<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall VM issue in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176774#M299</link>
    <description>&lt;P&gt;To be sure you're aware, the guest OS option in ESX is just for configuration presets. It doesn't actually do anything on an ongoing basis. You can change any vNIC to vmxnet3.&lt;/P&gt;
&lt;P&gt;Agreed with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;that you should really install a jumbo. R80.40 jumbo 192 has 2225 fixes over the initial release of R80.40.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2023 15:04:17 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2023-03-30T15:04:17Z</dc:date>
    <item>
      <title>Firewall VM issue</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176714#M294</link>
      <description>&lt;P&gt;Hi all experts.&lt;/P&gt;&lt;P&gt;Our question for experts experienced with deploying of Checkpoint firewall virtual instances.&lt;/P&gt;&lt;P&gt;We facing issue with deploying of Checkpoint R 80.40 virtual gateway.&lt;/P&gt;&lt;P&gt;Hypervisor -&amp;nbsp; ESXi VMware 6.5.0&lt;/P&gt;&lt;P&gt;Server HW – HP Proliant DL360 Gen8&lt;/P&gt;&lt;P&gt;CPU HW- intel Xeon CPU E5-2670&lt;/P&gt;&lt;P&gt;Checkpoint installation iso file - Check_Point_R80.40_T294.iso&lt;/P&gt;&lt;P&gt;VM general settings&lt;/P&gt;&lt;P&gt;Guest OS RHEL7 64-bit&lt;/P&gt;&lt;P&gt;HDD – 100 GB&lt;/P&gt;&lt;P&gt;Memory – 12GB&lt;/P&gt;&lt;P&gt;Number of the CPU – 4&lt;/P&gt;&lt;P&gt;Number of the vNIC -10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Installation has been completed successfully. But vNIC’s sequence doesn’t match with Checkoint gateway interfaces. For example if we disconnect vNIC – 1 on Checkpoint gateway eth5 going down. This issue has been solved with sk69621. We have found correct sequence’s for ID PCI bus Instead renaming eth’s.&lt;/P&gt;&lt;P&gt;Next step – performance test.&lt;/P&gt;&lt;P&gt;Using iperf we have tested bandwidth. Data rate was unstable form 40 Mbits/s to 413 Mbits/s. In CPview the SND CPU has utilization up to&amp;nbsp;100%&lt;/P&gt;&lt;P&gt;We decide to move another one CPU to SND. Using cpconfig we have set two CPU for SND and reboot the VM.&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Glenmark_Impex_0-1680169993606.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20312i22CC68BB1C03EC30/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Glenmark_Impex_0-1680169993606.png" alt="Glenmark_Impex_0-1680169993606.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our question is what we are doing wrong?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 09:58:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176714#M294</guid>
      <dc:creator>Glenmark_Impex</dc:creator>
      <dc:date>2023-03-30T09:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall VM issue</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176728#M295</link>
      <description>&lt;P&gt;Is there a JHF applied to this machine and can you share some specifics of the iperf test, were multiple parallel threads used or just a single flow?&lt;/P&gt;
&lt;P&gt;Which interface driver/type is used for the VM?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 11:56:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176728#M295</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-30T11:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall VM issue</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176734#M296</link>
      <description>&lt;P&gt;Dear Chris&lt;/P&gt;&lt;P&gt;Iperf test string -&amp;nbsp; iperf.exe -c 172.21.126.166 -p 443 -t 120&lt;/P&gt;&lt;P&gt;Clean installation with iso -&amp;nbsp;&lt;SPAN&gt;Check_Point_R80.40_T294.iso no any additional JHF were installed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;vNIC driver - VMXNET3. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We would like to use this driver instead E1000. It was major reason for choosing guest OS RHEL7 but no Other Linux.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 12:12:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176734#M296</guid>
      <dc:creator>Glenmark_Impex</dc:creator>
      <dc:date>2023-03-30T12:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall VM issue</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176737#M297</link>
      <description>&lt;P&gt;-P&amp;nbsp; should help with parallel threads up to the limits of the test hosts CPU.&lt;/P&gt;
&lt;P&gt;See an example here depending on the scale that you hope to achieve.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://fasterdata.es.net/performance-testing/network-troubleshooting-tools/iperf/multi-stream-iperf3/" target="_blank" rel="noopener"&gt;https://fasterdata.es.net/performance-testing/network-troubleshooting-tools/iperf/multi-stream-iperf3/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Deploying JHFs on top of the base image is recommended as best practice.&lt;/P&gt;
&lt;P&gt;Note OVA images are available here for reference:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk158292" target="_self"&gt;sk158292:&amp;nbsp;&lt;SPAN&gt;CloudGuard Network for Private Cloud images&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 12:28:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176737#M297</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-30T12:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall VM issue</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176738#M298</link>
      <description>&lt;P&gt;I can't make out the screenshot well, is the system no longer booting post the changes or something else?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 12:49:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176738#M298</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-30T12:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall VM issue</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176774#M299</link>
      <description>&lt;P&gt;To be sure you're aware, the guest OS option in ESX is just for configuration presets. It doesn't actually do anything on an ongoing basis. You can change any vNIC to vmxnet3.&lt;/P&gt;
&lt;P&gt;Agreed with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;that you should really install a jumbo. R80.40 jumbo 192 has 2225 fixes over the initial release of R80.40.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 15:04:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176774#M299</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-03-30T15:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall VM issue</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176783#M300</link>
      <description>&lt;P&gt;Yes, VM no longer bootable, but we have fresh install snapshot. No any changes for VM only cpconfig - CoreXL and VM has gone.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 16:15:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176783#M300</guid>
      <dc:creator>Glenmark_Impex</dc:creator>
      <dc:date>2023-03-30T16:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall VM issue</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176784#M301</link>
      <description>&lt;P&gt;Will try OVA from SK. Will see.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 16:18:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176784#M301</guid>
      <dc:creator>Glenmark_Impex</dc:creator>
      <dc:date>2023-03-30T16:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall VM issue</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176830#M302</link>
      <description>&lt;P&gt;Make sure you've tuned the configuration appropriately per:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk169252" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk169252&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Also, you really should install the latest recommended JHF:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/R80.40/R80.40_Downloads.htm?tocpath=_____3" target="_blank"&gt;https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/R80.40/R80.40_Downloads.htm?tocpath=_____3&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 03:55:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/176830#M302</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-31T03:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall VM issue</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/177831#M303</link>
      <description>&lt;P&gt;Dear Chris.&lt;/P&gt;&lt;P&gt;We have download tar archive with VMDK, OVF, CERT and MF files instead OVA.&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=103389" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=103389&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Gateway installation has been completed successfully. We can change numbers of vCPUs via VM settings or change CoreXL parameters&amp;nbsp; in cpconfig command without any issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for advices.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 08:32:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Firewall-VM-issue/m-p/177831#M303</guid>
      <dc:creator>Glenmark_Impex</dc:creator>
      <dc:date>2023-04-11T08:32:30Z</dc:date>
    </item>
  </channel>
</rss>

