<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High CPU utilization on firewall with two cores in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174948#M484</link>
    <description>&lt;P&gt;Dear Chris.&lt;/P&gt;&lt;P&gt;In total 138 rules, rule 137 contains "traceroute" service and templates were disabled.&lt;/P&gt;&lt;P&gt;But any way we will increase numbers of the CPU cores.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Mar 2023 12:38:05 GMT</pubDate>
    <dc:creator>Glenmark_Impex</dc:creator>
    <dc:date>2023-03-15T12:38:05Z</dc:date>
    <item>
      <title>High CPU utilization on firewall with two cores</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174712#M476</link>
      <description>&lt;P&gt;Hello all experts!&lt;BR /&gt;We need your advice what we can do for firewall optimization. Currently we are facing performance issue on our firewall. Main issue this is CPU utilization. During working hours we are checking CPUs utilization using cpview and time to time one of CPUs reach 100% of utilization.&lt;/P&gt;&lt;P&gt;Please find current config and "super seven" outputs below.&lt;/P&gt;&lt;P&gt;Enabled features:&lt;BR /&gt;FW, Remote Access VPN up to 50 remote users simultaneously, QoS, HTTPS insp, URL and APP filtering, IPS, Threat Prevention IPS, Anti-Bot and Anti-Virus.&lt;/P&gt;&lt;P&gt;[Expert@FW-MSCW-01-01:0]# fwaccel stat&lt;BR /&gt;Accelerator Status : on&lt;BR /&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;disabled from rule #137&lt;BR /&gt;Drop Templates : enabled&lt;BR /&gt;NAT Templates : disabled by user&lt;/P&gt;&lt;P&gt;Accelerator Features : Accounting, NAT, Cryptography, QOS, Routing,&lt;BR /&gt;HasClock, Templates, Synchronous, IdleDetection,&lt;BR /&gt;Sequencing, TcpStateDetect, AutoExpire,&lt;BR /&gt;DelayedNotif, TcpStateDetectV2, CPLS, McastRouting,&lt;BR /&gt;WireMode, DropTemplates, NatTemplates,&lt;BR /&gt;Streaming, MultiFW, AntiSpoofing, Nac,&lt;BR /&gt;ViolationStats, AsychronicNotif, ERDOS,&lt;BR /&gt;NAT64, GTPAcceleration, SCTPAcceleration,&lt;BR /&gt;McastRoutingV2&lt;BR /&gt;Cryptography Features : Tunnel, UDPEncapsulation, MD5, SHA1, NULL,&lt;BR /&gt;3DES, DES, CAST, CAST-40, AES-128, AES-256,&lt;BR /&gt;ESP, LinkSelection, DynamicVPN, NatTraversal,&lt;BR /&gt;EncRouting, AES-XCBC, SHA256&lt;/P&gt;&lt;P&gt;[Expert@FW-MSCW-01-01:0]# fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 5/4673 (0%)&lt;BR /&gt;Delayed conns/(Accelerated conns + PXL conns) : 225696/3136 (7196%)&lt;BR /&gt;Accelerated pkts/Total pkts : 12738732/58507915 (21%)&lt;BR /&gt;F2Fed pkts/Total pkts : 4980996/58507915 (8%)&lt;BR /&gt;PXL pkts/Total pkts : 40788187/58507915 (69%)&lt;BR /&gt;QXL pkts/Total pkts : 54107948/58507915 (92%)&lt;/P&gt;&lt;P&gt;[Expert@FW-MSCW-01-01:0]# grep -c ^processor /proc/cpuinfo&lt;BR /&gt;8&lt;/P&gt;&lt;P&gt;[Expert@FW-MSCW-01-01:0]# fw ctl affinity -r -l -v&lt;BR /&gt;CPU 0: eth0 (irq 67) eth3 (irq 59) eth4 (irq 67) eth7 (irq 59) eth8 (irq 67)&lt;BR /&gt;fw_1 fw_3 fw_5&lt;BR /&gt;CPU 1: eth1 (irq 75) eth2 (irq 83) eth5 (irq 75) eth6 (irq 83) eth9 (irq 75)&lt;BR /&gt;fw_0 fw_2 fw_4&lt;BR /&gt;CPU 2:&lt;BR /&gt;CPU 3:&lt;BR /&gt;CPU 4:&lt;BR /&gt;CPU 5:&lt;BR /&gt;CPU 6:&lt;BR /&gt;CPU 7:&lt;BR /&gt;All: rad pepd vpnd mpdaemon in.acapd usrchkd in.msd pdpd in.geod fwpushd rtmd fgd50 fwd lpd cpd cprid&lt;BR /&gt;The current license permits the use of CPUs 0, 1 only.&lt;/P&gt;&lt;P&gt;[Expert@FW-MSCW-01-01:0]# /sbin/cpuinfo&lt;BR /&gt;HyperThreading=disabled&lt;/P&gt;&lt;P&gt;[Expert@FW-MSCW-01-01:0]# netstat -ni&lt;BR /&gt;Kernel Interface table&lt;BR /&gt;Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg&lt;BR /&gt;eth0 1500 0 15796271 0 0 0 14023053 0 0 0 BMRU&lt;BR /&gt;eth1 1500 0 122082 0 0 0 117466 0 0 0 BMRU&lt;BR /&gt;eth2 1500 0 3033623 0 0 0 5755418 0 0 0 BMRU&lt;BR /&gt;eth3 1500 0 0 0 0 0 0 0 0 0 BMRU&lt;BR /&gt;eth4 1500 0 1123043 0 0 0 1533844 0 0 0 BMRU&lt;BR /&gt;eth5 1500 0 7958610 0 0 0 11024999 0 0 0 BMRU&lt;BR /&gt;eth6 1500 0 27535290 0 0 0 25386131 0 0 0 BMRU&lt;BR /&gt;eth7 1500 0 647122 0 0 0 620435 0 0 0 BMRU&lt;BR /&gt;eth8 1500 0 19183323 0 0 0 16698501 0 0 0 BMRU&lt;BR /&gt;eth8.111 1500 0 3677329 0 0 0 6900712 0 0 0 BMRU&lt;BR /&gt;eth8.150 1500 0 13944698 0 0 0 8995520 0 0 0 BMRU&lt;BR /&gt;eth8.220 1500 0 522098 0 0 0 650359 0 0 0 BMRU&lt;BR /&gt;eth8.230 1500 0 1039134 0 0 0 151978 0 0 0 BMRU&lt;BR /&gt;eth9 1500 0 288522 0 0 0 345532 0 0 0 BMRU&lt;BR /&gt;lo 16436 0 1440143 0 0 0 1440143 0 0 0 LRU&lt;/P&gt;&lt;P&gt;[Expert@FW-MSCW-01-01:0]# fw ctl multik stat&lt;BR /&gt;ID | Active | CPU | Connections | Peak&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;0 | Yes | 1 | 1401 | 1881&lt;BR /&gt;1 | Yes | 0 | 908 | 1401&lt;BR /&gt;2 | Yes | 1 | 723 | 917&lt;BR /&gt;3 | Yes | 0 | 954 | 1417&lt;BR /&gt;4 | Yes | 1 | 1211 | 1308&lt;BR /&gt;5 | Yes | 0 | 779 | 908&lt;/P&gt;&lt;P&gt;[Expert@FW-MSCW-01-01:0]# cpstat os -f multi_cpu -o 1&lt;BR /&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 100| 0| 100| ?| 10909|&lt;BR /&gt;| 2| 0| 59| 41| 59| ?| 10909|&lt;BR /&gt;| 3| 0| 0| 100| 0| ?| 10910|&lt;BR /&gt;| 4| 0| 0| 100| 0| ?| 10910|&lt;BR /&gt;| 5| 0| 0| 100| 0| ?| 10911|&lt;BR /&gt;| 6| 1| 3| 96| 4| ?| 10911|&lt;BR /&gt;| 7| 5| 3| 91| 9| ?| 10912|&lt;BR /&gt;| 8| 0| 1| 99| 1| ?| 10913|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@FW-MSCW-01-01:0]# free -m&lt;BR /&gt;total used free shared buffers cached&lt;BR /&gt;Mem: 11877 5778 6098 0 254 2535&lt;BR /&gt;-/+ buffers/cache: 2989 8888&lt;BR /&gt;Swap: 3067 0 3067&lt;/P&gt;&lt;P&gt;[Expert@FW-MSCW-01-01:0]# cpinfo -y all&lt;/P&gt;&lt;P&gt;This is Check Point CPinfo Build 914000196 for GAIA&lt;BR /&gt;[FW1]&lt;BR /&gt;HOTFIX_R77_30&lt;BR /&gt;HOTFIX_R77_30_JUMBO_HF Take: 351&lt;/P&gt;&lt;P&gt;FW1 build number:&lt;BR /&gt;This is Check Point's software version R77.30 - Build 165&lt;BR /&gt;kernel: R77.30 - Build 165&lt;/P&gt;&lt;P&gt;[SecurePlatform]&lt;BR /&gt;HOTFIX_R77_30_JUMBO_HF Take: 351&lt;/P&gt;&lt;P&gt;[CPinfo]&lt;BR /&gt;No hotfixes..&lt;/P&gt;&lt;P&gt;[PPACK]&lt;BR /&gt;HOTFIX_R77_30&lt;BR /&gt;HOTFIX_R77_30_JUMBO_HF Take: 351&lt;/P&gt;&lt;P&gt;[CVPN]&lt;BR /&gt;HOTFIX_R77_30&lt;BR /&gt;HOTFIX_R77_30_JUMBO_HF Take: 351&lt;/P&gt;&lt;P&gt;[CPUpdates]&lt;BR /&gt;GAIA_WD_UPDATE_SK109359 Take: 0&lt;BR /&gt;BUNDLE_R77_30_JUMBO_HF Take: 351&lt;/P&gt;&lt;P&gt;[DIAG]&lt;BR /&gt;HOTFIX_R77_30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 09:10:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174712#M476</guid>
      <dc:creator>Glenmark_Impex</dc:creator>
      <dc:date>2023-03-14T09:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on firewall with two cores</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174718#M477</link>
      <description>&lt;P&gt;This version is out of support ! Add 2 more cores and the issue will be resolved.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 09:45:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174718#M477</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-14T09:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on firewall with two cores</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174723#M478</link>
      <description>&lt;P&gt;We are considering increasing CPUs license number. But for now it would be helpful to know will update make our situation with CPUs utilization a little bit easier?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 10:06:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174723#M478</guid>
      <dc:creator>Glenmark_Impex</dc:creator>
      <dc:date>2023-03-14T10:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on firewall with two cores</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174728#M479</link>
      <description>&lt;P&gt;Yes, it certainly will ! With 2 cores only, you have no optimization possibilities. Four cores will help much.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 10:29:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174728#M479</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-14T10:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on firewall with two cores</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174745#M480</link>
      <description>&lt;P&gt;"Accept Templates : disabled by Firewall&amp;nbsp;&lt;SPAN&gt;disabled from rule #137&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What does this rule look like in the policy and how many rules are there in total?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 13:19:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174745#M480</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-14T13:19:33Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on firewall with two cores</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174747#M481</link>
      <description>&lt;P&gt;Guenther is 100% right. Yes, R77.30 is long time out of support, but if you add 2 more cored, you will be fine.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 13:22:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174747#M481</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-14T13:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on firewall with two cores</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174769#M482</link>
      <description>&lt;P&gt;Agree with the other posters, your firewall is just very busy for only two cores in an overlapping 2/2 split.&amp;nbsp; No glaring issues that need to be tuned.&amp;nbsp; Adding two more cores which will enable a non-overlapping 1/3 default split will make a big difference.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 14:37:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174769#M482</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-03-14T14:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on firewall with two cores</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174773#M483</link>
      <description>&lt;P&gt;With a 2 core system running R77.30, there really isn't much tuning you can do to improve performance.&lt;BR /&gt;You should upgrade to a supported release and add additional cores.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 14:46:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174773#M483</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-14T14:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on firewall with two cores</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174948#M484</link>
      <description>&lt;P&gt;Dear Chris.&lt;/P&gt;&lt;P&gt;In total 138 rules, rule 137 contains "traceroute" service and templates were disabled.&lt;/P&gt;&lt;P&gt;But any way we will increase numbers of the CPU cores.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 12:38:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174948#M484</guid>
      <dc:creator>Glenmark_Impex</dc:creator>
      <dc:date>2023-03-15T12:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on firewall with two cores</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174997#M485</link>
      <description>&lt;P&gt;In R80.10 and above traceroute wouldn't disable templates but given its at the bottom of the current policy it wouldn't have a significant impact here (refer:&amp;nbsp;&lt;SPAN&gt;sk32578).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 15:05:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/174997#M485</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-15T15:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on firewall with two cores</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/175001#M486</link>
      <description>&lt;P&gt;We have R77.30 Gateway. Update has been planned.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 15:16:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/High-CPU-utilization-on-firewall-with-two-cores/m-p/175001#M486</guid>
      <dc:creator>Glenmark_Impex</dc:creator>
      <dc:date>2023-03-15T15:16:33Z</dc:date>
    </item>
  </channel>
</rss>

