<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Slow HTTP connection is eating 80-90% of CPU core in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-HTTP-connection-is-eating-80-90-of-CPU-core/m-p/117893#M16682</link>
    <description>&lt;P&gt;Hello mates,&lt;/P&gt;&lt;P&gt;I have an issue with some FW overloads, while not so much traffic and connections are passing trough.&lt;/P&gt;&lt;P&gt;We have identified several heavy connections coming from S2S VPN taking about 80 % of a CPU core.&lt;BR /&gt;After some analysis with tcpdump/wireshark it appears that this connection bandwidth is about 162kbit/s for about 10 min capture (7mb file).&lt;BR /&gt;This is pretty slow connection for me, but is eating a lot of resources.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Devices are powerful enough - Supermicro equivalent of CP 5900, three devices with R80.30 running in a HA Cluster.&lt;BR /&gt;About 300Mb/s overall bandwidth and 65k connections according to CPview. TP blades are activated with IA and AppCtrl. (no HTTPS inspection)&lt;/P&gt;&lt;P&gt;Could you give me some hints how to find out if this connection is accelerated or is passing through F2F path.&lt;/P&gt;&lt;P&gt;Also tried to add to fast_accel table, but there are no hits and suppose traffic from VPN cannot be passed to fast_accel.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 07 May 2021 07:09:38 GMT</pubDate>
    <dc:creator>Dilian_Chernev</dc:creator>
    <dc:date>2021-05-07T07:09:38Z</dc:date>
    <item>
      <title>Slow HTTP connection is eating 80-90% of CPU core</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-HTTP-connection-is-eating-80-90-of-CPU-core/m-p/117893#M16682</link>
      <description>&lt;P&gt;Hello mates,&lt;/P&gt;&lt;P&gt;I have an issue with some FW overloads, while not so much traffic and connections are passing trough.&lt;/P&gt;&lt;P&gt;We have identified several heavy connections coming from S2S VPN taking about 80 % of a CPU core.&lt;BR /&gt;After some analysis with tcpdump/wireshark it appears that this connection bandwidth is about 162kbit/s for about 10 min capture (7mb file).&lt;BR /&gt;This is pretty slow connection for me, but is eating a lot of resources.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Devices are powerful enough - Supermicro equivalent of CP 5900, three devices with R80.30 running in a HA Cluster.&lt;BR /&gt;About 300Mb/s overall bandwidth and 65k connections according to CPview. TP blades are activated with IA and AppCtrl. (no HTTPS inspection)&lt;/P&gt;&lt;P&gt;Could you give me some hints how to find out if this connection is accelerated or is passing through F2F path.&lt;/P&gt;&lt;P&gt;Also tried to add to fast_accel table, but there are no hits and suppose traffic from VPN cannot be passed to fast_accel.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 07:09:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-HTTP-connection-is-eating-80-90-of-CPU-core/m-p/117893#M16682</guid>
      <dc:creator>Dilian_Chernev</dc:creator>
      <dc:date>2021-05-07T07:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Slow HTTP connection is eating 80-90% of CPU core</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-HTTP-connection-is-eating-80-90-of-CPU-core/m-p/117904#M16684</link>
      <description>&lt;P&gt;You could try to look at the output of "fwaccel conns" (&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_PerformanceTuning_AdminGuide/Content/Topics-PTG/CLI/fwaccel-conns.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_PerformanceTuning_AdminGuide/Content/Topics-PTG/CLI/fwaccel-conns.htm&lt;/A&gt;). Its really strange a single connection is using so much CPU time, maybe something else contributes to the problem? VPN Encryption like 3DES or a custom application with a complex regex maybe?&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 08:35:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-HTTP-connection-is-eating-80-90-of-CPU-core/m-p/117904#M16684</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-05-07T08:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: Slow HTTP connection is eating 80-90% of CPU core</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-HTTP-connection-is-eating-80-90-of-CPU-core/m-p/117969#M16690</link>
      <description>&lt;P&gt;In R80.30 all connections except those that are F2F should show up in the output of &lt;STRONG&gt;fwaccel conns&lt;/STRONG&gt;.&amp;nbsp; The only official way to see F2F connections is &lt;STRONG&gt;fw ctl multik gconn&lt;/STRONG&gt;, although there is the undocumented&lt;STRONG&gt;&amp;nbsp;fw_mux all&lt;/STRONG&gt; command which will show you the state of all connections regardless of acceleration status as it relates to the multiplexing of a stream across multiple worker cores.&amp;nbsp; See here:&lt;/P&gt;
&lt;H2 class="message-subject"&gt;&lt;SPAN class="lia-message-unread lia-message-unread-windows"&gt;&lt;A id="link_16" class="page-link lia-link-navigation lia-custom-event" href="https://community.checkpoint.com/t5/Security-Gateways/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/105183?search-action-id=25134144699&amp;amp;search-result-uid=105183" target="_blank"&gt;&lt;SPAN class="lia-search-match-lithium"&gt;fw&lt;/SPAN&gt; ctl fast_accel - some traffic still going slow&lt;/A&gt;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 May 2021 13:37:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-HTTP-connection-is-eating-80-90-of-CPU-core/m-p/117969#M16690</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-05-08T13:37:38Z</dc:date>
    </item>
  </channel>
</rss>

