<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange ( periodic ) packet loss in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138673#M21085</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1629"&gt;@EVSolovyev&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have or had a SR opened with Check Point support on this issue by any chance? If so, can you reply to me with the SR#?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Dolev&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jan 2022 18:22:07 GMT</pubDate>
    <dc:creator>Dolev</dc:creator>
    <dc:date>2022-01-17T18:22:07Z</dc:date>
    <item>
      <title>Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138428#M20999</link>
      <description>&lt;P&gt;Good afternoon.&lt;/P&gt;&lt;P&gt;We have a cluster (HA) of 15600 with R80.40 actual JHF. Faced with a problem - some time after restarting the active node, starts losing packets. I.e. everything is working fine, then suddenly a couple (usually 2) packets are lost. Rebooting the active device - the problem goes away for a while, but then comes back.&lt;/P&gt;&lt;P&gt;Our scheme - the CP cluster by 10 Gb SFP+ port on interface card is connected to the core switch, from which VLANs are going through a large multi-storey building. The gateway for all is the CP.&lt;/P&gt;&lt;P&gt;Looked for errors on the CP port toward the switch - no errors. Decided to find a new little switch and try to connect a test segment of users through it for test (now serching for witch). fw ctl zdebug drop show nothing.... While we are looking for a switch, maybe you can offer some ideas on debugging, please.&lt;/P&gt;&lt;P&gt;On screen we pings gateway for this net (on on CP's VLAN port) and google DNS server.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-14_102343.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14884iA0A9E9E42E263CD0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-14_102343.png" alt="2022-01-14_102343.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 07:47:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138428#M20999</guid>
      <dc:creator>EVSolovyev</dc:creator>
      <dc:date>2022-01-14T07:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138434#M21004</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1629"&gt;@EVSolovyev&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I would check the following:&lt;BR /&gt;1) Is your internet connection ok before the firewall?&lt;BR /&gt;2) Check if you have errors on the interfaces (RX-OVR, RX-ERR, RX-DRP)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # netstat -in&lt;BR /&gt;3) Is multi queueing enabled for the 10G interface?&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # mq_mng --show&amp;nbsp; -v&lt;BR /&gt;4) You can see a high utilisation of the software interrupts (si) in the SecureXL instances.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # fw ctl affinity -l&amp;nbsp; -&amp;gt; Check which cores are used for SecureXL (Interfaces)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # top + 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;gt; View the cores of the SecureXL instances&lt;BR /&gt;5) Running "show asset" command returns "Line Card Type: N/A" rather than properly identifying an installed 4 Port 10GBase-F SFP+&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; show asset&lt;BR /&gt;6) Do you see any interface errors in the file &lt;EM&gt;/var/log/messages&lt;BR /&gt;&lt;/EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cat &lt;EM&gt;/var/log/messages&lt;/EM&gt; | grep "NETDEV"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 08:48:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138434#M21004</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-01-14T08:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138438#M21005</link>
      <description>&lt;P&gt;Are these VSX appliances using virtual switches?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 09:10:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138438#M21005</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-01-14T09:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138440#M21006</link>
      <description>&lt;P&gt;VSX is disabled and not used.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 09:14:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138440#M21006</guid>
      <dc:creator>EVSolovyev</dc:creator>
      <dc:date>2022-01-14T09:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138442#M21007</link>
      <description>&lt;P&gt;ok thanks, I have a similar issue with VSX and VSWs, but as your not running VSX no point in bring this to the table.&lt;/P&gt;
&lt;P&gt;Can you confirm what jump your running?&amp;nbsp; I would ensure your running at least JHFA125 (GA is JHFA139)&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 09:31:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138442#M21007</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-01-14T09:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138448#M21008</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-14_135716.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14889i6A5FC75A124FB9EE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-14_135716.png" alt="2022-01-14_135716.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 10:57:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138448#M21008</guid>
      <dc:creator>EVSolovyev</dc:creator>
      <dc:date>2022-01-14T10:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138451#M21009</link>
      <description>&lt;P&gt;looks ok to me, I know we had issues with DNS packets and soon as we updated to that Jumbo issue was resolved.&lt;/P&gt;
&lt;P&gt;can you also confirm no debugging is running 'fw ctl debug 0'.&amp;nbsp; So we ensure its not a resource issues because of that.&lt;/P&gt;
&lt;P&gt;Additionally silly checks like duplex settings&lt;/P&gt;
&lt;P&gt;run this:&lt;/P&gt;
&lt;P&gt;ifconfig -a | grep encap | awk '{print $1}' | grep -v lo | grep -v bond | grep -v ":" | grep -v ^lo | xargs -I % sh -c 'ethtool %; ethtool -i %' | grep '^driver\|Speed\|Duplex\|Setting' | sed "s/^/ /g" | tr -d "\t" | tr -d "\n" | sed "s/Settings for/\nSettings for/g" | awk '{print $5 " "$7 "\t " $9 "\t" $3}' | grep -v "Unknown" | grep -v "\."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and of course what Heiko has suggested to check.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 11:24:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138451#M21009</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-01-14T11:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138457#M21010</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hello, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Thank you for the detailed answer.&lt;/P&gt;&lt;P&gt;1. I think, internet connected well - at this moment I see no droped packet to internet (ping about 2k packets).&lt;BR /&gt;2. There is no errors, but I see drops:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-14_141751.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14890i6EE59DBA53379A40/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-14_141751.png" alt="2022-01-14_141751.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;3. M&lt;SPAN&gt;ulti queueing enabled&amp;nbsp;on 4 cores:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-14_142111.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14891iE4FCD32EBA00DC34/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-14_142111.png" alt="2022-01-14_142111.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;4. In some times I see full utilization on some cores. But this is a rare occurrence and I have not yet been able to catch the process that does this. I think that fw_worker.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-14_142803.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14892iA528B00DF39A7E47/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-14_142803.png" alt="2022-01-14_142803.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-14_143014.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14893i5FE33DA9296D9401/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-14_143014.png" alt="2022-01-14_143014.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;5. No, all is good:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-14_143532.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14894i46E1AF27417E257E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-14_143532.png" alt="2022-01-14_143532.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;6. No, there is nothing....:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-14_143749.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14895i9073B5F71014A0DC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-14_143749.png" alt="2022-01-14_143749.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But....:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="photo_2022-01-13_18-43-48.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14896i90C1265C2F873531/image-size/medium?v=v2&amp;amp;px=400" role="button" title="photo_2022-01-13_18-43-48.jpg" alt="photo_2022-01-13_18-43-48.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What it can be?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 11:39:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138457#M21010</guid>
      <dc:creator>EVSolovyev</dc:creator>
      <dc:date>2022-01-14T11:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138458#M21011</link>
      <description>&lt;P&gt;You mention it happens on the active device. Is it always the same device displaying this behavior, or does it happen on whatever machine becomes active after reboot?&lt;/P&gt;&lt;P&gt;In addition to all what was explained here, you might want to do a failover and run the hardware diagnostics tool during a maintenance window. It could indicate if it's an issue with your NIC's.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 11:58:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138458#M21011</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2022-01-14T11:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138460#M21012</link>
      <description>&lt;P&gt;Duplex - first thing, that was checked. ) I see no CPU utilization.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-14_150442.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14897iE45A933B2786F89D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-14_150442.png" alt="2022-01-14_150442.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 12:06:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138460#M21012</guid>
      <dc:creator>EVSolovyev</dc:creator>
      <dc:date>2022-01-14T12:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138461#M21013</link>
      <description>&lt;P&gt;It happen on whatever machine becomes active after reboot, but not immediately - after some time. May be some hours, or days. In CP cluster we have 2 devices, but core switch is a single device with multiple line cards.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 12:11:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138461#M21013</guid>
      <dc:creator>EVSolovyev</dc:creator>
      <dc:date>2022-01-14T12:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138462#M21014</link>
      <description>&lt;P&gt;I have similar issues where after a reboot I get packet loss after about 4 weeks, but this is on a VSX system and R&amp;amp;D have confirmed a bug.&lt;/P&gt;
&lt;P&gt;You may want to log a TAC case, just in case its a bug; additionally perhaps installed the latest GA Jumbo as TAC will likely ask for this to be done.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 12:15:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138462#M21014</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-01-14T12:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138464#M21015</link>
      <description>&lt;P&gt;It can be seen that the RX-DRP are high. If the errors continue to increase means that the SNDs can no longer handle the traffic.&lt;BR /&gt;I would give the system more SND cores in the first step change from 4 to 6 cores. Thus, more cores should also be used for multi queueing. Thus, more cores should also be used for multi queueing.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 12:56:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138464#M21015</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-01-14T12:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138469#M21017</link>
      <description>&lt;P&gt;I agree with that, we increased our SND allocation to 6 cores; and we are running 15600s as well.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 13:23:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138469#M21017</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-01-14T13:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138483#M21025</link>
      <description>&lt;P&gt;First off you need to make sure your cluster is stable, as losing 2 ping packets in a row will generally happen when there is a non-graceful failover between members.&amp;nbsp; What is the failover count shown by &lt;STRONG&gt;cphaprob state&lt;/STRONG&gt; from expert mode?&lt;/P&gt;
&lt;P&gt;RX-DRPs could be the source of the drops, but those could also be non-IPv4 packets hitting the interface and getting dropped.&amp;nbsp; Please provide updated output of &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt; along with &lt;STRONG&gt;ethtool -S eth3&lt;/STRONG&gt; so we can distinguish between ring buffer drops and unknown protocol drops.&amp;nbsp; Based on the fact you are getting them on all interfaces they are probably unknown protocol drops.&amp;nbsp; If they are actually ring buffer drops you can look at the history of when that counter is getting incremented with &lt;STRONG&gt;sar -n EDEV&lt;/STRONG&gt; to see if it is slowly incrementing, or coming in clumps when you are experiencing the loss.&lt;/P&gt;
&lt;P&gt;The high CPU utilization on some workers could be caused by elephant flows, and any "mice" trapped on that worker core with an elephant flow will be degraded and possibly lose packets.&amp;nbsp; Any elephant flows in the last 24 hours reported by running&amp;nbsp;&lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt;?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 14:59:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138483#M21025</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-01-14T14:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138494#M21029</link>
      <description>&lt;P&gt;I'm sorry, but I don't understand&amp;nbsp;your advice.... My SND configuration:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-14_204813.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14899i51A6F5E41B22C85F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-14_204813.png" alt="2022-01-14_204813.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_PerformanceTuning_AdminGuide/Content/Topics-PTG/CoreXL-Allocating-Additional-CPU-Cores-to-CoreXL-SND.htm" target="_self"&gt;Here&lt;/A&gt;&amp;nbsp;we can see:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Best Practice&lt;/SPAN&gt;&amp;nbsp;- We recommend to allocate an additional CPU core to the CoreXL SND only if&amp;nbsp;&lt;EM&gt;all&lt;/EM&gt;&amp;nbsp;these conditions are met:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;There are at least 8 processing CPU cores.&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;In the output of the&amp;nbsp;top&amp;nbsp;command, the&amp;nbsp;idle&amp;nbsp;values for the CPU cores that run the CoreXL SND instances are in the 0%-5% range.&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;In the output of the&amp;nbsp;top&amp;nbsp;command, the sum of the&amp;nbsp;idle&amp;nbsp;values for the CPU cores that run the CoreXL&amp;nbsp;&lt;SPAN class=""&gt;Firewall&lt;/SPAN&gt;&amp;nbsp;instances is significantly higher than 100%.&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;If at least one of the above conditions is not met, the default CoreXL configuration is sufficient.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Whan I see cpview for CPU (screens are upper), I see, that about 100% utilization CPUs are mapped for fw_workers. I see never 100% utilization of SND cores.&lt;/P&gt;&lt;P&gt;And I'm sorry, but I can't understand, how to add 2 cores from fw to SND....&amp;nbsp; Am I need to decrease number of fw_workers in cpconfog only and free cores are automatically were added to SND after rebooting? Or to increase the number of SND cores I need to go some other way, which I have not yet been able to find?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jan 2022 17:51:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138494#M21029</guid>
      <dc:creator>EVSolovyev</dc:creator>
      <dc:date>2022-01-14T17:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138612#M21056</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for answer.&lt;/P&gt;&lt;P&gt;Yes, cluster is stable.&amp;nbsp;"&lt;SPAN&gt;What is the failover count shown by&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;cphaprob state&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;from expert mode?&lt;/SPAN&gt;" Info is here. 15 failovers is due to collegues rebooting the active device when losses start to occur. Reboot solves the problem for a few days.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-17_141618.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14913i055F7D2084444F5B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-17_141618.png" alt="2022-01-17_141618.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-17_142206.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14914iBA0FCE9B9CDDFBE8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-17_142206.png" alt="2022-01-17_142206.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-17_142832.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14915iB11522300E01BDE3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-17_142832.png" alt="2022-01-17_142832.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Yes, sometime we have a big traffic connections:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-01-17_143040.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14916iB7F5BF6B43B58F82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2022-01-17_143040.png" alt="2022-01-17_143040.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 11:34:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138612#M21056</guid>
      <dc:creator>EVSolovyev</dc:creator>
      <dc:date>2022-01-17T11:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138628#M21063</link>
      <description>&lt;P&gt;The constant rate of RX-DRP reported by sar would seem to indicate the presence of non-IPv4 protocols and probably not packet loss due to SNDs being overloaded, please provide the output of &lt;STRONG&gt;ethtool -S eth1-01&lt;/STRONG&gt; to be sure.&lt;/P&gt;
&lt;P&gt;Looks like you have quite a few elephant flows squashing "mice" connections when they get trapped on a worker core with an elephant flow which could be the source of your packet loss.&amp;nbsp; Make sure that priority queueing is enabled for when workers get fully loaded by running this command:&amp;nbsp;&lt;STRONG&gt;fw ctl multik prioq&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Beyond that you'll need to upgrade to R81 or later to take advantage of the pipeline paths that can spread the processing of elephant flows across multiple worker cores.&lt;/P&gt;
&lt;P&gt;Also please provide the output of&lt;STRONG&gt; fw ctl pstat&amp;nbsp;&lt;/STRONG&gt;just in case it is a resource limitation on the firewall.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 13:06:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138628#M21063</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-01-17T13:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138673#M21085</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1629"&gt;@EVSolovyev&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have or had a SR opened with Check Point support on this issue by any chance? If so, can you reply to me with the SR#?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Dolev&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jan 2022 18:22:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138673#M21085</guid>
      <dc:creator>Dolev</dc:creator>
      <dc:date>2022-01-17T18:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Strange ( periodic ) packet loss</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138714#M21091</link>
      <description>&lt;P&gt;Good afternoon.&lt;/P&gt;&lt;P&gt;No, we have not opened an SR at this time. The problem is that our support ran out, and we did not renew it in time. Now the process of buying it is underway. We are a state company and such processes are very slow. If we had tech support, I would have opened SR right away.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 09:19:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-periodic-packet-loss/m-p/138714#M21091</guid>
      <dc:creator>EVSolovyev</dc:creator>
      <dc:date>2022-01-18T09:19:54Z</dc:date>
    </item>
  </channel>
</rss>

