<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CPview and VSX - Analyse CPU Load per Instance per connection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121355#M17263</link>
    <description>&lt;P&gt;Thanks for that interesting read. However please note that I'm referring to the Top-protocols and Top-connections within the &lt;STRONG&gt;CPU&lt;/STRONG&gt; tab not the &lt;STRONG&gt;network&lt;/STRONG&gt; tab. We really want to have the column "% out of CPU" as you can see in my initial screenshot.&lt;/P&gt;&lt;P&gt;We are also going to &lt;STRONG&gt;R80.30&lt;/STRONG&gt; for all our VSX clusters.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jun 2021 12:03:52 GMT</pubDate>
    <dc:creator>Vincent_Croes</dc:creator>
    <dc:date>2021-06-16T12:03:52Z</dc:date>
    <item>
      <title>CPview and VSX - Analyse CPU Load per Instance per connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121338#M17260</link>
      <description>&lt;P&gt;Checkmates&lt;/P&gt;&lt;P&gt;Why is it that on VSX, we receive less functionality when using CPview? More specific: on regular gateways, we can analyze the CPU load per instance and view the top connection or top service that goes along with it.&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="instance_load.png" style="width: 724px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12198iD68E3648CDA2E647/image-size/large?v=v2&amp;amp;px=999" role="button" title="instance_load.png" alt="instance_load.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'm sure that the architecture behind VSX mode is not quite the same as a regular gateway and poses a different set of challenges but this screenshot is from a R80.10 gateway and yet to my knowledge this feature is still not implemented in VSX on R81. Is this not incredible useful?&lt;/P&gt;&lt;P&gt;I have checked with TAC &amp;amp; my local office, I also checked the support center but no-one can give me a proper tool to investigate CPU load in correlation with a specific connection. Also I requested an improvement via a form on the CP website but that seems to end up in someone spam folder.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 09:40:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121338#M17260</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-06-16T09:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: CPview and VSX - Analyse CPU Load per Instance per connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121354#M17262</link>
      <description>&lt;P&gt;The functionality difference stems from the traditional kernel space mode for INSPECT vs. process space mode (fwk processes - called User Space Firewall).&amp;nbsp; VSX has always used fwk processes to implement INSPECT and now the newer mainline gateways (including Quantums) are using USFW by default.&amp;nbsp; Some of the feature differences between VSX/USFW and kernel mode got called out in &lt;A href="https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/member-exclusives/432/3/CPX_Big_Game_Hunting_FINAL2.cleaned.pdf" target="_self"&gt;my CPX 2020 speech&lt;/A&gt;, and since then the feature gap has almost been completely closed by R&amp;amp;D.&amp;nbsp; Future development is likely to use USFW everywhere, so now we are starting to see some new features available exclusively in USFW mode but not kernel mode.&lt;/P&gt;
&lt;P&gt;As far as the &lt;STRONG&gt;cpview&lt;/STRONG&gt; screens you are missing you can get them back with the proper version/Jumbo HFA and by setting kernel variables&amp;nbsp;sim_top_conns_enable=1 &amp;amp; sim_top_proto_enable=1 as mentioned here:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167903&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;sk167903: CPview Top Connections and Protocols tabs show no data&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Those screens are not available at all for VSX R80.10 and earlier due to the older implementation of SecureXL in that version.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 11:52:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121354#M17262</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-06-16T11:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: CPview and VSX - Analyse CPU Load per Instance per connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121355#M17263</link>
      <description>&lt;P&gt;Thanks for that interesting read. However please note that I'm referring to the Top-protocols and Top-connections within the &lt;STRONG&gt;CPU&lt;/STRONG&gt; tab not the &lt;STRONG&gt;network&lt;/STRONG&gt; tab. We really want to have the column "% out of CPU" as you can see in my initial screenshot.&lt;/P&gt;&lt;P&gt;We are also going to &lt;STRONG&gt;R80.30&lt;/STRONG&gt; for all our VSX clusters.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 12:03:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121355#M17263</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-06-16T12:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: CPview and VSX - Analyse CPU Load per Instance per connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121358#M17265</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;You can use CPView today on VSX. But it is per VS, And the amount of statistics is currently very limited. Unfortunately, there is currently no way to monitor the statistics of the whole VSX appliance. There is a tab that’s collecting the information from all VSs and is storing them in one place. the new tab can be seen in the VS0 context only.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 12:34:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121358#M17265</guid>
      <dc:creator>Elad_Chomsky</dc:creator>
      <dc:date>2021-06-16T12:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: CPview and VSX - Analyse CPU Load per Instance per connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121365#M17266</link>
      <description>&lt;P&gt;Is there a way to request an improvement of this functionality? Or do you know if something is in the works?&lt;/P&gt;&lt;P&gt;Currently we are stuck troubleshooting high CPU load on FWK instances and we have no clue what is causing it. Involving TAC each issue is very time consuming especially when the problem is not always present.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 13:10:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121365#M17266</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-06-16T13:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: CPview and VSX - Analyse CPU Load per Instance per connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121423#M17276</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I will pass your request to the relevant R&amp;amp;D owners, and they will try to incorporate it into their plans. Meanwhile, regarding your issue, please try to see if one of the following is giving you the info:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;‘vsx stat –v’&lt;/LI&gt;
&lt;LI&gt;fw ctl pstat&lt;/LI&gt;
&lt;LI&gt;vsx resctrl stat&lt;/LI&gt;
&lt;LI&gt;vsx mstat&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 17 Jun 2021 07:00:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121423#M17276</guid>
      <dc:creator>Elad_Chomsky</dc:creator>
      <dc:date>2021-06-17T07:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: CPview and VSX - Analyse CPU Load per Instance per connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121429#M17277</link>
      <description>&lt;P&gt;Thank you, that is appreciated. In regards to the commands, those are known by us and do not give good insight on which flows are triggering more CPU usage. We are quite capable of finding out that something is wrong but drilling down to what exactly and being able to report this to our customer is a different story, hence my feature request.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 08:01:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CPview-and-VSX-Analyse-CPU-Load-per-Instance-per-connection/m-p/121429#M17277</guid>
      <dc:creator>Vincent_Croes</dc:creator>
      <dc:date>2021-06-17T08:01:11Z</dc:date>
    </item>
  </channel>
</rss>

