<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81 VSX in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/110082#M15091</link>
    <description>&lt;P&gt;We are planning to support Dynamic Split in VSX in a future version, as far as I know.&lt;/P&gt;</description>
    <pubDate>Sun, 07 Feb 2021 21:50:53 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-02-07T21:50:53Z</dc:date>
    <item>
      <title>R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/106569#M8616</link>
      <description>&lt;P&gt;I was wondering if anyone has actually deployed R81 in a VSX setup yet and if this has any&amp;nbsp; reported issues?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking to upgrade my R80.20 VSX setup to R80.40 or R81, would like to move to R81 but I think it may be a little too early for this.&lt;/P&gt;&lt;P&gt;Also I know the recommendation is to rebuild, but in the current climate remote upgrade is preferred method.&amp;nbsp; So I will likely do an inline upgrade; from what I can tell kernel version would get upgraded, multi-queue turned on and other parameters turned on by default such are CORE load balancing parameter (SK168513).&lt;/P&gt;&lt;P&gt;Clearly new filesystem would not get used, but I don't see this being hugely important at the gateway side (happy to be educated on this if I'm wrong).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 17:00:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/106569#M8616</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2020-12-29T17:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/106571#M8617</link>
      <description>&lt;P&gt;I have a large VSX on R80.30 3.10 environment and my plan is to upgrade management to R81 when the first HF is GA and the VSX to R80.40 after NY.&lt;/P&gt;&lt;P&gt;When it comes to VSX, I prefer to have a few levels of HF after the version becomes widely recommended, but I suppose it depends of your environment's complexity and the features you need.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 17:26:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/106571#M8617</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2020-12-29T17:26:02Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/106582#M8618</link>
      <description>&lt;P&gt;I do agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;here, when it comes to VSX i would wait a few HFA, normally i do wait for HFA above 100 for VSX.&lt;BR /&gt;Regarding R80.20 personally i think thats a pretty bad release and i would upgrade more or less directly after the holidays to an R80.30 3.10 or R80.40 (if needed)&lt;BR /&gt;&lt;BR /&gt;As far as we are told from our ATAM and PS we have worked with, filesystem on gateway side dosn´t really matter.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Magnus&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 20:06:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/106582#M8618</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2020-12-29T20:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/106591#M8619</link>
      <description>&lt;P&gt;thanks guys, this pretty much falls in line with what I was thinking.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Dec 2020 23:15:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/106591#M8619</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2020-12-29T23:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109853#M15005</link>
      <description>&lt;P&gt;Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note there is a bug in R80.40, related to logical interfaces not moving from VS0 to the relevant VS.&amp;nbsp; This apparently is a change in kernel 3.10.&amp;nbsp; Checkpoint have a fix (goes on top of Take_91).&amp;nbsp; I believe the fix is going to get integrated into a Jumbo.&lt;/P&gt;&lt;P&gt;The issue experienced is in-complete macs when reviewing the arp table on the VS's.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2021 21:43:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109853#M15005</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-02-04T21:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109888#M15019</link>
      <description>&lt;P&gt;Do you have more information about what happens and in which conditions? I'm using R80.40 VSX Take 89 at a customer (plan to go to T91 in the coming days) and didn't get that kind of issue, at least that I know of.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 09:28:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109888#M15019</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2021-02-05T09:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109890#M15020</link>
      <description>&lt;P&gt;If your already on R80.40 then I don't believe the issue is seen as you would already be running kernel version 3.10.&amp;nbsp; The issue seems to appear when moving from kernel version 2.9.18 to 3.10.&lt;/P&gt;&lt;P&gt;The upgrade process went fine, no errors (and Checkpoint where involved) however when we came to do testing, we noticed a number of connectivity issues; after investigation we determined that a number of logical interfaces where not seeing mac addresses.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TAC where not able to resolve this so information was gathered and we had to do a full roll back (Checkpoint seriously need to look into supporting the command 'vsx_util downgrade' option as well).&lt;/P&gt;&lt;P&gt;TAC then engaged R&amp;amp;D who investigated the debug files and determined an issue which was a bug, as a result a hotfix has been generated.&lt;/P&gt;&lt;P&gt;We are re-attempting this week, but we are going to do a clean build rather the in-place upgrade.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 09:40:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109890#M15020</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-02-05T09:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109893#M15022</link>
      <description>&lt;P&gt;Hi Alex,&lt;/P&gt;
&lt;P&gt;sk171753 is something to be aware of if using Virtual Switches / Routers.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 10:04:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109893#M15022</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-02-05T10:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109894#M15023</link>
      <description>&lt;P&gt;Alex separate question and perhaps we can take it offline if required, but what the performance like?&amp;nbsp; One of the reason for moving from R80.20 to R80.40 is to see if our overall performance issues are improved.&lt;/P&gt;&lt;P&gt;We have 15600 (rated to handle 10Gbps with 10 VS's according to the sizing tool) appliances and a total throughput of about 2.5Gbps, fwaccel reports majority of the traffic is being accelerated, but out overall CPU is really high compared to the about of throughput going through the appliances.&lt;/P&gt;&lt;P&gt;We have actually had to split the load across the two nodes because we start getting latency issue when everything is running on one node.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 09:50:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109894#M15023</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-02-05T09:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109895#M15024</link>
      <description>&lt;P&gt;Support for 'vsx_util downgrade' was introduced coinciding with the release of R81.&lt;/P&gt;
&lt;P&gt;It's now also more widely supported as I understand per sk166053&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 09:53:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109895#M15024</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-02-05T09:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109896#M15025</link>
      <description>&lt;P&gt;Obviously there are many factors into play when comparing performance, I'm using 16200 appliances (48 cores, 64GB RAM), if I recall correctly the 15000 series have 8 cores so 16 in HT and 8/16GB RAM?&lt;/P&gt;&lt;P&gt;With a mix of 10/40 GB adapters and SND set to 8 instead of the default 4 (CP recommendation), everything runs fine with the latest HF in terms of pure performance with a mix of VS running different blades. Even though the customer is doing gradual migration of their network to full segmentation behind this cluster, I don't see performance issues arising.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 10:20:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109896#M15025</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2021-02-05T10:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109909#M15027</link>
      <description>&lt;P&gt;15600 appliance has x2 CPUs&amp;nbsp; (16 cores each) so a total core count with HT of 32.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We current have the default 4 cores for SND and there is nothing to suggest these are even breaking a sweat (using some of Tim's handy advise to check things)&lt;/P&gt;&lt;P&gt;We have one node running one VS running FW/IPS blades only (We did have AV/ABOT turned on but this started causing perfomance issues).&amp;nbsp; The concurrent connections on this is around 250K. I've allocated 12 cores to this.&lt;/P&gt;&lt;P&gt;attached is a screenshot of the CPU usage.&amp;nbsp; Considering all of the above I would expect 4 cores max needed for this, and the total percentage utilisation to be below 20%.&lt;/P&gt;&lt;P&gt;Also note that the SND core utilisation is in the 10% and below section of the screenshot.&lt;/P&gt;&lt;P&gt;The other node is running the rest of the VS's&amp;nbsp; (5 VSs) and has a throughput level of about 1.5 - 2Gbps, and CORE utilisation, however concurrent connections are lower.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 11:59:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109909#M15027</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-02-05T11:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109910#M15028</link>
      <description>&lt;P&gt;Was this upgrade in-place from an earlier version, is dynamic dispatcher enabled?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 11:59:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109910#M15028</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-02-05T11:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109911#M15029</link>
      <description>&lt;P&gt;Clean build of R80.10 &amp;gt; In-place upgrade to R80.20, and dispatched is enabled with the specific kernel parameters enabled in the fwkern.conf file.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 12:01:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109911#M15029</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-02-05T12:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109912#M15030</link>
      <description>&lt;P&gt;This is dame handy to know!&amp;nbsp; But we where seeing the interfaces;&amp;nbsp; This said the the date of creation and update sounds like this could have been created as a result of our issue.&lt;/P&gt;&lt;P&gt;I confirmed with TAC that this was indeed created as a result of the issue we faced.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 19:04:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109912#M15030</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-02-07T19:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109922#M15035</link>
      <description>&lt;P&gt;Awesome! Finally&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 14:00:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/109922#M15035</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-02-05T14:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/110065#M15085</link>
      <description>&lt;P&gt;We have now completed the build to R80.40 with JHFA91 and specific fix related to SK&lt;SPAN&gt;171753.&amp;nbsp; We did try to allocate more SNDs&amp;nbsp; (total of 6 cores) but the system did not report the correct number of SNDs.&amp;nbsp; TAC are suspecting another bug, but this may be cosmetic - still under investigation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also I did not realize&amp;nbsp;that in order to increase the SNDs COREXL must be enabled in VS0,&amp;nbsp; if you disable this it reverted back to the default of 4 cores.&amp;nbsp; &amp;nbsp;I though you should always disable COREXL on VS0.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Would be nice if Dynamic split was supported in VSX, in this way we would not have to think about this.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 19:11:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/110065#M15085</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-02-07T19:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/110072#M15088</link>
      <description>&lt;P&gt;How did you increase your SND? I did it with affinity commands and never had to enable CoreXL on VS0.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 19:41:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/110072#M15088</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2021-02-07T19:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/110082#M15091</link>
      <description>&lt;P&gt;We are planning to support Dynamic Split in VSX in a future version, as far as I know.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Feb 2021 21:50:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/110082#M15091</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-07T21:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: R81 VSX</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/110129#M15109</link>
      <description>&lt;P&gt;Correct, VSX will be supported in the upcoming R81/R80.40 JHFs.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 08:54:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-VSX/m-p/110129#M15109</guid>
      <dc:creator>AmitShmuel</dc:creator>
      <dc:date>2021-02-08T08:54:28Z</dc:date>
    </item>
  </channel>
</rss>

