<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Most traffic taking PXL (medium) path, resulting in high CPU in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141703#M21899</link>
    <description>&lt;P&gt;Great! Inactivating IPS indeed fixed it too! Ok, job in hand to tweak IPS and maybe get more cores to this VS! Thanks heaps&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Feb 2022 17:51:20 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2022-02-16T17:51:20Z</dc:date>
    <item>
      <title>Most traffic taking PXL (medium) path, resulting in high CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141647#M21876</link>
      <description>&lt;P&gt;OK, I'm giving up as I can't understand why would most traffic be pushed via medium path in one of our perimeter GWs.&lt;/P&gt;
&lt;P&gt;Setup: GW running &lt;STRONG&gt;R80.40 T139&lt;/STRONG&gt;, blades enabled:&amp;nbsp;fw urlf appi ips identityServer.&lt;/P&gt;
&lt;P&gt;The only TP blade we have is IPS. Yet running &lt;STRONG&gt;ips off&lt;/STRONG&gt; command makes no difference at all. Whilst &lt;STRONG&gt;fw amw unload&lt;/STRONG&gt; restores expected state with most traffic being accelerated.&lt;/P&gt;
&lt;P&gt;This does not really make sense as AMW unload should only affect TP blades except IPS. But they are not even enabled!&lt;/P&gt;
&lt;P&gt;Here are two screenshots: before and after AMW unload:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15416i9A9CC28A7B2C8E85/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="lia-align-left"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15419i3A25622D329EA8AB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I look at actual connections - it's pretty much everything, even internal network to DNS is being sent to PXL.&lt;/P&gt;
&lt;P&gt;I tried adding explicit TP policy to exclude all internal networks:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15420i8C51B0564AC2A6DD/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But still no joy.&lt;/P&gt;
&lt;P&gt;What am I missing?? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 12:17:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141647#M21876</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-02-16T12:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Most traffic taking PXL (medium) path, resulting in high CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141667#M21886</link>
      <description>&lt;P&gt;Throughput acceleration (pkts) is unaffected by the state of AMW, for you it is the Accept templating rate that is being impacted (conns) as well as causing some traffic to go Medium Path.&amp;nbsp; Keep in mind that connections can migrate between different paths and be counted more than once, which is why Accelerated pkts/PXL/CPAS/F2F add up to more than 100%.&amp;nbsp; Let's focus on the templating rate.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ips off&lt;/STRONG&gt; only affects new connections, so you can't expect the acceleration percentage to dramatically change immediately.&amp;nbsp; Try actually unchecking the IPS blade (and ensuring all other TP blades are unchecked) then reinstall the Threat Prevention policy, then reinstall the Access Control policy in a separate operation.&amp;nbsp; Wait about 30 minutes for most existing connections to decay, how does it look then?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Usually Anti-bot is responsible for dramatically reducing connection templating rates (I even call this blade the "slayer" of templates in one of my books) and I'm wondering if there are still some Anti-bot hooks involved even when only IPS is enabled.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 14:35:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141667#M21886</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-02-16T14:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Most traffic taking PXL (medium) path, resulting in high CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141686#M21894</link>
      <description>&lt;P&gt;i actually run ips off -n which deletes templates, my understanding was that it would help to see effects faster. But lets try with IPS unchecked!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 15:36:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141686#M21894</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-02-16T15:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Most traffic taking PXL (medium) path, resulting in high CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141703#M21899</link>
      <description>&lt;P&gt;Great! Inactivating IPS indeed fixed it too! Ok, job in hand to tweak IPS and maybe get more cores to this VS! Thanks heaps&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 17:51:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141703#M21899</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-02-16T17:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: Most traffic taking PXL (medium) path, resulting in high CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141774#M21922</link>
      <description>&lt;P&gt;Yeah it is surprising how often IPS is the culprit in cases like this, but 90% of effective troubleshooting is knowing the right place to look...&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 13:09:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141774#M21922</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-02-17T13:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Most traffic taking PXL (medium) path, resulting in high CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141788#M21926</link>
      <description>&lt;P&gt;Indeed!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15430i91AD445238217C8E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 14:11:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Most-traffic-taking-PXL-medium-path-resulting-in-high-CPU/m-p/141788#M21926</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-02-17T14:11:21Z</dc:date>
    </item>
  </channel>
</rss>

