<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sim Affinity in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140256#M21507</link>
    <description>&lt;P&gt;Ah - we have 10Gb expansion card in the appliance - model is CPAC-4-10F&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Wed, 02 Feb 2022 15:14:28 GMT</pubDate>
    <dc:creator>Phill_Lunt</dc:creator>
    <dc:date>2022-02-02T15:14:28Z</dc:date>
    <item>
      <title>Sim Affinity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140183#M21479</link>
      <description>&lt;P&gt;Hi Checkmates!&lt;/P&gt;&lt;P&gt;I wonder if someone can help me - I need manually allocate 2 CPUs to two interfaces on our Security gateways while leaving the remaining CPUs for the gateways to automatically assign.&amp;nbsp; Is this possible and what is the process in R80.30?&amp;nbsp; Just to confirm what I need to achieve is this:&lt;/P&gt;&lt;P&gt;CPU0 - Eth3-01&lt;BR /&gt;CPU1 - Eth3-04&lt;BR /&gt;CPU2-5 - All remaining interfaces&lt;/P&gt;&lt;P&gt;Many thanks for your help!&lt;BR /&gt;Kind regards&lt;/P&gt;&lt;P&gt;P&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 09:42:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140183#M21479</guid>
      <dc:creator>Phill_Lunt</dc:creator>
      <dc:date>2022-02-02T09:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sim Affinity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140215#M21488</link>
      <description>&lt;P&gt;I'm not sure this is really what you want.&lt;/P&gt;
&lt;P&gt;I would recommend upgrading to R80.40 or above with dynamic balancing (sk164155) and monitor from there.&lt;/P&gt;
&lt;P&gt;Note on systems with fewer than eight cores there are additional considerations.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 12:05:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140215#M21488</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-02T12:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Sim Affinity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140216#M21489</link>
      <description>&lt;P&gt;Many thanks, Chris&lt;/P&gt;&lt;P&gt;The issue we have is that the 10Gb interfaces seem to get to a maximum of 2Gb throughout and the assigned CPU is then running at 100%.&amp;nbsp; My thought was that if we assign a dedicated CPU to each of the interfaces the throughput will be higher.&amp;nbsp; We are running R80.30 at the moment - is the upgrade an inplace uprgade or will we need to rebuild the mgmt appliance? SMS Appliance.&amp;nbsp; Thanks very much for your help.&lt;/P&gt;&lt;P&gt;P&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 12:02:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140216#M21489</guid>
      <dc:creator>Phill_Lunt</dc:creator>
      <dc:date>2022-02-02T12:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Sim Affinity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140218#M21490</link>
      <description>&lt;P&gt;By all means start by reviewing the Super7 output and more tailored advice might then be possible.&lt;/P&gt;
&lt;P&gt;Refer:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/td-p/40528" target="_blank"&gt;https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/td-p/40528&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Otherwise rebuilding management isn't mandatory to achieve the upgrade. Creation of recovery points (backup / snapshot / migrate export ) is recommended as a precaution.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 12:14:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140218#M21490</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-02T12:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: Sim Affinity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140232#M21493</link>
      <description>&lt;P&gt;Thanks Chris, I will grab the super 7 info and report back - really appreciate your help&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 12:55:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140232#M21493</guid>
      <dc:creator>Phill_Lunt</dc:creator>
      <dc:date>2022-02-02T12:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Sim Affinity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140250#M21503</link>
      <description>&lt;P&gt;Assigning a single SND CPU to service a 10 Gbps+ interface will only get you to 4-5Gbps at best before the single CPU is saturated.&amp;nbsp; What you need to do is enable Multi-Queue for the busy interfaces and possibly reduce the number of firewall workers in your CoreXL split so there are more SNDs available to keep up with your busy interfaces.&amp;nbsp; This assumes that your firewall NIC hardware supports Multi-Queue, what model is your gateway?&amp;nbsp; Also to echo Chris we will need to see Super Seven outputs.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Incidentally, in R81 and later all supported interfaces automatically have Multi-Queue enabled, and the CoreXL split is adjusted dynamically which would almost certainly completely avoid the issue you are experiencing.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 14:47:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140250#M21503</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-02-02T14:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: Sim Affinity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140254#M21505</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp; - thanks so much for this information.&amp;nbsp; We have 13800 appliances (nearing end of life!) and in fact we only need to support a 5Gb Internet circuit so we might get away with assigning a single CPU if indeed multiqueue is not supported on our hardware.&amp;nbsp; I will get the Super7 info sorted as soon as I can.&lt;/P&gt;&lt;P&gt;Thanks both - really really helpful!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 15:09:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140254#M21505</guid>
      <dc:creator>Phill_Lunt</dc:creator>
      <dc:date>2022-02-02T15:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Sim Affinity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140256#M21507</link>
      <description>&lt;P&gt;Ah - we have 10Gb expansion card in the appliance - model is CPAC-4-10F&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 15:14:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140256#M21507</guid>
      <dc:creator>Phill_Lunt</dc:creator>
      <dc:date>2022-02-02T15:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: Sim Affinity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140257#M21508</link>
      <description>&lt;P&gt;Looks like mutiqueue is supported but currently off:&lt;/P&gt;&lt;P&gt;cpmq get&lt;/P&gt;&lt;P&gt;Active ixgbe interfaces:&lt;BR /&gt;eth3-01 [Off]&lt;BR /&gt;eth3-04 [Off]&lt;/P&gt;&lt;P&gt;Active igb interfaces:&lt;BR /&gt;eth1-02 [Off]&lt;BR /&gt;eth1-03 [Off]&lt;BR /&gt;eth1-04 [Off]&lt;BR /&gt;eth1-05 [Off]&lt;BR /&gt;eth1-06 [Off]&lt;BR /&gt;eth1-07 [Off]&lt;BR /&gt;eth2-01 [Off]&lt;BR /&gt;eth2-02 [Off]&lt;BR /&gt;eth2-03 [Off]&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 15:20:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140257#M21508</guid>
      <dc:creator>Phill_Lunt</dc:creator>
      <dc:date>2022-02-02T15:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Sim Affinity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140259#M21509</link>
      <description>&lt;P&gt;This is where you should consider starting your tuning efforts if you need quick wins.&lt;/P&gt;
&lt;P&gt;Note 13800 appliances only support R80.40 and lower.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 15:26:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/140259#M21509</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-02T15:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Sim Affinity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/142617#M22074</link>
      <description>&lt;P&gt;Hi Timothy&lt;/P&gt;&lt;P&gt;Many thanks for your help with this.&amp;nbsp; We adjusted the number of CPUs available to the NICs (using cpconfig) and also enabled multiqueue on the 10Gb Interfaces.&amp;nbsp; This has vastly improved the throughput!&amp;nbsp; Thanks again to you and &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Phill&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2022 12:19:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Sim-Affinity/m-p/142617#M22074</guid>
      <dc:creator>Phill_Lunt</dc:creator>
      <dc:date>2022-02-28T12:19:51Z</dc:date>
    </item>
  </channel>
</rss>

