | * `$FWDIR/conf/usrchkd.conf` * `$FWDIR/orig/UCPortal/fwdir_conf/usrchkd.conf` * `$FWDIR/conf/fwauthd.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| usrchkd                | Notes                     | * This daemon is not monitored by Check Point WatchDog ("`cpwd_admin list`") * This daemon is spawned by the FWD daemon                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| usrchkd                | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usrchkd                | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| usrchkd                | To Restart                | `killall usrchkd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| usrchkd                | Debug                     | Note: It might also be required to collect the relevant Security Gateway kernel debug. 1. Start debug: `usrchk debug set all all` 2. Verify: `usrchk debug stat` 3. Replicate the issue. 4. Stop debug: `usrchk debug off` 5. Analyze: `$FWDIR/log/usrchkd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| usrchk                 | Description               | In the DLP Blade, this is the CLI client for the UserCheck daemon USRCHKD (this process runs only when it is called explicitly).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| usrchk                 | Path                      | `$FWDIR/bin/usrchk`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| usrchk                 | Log File                  | `$FWDIR/log/usrchk.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Threat Emulation Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
| ted                    | Description               | Threat Emulation daemon engine - responsible for emulating files and communication with the cloud.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ted                    | Path                      | `$FWDIR/teCurrentPack/temain`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ted                    | Log File                  | `$FWDIR/log/ted.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ted                    | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ted                    | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ted                    | Debug                     | "`tecli debug`" - refer to the [Threat Prevention Administration Guide](https://support.checkpoint.com/product/417) for your version                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| dlpu                   | Description               | DLP process - receives data from the Security Gateway kernel.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| dlpu                   | Path                      | `$FWDIR/bin/dlpu`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dlpu                   | Log File                  | `$FWDIR/log/dlpu.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| dlpu                   | Notes                     | The "`cpwd_admin list`" command shows the process as "`DLPU_<N>`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dlpu                   | To See the Current Status | `cpwd_admin list | grep -E "APP|DLPU_"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| dlpu                   | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| dlpu                   | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| dlpu                   | Debug                     | Refer to [sk73660](https://support.checkpoint.com/results/sk/sk73660): 1. Start debug: `fw debug dlpu on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug dlpu off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/dlpu.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| usrchkd                | Description               | Main UserCheck daemon, which deals with UserCheck requests (from CLI / from the user) that are sent from the UserCheck Web Portal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| usrchkd                | Path                      | `$FWDIR/bin/usrchkd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| usrchkd                | Log File                  | `$FWDIR/log/usrchkd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usrchkd                | Configuration File        | * `$FWDIR/conf/usrchkd.conf` * `$FWDIR/orig/UCPortal/fwdir_conf/usrchkd.conf` * `$FWDIR/conf/fwauthd.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| usrchkd                | Notes                     | * This daemon is not monitored by Check Point WatchDog ("`cpwd_admin list`") * This daemon is spawned by the FWD daemon                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| usrchkd                | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usrchkd                | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| usrchkd                | To Restart                | `killall usrchkd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| usrchkd                | Debug                     | Note: It might also be required to collect the relevant Security Gateway kernel debug. 1. Start debug: `usrchk debug set all all` 2. Verify: `usrchk debug stat` 3. Replicate the issue. 4. Stop debug: `usrchk debug off` 5. Analyze: `$FWDIR/log/usrchkd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| usrchk                 | Description               | The CLI client for the UserCheck daemon USRCHKD (this process runs only when it is called explicitly).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| usrchk                 | Path                      | `$FWDIR/bin/usrchk`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| usrchk                 | Log File                  | `$FWDIR/log/usrchk.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| scanengine_b           | Description               | Third-party engine.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| scanengine_b           | Path                      | `$FWDIR/teCurrentPack/scanengine_b`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| scanengine_b           | Log File                  | `$FWDIR/log/bdadvisor.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| scanengine_b           | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| scanengine_b           | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| scanengine_b           | Debug                     | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| scanengine_k           | Description               | Third-party engine.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| scanengine_k           | Path                      | `$FWDIR/teCurrentPack/scanengine_k`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| scanengine_k           | Log File                  | `$FWDIR/log/kavadvisor.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| scanengine_k           | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| scanengine_k           | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| scanengine_k           | Debug                     | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| scanengine_s           | Description               | Third-party engine.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| scanengine_s           | Path                      | `$FWDIR/teCurrentPack/scanengine_s`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| scanengine_s           | Log File                  | `$FWDIR/log/sopadvisor.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| scanengine_s           | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| scanengine_s           | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| scanengine_s           | Debug                     | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Threat Extraction Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
| scrub                  | Description               | Main CLI process for Threat Extraction.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| scrub                  | Path                      | `$FWDIR/bin/scrub`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| scrub                  | Log File                  | * `$FWDIR/log/scrubd.elg` * `/var/log/scrub/scrubd_messages` * `$CPDIR/log/scrub_plg.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| scrub                  | Configuration File        | `$FWDIR/conf/scrub_debug.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| scrub                  | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| scrub                  | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| scrub                  | Debug                     | 1. Start Threat Extraction debug: `scrub debug on` `scrub debug set all all` 2. Verify Threat Extraction debug is enabled: `scrub debug stat` 3. Start debug of `cp_file_convert` daemon: `for PROC in $(pgrep cp_file_convert) ; do fw debug $PROC on TDERROR_ALL_ALL=5 ; done` 4. Replicate the issue 5. Stop debug of `cp_file_convert` daemon: `for PROC in $(pgrep cp_file_convert) ; do fw debug $PROC off TDERROR_ALL_ALL=0 ; done` 6. Stop Threat Extraction debug: `scrub debug off` `scrub debug reset` 7. Verify Threat Extraction debug is disabled: `scrub debug stat` 8. Analyze: `$FWDIR/log/scrubd.elg*` `/var/log/jail/$FWDIR/log/scrub_cp_file_convertd.elg`                                                                                                                                                                                                                                |
| scrubd                 | Description               | Main Threat Extraction daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| scrubd                 | Path                      | `$FWDIR/bin/scrubd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| scrubd                 | Log File                  | * `$FWDIR/log/scrubd.elg` * `/var/log/scrub/scrubd_messages` * `$CPDIR/log/scrub_plg.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| scrubd                 | Configuration File        | `$FWDIR/conf/scrub_debug.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| scrubd                 | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| scrubd                 | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| scrubd                 | Debug                     | 1. Start Threat Extraction debug: `scrub debug on` `scrub debug set all all` 2. Verify Threat Extraction debug is enabled: `scrub debug stat` 3. Start debug of `cp_file_convert` daemon: `for PROC in $(pgrep cp_file_convert) ; do fw debug $PROC on TDERROR_ALL_ALL=5 ; done` 4. Replicate the issue 5. Stop debug of `cp_file_convert` daemon: `for PROC in $(pgrep cp_file_convert) ; do fw debug $PROC off TDERROR_ALL_ALL=0 ; done` 6. Stop Threat Extraction debug: `scrub debug off` `scrub debug reset` 7. Verify Threat Extraction debug is disabled: `scrub debug stat` 8. Analyze: `$FWDIR/log/scrubd.elg*` `/var/log/jail/$FWDIR/log/scrub_cp_file_convertd.elg`                                                                                                                                                                                                                                |
| scrub_cp_file_convertd | Description               | Converts various file formats to simple textual format for scanning by the Threat Extraction engine and by the Content Awareness Software Blade.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| scrub_cp_file_convertd | Path                      | `$FWDIR/bin/cp_file_convert`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| scrub_cp_file_convertd | Log File                  | * `/var/log/jail/$FWDIR/log/scrub_cp_file_convertd.elg` * `$FWDIR/log/cp_file_convert_start.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| scrub_cp_file_convertd | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| scrub_cp_file_convertd | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| scrub_cp_file_convertd | Debug                     | 1. Start debug: `for PROC in $(pgrep cp_file_convert) ; do fw debug $PROC on TDERROR_ALL_ALL=5 ; done` 2. Replicate the issue 3. Stop debug: `for PROC in $(pgrep cp_file_convert) ; do fw debug $PROC off TDERROR_ALL_ALL=0 ; done` 4. Analyze: `/var/log/jail/$FWDIR/log/scrub_cp_file_convertd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| in.emaild.mta          | Description               | E-Mail Security Server that receives e-mails sent by user and sends them to their destinations.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| in.emaild.mta          | Path                      | `$FWDIR/bin/fwssd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| in.emaild.mta          | Log File                  | * `$FWDIR/log/emaild.mta.elg` * `/var/log/scrub/in.emaild.mta_messages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| in.emaild.mta          | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| in.emaild.mta          | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| in.emaild.mta          | Debug                     | Refer to [sk139892 - MTA Engine Debugging](https://support.checkpoint.com/results/sk/sk139892)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| usrchkd                | Description               | Main UserCheck daemon, which deals with UserCheck requests (from CLI / from the user) that are sent from the UserCheck Web Portal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| usrchkd                | Path                      | `$FWDIR/bin/usrchkd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| usrchkd                | Log File                  | `$FWDIR/log/usrchkd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usrchkd                | Configuration File        | * `$FWDIR/conf/usrchkd.conf` * `$FWDIR/orig/UCPortal/fwdir_conf/usrchkd.conf` * `$FWDIR/conf/fwauthd.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| usrchkd                | Notes                     | * This daemon is not monitored by Check Point WatchDog ("`cpwd_admin list`") * This daemon is spawned by the FWD daemon                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| usrchkd                | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usrchkd                | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| usrchkd                | To Restart                | `killall usrchkd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| usrchkd                | Debug                     | Note: It might also be required to collect the relevant Security Gateway kernel debug. 1. Start debug: `usrchk debug set all all` 2. Verify: `usrchk debug stat` 3. Replicate the issue. 4. Stop debug: `usrchk debug off` 5. Analyze: `$FWDIR/log/usrchkd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| usrchk                 | Description               | The CLI client for the UserCheck daemon USRCHKD (this process runs only when it is called explicitly).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| usrchk                 | Path                      | `$FWDIR/bin/usrchk`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| usrchk                 | Log File                  | `$FWDIR/log/usrchk.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Zero Phishing Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |||
| zphd                   | Description               | Main Zero Phishing daemon on the Security Gateway: 1. Gets answers from the Check Point cloud 2. Determines the final counter-action taken when encountering a phishing site based on the Security Policy 3. Sends logs                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| zphd                   | Path                      | `$FWDIR/bin/zphd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| zphd                   | Log file                  | `$FWDIR/log/zphd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| zphd                   | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| zphd                   | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| zphd                   | Debug                     | 1. Start the ZPHD debug: `zph debug on` `zph debug set all all` 2. Make sure the ZPHD debug is enabled: `zph debug stat` 3. Replicate the issue. 4. Stop the ZPHD debug: `zph debug off` `zph debug reset` 5. Make sure the ZPHD debug is disabled: `zph debug stat` 6. Analyze: `$FWDIR/log/zphd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| usercheckportal_php    | Description               | UserCheck Web Portal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| usercheckportal_php    | Log file                  | `/opt/CPUserCheckPortal/log/zph`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| usercheckportal_php    | Configuration files       | `/opt/CPUserCheckPortal/phpincs/conf/proxy.ini` `/opt/CPUserCheckPortal/conf/httpd.conf` `/opt/CPUserCheckPortal/phpincs/conf/L10N/portal_en.php`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| usercheckportal_php    | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usercheckportal_php    | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| usercheckportal_php    | Debug                     | 1. Start the UserCheck Web Portal debug: 1. Run: `/opt/CPUserCheckPortal/scripts/logs_conf_server` 2. Select option "1" 2. Replicate the issue. 3. Stop the UserCheck Web Portal debug: 1. Run: `/opt/CPUserCheckPortal/scripts/logs_conf_server` 2. Select option "2" 4. Analyze: `/opt/CPUserCheckPortal/log/PortalLog.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Threat Prevention                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
| tp_conf_service        | Description               | Service for Threat Prevention Software Blades (R80.40 and higher) for updatable configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| tp_conf_service        | Path                      | `$FWDIR/bin/tp_conf_service`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| tp_conf_service        | Notes                     | The `cpwd_admin list` command shows the process as "`TP_CONF_SERVICE`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| tp_conf_service        | To See the Current Status | `cpwd_admin list | grep -E "APP|TP_CONF_SERVICE"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| tp_conf_service        | Log File                  | * In R81 and higher: `$FWDIR/log/tp_conf.elg` * In R80.40: `$FWDIR/log/tp_conf.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| tp_conf_service        | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| tp_conf_service        | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| tp_conf_service        | Configuration File        | `$FWDIR/conf/tp_conf.json`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| tp_conf_service        | Debug                     | 1. Stop the daemon: `cpwd_admin stop -name TP_CONF_SERVICE` 2. Start the daemon with debug logging: `cpwd_admin start -name TP_CONF_SERVICE -path $FWDIR/bin/tp_conf_service -command "tp_conf_service --conf=tp_conf.json --log=debug"` 3. Replicate the issue 4. Stop the daemon: `cpwd_admin stop -name TP_CONF_SERVICE` 5. Start the daemon with regular logging: `cpwd_admin start -name TP_CONF_SERVICE -path $FWDIR/bin/tp_conf_service -command "tp_conf_service --conf=tp_conf.json --log=error"` 6. Analyze the log file                                                                                                                                                                                                                                                                                                                                                                            |
| tpd                    | Description               | Threat Prevention Daemon - communicates with the kernel and deals with User Space tasks (R80.40 and higher).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| tpd                    | Path                      | `$FWDIR/bin/tpd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| tpd                    | Log File                  | `$FWDIR/log/tpd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| tpd                    | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| tpd                    | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| tpd                    | Debug                     | 1. Start debug: `fw debug tpd on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug tpd off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/tpd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| IPS Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |||
| in.geod                | Description               | Updates the IPS Geo Protection Database.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| in.geod                | Path                      | `$FWDIR/bin/fwssd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| in.geod                | Log File                  | `$FWDIR/log/geod.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| in.geod                | To Stop                   | `kill -KILL $(pidof in.geod)`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| in.geod                | To Start                  | After being killed, it will be restarted automatically                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| in.geod                | Debug                     | Refer to [sk102329](https://support.checkpoint.com/results/sk/sk102329): 1. Start debug: `fw debug in.geod on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug in.geod off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/geod.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| URL Filtering Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |||
| rad                    | Description               | Resource Advisor - responsible for the detection of Social Network widgets. The detection is done via an online Application Control database, which identifies URLs as applications.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| rad                    | Path                      | `$FWDIR/bin/rad`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| rad                    | Log File                  | `$FWDIR/log/rad.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| rad                    | Configuration File        | * `$FWDIR/conf/rad_scheme.C` * `$FWDIR/conf/rad_settings.C` * `$FWDIR/database/rad_services.C`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| rad                    | Notes                     | The "`cpwd_admin list`" command shows the process as "`RAD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| rad                    | To See the Current Status | `cpwd_admin list | grep -E "APP|RAD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| rad                    | To Stop                   | `rad_admin stop` or `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| rad                    | To Start                  | `rad_admin start` or `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| rad                    | Debug                     | Refer to [sk92743](https://support.checkpoint.com/results/sk/sk92743): 1. Start debug: `rad_admin rad debug on all` 2. Replicate the issue. 3. Stop debug: `rad_admin rad debug off ALL` 4. Analyze: `$FWDIR/log/rad.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| usrchkd                | Description               | Main UserCheck daemon, which deals with UserCheck requests (from CLI / from the user) that are sent from the UserCheck Web Portal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| usrchkd                | Path                      | `$FWDIR/bin/usrchkd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| usrchkd                | Log File                  | `$FWDIR/log/usrchkd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usrchkd                | Configuration File        | * `$FWDIR/conf/usrchkd.conf` * `$FWDIR/orig/UCPortal/fwdir_conf/usrchkd.conf` * `$FWDIR/conf/fwauthd.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| usrchkd                | Notes                     | * This daemon is not monitored by Check Point WatchDog ("`cpwd_admin list`") * This daemon is spawned by the FWD daemon                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| usrchkd                | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usrchkd                | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| usrchkd                | To Restart                | `killall usrchkd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| usrchkd                | Debug                     | Note: It might also be required to collect the relevant Security Gateway kernel debug. 1. Start debug: `usrchk debug set all all` 2. Verify: `usrchk debug stat` 3. Replicate the issue. 4. Stop debug: `usrchk debug off` 5. Analyze: `$FWDIR/log/usrchkd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| usrchk                 | Description               | The CLI client for the UserCheck daemon USRCHKD (this process runs only when it is called explicitly).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| usrchk                 | Path                      | `$FWDIR/bin/usrchk`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| usrchk                 | Log File                  | `$FWDIR/log/usrchk.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Application Control Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |||
| rad                    | Description               | Resource Advisor - responsible for the detection of Social Network widgets. The detection is done via an online Application Control database, which identifies URLs as applications.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| rad                    | Path                      | `$FWDIR/bin/rad`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| rad                    | Log File                  | `$FWDIR/log/rad.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| rad                    | Configuration File        | * `$FWDIR/conf/rad_scheme.C` * `$FWDIR/conf/rad_settings.C` * `$FWDIR/database/rad_services.C`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| rad                    | Notes                     | The "`cpwd_admin list`" command shows the process as "`RAD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| rad                    | To See the Current Status | `cpwd_admin list | grep -E "APP|RAD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| rad                    | To Stop                   | `rad_admin stop` or `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| rad                    | To Start                  | `rad_admin start` or `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| rad                    | Debug                     | Refer to [sk92743](https://support.checkpoint.com/results/sk/sk92743): 1. Start debug: `rad_admin rad debug on all` 2. Replicate the issue. 3. Stop debug: `rad_admin rad debug off ALL` 4. Analyze: `$FWDIR/log/rad.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Anti-Bot Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
| in.acapd               | Description               | Daemon that captures packets to download the traffic sample from logs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| in.acapd               | Path                      | `$FWDIR/bin/fwssd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| in.acapd               | Log File                  | `$FWDIR/log/acapd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| in.acapd               | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| in.acapd               | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| in.acapd               | Debug                     | Refer to [sk108179](https://support.checkpoint.com/results/sk/sk108179): 1. Start debug: `fw debug in.acapd on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug in.acapd off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/acapd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| rad                    | Description               | Resource Advisor - responsible for the detection of Social Network widgets. The detection is done via an online Application Control database, which identifies URLs as applications.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| rad                    | Path                      | `$FWDIR/bin/rad`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| rad                    | Log File                  | `$FWDIR/log/rad.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| rad                    | Configuration File        | * `$FWDIR/conf/rad_scheme.C` * `$FWDIR/conf/rad_settings.C` * `$FWDIR/database/rad_services.C`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| rad                    | Notes                     | The "`cpwd_admin list`" command shows the process as "`RAD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| rad                    | To See the Current Status | `cpwd_admin list | grep -E "APP|RAD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| rad                    | To Stop                   | `rad_admin stop` or `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| rad                    | To Start                  | `rad_admin start` or `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| rad                    | Debug                     | Refer to [sk92264](https://support.checkpoint.com/results/sk/sk92264): 1. Start debug: `rad_admin rad debug on all` 2. Replicate the issue. 3. Stop debug: `rad_admin rad debug off ALL` 4. Analyze: `$FWDIR/log/rad.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| usrchkd                | Description               | Main UserCheck daemon, which deals with UserCheck requests (from CLI / from the user) that are sent from the UserCheck Web Portal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| usrchkd                | Path                      | `$FWDIR/bin/usrchkd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| usrchkd                | Log File                  | `$FWDIR/log/usrchkd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usrchkd                | Configuration File        | * `$FWDIR/conf/usrchkd.conf` * `$FWDIR/orig/UCPortal/fwdir_conf/usrchkd.conf` * `$FWDIR/conf/fwauthd.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| usrchkd                | Notes                     | * This daemon is not monitored by Check Point WatchDog ("`cpwd_admin list`") * This daemon is spawned by the FWD daemon                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| usrchkd                | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usrchkd                | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| usrchkd                | To Restart                | `killall usrchkd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| usrchkd                | Debug                     | Note: It might also be required to collect the relevant Security Gateway kernel debug. 1. Start debug: `usrchk debug set all all` 2. Verify: `usrchk debug stat` 3. Replicate the issue. 4. Stop debug: `usrchk debug off` 5. Analyze: `$FWDIR/log/usrchkd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| usrchk                 | Description               | The CLI client for the UserCheck daemon USRCHKD (this process runs only when it is called explicitly).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| usrchk                 | Path                      | `$FWDIR/bin/usrchk`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| usrchk                 | Log File                  | `$FWDIR/log/usrchk.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Anti-Virus Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
| in.acapd               | Description               | Daemon that captures packets to download the traffic sample from logs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| in.acapd               | Path                      | `$FWDIR/bin/fwssd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| in.acapd               | Log File                  | `$FWDIR/log/acapd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| in.acapd               | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| in.acapd               | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| in.acapd               | Debug                     | Refer to [sk108179](https://support.checkpoint.com/results/sk/sk108179): 1. Start debug: `fw debug in.acapd on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug in.acapd off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/acapd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| in.emaild.mta          | Description               | E-Mail Security Server that receives e-mails sent by user and sends them to their destinations.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| in.emaild.mta          | Path                      | `$FWDIR/bin/fwssd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| in.emaild.mta          | Log File                  | `$FWDIR/log/emaild.mta.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| in.emaild.mta          | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| in.emaild.mta          | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| in.emaild.mta          | Debug                     | Refer to [sk60387](https://support.checkpoint.com/results/sk/sk60387): 1. Start debug: `fw debug in.emaild.mta on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug in.emaild.mta off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/emaild.mta.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| in.emaild.smtp         | Description               | SMTP Security Server that receives e-mails sent by user and sends them to their destinations.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| in.emaild.smtp         | Path                      | `$FWDIR/bin/fwssd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| in.emaild.smtp         | Log File                  | `$FWDIR/log/emaild.smtp.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| in.emaild.smtp         | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| in.emaild.smtp         | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| in.emaild.smtp         | Debug                     | Refer to [sk60387](https://support.checkpoint.com/results/sk/sk60387): 1. Start debug: `fw debug in.emaild.smtp on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug in.emaild.smtp off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/emaild.smtp.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| in.emaild.pop3         | Description               | POP3 Security Server that receives e-mails sent by user.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| in.emaild.pop3         | Path                      | `$FWDIR/bin/fwssd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| in.emaild.pop3         | Log File                  | `$FWDIR/log/emaild.pop3.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| in.emaild.pop3         | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| in.emaild.pop3         | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| in.emaild.pop3         | Debug                     | 1. Start debug: `fw debug in.emaild.pop3 on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug in.emaild.pop3 off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/emaild.pop3.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dlpu                   | Description               | DLP process - receives data from the Security Gateway kernel.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| dlpu                   | Path                      | `$FWDIR/bin/dlpu`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dlpu                   | Log File                  | `$FWDIR/log/dlpu.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| dlpu                   | Notes                     | The "`cpwd_admin list`" command shows the process as "`DLPU_<N>`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dlpu                   | To See the Current Status | `cpwd_admin list | grep -E "APP|DLPU_"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| dlpu                   | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| dlpu                   | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| dlpu                   | Debug                     | Refer to [sk73660](https://support.checkpoint.com/results/sk/sk73660): 1. Start debug: `fw debug dlpu on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug dlpu off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/dlpu.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| rad                    | Description               | Resource Advisor - responsible for the detection of Social Network widgets. The detection is done via an online Application Control database, which identifies URLs as applications.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| rad                    | Path                      | `$FWDIR/bin/rad`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| rad                    | Log File                  | `$FWDIR/log/rad.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| rad                    | Configuration File        | * `$FWDIR/conf/rad_scheme.C` * `$FWDIR/conf/rad_settings.C` * `$FWDIR/database/rad_services.C`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| rad                    | Note                      | The "`cpwd_admin list`" command shows the process as "`RAD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| rad                    | To See the Current Status | `cpwd_admin list | grep -E "APP|RAD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| rad                    | To Stop                   | `rad_admin stop` or `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| rad                    | To Start                  | `rad_admin start` or `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| rad                    | Debug                     | Refer to [sk92264](https://support.checkpoint.com/results/sk/sk92264): 1. Start debug: `rad_admin rad debug on all` 2. Replicate the issue. 3. Stop debug: `rad_admin rad debug off ALL` 4. Analyze: `$FWDIR/log/rad.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| usrchkd                | Description               | Main UserCheck daemon, which deals with UserCheck requests (from CLI / from the user) that are sent from the UserCheck Web Portal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| usrchkd                | Path                      | `$FWDIR/bin/usrchkd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| usrchkd                | Log File                  | `$FWDIR/log/usrchkd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usrchkd                | Configuration File        | * `$FWDIR/conf/usrchkd.conf` * `$FWDIR/orig/UCPortal/fwdir_conf/usrchkd.conf` * `$FWDIR/conf/fwauthd.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| usrchkd                | Notes                     | * This daemon is not monitored by Check Point WatchDog ("`cpwd_admin list`") * This daemon is spawned by the FWD daemon                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| usrchkd                | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| usrchkd                | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| usrchkd                | To Restart                | `killall usrchkd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| usrchkd                | Debug                     | Note: It might also be required to collect the relevant Security Gateway kernel debug. 1. Start debug: `usrchk debug set all all` 2. Verify: `usrchk debug stat` 3. Replicate the issue. 4. Stop debug: `usrchk debug off` 5. Analyze: `$FWDIR/log/usrchkd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| usrchk                 | Description               | The CLI client for the UserCheck daemon USRCHKD (this process runs only when it is called explicitly).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| usrchk                 | Path                      | `$FWDIR/bin/usrchk`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| usrchk                 | Log File                  | `$FWDIR/log/usrchk.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Anti-Spam Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
| in.emaild.smtp         | Description               | SMTP Security Server that receives e-mails sent by user and sends them to their destinations.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| in.emaild.smtp         | Path                      | `$FWDIR/bin/fwssd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| in.emaild.smtp         | Log File                  | `$FWDIR/log/emaild.smtp.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| in.emaild.smtp         | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| in.emaild.smtp         | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| in.emaild.smtp         | Debug                     | Refer to [sk60387](https://support.checkpoint.com/results/sk/sk60387): 1. Start debug: `fw debug in.emaild.smtp on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug in.emaild.smtp off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/emaild.smtp.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| in.msd                 | Description               | Mail Security Daemon that queries the Commtouch engine for reputation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| in.msd                 | Path                      | `$FWDIR/bin/fwssd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| in.msd                 | Log File                  | `$FWDIR/log/msd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| in.msd                 | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| in.msd                 | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| in.msd                 | Debug                     | Refer to [sk92264](https://support.checkpoint.com/results/sk/sk92264): 1. Start debug: `fw debug in.msd on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug in.msd off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/msd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ctasd                  | Description               | Commtouch Anti-Spam daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ctasd                  | Path                      | `/opt/aspam_engine/ctipd/bin/ctasd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ctasd                  | Configuration File        | `/opt/aspam_engine/ctasd/conf/ctasd.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ctasd                  | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ctasd                  | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ctipd                  | Description               | Commtouch IP Reputation daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| ctipd                  | Path                      | `/opt/aspam_engine/ctipd/bin/ctipd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ctipd                  | Log File                  | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ctipd                  | Configuration File        | `/opt/aspam_engine/ctipd/conf/ctipd.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ctipd                  | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ctipd                  | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ctipd                  | Debug                     | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Monitoring Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
| rtmd                   | Description               | Real Time traffic statistics.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| rtmd                   | Path                      | `$FWDIR/bin/rtm`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| rtmd                   | Log File                  | `$FWDIR/log/rtmd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| rtmd                   | Notes                     | The "`cpwd_admin list`" command shows the process as "`RTMD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| rtmd                   | To See the Current Status | `cpwd_admin list | grep -E "APP|RTMD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| rtmd                   | To Stop                   | `rtmstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| rtmd                   | To Start                  | `rtmstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| rtmd                   | Debug                     | Refer to [skI2821](https://support.checkpoint.com/results/sk/skI2821): 1. Start debug: `rtm debug on TDERROR_ALL_ALL=5` `rtm debug on OPSEC_DEBUG_LEVEL=3` 2. Replicate the issue 3. Stop debug: `rtm debug off TDERROR_ALL_ALL=0` `rtm debug off OPSEC_DEBUG_LEVEL=0 ` 4. Analyze: `$FWDIR/log/rtmd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cpstat_monitor         | Description               | Process is responsible for collecting and sending information to SmartView Monitor.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cpstat_monitor         | Path                      | `$FWDIR/bin/cpstat_monitor`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cpstat_monitor         | Log File                  | `$FWDIR/log/cpstat_monitor.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| cpstat_monitor         | Notes                     | * The "`cpwd_admin list`" command shows the process as "`CPSM`". * By default, does not run in the context of Domain Management Servers. * By default, in MGMT HA runs only on the "Active" Security Management Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cpstat_monitor         | To See the Current Status | `cpwd_admin list | grep -E "APP|CPSM"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| cpstat_monitor         | To Stop                   | `cpwd_admin stop -name CPSM`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| cpstat_monitor         | To Start                  | `cpwd_admin start -name CPSM -path "$FWDIR/bin/cpstat_monitor" -command "cpstat_monitor"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cpstat_monitor         | Debug                     | Refer to [sk108177](https://support.checkpoint.com/results/sk/sk108177)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| HTTPS Inspection                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
| wstlsd                 | Description               | Handles SSL handshake for HTTPS Inspected connections.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| wstlsd                 | Path                      | `$CPDIR/bin/wstlsd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| wstlsd                 | Log File                  | `$FWDIR/log/wstlsd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| wstlsd                 | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| wstlsd                 | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| wstlsd                 | Debug                     | Refer to [sk105559](https://support.checkpoint.com/results/sk/sk105559): 1. Start debug: `for PROC in $(pidof wstlsd) ; do fw debug $PROC on TDERROR_ALL_ALL=6 ; done` 2. Replicate the issue (it is very important to collect the relevant traffic using both TCPDump tool and the FW Monitor). 3. Stop debug: `for PROC in $(pidof wstlsd) ; do fw debug $PROC off TDERROR_ALL_ALL=0 ; done` 4. Analyze: `$FWDIR/log/wstlsd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| pkxld                  | Description               | Performs asymmetric key operations for HTTPS Inspection (R77.30 and higher)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| pkxld                  | Path                      | `$CPDIR/bin/pkxld`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| pkxld                  | Log File                  | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| pkxld                  | Notes                     | Refer to [sk104717](https://support.checkpoint.com/results/sk/sk104717)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| pkxld                  | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| pkxld                  | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| pkxld                  | Debug                     | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| HTTP/HTTPS Proxy                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
| wsdnsd                 | Description               | DNS Resolver (in R77.30 and higher) - used for resolving all Domain Objects. The process is started and stopped during policy installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| wsdnsd                 | Path                      | `$FWDIR/bin/wsdnsd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| wsdnsd                 | Log File                  | `$FWDIR/log/wsdnsd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| wsdnsd                 | Notes                     | The "`cpwd_admin list`" command shows the process as "`WSDNSD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| wsdnsd                 | To See the Current Status | `cpwd_admin list | grep -E "APP|WSDNSD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| wsdnsd                 | To Stop                   | `cpwd_admin stop -name WSDNSD -path "$FWDIR/bin/wsdnsd" -command "kill -SIGTERM $(pidof $FWDIR/bin/wsdnsd)"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| wsdnsd                 | To Start                  | `cpwd_admin start -name WSDNSD -path "$FWDIR/bin/wsdnsd" -command "wsdnsd"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| wsdnsd                 | Debug                     | Refer to [sk106443](https://support.checkpoint.com/results/sk/sk106443): 1. Start debug: `fw debug wsdnsd on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug wsdnsd off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/wsdnsd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Cluster                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
| cphamcset              | Description               | Clustering daemon - responsible for opening sockets on the NICs to allow them to pass multicast traffic (CCP) to the machine.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| cphamcset              | Path                      | `$FWDIR/bin/cphamcset`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| cphamcset              | Log File                  | `$FWDIR/log/cphamcset.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cphamcset              | Notes                     | * Refer to [ATRG: ClusterXL R6x and R7x](https://support.checkpoint.com/results/sk/sk93306). * Log file exists only in R77.20 and higher                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cphamcset              | To Stop                   | `cphastop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cphamcset              | To Start                  | `cphastart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cphamcset              | Debug                     | 1. Stop clustering: `cphastop` 2. Start under debug: `cphamcset -d` 3. Stop clustering: `cphastop` 4. Start clustering: `cphastart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cphaprob               | Description               | Process that lists the state of cluster members, cluster interfaces and Critical Devices (Pnotes).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| cphaprob               | Path                      | `$FWDIR/bin/cphaprob`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cphaprob               | Configuration File        | `$FWDIR/conf/cphaprob.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cphaprob               | Notes                     | Refer to [ATRG: ClusterXL R6x and R7x](https://support.checkpoint.com/results/sk/sk93306) - Chapter "ClusterXL Monitoring and Troubleshooting" - 'cphaprob' command.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cphaprob               | To Stop                   | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cphaprob               | To Start                  | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cphaprob               | Debug                     | "`cphaprob -D <command>`" (e.g., "`cphaprob -D state`")                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cphaconf               | Description               | Cluster configuration process - installs the cluster configuration into Check Point kernel on cluster members.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| cphaconf               | Path                      | `$FWDIR/bin/cphaconf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cphaconf               | Log File                  | `$FWDIR/log/cphaconf.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cphaconf               | Notes                     | * Refer to [ATRG: ClusterXL R6x and R7x](https://support.checkpoint.com/results/sk/sk93306) - Chapter "ClusterXL Monitoring and Troubleshooting" - 'cphaconf' command. * Log file exists only in R77.20 and higher                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| cphaconf               | To Stop                   | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cphaconf               | To Start                  | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cphaconf               | Debug                     | Refer to [ATRG: ClusterXL R6x and R7x](https://support.checkpoint.com/results/sk/sk93306) - Chapter "ClusterXL Monitoring and Troubleshooting" - 'cphaconf' command - 'cphaconf debug_data'.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| cphastart              | Description               | Starts the cluster and state synchronization.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| cphastart              | Path                      | `$FWDIR/bin/cphastart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| cphastart              | Log File                  | `$FWDIR/log/cphastart.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cphastart              | Notes                     | * Refer to [ATRG: ClusterXL R6x and R7x](https://support.checkpoint.com/results/sk/sk93306) - Chapter "ClusterXL Monitoring and Troubleshooting" - 'cphastart' and 'cphastop' commands. * Log file exists only in R77.20 and higher                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cphastart              | To Stop                   | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cphastart              | To Start                  | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cphastart              | Debug                     | "`cphastart -d`" - refer to [sk39842](https://support.checkpoint.com/results/sk/sk39842)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cphastop               | Description               | Stops the cluster and state synchronization.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| cphastop               | Path                      | `$FWDIR/bin/cphastop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cphastop               | Notes                     | Refer to [ATRG: ClusterXL R6x and R7x](https://support.checkpoint.com/results/sk/sk93306) - Chapter "ClusterXL Monitoring and Troubleshooting" - 'cphastart' and 'cphastop' commands.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cphastop               | To Stop                   | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cphastop               | To Start                  | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cphastop               | Debug                     | Standard CSH script debugging (`csh -x -v $FWDIR/bin/cphastop`)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| cxld                   | Description               | Runs the cluster Full Sync (R81 and higher).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| cxld                   | Path                      | `$FWDIR/bin/cxld`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cxld                   | Log File                  | `$FWDIR/log/cxld.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cxld                   | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cxld                   | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cxld                   | Debug                     | Runs with debug by default                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| SecureXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
| sxl_statd              | Description               | Daemon that collects statistics information from the SecureXL on the Host appliance (R80.20 and higher).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| sxl_statd              | Path                      | `$FWDIR/bin/sxl_statd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| sxl_statd              | Log File                  | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| sxl_statd              | Notes                     | The "`cpwd_admin list`" command shows the process as "`SXL_STATD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| sxl_statd              | To See the Current Status | `cpwd_admin list | grep -E "APP|SXL_STATD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| sxl_statd              | To Stop                   | `cpwd_admin stop -name SXL_STATD`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| sxl_statd              | To Start                  | `cpwd_admin start -name SXL_STATD -path "$FWDIR/bin/sxl_statd" -command "sxl_statd"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| sxl_statd              | Debug                     | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| CoreXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
| dsd                    | Description               | Dynamic Balancing (initially called "Dynamic Split") daemon - responsible for dynamically adjusting CoreXL for optimized CPU resources allocation, based on continuous monitoring of system resources (R80.40 and higher)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| dsd                    | Path                      | `$FWDIR/bin/dsd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| dsd                    | Log File                  | `$FWIDR/log/dsd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| dsd                    | Notes                     | * The "`cpwd_admin list`" command shows the process as "`SDAEMON`". * See the [Performance Tuning Administration Guide](https://support.checkpoint.com/product/530) for your version.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| dsd                    | To See the Current Status | `cpwd_admin list | grep -E "APP|SDAEMON"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| dsd                    | To Disable / Stop         | In Gaia Clish / Gaia gClish: 1. Get the current state: `show dynamic-balancing state` 2. If enabled: * To disable: `set dynamic-balancing state disable` `reboot` * To only stop (without reboot): `set dynamic-balancing state stop` In the Expert mode: 1. Get the current state: `dynamic_split -p` 2. If enabled: * To disable: `dynamic_split -o disable` `reboot` * To only stop (without reboot): `dynamic_split -o stop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| dsd                    | To Enable / Start         | In R81 and higher, this feature is enabled by default. In Gaia Clish / Gaia gClish: 1. Get the current state: `show dynamic-balancing state` 2. If disabled, then enable and reboot: `set dynamic-balancing state enable` `reboot` 3. If enabled but stopped, then start (without reboot): `set dynamic-balancing state start` In the Expert mode: 1. Get the current state: `dynamic_split -p` 2. If disabled, then enable and reboot: `dynamic_split -o enable` `reboot` 3. If enabled but stopped, then start (without reboot): `dynamic_split -o start`                                                                                                                                                                                                                                                                                                                                                   |
| dsd                    | Debug                     | None                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| VSX                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |||
| CPUS_USGS              | Description               | Special task in the Check Point WatchDog on a Scalable Platform Security Group in the VSX mode (Maestro and Chassis) in R81.20 and higher. This task runs a Python script that collects the Resource Control data (CPU and Memory utilization) from each Virtual System and sends it to the "`asg perf`" tool.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| CPUS_USGS              | Path                      | `/usr/scripts/get_cpus_usages/get_cpus_usages`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| CPUS_USGS              | Log File                  | * `/var/log/cpus_usages.log` * `/tmp/cpus_usages.txt`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| CPUS_USGS              | To See the Current Status | `service get_cpus_usages status`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| CPUS_USGS              | To Stop                   | `service get_cpus_usages stop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| CPUS_USGS              | To Start                  | `service get_cpus_usages start`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| CPUS_USGS              | To Restart                | `service get_cpus_usages restart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| CPUS_USGS              | Debug                     | Standard Python script debugging                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| SD-WAN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
| sdwan_steering         | Description               | SD-WAN steering process (see [sk180605](https://support.checkpoint.com/results/sk/sk180605)).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| sdwan_steering         | Path                      | `$FWDIR/bin/sdwan_steering`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| sdwan_steering         | Log File                  | `$FWDIR/log/sdwan_steering.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| sdwan_steering         | Configuration File        | `$FWDIR/conf/sdwan/sdwan_steering_params.json`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| sdwan_steering         | Policy File               | `$FWDIR/state/local/SDWAN/sdwan_steering_policy.json`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| sdwan_steering         | To See the Current Status | `cpwd_admin list | grep -E "APP|SDWAN_STEERING"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| sdwan_steering         | To Stop                   | `sdwan_steering_stop -name FWD -path "$FWDIR/bin/sdwan_steering" -command "sdwan_steering_stop"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| sdwan_steering         | To Start                  | `sdwan_steering_start -name FWD -path "$FWDIR/bin/sdwan_steering" -command "sdwan_steering_start"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| sdwan_steering         | Debug                     | 1. Start debug: `fw debug sdwan_steering on TDERROR_ALL_SDWAN=5` 2. Replicate the issue 3. Stop debug: `fw debug sdwan_steering off TDERROR_ALL_SDWAN=0` 4. Analyze: `$FWDIR/log/sdwan_steering.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

{#Filter_3Table}

Security Management Software Blades and Features {#Security Management Software Blades and Features}
----------------------------------------------------------------------------------------------------

Enter the string you are searching for in this table:

{#Security Management Software Blades and Features - Network Policy Management Blade}{#Security Management Software Blades and Features - Endpoint Policy Management Blade}{#Security Management Software Blades and Features - Monitoring Blade}{#Security Management Software Blades and Features - Provisioning Blade}{#Security Management Software Blades and Features - SmartReporter Blade}{#Security Management Software Blades and Features - SmartEvent Blade}{#Security Management Software Blades and Features - Logging & Status Blade}{#Security Management Software Blades and Features - Management Portal}{#Security Management Software Blades and Features - SmartLog}{#Security Management Software Blades and Features - Internal CA}{#Security Management Software Blades and Features - Compliance Blade}{#Security Management Software Blades and Features - SofaWare Management Server}{#Security Management Software Blades and Features - OPSEC LEA}

|-------------------------|---------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Daemon                  | Section                   | Information                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| Network Policy Management Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||
| cpm                     | Description               | From a Security Management Server R80 and higher: * Serves requests from SmartConsole * Responsible for writing all information to the PostgreSQL and SOLR databases                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cpm                     | Path                      | `$FWDIR/scripts/cpm.sh`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| cpm                     | Log File                  | `$FWDIR/log/cpm.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cpm                     | Notes                     | The "`cpwd_admin list`" command shows the process as "`CPM`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| cpm                     | To See the Current Status | `cpwd_admin list | grep -E "APP|CPM"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cpm                     | To Stop                   | `cpstop` In addition, you can use the `ngm_stop.sh` script (refer to [sk111772](https://support.checkpoint.com/results/sk/sk111772)): * `$FWDIR/scripts/ngm_stop.sh` (refer to `$FWDIR/log/ngm_stop.elg`) * `$MDS_TEMPLATE/scripts/ngm_stop.sh` (refer to `$MDS_TEMPLATE/log/ngm_stop.elg`)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cpm                     | To Start                  | `cpstart` In addition, you can use the `ngm_start.sh` script (refer to [sk111772](https://support.checkpoint.com/results/sk/sk111772)): * `$FWDIR/scripts/ngm_start.sh` (refer to `$FWDIR/log/ngm_start.elg`) * `$MDS_TEMPLATE/scripts/ngm_start.sh` (refer to `$MDS_TEMPLATE/log/ngm_start.elg`)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cpm                     | Debug                     | Refer to [sk183144](https://support.checkpoint.com/results/sk/sk183144)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| cpm                     | Core Dump                 | To generate a core dump file for the CPM process: 1. Run in the Expert mode: `$MDS_FWDIR/scripts/cpm_dump.sh` 2. Get the core dump file for the CPM process from this directory: `/var/log/dump/usermode/`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| fwm                     | Description               | Communication between SmartConsole applications and Security Management Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| fwm                     | Path                      | `$FWDIR/bin/fwm`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| fwm                     | Log File                  | `$FWDIR/log/fwm.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| fwm                     | Notes                     | The "`cpwd_admin list`" command shows the process as "`FWM`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| fwm                     | To See the Current Status | `cpwd_admin list | grep -E "APP|FWM"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| fwm                     | To Stop                   | * Security Management Server: `cpwd_admin stop -name FWM -path "$FWDIR/bin/fwm" -command "fw kill fwm"` * Domain Management Server on a Multi-Domain Security Management Server: `mdsstop_customer <IP Address of Domain Management Server>` In addition, in R80 and higher, you can use the `ngm_stop.sh` script (refer to [sk111772](https://support.checkpoint.com/results/sk/sk111772)): * `$FWDIR/scripts/ngm_stop.sh` (refer to `$FWDIR/log/ngm_stop.elg`) * `$MDS_TEMPLATE/scripts/ngm_stop.sh` (refer to `$MDS_TEMPLATE/log/ngm_stop.elg`)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| fwm                     | To Start                  | * Security Management Server: `cpwd_admin start -name FWM -path "$FWDIR/bin/fwm" -command "fwm"` * Domain Management Server on a Multi-Domain Security Management Server: `mdsstart_customer <IP Address of Domain Management Server>` In addition, in R80 and higher, you can use the `ngm_start.sh` script (refer to [sk111772](https://support.checkpoint.com/results/sk/sk111772)): * `$FWDIR/scripts/ngm_start.sh` (refer to `$FWDIR/log/ngm_start.elg`) * `$MDS_TEMPLATE/scripts/ngm_start.sh` (refer to `$MDS_TEMPLATE/log/ngm_start.elg`)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| fwm                     | Debug                     | * Security Management Server - refer to [sk86186](https://support.checkpoint.com/results/sk/sk86186): 1. Start debug: `fw debug fwm on TDERROR_ALL_ALL=5` `fw debug fwm on OPSEC_DEBUG_LEVEL=3` 2. Replicate the issue 3. Stop debug: `fw debug fwm off TDERROR_ALL_ALL=0` `fw debug fwm off OPSEC_DEBUG_LEVEL=0` 4. Analyze: `$FWDIR/log/fwm.elg*` * Domain Management Server - refer to [sk33207](https://support.checkpoint.com/results/sk/sk33207): 1. Switch to the context of the relevant Domain Management Server: `mdsenv <Domain_Name>` 2. Start debug: `fw debug fwm on TDERROR_ALL_ALL=5` `fw debug fwm on OPSEC_DEBUG_LEVEL=3` 3. Replicate the issue 4. Stop debug: `fw debug fwm off TDERROR_ALL_ALL=0` `fw debug fwm off OPSEC_DEBUG_LEVEL=0` 5. Analyze: `$FWDIR/log/fwm.elg*` * Multi-Domain Security Management Server - refer to [sk33208](https://support.checkpoint.com/results/sk/sk33208): 1. Start debug: `fw debug mds on TDERROR_ALL_ALL=5` `fw debug mds on OPSEC_DEBUG_LEVEL=3` 2. Replicate the issue 3. Stop debug: `fw debug mds off TDERROR_ALL_ALL=0` `fw debug mds off OPSEC_DEBUG_LEVEL=0` 4. Analyze: `$MDS_TEMPLATE/log/mds.elg*` |
| fwmha                   | Description               | Communication between Management Servers in the Management High Availability mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| fwmha                   | Path                      | `$FWDIR/bin/fwmha`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| fwmha                   | Log File                  | `$FWDIR/log/fwmha.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| fwmha                   | Notes                     | The "`cpwd_admin list`" command shows the process as "`FWMHA`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| fwmha                   | To See the Current Status | `cpwd_admin list | grep -E "APP|FWMHA"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| fwmha                   | To Stop                   | * Security Management Server: `cpstop` * Domain Management Server on a Multi-Domain Security Management Server: `mdsstop_customer <IP Address of Domain Management Server>`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| fwmha                   | To Start                  | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| java_repository_manager | Description               | This process exists starting from the R81 version. Repository Manager for central installation of Hotfixes and Upgrade Packages from SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| java_repository_manager | Path                      | `$REPMANDIR/bin/java_repository_manager`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| java_repository_manager | Log File                  | * `$REPMANDIR/log/java_repository_manager.log` * `$REPMANDIR/log/RepositoryManager.log` * `$REPMANDIR/log/RepManStart.log` * `$REPMANDIR/log/RepManStop.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| java_repository_manager | Notes                     | The "`cpwd_admin list`" command shows the process as "`REPMAN`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| java_repository_manager | To See the Current Status | `cpwd_admin list | grep -E "APP|REPMAN"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| java_repository_manager | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| java_repository_manager | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Endpoint Policy Management Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
| uepm                    | Description               | Endpoint Management Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| uepm                    | Path                      | `$UEPMDIR/bin/uepm`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| uepm                    | Log File                  | `$UEPMDIR/logs/server_messages.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| uepm                    | To Stop                   | `uepm_stop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| uepm                    | To Start                  | `uepm_start`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| uepm                    | Debug                     | `uepm debug` Also refer to [sk92619](https://support.checkpoint.com/results/sk/sk92619)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| httpd                   | Description               | Communication with Endpoint Security Clients.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| httpd                   | Path                      | `$UEPMDIR/apache22/bin/httpd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| httpd                   | To Stop                   | `uepm_stop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| httpd                   | To Start                  | `uepm_start`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Monitoring Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
| rtmd                    | Description               | Real Time traffic statistics.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| rtmd                    | Path                      | `$FWDIR/bin/rtm`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| rtmd                    | Log File                  | `$FWDIR/log/rtmd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| rtmd                    | Notes                     | The "`cpwd_admin list`" command shows the process as "`RTMD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| rtmd                    | To See the Current Status | `cpwd_admin list | grep -E "APP|RTMD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| rtmd                    | To Stop                   | `rtmstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| rtmd                    | To Start                  | `rtmstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| rtmd                    | Debug                     | Refer to [skI2821](https://support.checkpoint.com/results/sk/skI2821): 1. Start debug: `rtm debug on TDERROR_ALL_ALL=5` `rtm debug on OPSEC_DEBUG_LEVEL=3` 2. Replicate the issue 3. Stop debug: `rtm debug off TDERROR_ALL_ALL=0` `rtm debug off OPSEC_DEBUG_LEVEL=0 ` 4. Analyze: `$FWDIR/log/rtmd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| cpstat_monitor          | Description               | Responsible for collecting and sending information to SmartView Monitor. By default, does not run in the context of Domain Management Servers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cpstat_monitor          | Path                      | `$FWDIR/bin/cpstat_monitor`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cpstat_monitor          | Log File                  | `$FWDIR/log/cpstat_monitor.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cpstat_monitor          | Notes                     | The "`cpwd_admin list`" command shows the process as "`CPSM`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cpstat_monitor          | To See the Current Status | `cpwd_admin list | grep -E "APP|CPSM"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| cpstat_monitor          | To Stop                   | `cpwd_admin stop -name CPSM`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| cpstat_monitor          | To Start                  | `cpwd_admin start -name CPSM -path "$FWDIR/bin/cpstat_monitor" -command "cpstat_monitor"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| cpstat_monitor          | Debug                     | Refer to [sk108177](https://support.checkpoint.com/results/sk/sk108177)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Provisioning Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
| status_proxy            | Description               | Status collection of ROBO Gateways - SmartLSM / SmartProvisioning status proxy. This process runs only on Security Management Server / Domain Management Servers that are activated for Large Scale Management / SmartProvisioning.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| status_proxy            | Path                      | `$FWDIR/bin/status_proxy`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| status_proxy            | Log File                  | `$FWDIR/log/status_proxy.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| status_proxy            | Notes                     | The "`cpwd_admin list`" command shows the process as "`STPR`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| status_proxy            | To See the Current Status | `cpwd_admin list | grep -E "APP|STPR"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| status_proxy            | To Stop                   | `cpwd_admin stop -name STPR`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| status_proxy            | To Start                  | `cpwd_admin start -name STPR -path "$FWDIR/bin/status_proxy" -command "status_proxy"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| status_proxy            | Debug                     | Refer to [sk108182](https://support.checkpoint.com/results/sk/sk108182)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| SmartReporter Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
| SVRServer               | Description               | Controller for the SmartReporter product. Traffic is sent over SSL.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| SVRServer               | Path                      | `$RTDIR/bin/SVRServer`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| SVRServer               | Log File                  | `$RTDIR/log/SVRServer.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| SVRServer               | Notes                     | The "`cpwd_admin list`" command shows the process as "`SVR`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| SVRServer               | To See the Current Status | `cpwd_admin list | grep -E "APP|SVR"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| SVRServer               | To Stop                   | `rmdstop` or `cpwd_admin stop -name SVR -path $RTDIR/bin/SVRServer -command "SVRServer kill SVRServer"` Also refer to [sk105485](https://support.checkpoint.com/results/sk/sk105485)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| SVRServer               | To Start                  | `rmdstart` or `cpwd_admin start -name SVR -path "$RTDIR/bin/SVRServer" -command "SVRServer"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| SVRServer               | Debug                     | Refer to [sk93970](https://support.checkpoint.com/results/sk/sk93970)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| log_consolidator        | Description               | Log Consolidator for the SmartReporter product.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| log_consolidator        | Path                      | `$RTDIR/log_consolidator_engine/bin/log_consolidator`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| log_consolidator        | Log File                  | `$RTDIR/log_consolidator_engine/log/<Log_Server_IP_Address>/lc_rt.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| log_consolidator        | Configuration File        | * `$RTDIR/log_consolidator_engine/conf/lc_rt_default.conf` * `$RTDIR/log_consolidator_engine/conf/<Log_Server_IP_Address>/lc_rt_default.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| log_consolidator        | Notes                     | The "`cpwd_admin list`" command shows the process as "`LC_<IP_Address _of_Log_Server>`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| log_consolidator        | To See the Current Status | `cpwd_admin list | grep -E "APP|LC_"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| log_consolidator        | To Stop                   | `rmdstop` or `evstop` or `log_consolidator -C -m stop -s <IP_Address _of_Log_Server> [-g <Domain_Name>]` and then `log_consolidator -C -m exit -s <IP_Address _of_Log_Server> [-g <Domain_Name>]`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| log_consolidator        | To Start                  | `rmdstart` or `evstart` or `log_consolidator -C -m start -s <IP_Address _of_Log_Server> [-g <Domain_Name>]`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| dbsync                  | Description               | DBsync enables SmartReporter to synchronize data stored in different parts of the network. After SIC is established, DBsync connects to the management server to retrieve all the objects. After the initial synchronization, it gets updates whenever an object is saved. In distributed information systems, DBsync provides one-way synchronization of data between the Security Management Servers object database and the SmartReporter computer, and supports configuration and administration of distributed systems.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| dbsync                  | Path                      | `$RTDIR/bin/dbsync`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| dbsync                  | Log File                  | * In R80 and higher: `$FWDIR/log/dbsync.elg` * R77.30 and lower: `$RTDIR/log/dbsync.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dbsync                  | Notes                     | The "`cpwd_admin list`" command shows the process as "`DBSYNC`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| dbsync                  | To See the Current Status | `cpwd_admin list | grep -E "APP|DBSYNC"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dbsync                  | To Stop                   | * In R80 and higher: Runs as part of CPM * In R77.30 and lower: `rmdstop` or `evstop` or `cpwd_admin stop -name DBSYNC`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| dbsync                  | To Start                  | * In R80 and higher: Runs as part of CPM * In R77.30 and lower: `rmdstart` or `evstart` or `cpwd_admin start -name DBSYNC -path "$RTDIR/bin/dbsync" -command "dbsync"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| dbsync                  | Debug                     | Refer to [sk93970](https://support.checkpoint.com/results/sk/sk93970)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| postgres                | Description               | PostgreSQL server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| postgres                | Path                      | `$CPDIR/database/postgresql/bin/postgres`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| postgres                | Log File                  | `$RTDIR/events_db/data/pg_log/postgresql-YYY-MM-DD_HHMMSS.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| postgres                | Configuration File        | The path depends on the software version. Your server may not contain all the files listed below: * `$CPDIR/conf/postgresql/postgresql.conf` * `$CPDIR/database/postgresql/data/postgresql.conf` or using another env variable: `$PGDATA/postgresql.conf` * `$RTDIR/events_db/data/postgresql.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| postgres                | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| postgres                | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| postgres                | Debug                     | "`su cp_postgres -c "$CPDIR/database/postgresql/bin/pg_ctl -D $RTDIR/events_db/data start`" Also refer to [sk93970](https://support.checkpoint.com/results/sk/sk93970)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| SmartEvent Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
| cpsead                  | Description               | Responsible for Correlation Unit functionality.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cpsead                  | Path                      | `$RTDIR/bin/cpsead`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cpsead                  | Log File                  | `$RTDIR/log/cpsead.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| cpsead                  | Notes                     | The "`cpwd_admin list`" command shows the process as "`CPSEAD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cpsead                  | To See the Current Status | `cpwd_admin list | grep -E "APP|CPSEAD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| cpsead                  | To Stop                   | `evstop` or `cpwd_admin stop -name CPSEAD` Also refer to [sk105485](https://support.checkpoint.com/results/sk/sk105485)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| cpsead                  | To Start                  | `evstart` or `cpwd_admin start -name CPSEAD -path "$RTDIR/bin/cpsead" -command "cpsead"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| cpsead                  | Debug                     | Refer to [sk95153](https://support.checkpoint.com/results/sk/sk95153), [sk105806](https://support.checkpoint.com/results/sk/sk105806), [sk93970](https://support.checkpoint.com/results/sk/sk93970)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cpsemd                  | Description               | Responsible for logging into the SmartEvent GUI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| cpsemd                  | Path                      | `$RTDIR/bin/cpsemd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cpsemd                  | Log File                  | `$RTDIR/log/cpsemd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| cpsemd                  | Notes                     | The "`cpwd_admin list`" command shows the process as "`CPSEMD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cpsemd                  | To See the Current Status | `cpwd_admin list | grep -E "APP|CPSEMD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| cpsemd                  | To Stop                   | `evstop` or `cpwd_admin stop -name CPSEMD`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| cpsemd                  | To Start                  | `evstart` or `cpwd_admin start -name CPSEMD -path "$RTDIR/bin/cpsemd" -command "cpsemd"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| cpsemd                  | Debug                     | Refer to [sk95153](https://support.checkpoint.com/results/sk/sk95153), [sk105806](https://support.checkpoint.com/results/sk/sk105806), [sk93970](https://support.checkpoint.com/results/sk/sk93970)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| dbsync                  | Description               | DBsync enables SmartEvent to synchronize data stored in different parts of the network. In distributed information systems, DBsync provides one-way synchronization of data between the Security Management Server's object database and the SmartEvent computer, and supports configuration and administration of distributed systems. DBsync initially connects to the Management Server, with which SIC is established. It retrieves all the objects and after the initial synchronization it gets updates whenever an object is saved.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| dbsync                  | Path                      | `$RTDIR/bin/dbsync`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| dbsync                  | Log File                  | `$RTDIR/log/dbsync.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| dbsync                  | Notes                     | The "`cpwd_admin list`" command shows the process as "`DBSYNC`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| dbsync                  | To See the Current Status | `cpwd_admin list | grep -E "APP|DBSYNC"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dbsync                  | To Stop                   | `evstop` or `cpwd_admin stop -name DBSYNC`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| dbsync                  | To Start                  | `evstart` or `cpwd_admin start -name DBSYNC -path "$RTDIR/bin/dbsync" -command "dbsync"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| dbsync                  | Debug                     | Refer to [sk93970](https://support.checkpoint.com/results/sk/sk93970)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| java_solr               | Description               | Starting in R80 (SmartEvent NGSE was integrated). Jetty Server. Events are stored in the SOLR database.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| java_solr               | Path                      | `$RTDIR/bin/java_solr`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| java_solr               | Log File                  | * `$RTDIR/log/solr.log` * `$RTDIR/log/solrRun.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| java_solr               | Notes                     | The "`cpwd_admin list`" command shows the process as "`SOLR`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| java_solr               | To See the Current Status | `cpwd_admin list | grep -E "APP|SOLR"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| java_solr               | Configuration File        | * `$RTDIR/rfl_server/solr/solr.xml` (R80.10 and higher) * `$RTDIR/conf/jetty.xml` (R80 and higher) * `$RTDIR/conf/solr.log4j.properties` (R80 and higher) * `$RTDIR/conf/solrConnectionConfig.xml` (R80 and higher) * `$RTDIR/log_indexes/solr.xml` (R80 and higher)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| java_solr               | To Stop                   | `evstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| java_solr               | To Start                  | `evstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| java_solr               | Debug                     | Refer to [sk105806](https://support.checkpoint.com/results/sk/sk105806): 1. `SmartEventSetDebugLevel solr <Debug_Level>` 2. `$FWDIR/scripts/solr_debug.py {on | off}`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| LogCore                 | Description               | Starting in R80 (SmartEvent NGSE was integrated). Manages the queries it gets from the consumer processes, forwards them to SOLR database and returns the results. Also in charge of resolving and database maintenance (clean up old indexes to have space for the new ones).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| LogCore                 | Path                      | `$RTDIR/bin/LogCore`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| LogCore                 | Log File                  | * `$RTDIR/log/RFL.log` * `$RTDIR/log/rflRun.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| LogCore                 | Notes                     | The "`cpwd_admin list`" command shows the process as "`RFL`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| LogCore                 | To See the Current Status | `cpwd_admin list | grep -E "APP|RFL"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| LogCore                 | Configuration File        | * `$RTDIR/conf/rfl.log4j.properties` * `$RTDIR/conf/rfl.log4j.properties.forUpgrade` * `$RTDIR/conf/rflConfig.xml`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| LogCore                 | To Stop                   | `evstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| LogCore                 | To Start                  | `evstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| LogCore                 | Debug                     | Refer to [sk105806](https://support.checkpoint.com/results/sk/sk105806): `SmartEventSetDebugLevel rfl <Debug_Level>`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| SmartView               | Description               | SmartEvent Web Application that allows you to connect to SmartEvent NGSE server (at `https://<IP_Address_of_SmartEvent_Server>/smartview/`) and see the event views and analysis directly from a Web Browser, without installing SmartConsole. The Web page comes with predefined views that you can customize. Refer to [sk105684](https://support.checkpoint.com/results/sk/sk105684).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| SmartView               | Path                      | `$RTDIR/bin/SmartView`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| SmartView               | Log File                  | * `$RTDIR/log/smartview.log` * `$RTDIR/log/SmartViewRun.log` * `$RTDIR/log/smartview-service.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| SmartView               | Notes                     | The "`cpwd_admin list`" command shows the process as "`SMARTVIEW`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| SmartView               | To See the Current Status | `cpwd_admin list | grep -E "APP|SMARTVIEW"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| SmartView               | Configuration File        | `$RTDIR/conf/smartview.log4j.properties`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| SmartView               | To Stop                   | `evstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| SmartView               | To Start                  | `evstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| SmartView               | Debug                     | Refer to [sk105806](https://support.checkpoint.com/results/sk/sk105806). `SmartEventSetDebugLevel smartview <Debug_Level>`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| log_indexer             | Description               | Starting in R80 (SmartEvent NGSE was integrated). Log indexer.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| log_indexer             | Path                      | `$RTDIR/log_indexer/log_indexer`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| log_indexer             | Log File                  | * `$RTDIR/log_indexer/log/log_indexer.elg` * `$RTDIR/log_indexer/log/log_indexerRun.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| log_indexer             | Notes                     | The "`cpwd_admin list`" command shows the process as "`INDEXER`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| log_indexer             | To See the Current Status | `cpwd_admin list | grep -E "APP|INDEXER"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| log_indexer             | Configuration File        | * `$RTDIR/log_indexer/conf/log_indexer_settings.conf` * `$RTDIR/log_indexer/log_indexer_custom_settings.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| log_indexer             | To Stop                   | `evstop` Important - On a Multi-Domain Server, the `evstop` command stops the `log_indexer` process for all levels (MDS and Domains)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| log_indexer             | To Start                  | * On a Security Management Server: `evstart` * On a Multi-Domain Server - for MDS context only: `evstart` * On a Multi-Domain Server - for MDS context and Domain contexts: `mdsstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| postgres                | Description               | PostgreSQL server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| postgres                | Path                      | `$CPDIR/database/postgresql/bin/postgres`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| postgres                | Log File                  | `$RTDIR/events_db/data/pg_log/postgresql-YYY-MM-DD_HHMMSS.log`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| postgres                | Configuration File        | `$RTDIR/events_db/data/postgresql.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| postgres                | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| postgres                | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| postgres                | Debug                     | "`su cp_postgres -c "$CPDIR/database/postgresql/bin/pg_ctl -D $RTDIR/events_db/data start`" Also refer to [sk93970](https://support.checkpoint.com/results/sk/sk93970)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Logging \& Status Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
| cplmd                   | Description               | To get the data that should be presented in SmartView Tracker, the FWM spawns a child process CPLMD, which reads the information from the log file and performs unification (if necessary). Upon receiving an answer from CPLMD, FWM transfers it to SmartView Tracker.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| cplmd                   | Path                      | `$FWDIR/bin/cplmd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cplmd                   | Log File                  | `$FWDIR/log/cplmd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| cplmd                   | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| cplmd                   | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| cplmd                   | Debug                     | Refer to [sk86324](https://support.checkpoint.com/results/sk/sk86324): 1. Start debug: `fw debug cplmd on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug cplmd off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/cplmd.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Management Portal                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
| cpwmd                   | Description               | Check Point Web Management Daemon - back-end for Management Portal / SmartPortal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cpwmd                   | Path                      | `$WEBDIR/bin/cpwmd`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cpwmd                   | Log File                  | `/opt/CPportal-<RXX>/portal/log/cpwmd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| cpwmd                   | Notes                     | The "`cpwd_admin list`" command shows the process as "`CPWMD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| cpwmd                   | To See the Current Status | `cpwd_admin list | grep -E "APP|CPWMD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| cpwmd                   | To Stop                   | `cpwd_admin stop -name CPWMD`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cpwmd                   | To Start                  | `cpwd_admin start -name CPWMD -path "$WEBDIR/bin/cpwmd" -command "cpwmd -D -app SmartPortal"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cpwmd                   | Debug                     | Refer to [sk31023](https://support.checkpoint.com/results/sk/sk31023)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cp_http_server          | Description               | HTTP Server for Management Portal (SmartPortal) and for OS WebUI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cp_http_server          | Path                      | `$WEBDIR/bin/cp_http_server`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| cp_http_server          | Log File                  | Refer to [sk31023](https://support.checkpoint.com/results/sk/sk31023); [sk30634](https://support.checkpoint.com/results/sk/sk30634)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| cp_http_server          | Configuration File        | `$MPDIR/conf/cp_httpd_admin.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cp_http_server          | Notes                     | The "`cpwd_admin list`" command shows the process as "`CPHTTPD`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| cp_http_server          | To See the Current Status | `cpwd_admin list | grep -E "APP|CPHTTPD"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| cp_http_server          | To Stop                   | `cpwd_admin stop -name CPHTTPD`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| cp_http_server          | To Start                  | `cpwd_admin start -name CPHTTPD -path "$WEBDIR/bin/cp_http_server" -command "cp_http_server -f '$MPDIR/conf/cp_httpd_admin.conf'"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cp_http_server          | Debug                     | Refer to [sk31023](https://support.checkpoint.com/results/sk/sk31023)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| SmartLog                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |||
| smartlog_server         | Description               | SmartLog product.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| smartlog_server         | Path                      | `$SMARTLOGDIR/smartlog_server`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| smartlog_server         | Log File                  | `$SMARTLOGDIR/log/smartlog_server.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| smartlog_server         | Notes                     | The "`cpwd_admin list`" command shows the process as "`SMARTLOG_SERVER`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| smartlog_server         | To See the Current Status | `cpwd_admin list | grep -E "APP|SMARTLOG_SERVER"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| smartlog_server         | To Stop                   | `smartlogstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| smartlog_server         | To Start                  | `smartlogstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| smartlog_server         | Debug                     | 1. Stop SmartLog: `smartlogstop` 2. Start SmartLog under debug: `env TDERROR_ALL_ALL=5 $SMARTLOGDIR/smartlog_server 1>> /var/log/smartlog.debug 2>> /var/log/smartlog.debug` 3. Replicate the issue 4. Stop debug - press CTRL+C. 5. Start SmartLog normally: `smartlogstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Internal CA                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
| cpca                    | Description               | Check Point Internal Certificate Authority (ICA): * SIC certificate pulling * Certificate enrollment * CRL fetch * Admin WebUI Note: By default, in MGMT HA, it runs only on "Active" Security Management Server. On the "Backup" Security Management Server, the "`cpstat mg`" command will show "`SmartCenter CA is not running`".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cpca                    | Path                      | `$FWDIR/bin/cpca`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cpca                    | Log File                  | `$FWDIR/log/cpca.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cpca                    | To Stop                   | * Security Management Server: `cpstop` * Domain Management Server on a Multi-Domain Security Management Server: `mdsstop_customer <IP Address of Domain Management Server>`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cpca                    | To Start                  | * Security Management Server: `cpstart` * Domain Management Server on a Multi-Domain Security Management Server: `mdsstart_customer <IP Address of Domain Management Server>`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cpca                    | Debug                     | Refer to [sk60338](https://support.checkpoint.com/results/sk/sk60338): 1. Start debug: `fw debug cpca on TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `fw debug cpca off TDERROR_ALL_ALL=0` 4. Analyze: `$FWDIR/log/cpca.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Compliance Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
| interpreter             | Description               | Process is responsible for Compliance Blade database scan.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| interpreter             | Path                      | `$FWDIR/bin/interpreter`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| interpreter             | Log File                  | * In R77 and higher: `$FWDIR/log/grc_interpreter.elg` * In R76: `/opt/CPPIgrc-R76/bin/grc_interpreter.elg` * In R75.40, R75.45, R75.46, R75.47: `/opt/CPPIgrc-R75.40/bin/grc_interpreter.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| interpreter             | Configuration File        | In R82.10 and higher: $FWDIR/conf/grc.conf is not exists R77 and higher: `$FWDIR/conf/grc.conf`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| interpreter             | Notes                     | This process is not monitored by Check Point WatchDog ("`cpwd_admin list`")                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| interpreter             | To Stop                   | `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| interpreter             | To Start                  | `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| interpreter             | Debug                     | * In R82.10 and higher You do not need to stop the service. run mgmt_cli set compliance-settings "debug-mode" true * In R77 and higher: 1. Stop Check Point service with "`cpstop`" command 2. Either run "`interpreter debug=1`" command, or in configuration file "`grc.conf`", manually set the value of "`debugMode`" from "0" to "1" 3. Start Check Point service with "`cpstart`" command * In R75.4x, R76: 1. Stop Check Point service with "`cpstop`" command 2. In configuration file "`grc.conf`", manually set the value of "`debugMode`" from "0" to "1" 3. Start Check Point service with "`cpstart`" command <br /> In addition, refer to the "`interpreter -help`" command and to [sk92861](https://support.checkpoint.com/results/sk/sk92861)                                                                                                                                                                                                                                                                                                                                                                                                           |
| SofaWare Management Server (Service Center for centrally managed Edge devices)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |||
| sms                     | Description               | Manages communication (status collection, logs collection, policy update, configuration update) with UTM-1 Edge Security Gateways. This process runs only on Security Management Server / Multi-Domain Security Management Servers that manage UTM-1 Edge devices.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| sms                     | Path                      | `$FWDIR/bin/sms`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| sms                     | Configuration File        | `$FWDIR/conf/sofaware/SWManagementServer.ini`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| sms                     | Notes                     | The "`cpwd_admin list`" command shows the process as "`VPN-1 Embedded Connector`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| sms                     | To See the Current Status | `cpwd_admin list | grep -E "APP|Embedded"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| sms                     | To Stop                   | `smsstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| sms                     | To Start                  | `smsstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| sms                     | Debug                     | Refer to [sk60780](https://support.checkpoint.com/results/sk/sk60780)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| OPSEC LEA (Log Export API)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
| lea_session             | Description               | Responsible for OPSEC LEA session between the OPSEC LEA Client and the OPSEC LEA Server on Check Point Management Server / Log Server. Spawned by the FWD daemon.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| lea_session             | Path                      | `$FWDIR/bin/lea_session`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| lea_session             | Configuration File        | `$FWDIR/conf/fwopsec.conf` Refer to "`lea_server`" lines                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| lea_session             | Log File                  | `$FWDIR/log/lea_session.<PID>.elg`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| lea_session             | Notes                     | The "`top`" and "`ps`" commands show the process as "`lea_session`"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| lea_session             | To Stop                   | `cpwd_admin stop -name FWD -path "$FWDIR/bin/fwd" -command "fw kill fwd"` or `cpstop`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| lea_session             | To Start                  | `cpwd_admin start -name FWD -path "$FWDIR/bin/fwd" -command "fwd"` or `cpstart`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| lea_session             | Debug                     | Refer to [sk86321](https://support.checkpoint.com/results/sk/sk86321): 1. Start debug: `fw debug fwd on TDERROR_ALL_ALL=5` `fw debug fwd on OPSEC_DEBUG_LEVEL=3` 2. Replicate the issue 3. Stop debug: `fw debug fwd off TDERROR_ALL_ALL=0` `fw debug fwd off OPSEC_DEBUG_LEVEL=0` 4. Analyze: `$FWDIR/log/lea_session.<PID>.elg*`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |

{#Filter_4Table}

Scalable Platforms {#Scalable Platforms}
----------------------------------------

Enter the string you are searching for in this table:

|--------|---------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Daemon | Section                   | Information                                                                                                                                                                                                                                                                     |
| authd  | Description               | Responsible for authentication between Maestro Orchestrators (R82 and higher) - manages SSL certificates See the *Scalable Platforms Administration Guide* for your version \> Chapter "Working with Quantum Maestro" \> Section "Authentication between Maestro Orchestrators" |
| authd  | Log File                  | `/var/log/authd.log` `/var/log/authd_essentials.log`                                                                                                                                                                                                                            |
| authd  | To See the Current Status | `ls -l /var/run/authd.pid` If this file exists, then the daemon is currently running                                                                                                                                                                                            |
| authd  | To Stop                   | `authd stop` or `tellpm process:authd`                                                                                                                                                                                                                                          |
| authd  | To Start                  | `authd start` or `tellpm process:authd t`                                                                                                                                                                                                                                       |
| authd  | Debug                     | None                                                                                                                                                                                                                                                                            |
| smartd | Description               | Responsible for LLDP updates between Maestro Orchestrators and the connected Maestro Security Appliances Runs on both Maestro Orchestrators and Maestro Security Appliances                                                                                                     |
| smartd | Log File                  | `/var/log/smartd.log` `/var/log/smartd.log.dbg` `/var/log/smartd_essential.log`                                                                                                                                                                                                 |
| smartd | To See the Current Status | `ps auxw | grep -v grep | grep smartd`                                                                                                                                                                                                                                          |
| smartd | To Stop                   | `smartd stop` or `tellpm process:smartd`                                                                                                                                                                                                                                        |
| smartd | To Start                  | `smartd start` or `tellpm process:smartd t`                                                                                                                                                                                                                                     |
| smartd | Debug                     | When needed, Check Point Support provides the instructions                                                                                                                                                                                                                      |

{#Filter_5Table}

Quantum Spark Appliances (2000 / 1900 / 1800 / 1600 / 1500 / 1400 / 1200R / 1100 / 900 / 700 / 600) {#Quantum Spark Appliances}
-------------------------------------------------------------------------------------------------------------------------------

Enter the string you are searching for in this table:

|----------|---------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Daemon   | Section                   | Information                                                                                                                                                              |
| sfwd     | Description               | Main process: * Logging * Policy installation * VPN negotiation * Identity Awareness enforcement * UserCheck enforcement * etc.                                          |
| sfwd     | Log File                  | `$FWDIR/log/sfwd.elg` Also refer to `$FWDIR/log/cpwd.elg`                                                                                                                |
| sfwd     | Notes                     | * The "`cpwd_admin list`" command shows the process as "`SFWD`". * The "`ps auxw`" command shows the process as "`fw sfwd`".                                             |
| sfwd     | To See the Current Status | `cpwd_admin list | grep -E "APP|SFWD"`                                                                                                                                   |
| sfwd     | To Stop                   | `$FWDIR/bin/cpwd_admin stop -name SFWD`                                                                                                                                  |
| sfwd     | To Start                  | `$FWDIR/bin/cpwd_admin start -name SFWD -path $FWDIR/bin/fw -command "fw sfwd"`                                                                                          |
| sfwd     | Debug                     | Refer to [sk86321](https://support.checkpoint.com/results/sk/sk86321)                                                                                                    |
| cposd    | Description               | SMB-specific daemon responsible for OS Networking operations.                                                                                                            |
| cposd    | Log File                  | `$FWDIR/log/cposd.elg`                                                                                                                                                   |
| cposd    | Notes                     | The "`cpwd_admin list`" command shows the process as "`cposd`"                                                                                                           |
| cposd    | To See the Current Status | `cpwd_admin list | grep -E "APP|cposd"`                                                                                                                                  |
| cposd    | To Stop                   | `cpwd_admin stop -name cposd`                                                                                                                                            |
| cposd    | To Start                  | `cpwd_admin start -name cposd -path /pfrm2.0/bin/cposd -command "cposd"`                                                                                                 |
| rtdbd    | Description               | Real Time database daemon.                                                                                                                                               |
| rtdbd    | Configuration File        | `/pfrm2.0/etc/rtdbd.conf`                                                                                                                                                |
| rtdbd    | Notes                     | The "`cpwd_admin list`" command shows the process as "`RTDB`"                                                                                                            |
| rtdbd    | To See the Current Status | `cpwd_admin list | grep -E "APP|RTDB"`                                                                                                                                   |
| rtdbd    | To Stop                   | `$FWDIR/bin/cpwd_admin stop -name RTDB`                                                                                                                                  |
| rtdbd    | To Start                  | `$FWDIR/bin/cpwd_admin start -name RTDB -path /pfrm2.0/bin/rtdbd -command "rtdbd"`                                                                                       |
| dropbear | Description               | LightWeight SSH server. * This process does not exist starting from the R80.20.60 and R81.10.00 versions. * This process does not exist on 900, 700, and 600 SMB models. |
| dropbear | Notes                     | The "`cpwd_admin list`" command shows the process as "`dropbear`"                                                                                                        |
| dropbear | To See the Current Status | `cpwd_admin list | grep -E "APP|dropbear"`                                                                                                                               |
| dropbear | To Stop                   | None                                                                                                                                                                     |
| dropbear | To Start                  | None                                                                                                                                                                     |

{#Filter_6Table}

Endpoint Security Client {#Endpoint Security Client}
----------------------------------------------------

Enter the string you are searching for in this table:

|----------------------------------|-----------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Daemon                           | Section                                                                                       | Information                                                                                                                                                                                                                                                                                                   |
| cpda.exe                         | Check Point Client connection service (Device Agent) - Check Point Endpoint Agent             | Roles: * Communication with Harmony Endpoint Server - HTTPS * Heart Beat \& Sync * Endpoint Authentication * Software Deployment * Managing Client State * EMON (Reporting) Data * Files \& Drivers Download * Policy Download                                                                                |
| IDAFServerHostService.exe        | Check Point Device Auxiliary Framework Host                                                   | Roles: * Communication with Harmony Endpoint Security Blades and with Device Agent * Policy Storage (persistent) * Provider Info Store EMON (Reporting), Harmony Endpoint Client state status and SYNC * Harmony Endpoint Security Logs Store (persistent) and Logs from each Harmony Endpoint Security Blade |
| EPWD.exe                         | Check Point Endpoint Client Watchdog service                                                  | Keeps the Harmony Endpoint Security Blades, services, and processes running.                                                                                                                                                                                                                                  |
| Imguardsvc64.exe                 | Check Point Capsule Docs Client Service                                                       | Enables the Check Point Capsule Docs Client. If this service is stopped, then content protected with Check Point Capsule Docs will be unavailable.                                                                                                                                                            |
| Imdci.exe                        | Check Point Capsule Docs DCI Process                                                          | Enables the Check Point Capsule Docs Client. If this service is stopped, then content protected with Check Point Capsule Docs will be unavailable.                                                                                                                                                            |
| FDE_srv.exe                      | Check Point Full Disk Encryption                                                              | Responsible for boot protection, Preboot Authentication and providing strong encryption to ensure that only authorized users can access data stored on the machine/device.                                                                                                                                    |
| CPFileAnlyz.exe (formerly TESvc) | * Check Point Endpoint Threat Emulation * Check Point Harmony Agent Threat Emulation (32 bit) | Check Point Endpoint Security File Analyzer silently protects your computer from potential malware. Monitors file creations on the system, scans each file and emulates it if needed.                                                                                                                         |
| vsmon.exe                        | Check Point Endpoint Security Network Protection                                              | Protects your network and your computer from unauthorized network access.                                                                                                                                                                                                                                     |
| Compliance.exe                   | Check Point Endpoint Security Compliance                                                      | Checks conformance of the computer to the security policies.                                                                                                                                                                                                                                                  |
| epab_svc.exe                     | Check Point Endpoint Security Anti-Bot service                                                | Detects bot-infected machines and prevents bot damages by blocking bot C\&C communications.                                                                                                                                                                                                                   |
| NEM_svc.exe                      | Check Point Endpoint Security Bitlocker Management                                            | Our Bitlocker Management service uses APIs provided by Microsoft Windows to control and to manage Bitlocker.                                                                                                                                                                                                  |
| RemediationService.exe           | Check Point Endpoint Security Remediation service                                             | Responsible for remediation of files. In practice, we quarantine a file (quarantine means creating a backup and then deleting the file) or deleting of malicious processes.                                                                                                                                   |
| EFRService.exe                   | Check Point Endpoint Security Forensics service                                               | Constantly monitors the system operation and gathers the information in to a dedicated database. When triggered, the `EFRService` is analyzing the collected data and generating a report.                                                                                                                    |
| cptrayUI.exe                     | Check Point Endpoint Security Client UI Service                                               | Responsible for all the UI aspects. Everything visual/graphical you can see in the Harmony Endpoint Client.                                                                                                                                                                                                   |
| cptrayLogic.exe                  | Check Point Endpoint Security Client UI Service                                               | Responsible for all Logic / Status data. Everything as far a textual and dynamic updates.                                                                                                                                                                                                                     |
| disknet.exe                      | * Check Point ESME Client * Check Point Endpoint Security MEPP Service                        | Main Media Encryption \& Port Protection (MEPP) Service.                                                                                                                                                                                                                                                      |
| ServiceRequest.exe               | * Check Point ESME Client * Check Point Endpoint Security MEPP Service                        | Helps support the MEPP Blade / Application.                                                                                                                                                                                                                                                                   |
| Unlock.exe                       | * Check Point ESME Client * Check Point Endpoint Security MEPP Service                        | Used for the Access to Business Data.exe. This is the Explorer Utility used with MEPP.                                                                                                                                                                                                                        |
| TracSrvWrapper.exe               | Check Point Endpoint Connect - Check Point Endpoint Security VPN Service                      | Main Remote Access VPN Blade Service.                                                                                                                                                                                                                                                                         |
| TrGui.exe                        | Check Point Endpoint Connect - Check Point Endpoint Security VPN Service                      | Remote Access VPN Blade UI Service.                                                                                                                                                                                                                                                                           |
| TracCAPI.exe                     | Check Point Endpoint Connect - Check Point Endpoint Security VPN Service                      | Provides access to users certificate storage for authentication. VPN service runs under SYSTEM account and cannot access personal certificates of users. The `TracSrvWrapper.exe` service launches `TracCAPI.exe` under the user's account, and `TracCAPI.exe` reads the user's certificates.                 |
| VPN_ProxyServer.exe              | Check Point Endpoint Connect - Check Point Endpoint Security VPN Service                      | Simulates a HTTP Server which hosts a PAC File in order to handle and use Proxy. Starting with Windows 10, PAC files cannot be accessed through a `file://` protocol. Only `http://` is allowed.                                                                                                              |

{#Filter_7Table}

Additional Processes {#Additional Processes}
--------------------------------------------

Enter the string you are searching for in this table:

|-----------------------|---------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Daemon                | Section                   | Information                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| mpdaemon              | Description               | On Security Gateway and Management Server. Platform Portal / Multi Portal (`https://<IP_Address>/`). Each portal has its Apache server (which can have multiple processes). The `mpdaemon` process is responsible for starting these web servers.                                                                                                                                                                                           |
| mpdaemon              | Path                      | `$CPDIR/bin/mpdaemon`                                                                                                                                                                                                                                                                                                                                                                                                                       |
| mpdaemon              | Log File                  | * `$CPDIR/log/mpdaemon.elg` * `$CPDIR/log/mpclient.elg`                                                                                                                                                                                                                                                                                                                                                                                     |
| mpdaemon              | Configuration File        | `$CPDIR/conf/mpdaemon.conf`                                                                                                                                                                                                                                                                                                                                                                                                                 |
| mpdaemon              | Notes                     | The "`cpwd_admin list`" command shows the process as "`MPDAEMON`".                                                                                                                                                                                                                                                                                                                                                                          |
| mpdaemon              | To See the Current Status | `cpwd_admin list | grep -E "APP|MPDAEMON"`                                                                                                                                                                                                                                                                                                                                                                                                  |
| mpdaemon              | To Stop                   | `cpwd_admin stop -name MPDAEMON` or `mpclient stopall`                                                                                                                                                                                                                                                                                                                                                                                      |
| mpdaemon              | To Start                  | `cpwd_admin start -name MPDAEMON -path "$CPDIR/bin/mpdaemon" -command "mpdaemon $CPDIR/log/mpdaemon.elg $CPDIR/conf/mpdaemon.conf"`                                                                                                                                                                                                                                                                                                         |
| mpdaemon              | Debug                     | Refer to [sk87920](https://support.checkpoint.com/results/sk/sk87920): 1. Start debug: `mpclient debug on` `mpclient debug set TDERROR_ALL_ALL=5` 2. Replicate the issue 3. Stop debug: `mpclient debug set TDERROR_ALL_ALL=0` `mpclient debug off`                                                                                                                                                                                         |
| CloudGuard Controller | Description               | CloudGuard Controller (Management Server)                                                                                                                                                                                                                                                                                                                                                                                                   |
| CloudGuard Controller | Path                      | `$VSECDIR`                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| CloudGuard Controller | Log File                  | `$MDS_FWDIR/log/cloud_proxy.elg`                                                                                                                                                                                                                                                                                                                                                                                                            |
| CloudGuard Controller | Configuration File        | `$MDS_FWDIR/conf/vsec.conf`                                                                                                                                                                                                                                                                                                                                                                                                                 |
| CloudGuard Controller | Notes                     | The "`cpwd_admin list`" command shows the process as "`CLOUDGUARD`"                                                                                                                                                                                                                                                                                                                                                                         |
| CloudGuard Controller | To See the Current Status | `cpwd_admin list | grep -E "APP|CLOUDGUARD"`                                                                                                                                                                                                                                                                                                                                                                                                |
| CloudGuard Controller | To Stop                   | * To stop temporarily: `vsec stop` * To stop permanently: `vsec off`                                                                                                                                                                                                                                                                                                                                                                        |
| CloudGuard Controller | To Start                  | * To start after "`vsec stop`", run: `vsec start` * To start after "`vsec off`", run: `vsec on`                                                                                                                                                                                                                                                                                                                                             |
| CloudGuard Controller | Debug                     | Refer to [sk115657](https://support.checkpoint.com/results/sk/sk115657)                                                                                                                                                                                                                                                                                                                                                                     |
| avi_del_tmp_files     | Description               | Shell script (from `$FWDIR/bin/`) that periodically deletes various old temporary Anti-Virus files on Security Gateway and Management Server.                                                                                                                                                                                                                                                                                               |
| avi_del_tmp_files     | Path                      | `$FWDIR/bin/avi_del_tmp_files`                                                                                                                                                                                                                                                                                                                                                                                                              |
| avi_del_tmp_files     | Log File                  | `$FWDIR/log/avi_del_tmp_files.elg`                                                                                                                                                                                                                                                                                                                                                                                                          |
| avi_del_tmp_files     | Notes                     | The "`cpwd_admin list`" command shows the process as "`CI_CLEANUP`".                                                                                                                                                                                                                                                                                                                                                                        |
| avi_del_tmp_files     | To See the Current Status | `cpwd_admin list | grep -E "APP|CI_CLEANUP"`                                                                                                                                                                                                                                                                                                                                                                                                |
| avi_del_tmp_files     | To Stop                   | `cpwd_admin stop -name CI_CLEANUP`                                                                                                                                                                                                                                                                                                                                                                                                          |
| avi_del_tmp_files     | To Start                  | `cpwd_admin start -name CI_CLEANUP -path $FWDIR/bin/avi_del_tmp_files -command "avi_del_tmp_files"`                                                                                                                                                                                                                                                                                                                                         |
| avi_del_tmp_files     | Debug                     | Standard CSH script debugging (`csh -x -v $FWDIR/bin/avi_del_tmp_files`)                                                                                                                                                                                                                                                                                                                                                                    |
| ci_http_server        | Description               | HTTP Server for Content Inspection on a Security Gateway.                                                                                                                                                                                                                                                                                                                                                                                   |
| ci_http_server        | Path                      | `$FWDIR/bin/ci_http_server`                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ci_http_server        | Log File                  | `$FWDIR/log/cphttpd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                    |
| ci_http_server        | Configuration File        | `$FWDIR/conf/cihs.conf`                                                                                                                                                                                                                                                                                                                                                                                                                     |
| ci_http_server        | Notes                     | The "`cpwd_admin list`" command shows the process as "`CIHS`"                                                                                                                                                                                                                                                                                                                                                                               |
| ci_http_server        | To See the Current Status | `cpwd_admin list | grep -E "APP|CIHS"`                                                                                                                                                                                                                                                                                                                                                                                                      |
| ci_http_server        | To Stop                   | `cpwd_admin stop -name CIHS`                                                                                                                                                                                                                                                                                                                                                                                                                |
| ci_http_server        | To Start                  | `cpwd_admin start -name CIHS -path $FWDIR/bin/ci_http_server -command "ci_http_server -j -f $FWDIR/conf/cihs.conf"`                                                                                                                                                                                                                                                                                                                         |
| ci_http_server        | Debug                     | 1. Stop: `cpwd_admin stop -name CIHS` 2. Start under debug (with "-v" flag): `cpwd_admin start -name CIHS -path $FWDIR/bin/ci_http_server -command "ci_http_server -v -j -f $FWDIR/conf/cihs.conf"` 3. Replicate the issue 4. Stop: `cpwd_admin stop -name CIHS` 5. Start normally: `cpwd_admin start -name CIHS -path $FWDIR/bin/ci_http_server -command "ci_http_server -j -f $FWDIR/conf/cihs.conf"`                                     |
| cp_http_server        | Description               | On Security Gateway and Management Server. HTTP Server for OS WebUI and Management Portal (SmartPortal).                                                                                                                                                                                                                                                                                                                                    |
| cp_http_server        | Path                      | `$WEBDIR/bin/cp_http_server`                                                                                                                                                                                                                                                                                                                                                                                                                |
| cp_http_server        | Log File                  | `$FWDIR/log/cphttpd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                    |
| cp_http_server        | Configuration File        | `$MPDIR/conf/cp_httpd_admin.conf`                                                                                                                                                                                                                                                                                                                                                                                                           |
| cp_http_server        | Notes                     | The "`cpwd_admin list`" command shows the process as "`CPHTTPD`".                                                                                                                                                                                                                                                                                                                                                                           |
| cp_http_server        | To See the Current Status | `cpwd_admin list | grep -E "APP|CPHTTPD"`                                                                                                                                                                                                                                                                                                                                                                                                   |
| cp_http_server        | To Stop                   | `cpwd_admin stop -name CPHTTPD`                                                                                                                                                                                                                                                                                                                                                                                                             |
| cp_http_server        | To Start                  | `cpwd_admin start -name CPHTTPD -path "$WEBDIR/bin/cp_http_server" -command "cp_http_server -f '$MPDIR/conf/cp_httpd_admin.conf'"`                                                                                                                                                                                                                                                                                                          |
| cp_http_server        | Debug                     | 1. Stop: `cpwd_admin stop -name CPHTTPD` 2. Start under debug (with "-v" flag): `cpwd_admin start -name CPHTTPD -path "$WEBDIR/bin/cp_http_server" -command "cp_http_server -v -f '$MPDIR/conf/cp_httpd_admin.conf'"` 3. Replicate the issue 4. Stop: `cpwd_admin stop -name CPHTTPD` 5. Start normally: `cpwd_admin start -name CPHTTPD -path "$WEBDIR/bin/cp_http_server" -command "cp_http_server -f '$MPDIR/conf/cp_httpd_admin.conf'"` |
| cpviewd               | Description               | On Security Gateway and Management Server. CPView Utility daemon ([sk101878](https://support.checkpoint.com/results/sk/sk101878)).                                                                                                                                                                                                                                                                                                          |
| cpviewd               | Path                      | * In R77.30 and higher: `$CPDIR/bin/cpviewd` * In R77, R77.10, R77.20: `$FWDIR/bin/cpviewd`                                                                                                                                                                                                                                                                                                                                                 |
| cpviewd               | Log File                  | * In R82 and higher: * Management Server and Security Gateway: `$CPDIR/log/cpviewd.elg` * VSX Gateway: `$CPDIR/log/cpviewd.elg.vs<VSID>` * In R81.20 and lower: See the start and stop messages in `$CPDIR/log/cpwd.elg`                                                                                                                                                                                                                    |
| cpviewd               | Configuration File        | `$CPDIR/conf/cpview_conf.xml`                                                                                                                                                                                                                                                                                                                                                                                                               |
| cpviewd               | Notes                     | The "`cpwd_admin list`" command shows the process as "`CPVIEWD`".                                                                                                                                                                                                                                                                                                                                                                           |
| cpviewd               | To See the Current Status | `cpwd_admin list | grep -E "APP|CPVIEWD"`                                                                                                                                                                                                                                                                                                                                                                                                   |
| cpviewd               | To Stop                   | `cpwd_admin stop -name CPVIEWD`                                                                                                                                                                                                                                                                                                                                                                                                             |
| cpviewd               | To Start                  | * In R77.30 and higher: `cpwd_admin start -name CPVIEWD -path "$CPDIR/bin/cpviewd" -command "cpviewd"` * In R77, R77,10, R77.20: `cpwd_admin start -name CPVIEWD -path "$FWDIR/bin/cpviewd" -command "cpviewd"`                                                                                                                                                                                                                             |
| cpviewd               | Debug                     | Refer to [sk101878](https://support.checkpoint.com/results/sk/sk101878)                                                                                                                                                                                                                                                                                                                                                                     |
| cpview_services       | Description               | On Security Gateway and Management Server. CPView Utility Services daemon ([sk101878](https://support.checkpoint.com/results/sk/sk101878)).                                                                                                                                                                                                                                                                                                 |
| cpview_services       | Path                      | `$CPDIR/bin/cpview_services`                                                                                                                                                                                                                                                                                                                                                                                                                |
| cpview_services       | Log File                  | * Management Server and Security Gateway: * In R80.30 and higher: `$CPDIR/log/cpview_services.elg` * In R77.30 - R80.20: `$CPDIR/log/hservice.elg` * VSX Gateway: * In R80.30 and higher: `$CPDIR/log/cpview_services.elg.<VSID>` * In R77.30 - R80.20: `$CPDIR/log/hservice.elg.<VSID>`                                                                                                                                                    |
| cpview_services       | Configuration File        | `$CPDIR/conf/cpview_services_conf.xml`                                                                                                                                                                                                                                                                                                                                                                                                      |
| cpview_services       | Notes                     | The "`cpwd_admin list`" command shows the process as "`CPVIEWS`".                                                                                                                                                                                                                                                                                                                                                                           |
| cpview_services       | To See the Current Status | `cpwd_admin list | grep -E "APP|CPVIEWS"`                                                                                                                                                                                                                                                                                                                                                                                                   |
| cpview_services       | To Stop                   | `cpwd_admin stop -name CPVIEWS`                                                                                                                                                                                                                                                                                                                                                                                                             |
| cpview_services       | To Start                  | `cpwd_admin start -name CPVIEWS -path "$CPDIR/bin/cpview_services" -command "cpview_services"`                                                                                                                                                                                                                                                                                                                                              |
| cpview_services       | Debug                     | Refer to [sk101878](https://support.checkpoint.com/results/sk/sk101878)                                                                                                                                                                                                                                                                                                                                                                     |
| cpview_historyd       | Description               | On Security Gateway and Management Server. CPView Utility History daemon ([sk101878](https://support.checkpoint.com/results/sk/sk101878)).                                                                                                                                                                                                                                                                                                  |
| cpview_historyd       | Path                      | * In R77.30 and higher: `$CPDIR/bin/cpview_historyd` * In R77, R77.10, R77.20: `$FWDIR/bin/cpview_historyd`                                                                                                                                                                                                                                                                                                                                 |
| cpview_historyd       | Log File                  | `/var/log/CPView_history/CPViewDB.dat`                                                                                                                                                                                                                                                                                                                                                                                                      |
| cpview_historyd       | Notes                     | The "`cpwd_admin list`" command shows the process as "`HISTORYD`"                                                                                                                                                                                                                                                                                                                                                                           |
| cpview_historyd       | To See the Current Status | `cpwd_admin list | grep -E "APP|HISTORYD"`                                                                                                                                                                                                                                                                                                                                                                                                  |
| cpview_historyd       | To Stop                   | `cpview --history off`                                                                                                                                                                                                                                                                                                                                                                                                                      |
| cpview_historyd       | To Start                  | `cpview --history on`                                                                                                                                                                                                                                                                                                                                                                                                                       |
| cpview_api_service    | Description               | This process exists starting from the R82 version. CPView Utility API Service daemon ([sk101878](https://support.checkpoint.com/results/sk/sk101878)) on a Security Gateway and a Management Server.                                                                                                                                                                                                                                        |
| cpview_api_service    | Path                      | `$CPDIR/bin/cpview_api_service`                                                                                                                                                                                                                                                                                                                                                                                                             |
| cpview_api_service    | Log File                  | * Management Server and Security Gateway: `$CPDIR/log/cpview_api_service.elg` * VSX Gateway: `$CPDIR/log/cpview_api_service.elg.vs<VSID>`                                                                                                                                                                                                                                                                                                   |
| cpview_api_service    | Configuration File        | `$CPDIR/conf/cpview_api_service_conf.xml`                                                                                                                                                                                                                                                                                                                                                                                                   |
| cpview_api_service    | Notes                     | The "`cpwd_admin list`" command shows the process as "`CVIEWAPIS`"                                                                                                                                                                                                                                                                                                                                                                          |
| cpview_api_service    | To See the Current Status | `cpwd_admin list | grep -E "APP|CVIEWAPIS"`                                                                                                                                                                                                                                                                                                                                                                                                 |
| cpview_api_service    | To Stop                   | `cpview --api_service off`                                                                                                                                                                                                                                                                                                                                                                                                                  |
| cpview_api_service    | To Start                  | `cpview --api_service on`                                                                                                                                                                                                                                                                                                                                                                                                                   |
| cpsnmpd               | Description               | On Security Gateway and Management Server: * Listens on UDP port 260 and is capable of responding to SNMP queries for Check Point OIDs only (under OID .1.3.6.1.4.1.2620) * Accepts only SNMPv1 * Supplied as a part of Check Point Suite (`$CPDIR/bin/cpsnmpd`)                                                                                                                                                                            |
| cpsnmpd               | To Stop                   | `killall cpsnmpd`                                                                                                                                                                                                                                                                                                                                                                                                                           |
| cpsnmpd               | To Start                  | `cpsnmpd -p 260`                                                                                                                                                                                                                                                                                                                                                                                                                            |
| cpsnmpd               | Debug                     | Refer to [sk66384](https://support.checkpoint.com/results/sk/sk66384)                                                                                                                                                                                                                                                                                                                                                                       |
| lpd                   | Description               | Log Parser Daemon - Search predefined patterns in log files.                                                                                                                                                                                                                                                                                                                                                                                |
| lpd                   | Path                      | `$DIAGDIR/bin/lpd`                                                                                                                                                                                                                                                                                                                                                                                                                          |
| lpd                   | Log File                  | `$FWDIR/log/lpd.elg`                                                                                                                                                                                                                                                                                                                                                                                                                        |
| lpd                   | Configuration File        | `$DIAGDIR/signatures/sdb.dat`                                                                                                                                                                                                                                                                                                                                                                                                               |
| lpd                   | Notes                     | The "`cpwd_admin list`" command shows the process as "`LPD`"                                                                                                                                                                                                                                                                                                                                                                                |
| lpd                   | To See the Current Status | `cpwd_admin list | grep -E "APP|LPD"`                                                                                                                                                                                                                                                                                                                                                                                                       |
| lpd                   | To Stop                   | `cpwd_admin stop -name LPD`                                                                                                                                                                                                                                                                                                                                                                                                                 |
| lpd                   | To Start                  | `cpwd_admin start -name LPD -path "$DIAGDIR/bin/lpd" -command "lpd"`                                                                                                                                                                                                                                                                                                                                                                        |
| lpd                   | Debug                     | * Start debug: `fw debug lpd on TDERROR_ALL_ALL=5` * Stop debug: `fw debug lpd off TDERROR_ALL_ALL=0` * Replicate the issue * Analyze: `$FWDIR/log/lpd.elg*`                                                                                                                                                                                                                                                                                |
| spike_detective       | Description               | CPU Spike Detective - see [sk166454](https://support.checkpoint.com/results/sk/sk166454) * Non-Scalable Platforms - R81 and higher, R80.40 Jumbo Take 69 (and higher) * On Maestro and Scalable Chassis - R81.10 and higher                                                                                                                                                                                                                 |
| spike_detective       | Path                      | `$FWDIR/bin/spike_detective`                                                                                                                                                                                                                                                                                                                                                                                                                |
| spike_detective       | Log File                  | * `CPView > CPU > Spikes` * `/var/log/spike_detective/spike_detective.log` * `/var/log/messages` (in R81 and higher) * `/var/log/spike_detective/data_spike_general_<Date>_<Time>/*` * `/var/log/spike_detective/data_spike_thread_<Thread_ID>_<Date>_<Time>` * `/var/log/spike_detective/data_spike_cpu_<Core_Number>_<Date>_<Time>`                                                                                                       |
| spike_detective       | Notes                     | The "`cpwd_admin list`" command shows the process as "`SPIKE_DETECTIVE`"                                                                                                                                                                                                                                                                                                                                                                    |
| spike_detective       | To See the Current Status | `cpwd_admin list | grep -E "APP|SPIKE_DETECTIVE"`                                                                                                                                                                                                                                                                                                                                                                                           |
| spike_detective       | Configuration File        | `$FWDIR/conf/spike_detective_conf.xml`                                                                                                                                                                                                                                                                                                                                                                                                      |
| spike_detective       | To Disable                | 1. `$CPDIR/bin/cpprod_util CPPROD_SetValue fw1 SpikedetectiveOff 4 1 1` 2. `reboot`                                                                                                                                                                                                                                                                                                                                                         |
| spike_detective       | To Enable                 | Note - In R81 and higher, this tool is enabled by default 1. `$CPDIR/bin/cpprod_util CPPROD_SetValue fw1 SpikedetectiveOff 4 0 1` 2. `reboot`                                                                                                                                                                                                                                                                                               |
| spike_detective       | To Stop                   | `cpwd_admin stop -name SPIKE_DETECTIVE`                                                                                                                                                                                                                                                                                                                                                                                                     |
| spike_detective       | To Start                  | `cpwd_admin start -name SPIKE_DETECTIVE -path $FWDIR/bin/spike_detective -command "spike_detective"`                                                                                                                                                                                                                                                                                                                                        |
| spike_detective       | Debug                     | None                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| cpview_exporter       | Description               | Part of Skyline - see [sk178566](https://support.checkpoint.com/results/sk/sk178566). CPView Exporter is a service that queries CPView at defined intervals, collects the metrics, and exports them to an OpenTelemetry Collector. For more information, see [sk180521](https://support.checkpoint.com/results/sk/sk180521).                                                                                                                |
| cpview_exporter       | Path                      | `$CPVIEWEXPORTER_DIR/cpview_exporter`                                                                                                                                                                                                                                                                                                                                                                                                       |
| cpview_exporter       | Log File                  |                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| cpview_exporter       | Notes                     | The "`cpwd_admin list`" command shows the process as "`OTLPAGENT`"                                                                                                                                                                                                                                                                                                                                                                          |
| cpview_exporter       | To See the Current Status | `cpwd_admin list | grep -E "APP|OTLPAGENT"`                                                                                                                                                                                                                                                                                                                                                                                                 |
| cpview_exporter       | Configuration File        | `$CPVIEWEXPORTER_DIR/config.yaml`                                                                                                                                                                                                                                                                                                                                                                                                           |
| cpview_exporter       | To Stop                   | `$CPVIEWEXPORTER_DIR/CPviewExporterCli.sh stop`                                                                                                                                                                                                                                                                                                                                                                                             |
| cpview_exporter       | To Start                  | `$CPVIEWEXPORTER_DIR/CPviewExporterCli.sh start`                                                                                                                                                                                                                                                                                                                                                                                            |
| otlp_agent            | Description               | Part of Skyline - see [sk178566](https://support.checkpoint.com/results/sk/sk178566). The OpenTelemetry Agent is a new method to generate and report metrics on Check Point devices, as part of the Skyline OpenTelemetry flow, additional to CPView. For more information, see [sk181615](https://support.checkpoint.com/results/sk/sk181615).                                                                                             |
| otlp_agent            | Path                      | `$CPOTLPAGENT_DIR/otlp_agent`                                                                                                                                                                                                                                                                                                                                                                                                               |
| otlp_agent            | Log File                  | `$CPOTLPAGENT_DIR/otlp_agent.elg`                                                                                                                                                                                                                                                                                                                                                                                                           |
| otlp_agent            | Notes                     | The "`cpwd_admin list`" command shows the process as "`OTLPAGENTDEMON`"                                                                                                                                                                                                                                                                                                                                                                     |
| otlp_agent            | To See the Current Status | `cpwd_admin list | grep -E "APP|OTLPAGENTDEMON"`                                                                                                                                                                                                                                                                                                                                                                                            |
| otlp_agent            | Configuration File        | * `$CPOTLPAGENT_DIR/events.yaml` * `$CPOTLPAGENT_DIR/otlp_agent_schema.json`                                                                                                                                                                                                                                                                                                                                                                |
| otlp_agent            | To Stop                   | `$CPOTLPAGENT_DIR/CPotlpagentCli.sh stop`                                                                                                                                                                                                                                                                                                                                                                                                   |
| otlp_agent            | To Start                  | `$CPOTLPAGENT_DIR/CPotlpagentCli.sh start`                                                                                                                                                                                                                                                                                                                                                                                                  |
| otlpcol               | Description               | Part of Skyline - see [sk178566](https://support.checkpoint.com/results/sk/sk178566). OpenTelemetry Collector (CPotelcol) is an open-source service that receives metrics from multiple Agents and exports them to an external endpoint (a different OpenTelemetry Collector or Prometheus Remote Write). For more information, see [sk180522](https://support.checkpoint.com/results/sk/sk180522).                                         |
| otlpcol               | Path                      | * `$CPOTELCOL_DIR/otlpcol` * `$CPOTELCOL_DIR/otelcol` * `$CPOTELCOL_DIR/sklnctl` * `$CPOTELCOL_DIR/skyline_explorer`                                                                                                                                                                                                                                                                                                                        |
| otlpcol               | Log File                  | * `$CPOTELCOL_DIR/otelcol.log` * `$CPOTELCOL_DIR/sklnctl.log`                                                                                                                                                                                                                                                                                                                                                                               |
| otlpcol               | Notes                     | The "`cpwd_admin list`" command shows the process as "`CPOTELCOL`"                                                                                                                                                                                                                                                                                                                                                                          |
| otlpcol               | To See the Current Status | `cpwd_admin list | grep -E "APP|CPOTELCOL"`                                                                                                                                                                                                                                                                                                                                                                                                 |
| otlpcol               | Configuration File        | `$CPOTELCOL_DIR/config.json`                                                                                                                                                                                                                                                                                                                                                                                                                |
| otlpcol               | To Stop                   | `$CPOTELCOL_DIR/CPotelcolCli.sh stop`                                                                                                                                                                                                                                                                                                                                                                                                       |
| otlpcol               | To Start                  | `$CPOTELCOL_DIR/CPotelcolCli.sh start`                                                                                                                                                                                                                                                                                                                                                                                                      |

{#Filter_8Table}

Related solutions {#Related solutions}
--------------------------------------

* [sk52421 - Ports used by Check Point software](https://support.checkpoint.com/results/sk/sk52421)
* [sk25766 - Security Servers - daemon names and definitions](https://support.checkpoint.com/results/sk/sk25766)
* [sk113113 - Security Management Servers and supported managed Security Gateways](https://support.checkpoint.com/results/sk/sk113113)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
