<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CoreXL SND and FW Instance for VSX in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110051#M15077</link>
    <description>&lt;P&gt;I belive you can do this by using fw ctl affinity -s&lt;/P&gt;&lt;P&gt;also remember that each VS core allocation should remain within the same CPU.&lt;/P&gt;&lt;P&gt;good command that Tim provided:&lt;/P&gt;&lt;P&gt;cat /proc/cpuinfo | awk '/processor/{c=$3} /physical id/{p=$4} /core id/{d=$4; print p,"-",d,"-",c}'| sort -k1n,1 -k3n,3 -k5n,5&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;VS1 = CPU 0, core 5,21,6,22&lt;/P&gt;</description>
    <pubDate>Sun, 07 Feb 2021 14:10:03 GMT</pubDate>
    <dc:creator>genisis__</dc:creator>
    <dc:date>2021-02-07T14:10:03Z</dc:date>
    <item>
      <title>CoreXL SND and FW Instance for VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110026#M15071</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have project to implement VSX on checkpoint 28000 (72 cpu with SMT) and I have plan to assign 20 cpu for SND and &lt;SPAN&gt;others for fw instance share to all vsx and I have question as below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1.Can I just allocate 20 cpu for SND and auto assign to all interface like non vsx gateway ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2.When I set 32 cpu for fw instance on smart console how I see what cpu number that allocate from this setting ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3.From question no.2 if I have 3 vsx all vsx will use same cpu or not ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 09:41:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110026#M15071</guid>
      <dc:creator>Kosin_Usuwanthi</dc:creator>
      <dc:date>2021-02-07T09:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: CoreXL SND and FW Instance for VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110032#M15072</link>
      <description>&lt;P&gt;If you mean can you take advantage of the dynamic spit feature, then no it's not supported in VSX mode. Please see&amp;nbsp;&lt;SPAN&gt;sk164155&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Not supported:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Check Point Appliances that run in VSX mode (regardless of the number of CPU cores), Check Point Maestro&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Sun, 07 Feb 2021 12:49:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110032#M15072</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-02-07T12:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: CoreXL SND and FW Instance for VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110045#M15075</link>
      <description>&lt;P&gt;Thank you but I'm not mean dynamic balance just like when we use cpconfig and allocate cpu fw instance and others for snd.&lt;/P&gt;&lt;P&gt;I don't want to manual assign cpu number for fw instance and snd.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 13:07:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110045#M15075</guid>
      <dc:creator>Kosin_Usuwanthi</dc:creator>
      <dc:date>2021-02-07T13:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: CoreXL SND and FW Instance for VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110051#M15077</link>
      <description>&lt;P&gt;I belive you can do this by using fw ctl affinity -s&lt;/P&gt;&lt;P&gt;also remember that each VS core allocation should remain within the same CPU.&lt;/P&gt;&lt;P&gt;good command that Tim provided:&lt;/P&gt;&lt;P&gt;cat /proc/cpuinfo | awk '/processor/{c=$3} /physical id/{p=$4} /core id/{d=$4; print p,"-",d,"-",c}'| sort -k1n,1 -k3n,3 -k5n,5&lt;/P&gt;&lt;P&gt;example:&lt;/P&gt;&lt;P&gt;VS1 = CPU 0, core 5,21,6,22&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 14:10:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110051#M15077</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-02-07T14:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: CoreXL SND and FW Instance for VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110108#M15103</link>
      <description>&lt;P&gt;I have set 32 cpu for each vsx on smart console but when I show fw ctl affinity -l it show cpu per each vsx more than 32 cpu&lt;/P&gt;&lt;P&gt;fw ctl affinity -l&lt;BR /&gt;Interface Mgmt: CPU 0&lt;BR /&gt;VS_0 fwk: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71&lt;BR /&gt;VS_1 fwk: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71&lt;BR /&gt;VS_2 fwk: CPU 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71&lt;BR /&gt;Interface eth7-01: has multi queue enabled&lt;BR /&gt;Interface eth7-02: has multi queue enabled&lt;BR /&gt;Interface eth3-01: has multi queue enabled&lt;BR /&gt;Interface eth3-02: has multi queue enabled&lt;BR /&gt;Interface eth5-01: has multi queue enabled&lt;BR /&gt;Interface eth8-07: has multi queue enabled&lt;BR /&gt;Interface eth8-08: has multi queue enabled&lt;BR /&gt;Interface eth6-01: has multi queue enabled&lt;BR /&gt;Interface Sync: has multi queue enabled&lt;BR /&gt;Interface eth5-02: has multi queue enabled&lt;BR /&gt;Interface eth6-02: has multi queue enabled&lt;BR /&gt;Interface eth1-01: has multi queue enabled&lt;BR /&gt;Interface eth6-03: has multi queue enabled&lt;BR /&gt;Interface eth1-02: has multi queue enabled&lt;BR /&gt;Interface eth6-04: has multi queue enabled&lt;BR /&gt;Interface eth2-01: has multi queue enabled&lt;BR /&gt;Interface eth2-02: has multi queue enabled&lt;BR /&gt;Interface eth2-03: has multi queue enabled&lt;BR /&gt;Interface eth2-04: has multi queue enabled&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 04:44:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110108#M15103</guid>
      <dc:creator>Kosin_Usuwanthi</dc:creator>
      <dc:date>2021-02-08T04:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: CoreXL SND and FW Instance for VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110134#M15113</link>
      <description>&lt;P&gt;I believe this is normal unless you have manually setup affinity using 'sim affinity -s'&amp;nbsp; ('ve not personally used this but I believe this is the reason why you are seeing the above output).&lt;/P&gt;&lt;P&gt;another handy command found here.&lt;/P&gt;&lt;P&gt;go into the VS:&lt;/P&gt;&lt;P&gt;top -d 1 -H -p $(pgrep fwk$(echo $INSTANCE_VSID))&lt;/P&gt;&lt;P&gt;This will show you the fwk process utilisation for this VS.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 09:11:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CoreXL-SND-and-FW-Instance-for-VSX/m-p/110134#M15113</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-02-08T09:11:18Z</dc:date>
    </item>
  </channel>
</rss>

