<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The security gateway is dropping packets due to CoreXL queue size in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-security-gateway-is-dropping-packets-due-to-CoreXL-queue/m-p/122802#M17577</link>
    <description>&lt;P&gt;Is SecureXL active? Please print the output of "fwaccel stats -s" and "fwaccel stat".&lt;BR /&gt;Did you identify the connection thats causing the load? If the load is caused by a high bandwidth trustworthy connection like storage replication or backup, you can use fast_accel to bypass fw_worker, see sk156672.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jul 2021 07:41:51 GMT</pubDate>
    <dc:creator>Benedikt_Weissl</dc:creator>
    <dc:date>2021-07-02T07:41:51Z</dc:date>
    <item>
      <title>The security gateway is dropping packets due to CoreXL queue size</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-security-gateway-is-dropping-packets-due-to-CoreXL-queue/m-p/122799#M17575</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We observed that The security gateway is dropping packets due to CoreXL queue size.&lt;/P&gt;&lt;P&gt;Some of the core only havely utilized.&lt;/P&gt;&lt;P&gt;OS : R80.30 with jumbo hotfix take_227&lt;/P&gt;&lt;P&gt;Initially we observed this issue on non production hour like on week end where we basically reboot our firewall or connected switch or other testing.&lt;/P&gt;&lt;P&gt;But now we also see this issue on the production hour.&lt;/P&gt;&lt;P&gt;I need to understand what exactly issue is.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Query&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;1. What exactly the reason even the Dynamic Dispatcher is enable and still few FW_Worker is fully utilized ?&lt;/P&gt;&lt;P&gt;2. As this issue is not on the SND level , so here FW_worker is fully utilized so we are getting packets drop so is this the first approach to fine tune the core configuration instead of increase the queue size ?&lt;/P&gt;&lt;P&gt;3. If we increased the input queue size to overcome the issue as mention on the sk61143 did the issue will resolved ?&lt;/P&gt;&lt;P&gt;4. As we know that we basically increase the buffer so is this resolve the issue or increase the latency ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="core conf.PNG" style="width: 448px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12405i7BFE10A774B1C47F/image-size/large?v=v2&amp;amp;px=999" role="button" title="core conf.PNG" alt="core conf.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Pls suggest a best suggestion to over come this issue.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 07:11:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-security-gateway-is-dropping-packets-due-to-CoreXL-queue/m-p/122799#M17575</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2021-07-02T07:11:26Z</dc:date>
    </item>
    <item>
      <title>Re: The security gateway is dropping packets due to CoreXL queue size</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-security-gateway-is-dropping-packets-due-to-CoreXL-queue/m-p/122802#M17577</link>
      <description>&lt;P&gt;Is SecureXL active? Please print the output of "fwaccel stats -s" and "fwaccel stat".&lt;BR /&gt;Did you identify the connection thats causing the load? If the load is caused by a high bandwidth trustworthy connection like storage replication or backup, you can use fast_accel to bypass fw_worker, see sk156672.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 07:41:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-security-gateway-is-dropping-packets-due-to-CoreXL-queue/m-p/122802#M17577</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-07-02T07:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: The security gateway is dropping packets due to CoreXL queue size</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-security-gateway-is-dropping-packets-due-to-CoreXL-queue/m-p/122817#M17584</link>
      <description>&lt;P&gt;An imbalance of utilization on Instances/Workers even with the Dynamic Dispatcher enabled is usually the result of elephant flows (what Check Point calls "heavy connections").&amp;nbsp; In your R80.30 release all packets of a single connection can only be processed on one Instance/Worker; later releases utilize the pipeline paths to help spread out this load.&amp;nbsp; As mentioned earlier in the thread you can fastaccel the traffic if it doesn't need to be handled in the F2F path for some reason.&amp;nbsp; This workaround and how to diagnose load imbalance problems like this are covered in my &lt;A href="https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/member-exclusives/432/3/CPX_Big_Game_Hunting_FINAL2.cleaned.pdf" target="_self"&gt;CPX 2020 speech&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Generally, increasing the buffer sizes (including CoreXL queues &amp;amp; ring buffers for NICs) is not recommended as it is only addressing a symptom of the problem and not the cause.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jul 2021 13:29:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-security-gateway-is-dropping-packets-due-to-CoreXL-queue/m-p/122817#M17584</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-07-02T13:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: The security gateway is dropping packets due to CoreXL queue size</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-security-gateway-is-dropping-packets-due-to-CoreXL-queue/m-p/152761#M25486</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp; Thanks for the details&lt;/P&gt;&lt;P&gt;Hi Tim and Checkmates Team,&lt;/P&gt;&lt;P&gt;Again we face this issue.&lt;/P&gt;&lt;DIV&gt;Compare to other days during the&amp;nbsp; mock (week end) we observed more packets drop due to the &amp;nbsp;CoreXL queue size.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;As the release of all packets of a single connection can only be processed on one Instance/Worker. Might be because of single heavy connections cause this issue.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Below update from TAC :&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;&lt;U&gt;Query:&lt;/U&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1. What exactly the reason even the Dynamic Dispatcher is enable and still few FW_Worker is fully utilized ? -&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Because of the stateful inspection&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2. As this issue is not on the SND level , so here FW_worker is fully utilized so we are getting packets drop so is this the first approach to fine tune the core configuration instead of increase the queue size ?&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;No fw_worker is not fully utilized and packet is dropped , it is the core queue which is full, I am checking and testing internally if we can increase the queue or even checking if the report is legit.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;3. If we increased the queue size to overcome the issue as mention on the SK , &amp;nbsp;did the issue will resolved ? -&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Most cases 4GB was sufficient , but in your environment you still face but known via pro report.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;4.&amp;nbsp;Is this fastaccel the traffic , if it doesn't need to be handled in the F2F path for some reason ? -&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Nothing to do with our issue , But if the traffic is not accelerate yes takes f2f path consuming massive CPU&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;As we know that , we basically by increase the buffer so is this resolve the issue or increase the latency ? -&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Resolves issue , Latency level is not extensively.&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Jul 2022 06:46:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-security-gateway-is-dropping-packets-due-to-CoreXL-queue/m-p/152761#M25486</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2022-07-12T06:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: The security gateway is dropping packets due to CoreXL queue size</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-security-gateway-is-dropping-packets-due-to-CoreXL-queue/m-p/154291#M26118</link>
      <description>&lt;P&gt;Will need to see outputs of &lt;STRONG&gt;enabled_blades&lt;/STRONG&gt; and the &lt;A href="https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/m-p/40528" target="_self"&gt;Super Seven&lt;/A&gt; to assess further.&amp;nbsp; It is rather unusual to be dropping traffic in the CoreXL queues without issues occurring elsewhere in the firewall at the same time.&amp;nbsp; If we confirm large amounts of F2F I will share some debugging commands that can be used to determine why the traffic is going F2F as there can be many causes.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2022 19:11:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/The-security-gateway-is-dropping-packets-due-to-CoreXL-queue/m-p/154291#M26118</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-08-01T19:11:13Z</dc:date>
    </item>
  </channel>
</rss>

