<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Performance issues : Loss of packets in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61679#M12417</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/33847"&gt;@Zia&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Could you see RX errors?&lt;/P&gt;
&lt;P&gt;# netstat -in&lt;BR /&gt;&lt;BR /&gt;Could you see CPU performance issues (software interruts or hw interrupts)?&lt;/P&gt;
&lt;P&gt;# top + key 1&lt;/P&gt;
&lt;P&gt;Which network card drivers are you use?&lt;/P&gt;
&lt;P&gt;# ethtool -i ethX&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On firewall 1 I can see 95% PXL traffic on firewall 2 I can see only 0% and heavy F2F traffic (100%). I think SecureXL is disabled on firewall 2.&amp;nbsp; Check SecureXL on FW 2.&lt;/P&gt;
&lt;P&gt;# fwaccel stat&lt;/P&gt;
&lt;P&gt;Are deamons to be visible they generating high load?&lt;/P&gt;
&lt;P&gt;# top &lt;BR /&gt;&lt;BR /&gt;(More see here: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97638&amp;amp;partition=General&amp;amp;product=All%22" target="_self"&gt; Check Point Processes and Daemons)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards &lt;BR /&gt;Heiko&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 02 Sep 2019 20:35:42 GMT</pubDate>
    <dc:creator>HeikoAnkenbrand</dc:creator>
    <dc:date>2019-09-02T20:35:42Z</dc:date>
    <item>
      <title>Performance issues : Loss of packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61664#M12413</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I would like the help of the experts here.&lt;/P&gt;&lt;P&gt;We have 2 firewall (5400 model) HA configured and a HP server that acts as the SMS.&amp;nbsp;All of them run under Gaia R80.10.&lt;/P&gt;&lt;P&gt;Here are my main issues:&lt;/P&gt;&lt;P&gt;-We have severe case of packet loss in all of the interfaces of the active firewall and as a result the network is very slow.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance for all of your suggestions and helpful tips.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;*********************************************************************&lt;/P&gt;&lt;P&gt;[Expert@Firewall-1:0]# enabled_blades&lt;BR /&gt;fw vpn cvpn urlf av appi ips identityServer anti_bot vpn&lt;/P&gt;&lt;P&gt;*********************************************************************&lt;/P&gt;&lt;P&gt;[Expert@Firewall-1:0]# fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 2/1574 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 118218/167295927 (0%)&lt;BR /&gt;F2Fed pkts/Total pkts : 6917099/167295927 (4%)&lt;BR /&gt;PXL pkts/Total pkts : 160260610/167295927 (95%)&lt;BR /&gt;QXL pkts/Total pkts : 0/167295927 (0%)&lt;BR /&gt;*********************************************************************&lt;/P&gt;&lt;P&gt;[Expert@Firewall-1:0]# fw ctl multik stat&lt;BR /&gt;ID | Active | CPU | Connections | Peak&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;0 | Yes | 1 | 823 | 11716&lt;BR /&gt;1 | Yes | 0 | 766 | 11359&lt;/P&gt;&lt;P&gt;*********************************************************************&lt;/P&gt;&lt;P&gt;[Expert@Firewall-1:0]# free -m&lt;BR /&gt;total used free shared buffers cached&lt;BR /&gt;Mem: 7744 7160 584 0 449 3521&lt;BR /&gt;-/+ buffers/cache: 3188 4555&lt;BR /&gt;Swap: 18394 19 18375&lt;/P&gt;&lt;P&gt;*********************************************************************&lt;/P&gt;&lt;P&gt;[Expert@Firewall-2]# fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 0/32 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 0/2924244 (0%)&lt;BR /&gt;F2Fed pkts/Total pkts : 2924244/2924244 (100%)&lt;BR /&gt;PXL pkts/Total pkts : 0/2924244 (0%)&lt;BR /&gt;QXL pkts/Total pkts : 0/2924244 (0%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2019 17:23:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61664#M12413</guid>
      <dc:creator>Zia</dc:creator>
      <dc:date>2019-09-02T17:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Performance issues : Loss of packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61665#M12414</link>
      <description>I think the output of the "Super Seven" commands would be helpful.&lt;BR /&gt;See: &lt;A href="https://community.checkpoint.com/t5/General-Topics/Super-Seven-Performance-Assessment-Commands-s7pac/m-p/40528" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Super-Seven-Performance-Assessment-Commands-s7pac/m-p/40528&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;With most of your traffic hitting PXL (expected because of App Control, IPS, and Anti-Bot being active), some policy optimization may be required.</description>
      <pubDate>Mon, 02 Sep 2019 17:46:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61665#M12414</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-02T17:46:01Z</dc:date>
    </item>
    <item>
      <title>Re: Performance issues : Loss of packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61668#M12415</link>
      <description>&lt;P&gt;according to your fw ctl multik stat you have only 2 FW instances, can you increase it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2019 18:43:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61668#M12415</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2019-09-02T18:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Performance issues : Loss of packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61674#M12416</link>
      <description>&lt;P&gt;Need to see the "Super Seven" outputs as Dameon suggested, especially &lt;STRONG&gt;netstat -ni;&amp;nbsp;&lt;/STRONG&gt;my guess is your packet loss can be attributed to RX-DRPs. Also please identify which interface name is used for cluster sync.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The 5400 is a 2-core system which puts it between a rock and a hard place to some degree, the only possible CoreXL adjustment is to disable it thus producing a 1/1 split of SND/IRQ cores vs. Firewall Worker cores as opposed to your current default 2/2 split which causes cache thrashing on the cores under load due to overlapping functions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2019 19:35:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61674#M12416</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-09-02T19:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Performance issues : Loss of packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61679#M12417</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/33847"&gt;@Zia&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Could you see RX errors?&lt;/P&gt;
&lt;P&gt;# netstat -in&lt;BR /&gt;&lt;BR /&gt;Could you see CPU performance issues (software interruts or hw interrupts)?&lt;/P&gt;
&lt;P&gt;# top + key 1&lt;/P&gt;
&lt;P&gt;Which network card drivers are you use?&lt;/P&gt;
&lt;P&gt;# ethtool -i ethX&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On firewall 1 I can see 95% PXL traffic on firewall 2 I can see only 0% and heavy F2F traffic (100%). I think SecureXL is disabled on firewall 2.&amp;nbsp; Check SecureXL on FW 2.&lt;/P&gt;
&lt;P&gt;# fwaccel stat&lt;/P&gt;
&lt;P&gt;Are deamons to be visible they generating high load?&lt;/P&gt;
&lt;P&gt;# top &lt;BR /&gt;&lt;BR /&gt;(More see here: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97638&amp;amp;partition=General&amp;amp;product=All%22" target="_self"&gt; Check Point Processes and Daemons)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards &lt;BR /&gt;Heiko&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2019 20:35:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61679#M12417</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-09-02T20:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: Performance issues : Loss of packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61680#M12418</link>
      <description>&lt;P&gt;If you use R80.20+ check this:&lt;/P&gt;
&lt;P&gt;# &lt;STRONG&gt;fw ctl multik utilize&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; &amp;gt; shows the CoreXL queue utilization for each CoreXL FW instance&lt;/P&gt;
&lt;P&gt;# &lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp; &amp;gt; shows the table with heavy connections&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2019 20:41:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61680#M12418</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-09-02T20:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: Performance issues : Loss of packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61685#M12419</link>
      <description>&lt;P&gt;&amp;gt; On firewall 1 I can see 95% PXL traffic on firewall 2 I can see only 0% and heavy F2F traffic (100%). I think SecureXL is disabled on firewall 2. Check SecureXL on FW 2.&lt;/P&gt;
&lt;P&gt;Actually Heiko if Firewall-2 is the standby member in a ClusterXL HA cluster it is normal to see 100% F2F, as all traffic on that system is to and from the standby firewall itself which always goes F2F.&amp;nbsp; So SecureXL is probably enabled on Firewall-2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2019 22:43:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61685#M12419</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-09-02T22:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: Performance issues : Loss of packets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61718#M12420</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2019 10:19:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Performance-issues-Loss-of-packets/m-p/61718#M12420</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-09-03T10:19:57Z</dc:date>
    </item>
  </channel>
</rss>

