<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiqueue without Secreuxl in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67663#M12062</link>
    <description>&lt;P&gt;In R80.10 and earlier, SecureXL had to be enabled to use Multi-Queue due to the interaction with SecureXL automatic interface affinity, which would poll interface load every 60 seconds and shuffle interfaces around that did not have Multi-Queue enabled on the various SND/IRQ/Dispatcher cores trying to balance the load.&lt;/P&gt;
&lt;P&gt;Automatic interface affinity as it was performed in R80.10 and earlier is gone in R80.20 and later due to the big architectural changes in SecureXL, and even when you turn off SecureXL in R80.20 and later, it is not really completely disabled quite like it was in R80.10 and earlier.&amp;nbsp; If you have SecureXL disabled with &lt;STRONG&gt;fwaccel off&lt;/STRONG&gt; in R80.20+ due to your issue, yes you most definitely want to keep using Multi-Queue and it will still work.&amp;nbsp; If you can disable SecureXL selectively as described in these SKs that is always preferable to just turning it all off:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" style="font-family: DIN; font-size: 14px; color: #ba2454; cursor: pointer; text-decoration: none; font-weight: 400; display: inline-block; vertical-align: top; overflow: hidden; padding-left: 3px; text-align: left; text-overflow: ellipsis; white-space: nowrap; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" target="_blank"&gt;sk104468: How to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;disable&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SecureXL&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for specific IP addresses&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" style="font-family: DIN; font-size: 14px; color: #ba2454; cursor: pointer; text-decoration: underline; font-weight: 400; display: inline-block; vertical-align: top; overflow: hidden; padding-left: 3px; text-align: left; text-overflow: ellipsis; white-space: nowrap; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk151114&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk151114: "&lt;STRONG&gt;fwaccel&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;off&lt;/STRONG&gt;" does not affect disabling acceleration of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;VPN&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tunnels in R80.20 and above&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Starting in R80.30 with Gaia kernel 3.10, Multi-Queue is enabled by default on all interfaces except the management interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 17 Nov 2019 14:29:46 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2019-11-17T14:29:46Z</dc:date>
    <item>
      <title>Multiqueue without Secreuxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67653#M12059</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;Due to some service impact reason we have to disable securexl in our customer production network, to improve network performance we turned on multiqueue on some interfaces, accord to some documents and SK I know multiqueue is only relevant with securexl enabled, but I know multiqueue is linux thing not check point proprietary, so we really don't have any benefit to turn multiqueue on with securexl off?&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2019 12:33:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67653#M12059</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-11-17T12:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Multiqueue without Secreuxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67659#M12060</link>
      <description>&lt;P&gt;Gateway version and Jumbo HFA level?&amp;nbsp; The answer will depend quite a bit on this piece of information...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2019 13:25:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67659#M12060</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-11-17T13:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Multiqueue without Secreuxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67661#M12061</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;All R80.20 with jumbo hotfix take 118.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2019 13:35:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67661#M12061</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-11-17T13:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: Multiqueue without Secreuxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67663#M12062</link>
      <description>&lt;P&gt;In R80.10 and earlier, SecureXL had to be enabled to use Multi-Queue due to the interaction with SecureXL automatic interface affinity, which would poll interface load every 60 seconds and shuffle interfaces around that did not have Multi-Queue enabled on the various SND/IRQ/Dispatcher cores trying to balance the load.&lt;/P&gt;
&lt;P&gt;Automatic interface affinity as it was performed in R80.10 and earlier is gone in R80.20 and later due to the big architectural changes in SecureXL, and even when you turn off SecureXL in R80.20 and later, it is not really completely disabled quite like it was in R80.10 and earlier.&amp;nbsp; If you have SecureXL disabled with &lt;STRONG&gt;fwaccel off&lt;/STRONG&gt; in R80.20+ due to your issue, yes you most definitely want to keep using Multi-Queue and it will still work.&amp;nbsp; If you can disable SecureXL selectively as described in these SKs that is always preferable to just turning it all off:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" style="font-family: DIN; font-size: 14px; color: #ba2454; cursor: pointer; text-decoration: none; font-weight: 400; display: inline-block; vertical-align: top; overflow: hidden; padding-left: 3px; text-align: left; text-overflow: ellipsis; white-space: nowrap; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" target="_blank"&gt;sk104468: How to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;disable&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SecureXL&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;for specific IP addresses&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" style="font-family: DIN; font-size: 14px; color: #ba2454; cursor: pointer; text-decoration: underline; font-weight: 400; display: inline-block; vertical-align: top; overflow: hidden; padding-left: 3px; text-align: left; text-overflow: ellipsis; white-space: nowrap; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; letter-spacing: normal; orphans: 2; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; background-color: #ffffff; max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk151114&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk151114: "&lt;STRONG&gt;fwaccel&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;off&lt;/STRONG&gt;" does not affect disabling acceleration of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;VPN&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tunnels in R80.20 and above&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Starting in R80.30 with Gaia kernel 3.10, Multi-Queue is enabled by default on all interfaces except the management interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2019 14:29:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67663#M12062</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-11-17T14:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: Multiqueue without Secreuxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67664#M12063</link>
      <description>&lt;P&gt;Hi Mr. Hall,&lt;/P&gt;&lt;P&gt;Thanks for your reply, it really helps, unfortunately sk104468 won't do the trick becasue it's CDN service, we can't not predcit which ip address would be used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2019 14:37:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67664#M12063</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-11-17T14:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: Multiqueue without Secreuxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67676#M12064</link>
      <description>Why must you disable SecureXL?</description>
      <pubDate>Sun, 17 Nov 2019 21:58:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67676#M12064</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-17T21:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Multiqueue without Secreuxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67679#M12065</link>
      <description>&lt;P&gt;Do you know which port(s) the CDN is using?&amp;nbsp; If so you can use the little-known &lt;STRONG&gt;tcp_f2f_ports&lt;/STRONG&gt; directive mentioned in that SK to force certain ports F2F regardless of IP address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Nov 2019 22:11:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67679#M12065</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-11-17T22:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: Multiqueue without Secreuxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67699#M12066</link>
      <description>&lt;LI-SPOILER&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;It's https connections so I think disable that port is almost equals to disable all traffic get int to securexl.&lt;/LI-SPOILER&gt;</description>
      <pubDate>Mon, 18 Nov 2019 08:35:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67699#M12066</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-11-18T08:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: Multiqueue without Secreuxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67703#M12067</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Okay I'll try to explain this with my poor English.&lt;/P&gt;&lt;P&gt;As you can see the below topology:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="topology.JPG" style="width: 504px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3173iE3DF4EE0FA60B9EF/image-size/large?v=v2&amp;amp;px=999" role="button" title="topology.JPG" alt="topology.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Client is using Firewall PBR and transparent proxy for internet access.&lt;/P&gt;&lt;P&gt;All client's http/https traficc will go through core switch-&amp;gt;CP15600 then F5, F5 will distribute web service to proxy servers, then proxy will do the internet service for clients.&lt;/P&gt;&lt;P&gt;Most of web pages are ok, except this import one:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.tycc.gov.tw/LiveVideo/history.aspx" target="_blank" rel="noopener"&gt;https://www.tycc.gov.tw/LiveVideo/history.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It's a live videos history link, you may click on any square to see one of Taiwan parilament live stream backup, from the source code of any video clip, you can see the video was uploaded to the following link:&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;jwplayer("__CCDNPlayer1081118").setup({

    'width':'100%',

    'height':'100%',

    file: "&lt;STRONG&gt;https://flv.ccdntech.com/vod/_definst_/mp4:vod166/vod166_Live/20191118105959_live_dms.mp4/playlist.m3u8?wowzaplaystart=1795000"&lt;/STRONG&gt;,

    autostart:true,&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;With PBR+transparent proxy, most of clients can't replay this videos, they tried so many times only 1 or 2 times can display.&lt;/P&gt;&lt;P&gt;If traffic is not going through F5(No proxy), everything is fine, but that's not allowed.&lt;/P&gt;&lt;P&gt;It client using explicit proxy(Manually configured on browser), everything is fine, but that's not impossible, they claimed former firewall(Fortigate) don't need to do that.&lt;/P&gt;&lt;P&gt;If I turned off securexl, everything is fine, that's what they can accept, but I'm afraid of I/O issue so I turned on multiqueue and give 2 more cores to snd(There are 16 cores on CP15600).&lt;/P&gt;&lt;P&gt;Any better idea would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 09:36:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67703#M12067</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-11-18T09:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: Multiqueue without Secreuxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67707#M12068</link>
      <description>&lt;P&gt;As this is a deep SecureXL PBR issue, what is the statement from TAC / R&amp;amp;D here ?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 10:02:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67707#M12068</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-11-18T10:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: Multiqueue without Secreuxl</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67740#M12069</link>
      <description>Sounds like you should open a TAC case.&lt;BR /&gt;Specifically because disabling SecureXL should never be the solution to a problem.</description>
      <pubDate>Mon, 18 Nov 2019 16:12:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiqueue-without-Secreuxl/m-p/67740#M12069</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-18T16:12:52Z</dc:date>
    </item>
  </channel>
</rss>

