<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help wanted - troubleshooting potential interface / performance issues in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145558#M22945</link>
    <description>&lt;P&gt;Normally multi-queue would be enabled by default with the new kernel post upgrade.&lt;/P&gt;
&lt;P&gt;But please check it as Tim has described above with respect to the SND assignment/allocation.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Apr 2022 05:01:18 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2022-04-06T05:01:18Z</dc:date>
    <item>
      <title>Help wanted - troubleshooting potential interface / performance issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145374#M22889</link>
      <description>&lt;P&gt;Dear CPUG,&lt;/P&gt;&lt;P&gt;a few days ago, we have seen lots of buffering during an online meeting in our office.&lt;/P&gt;&lt;P&gt;After putting some investigation into it, our network team figured out, that on the internet switch port, connected to our external firewall interface, there were some &lt;STRONG&gt;output drops&lt;/STRONG&gt; and &lt;STRONG&gt;pause inputs&lt;/STRONG&gt;&amp;nbsp;(see below) which might be caused by the firewall, being unable to process the traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We run R80.30 on a 5000 Appliance with 32 GB Memory, running at ~40% CPU&lt;/P&gt;&lt;P&gt;The peak bandwidth we could see during that day, when the buffering happened was 1,5 Gbit/s - on a 10GB/s line and 5 Gbit/s internet speed...&lt;/P&gt;&lt;P&gt;So I can not imagine that this can't be handled by the firewall - however, I am looking for some ways to prove, that it is not the firewall...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not see any errors on said firewall interface in clish "show interface"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Statistics:&lt;BR /&gt;TX bytes:14422795901250 packets:16529204292 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;RX bytes:10209799558665 packets:15177341589 errors:0 dropped:0 overruns:0 frame:0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any commands which might show another issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance and BR,&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;--- SWITCH INTERFACE ---&lt;/P&gt;&lt;P&gt;#sh int Te1/1/4&lt;/P&gt;&lt;P&gt;TenGigabitEthernet1/1/4 is up, line protocol is up (connected)&lt;/P&gt;&lt;P&gt;&amp;nbsp; Hardware is Ten Gigabit Ethernet, address is&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Description:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; MTU 1500 bytes, BW 10000000 Kbit/sec, DLY 10 usec,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; reliability 255/255, txload 19/255, rxload 33/255&lt;/P&gt;&lt;P&gt;&amp;nbsp; Encapsulation ARPA, loopback not set&lt;/P&gt;&lt;P&gt;&amp;nbsp; Keepalive not set&lt;/P&gt;&lt;P&gt;&amp;nbsp; Full-duplex, 10Gb/s, link type is auto, media type is SFP-10GBase-SR&lt;/P&gt;&lt;P&gt;&amp;nbsp; input flow-control is on, output flow-control is unsupported&lt;/P&gt;&lt;P&gt;&amp;nbsp; ARP type: ARPA, ARP Timeout 04:00:00&lt;/P&gt;&lt;P&gt;&amp;nbsp; Last input never, output 00:00:01, output hang never&lt;/P&gt;&lt;P&gt;&amp;nbsp; Last clearing of "show interface" counters 23:56:12&lt;/P&gt;&lt;P&gt;&amp;nbsp; Input queue: 0/2000/0/0 (size/max/drops/flushes); &lt;U&gt;&lt;STRONG&gt;Total output drops: 86&lt;/STRONG&gt;&lt;/U&gt; ---------&lt;/P&gt;&lt;P&gt;&amp;nbsp; Queueing strategy: fifo&lt;/P&gt;&lt;P&gt;&amp;nbsp; Output queue: 0/40 (size/max)&lt;/P&gt;&lt;P&gt;&amp;nbsp; 30 second input rate 1302386000 bits/sec, 169485 packets/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 30 second output rate 750619000 bits/sec, 139352 packets/sec&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5718861587 packets input, 5274589864997 bytes, 0 no buffer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Received 60170 broadcasts (1433 multicasts)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 runts, 0 giants, 0 throttles&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 watchdog, 1433 multicast, &lt;U&gt;&lt;STRONG&gt;46 pause input&lt;/STRONG&gt; &lt;/U&gt;-----------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 input packets with dribble condition detected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4876618459 packets output, 3279140072750 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Output 179073 broadcasts (0 multicasts)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 output errors, 0 collisions, 0 interface resets&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 unknown protocol drops&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 babbles, 0 late collision, 0 deferred&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 lost carrier, 0 no carrier, 0 pause output&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 output buffer failures, 0 output buffers swapped out&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 13:33:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145374#M22889</guid>
      <dc:creator>T_Sonnberger</dc:creator>
      <dc:date>2022-04-04T13:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: Help wanted - troubleshooting potential interface / performance issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145384#M22896</link>
      <description>&lt;P&gt;You can try ethtool command as well and cpview would give you lots of good info as well. Is there particular interface you are having issues with?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 14:16:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145384#M22896</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-04T14:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Help wanted - troubleshooting potential interface / performance issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145396#M22898</link>
      <description>&lt;P&gt;Which model of 5000 series appliance and is multi-queue enabled?&lt;/P&gt;
&lt;P&gt;Disabling flow-control is also something that can be investigated pending other findings.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 14:43:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145396#M22898</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-04-04T14:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: Help wanted - troubleshooting potential interface / performance issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145397#M22899</link>
      <description>&lt;P&gt;Please provide output of &lt;STRONG&gt;enabled_blades&lt;/STRONG&gt; and the "Super Seven" commands.&amp;nbsp; Hopefully the firewall has not been rebooted since you experienced the issues so we can see what happened.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/m-p/40528?search-action-id=41693809848&amp;amp;search-result-uid=40528" target="_blank"&gt;https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/m-p/40528&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The router counters you highlighted might be significant, but we need to look at the firewall first as those router counter values might as well be a single drop of water in a big lake.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 14:52:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145397#M22899</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-04-04T14:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Help wanted - troubleshooting potential interface / performance issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145446#M22919</link>
      <description>&lt;P&gt;Thank you all for the replies! I really appreciate the support.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The exact Model is:&lt;/P&gt;&lt;P&gt;Platform: PL-20-00&lt;BR /&gt;Model: Check Point 5600&lt;/P&gt;&lt;P&gt;The interface in Question is eth1-03 - however, compared to eth1-02/ eth1-01 this should serve much less traffic than the others facing to the internal network or DMZs&lt;/P&gt;&lt;P&gt;Here is the output of the firewall, that was active while the issue happened (gw5). Unfortunately, the firewall failed over soon after the event, so I have attached the output of the actual active FW as well (gw6).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@gw5:0]# enabled_blades&lt;BR /&gt;fw vpn urlf av appi ips identityServer SSL_INSPECT anti_bot vpn&lt;/P&gt;&lt;P&gt;[Expert@gw5:0]# fwaccel stat&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;|0 |SND |enabled |eth2,eth3,eth4,Sync,Mgmt,|&lt;BR /&gt;| | | |eth1-01,eth1-02,eth1-03 |Acceleration,Cryptography |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,NULL,3DES,DES,CAST, |&lt;BR /&gt;| | | | |CAST-40,AES-128,AES-256,ESP, |&lt;BR /&gt;| | | | |LinkSelection,DynamicVPN, |&lt;BR /&gt;| | | | |NatTraversal,AES-XCBC,SHA256 |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;/P&gt;&lt;P&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;Layer Network disables template offloads from rule #13&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Drop Templates : disabled&lt;BR /&gt;NAT Templates : disabled by Firewall&lt;BR /&gt;Layer Network disables template offloads from rule #13&lt;BR /&gt;Throughput acceleration still enabled.&lt;/P&gt;&lt;P&gt;[Expert@gw5:0]# fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 0/0 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 79169306167/98610388965 (80%)&lt;BR /&gt;F2Fed pkts/Total pkts : 8275669186/98610388965 (8%)&lt;BR /&gt;F2V pkts/Total pkts : 278906653/98610388965 (0%)&lt;BR /&gt;CPASXL pkts/Total pkts : 37397/98610388965 (0%)&lt;BR /&gt;PSLXL pkts/Total pkts : 11165376215/98610388965 (11%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/98610388965 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/98610388965 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/98610388965 (0%)&lt;/P&gt;&lt;P&gt;[Expert@gw5:0]# grep -c ^processor /proc/cpuinfo&lt;BR /&gt;4&lt;/P&gt;&lt;P&gt;[Expert@gw5:0]# fw ctl affinity -l -r&lt;BR /&gt;CPU 0: eth2 eth3 eth4 Sync Mgmt eth1-01 eth1-02 eth1-03&lt;BR /&gt;CPU 1: fw_2&lt;BR /&gt;usrchkd in.acapd cprid rad lpd topod wsdnsd mpdaemon vpnd pepd in.asessiond fwd pdpd in.pingd cpd cprid&lt;BR /&gt;CPU 2: fw_1&lt;BR /&gt;usrchkd in.acapd cprid rad lpd topod wsdnsd mpdaemon vpnd pepd in.asessiond fwd pdpd in.pingd cpd cprid&lt;BR /&gt;CPU 3: fw_0&lt;BR /&gt;usrchkd in.acapd cprid rad lpd topod wsdnsd mpdaemon vpnd pepd in.asessiond fwd pdpd in.pingd cpd cprid&lt;BR /&gt;All:&lt;/P&gt;&lt;P&gt;[Expert@gw5:0]# netstat -ni&lt;BR /&gt;Kernel Interface table&lt;BR /&gt;Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg&lt;BR /&gt;Mgmt 1500 0 80129483 0 0 0 107954387 0 0 0 BMRU&lt;BR /&gt;Sync 1500 0 137406541 0 0 0 217289236 0 0 0 BMRU&lt;BR /&gt;eth1-01 1500 0 18533478320 0 1030150 0 12882294670 0 0 0 BMRU&lt;BR /&gt;eth1-02 1500 0 37678299521 0 241708 0 37142992315 0 0 0 BMRU&lt;BR /&gt;eth1-03 1500 0 25318615396 0 0 0 27537390124 0 0 0 BMRU&lt;BR /&gt;eth2 1500 0 4768790562 2 2329 2329 8472705408 0 0 0 BMRU&lt;BR /&gt;eth3 1500 0 862009675 0 0 0 1102186634 0 0 0 BMRU&lt;/P&gt;&lt;P&gt;[Expert@gw5:0]# fw ctl multik stat&lt;BR /&gt;ID | Active | CPU | Connections | Peak&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;0 | Yes | 3 | 7636 | 58884&lt;BR /&gt;1 | Yes | 2 | 7538 | 56644&lt;BR /&gt;2 | Yes | 1 | 7756 | 58696&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@gw5:0]# cpstat os -f multi_cpu -o 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 0| 100| 0| ?| 1325|&lt;BR /&gt;| 2| 0| 1| 99| 1| ?| 1325|&lt;BR /&gt;| 3| 1| 1| 98| 2| ?| 1325|&lt;BR /&gt;| 4| 1| 2| 97| 3| ?| 1325|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;======================================================================================================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@gw6:0]# fwaccel stat&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;|0 |SND |enabled |eth2,eth3,eth4,Sync,Mgmt,|&lt;BR /&gt;| | | |eth1-01,eth1-02,eth1-03 |Acceleration,Cryptography |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,NULL,3DES,DES,CAST, |&lt;BR /&gt;| | | | |CAST-40,AES-128,AES-256,ESP, |&lt;BR /&gt;| | | | |LinkSelection,DynamicVPN, |&lt;BR /&gt;| | | | |NatTraversal,AES-XCBC,SHA256 |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;/P&gt;&lt;P&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;Layer Network disables template offloads from rule #13&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Drop Templates : disabled&lt;BR /&gt;NAT Templates : disabled by Firewall&lt;BR /&gt;Layer Network disables template offloads from rule #13&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;[Expert@gw6:0]# fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 16862/26062 (64%)&lt;BR /&gt;Accelerated pkts/Total pkts : 52099672116/65805199783 (79%)&lt;BR /&gt;F2Fed pkts/Total pkts : 7033490038/65805199783 (10%)&lt;BR /&gt;F2V pkts/Total pkts : 202645903/65805199783 (0%)&lt;BR /&gt;CPASXL pkts/Total pkts : 29425/65805199783 (0%)&lt;BR /&gt;PSLXL pkts/Total pkts : 6672008204/65805199783 (10%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/65805199783 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/65805199783 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/65805199783 (0%)&lt;BR /&gt;[Expert@gw6:0]# grep -c ^processor /proc/cpuinfo&lt;BR /&gt;4&lt;BR /&gt;[Expert@gw6:0]# fw ctl affinity -l -r&lt;BR /&gt;CPU 0: eth2 eth3 eth4 Sync Mgmt eth1-01 eth1-02 eth1-03&lt;BR /&gt;CPU 1: fw_2&lt;BR /&gt;mpdaemon pepd pdpd rad topod in.acapd in.asessiond lpd in.pingd cprid fwd usrchkd vpnd wsdnsd cprid cpd&lt;BR /&gt;CPU 2: fw_1&lt;BR /&gt;mpdaemon pepd pdpd rad topod in.acapd in.asessiond lpd in.pingd cprid fwd usrchkd vpnd wsdnsd cprid cpd&lt;BR /&gt;CPU 3: fw_0&lt;BR /&gt;mpdaemon pepd pdpd rad topod in.acapd in.asessiond lpd in.pingd cprid fwd usrchkd vpnd wsdnsd cprid cpd&lt;BR /&gt;All:&lt;BR /&gt;[Expert@gw6:0]# netstat -ni&lt;BR /&gt;Kernel Interface table&lt;BR /&gt;Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg&lt;BR /&gt;Mgmt 1500 0 59443411 0 0 0 80442447 0 0 0 BMRU&lt;BR /&gt;Sync 1500 0 221146723 0 213 213 173510428 0 0 0 BMRU&lt;BR /&gt;eth1-01 1500 0 12325817578 0 547458 0 8615993166 0 0 0 BMRU&lt;BR /&gt;eth1-02 1500 0 25981253604 0 89046 0 25408674761 0 0 0 BMRU&lt;BR /&gt;eth1-03 1500 0 16681713676 0 0 0 18166382645 0 0 0 BMRU&lt;BR /&gt;eth2 1500 0 3596415052 0 121 121 6063612802 0 0 0 BMRU&lt;BR /&gt;eth3 1500 0 656401340 0 0 0 789934560 0 0 0 BMRU&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@gw6:0]# fw ctl multik stat&lt;BR /&gt;ID | Active | CPU | Connections | Peak&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;0 | Yes | 3 | 8889 | 54242&lt;BR /&gt;1 | Yes | 2 | 8902 | 52141&lt;BR /&gt;2 | Yes | 1 | 9096 | 54035&lt;BR /&gt;[Expert@gw6:0]# cpstat os -f multi_cpu -o 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 15| 85| 15| ?| 65868|&lt;BR /&gt;| 2| 2| 12| 86| 14| ?| 65868|&lt;BR /&gt;| 3| 2| 11| 86| 14| ?| 65868|&lt;BR /&gt;| 4| 4| 17| 79| 21| ?| 65868|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 04:28:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145446#M22919</guid>
      <dc:creator>T_Sonnberger</dc:creator>
      <dc:date>2022-04-05T04:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Help wanted - troubleshooting potential interface / performance issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145447#M22920</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Platform: PL-20-00&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Model: Check Point 5600&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Multi-Queue seems to be disabled&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 04:59:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145447#M22920</guid>
      <dc:creator>T_Sonnberger</dc:creator>
      <dc:date>2022-04-05T04:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Help wanted - troubleshooting potential interface / performance issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145488#M22926</link>
      <description>&lt;P&gt;You should definitely enable multi q, that will help.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_PerformanceTuning_AdminGuide/Topics-PTG/MQ-Basic-Configuration.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_PerformanceTuning_AdminGuide/Topics-PTG/MQ-Basic-Configuration.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 11:30:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145488#M22926</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-05T11:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Help wanted - troubleshooting potential interface / performance issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145523#M22939</link>
      <description>&lt;P&gt;About 80% of your traffic is fully accelerated but with your 1/3 default split only one CPU can be used to process that 80% of your traffic.&amp;nbsp; The 40% total CPU number is averaging all 4 together, and probably does not reflect CPU 0 getting killed as the only SND.&amp;nbsp; Multi-Queue is not possible with only 1 SND.&lt;/P&gt;
&lt;P&gt;Would suggest moving to a 2/2 split by reducing instances from 3 to 2 which would allow Multi-Queue to be used; you'll need to manually enable Multi-Queue on your busy interfaces after the core split change unless you are using the Gaia 3.10 version of R80.30.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 17:06:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145523#M22939</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-04-05T17:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Help wanted - troubleshooting potential interface / performance issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145556#M22944</link>
      <description>&lt;P&gt;Dear Timothy,&lt;/P&gt;&lt;P&gt;thank you very much for the explanation and support!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will have an upgrade to 81.10 tomorrow and will upgrade/ (fresh install 3.10) on the firewalls afterwards as well.&lt;/P&gt;&lt;P&gt;I will apply those changes then!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 04:32:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145556#M22944</guid>
      <dc:creator>T_Sonnberger</dc:creator>
      <dc:date>2022-04-06T04:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: Help wanted - troubleshooting potential interface / performance issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145558#M22945</link>
      <description>&lt;P&gt;Normally multi-queue would be enabled by default with the new kernel post upgrade.&lt;/P&gt;
&lt;P&gt;But please check it as Tim has described above with respect to the SND assignment/allocation.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 05:01:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145558#M22945</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-04-06T05:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Help wanted - troubleshooting potential interface / performance issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145588#M22950</link>
      <description>&lt;P&gt;R81.10 will enable Multi-Queue by default on all interfaces that support it, and will also utilize Dynamic Split so it should adjust to a 2/2 split all on its own.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 11:45:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Help-wanted-troubleshooting-potential-interface-performance/m-p/145588#M22950</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-04-06T11:45:19Z</dc:date>
    </item>
  </channel>
</rss>

