<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SecureXL optimisation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150446#M24419</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the output of&amp;nbsp;&lt;STRONG&gt;enabled_blades&lt;/STRONG&gt; &amp;amp;&amp;nbsp;&lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@:0]# enabled_blades&lt;BR /&gt;fw vpn urlf av appi ips identityServer SSL_INSPECT anti_bot mon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@:0]# netstat -ni&lt;BR /&gt;Kernel Interface table&lt;BR /&gt;Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg&lt;BR /&gt;Mgmt 1500 0 384765362 0 20882 15248 398446895 0 0 0 BMRU&lt;BR /&gt;eth1-03 1500 0 902378366 0 5634 12839 697623630 0 0 0 BMRU&lt;BR /&gt;eth1-03.581 1500 0 900376330 0 226076 0 695448107 0 1712314 0 BMRU&lt;BR /&gt;eth1-03.686 1500 0 361402 0 92 0 722772 0 2 0 BMRU&lt;BR /&gt;eth1-03.687 1500 0 637361 0 22234 0 1168873 0 7 0 BMRU&lt;BR /&gt;eth1-03.743 1500 0 378622 0 0 0 284656 0 10 0 BMRU&lt;BR /&gt;eth1-06 1500 0 107088539 0 3392 0 123824500 0 0 0 BMRU&lt;BR /&gt;eth1-06.245 1500 0 730980 0 24 0 535540 0 6 0 BMRU&lt;BR /&gt;eth1-06.653 1500 0 1258448 0 0 0 5162 0 0 0 BMRU&lt;BR /&gt;eth1-06.714 1500 0 0 0 0 0 1700 0 0 0 BMRU&lt;BR /&gt;eth1-06.1237 1500 0 105047172 0 505 0 123282872 0 382714 0 BMRU&lt;BR /&gt;eth1-07 1500 0 87130863 0 0 0 213715171 0 0 0 BMRU&lt;BR /&gt;eth1-07.883 1500 0 20684965 0 648 0 30742018 0 790 0 BMRU&lt;BR /&gt;eth1-07.1500 1500 0 62166146 0 13 0 180804616 0 556382 0 BMRU&lt;BR /&gt;eth1-07.1919 1500 0 2375698 0 0 0 1790027 0 19 0 BMRU&lt;BR /&gt;eth1-07.1920 1500 0 1907809 0 1898 0 379292 0 4 0 BMRU&lt;BR /&gt;eth1-08 1500 0 16764049 0 10337 0 11586790 0 0 0 BMRU&lt;BR /&gt;eth2-01 1500 0 846477148 0 10176 0 1477009658 0 0 0 BMRU&lt;BR /&gt;eth2-01.10 1500 0 846467807 0 0 0 1477010086 0 4 0 BMRU&lt;BR /&gt;eth2-02 1500 0 2711422160 3 10176 0 2894806629 0 0 0 BMRU&lt;BR /&gt;eth2-02.91 1500 0 30318227 0 0 0 1965481 0 4 0 BMRU&lt;BR /&gt;eth2-02.155 1500 0 39643313 0 0 0 21983075 0 0 0 BMRU&lt;BR /&gt;eth2-02.156 1500 0 40983565 0 0 0 22244626 0 0 0 BMRU&lt;BR /&gt;eth2-02.176 1500 0 17 0 0 0 1699 0 0 0 BMRU&lt;BR /&gt;eth2-02.177 1500 0 31 0 0 0 1706 0 0 0 BMRU&lt;BR /&gt;eth2-02.178 1500 0 24 0 0 0 1706 0 0 0 BMRU&lt;BR /&gt;eth2-02.179 1500 0 1377013 0 0 0 6134425 0 0 0 BMRU&lt;BR /&gt;eth2-02.286 1500 0 17 0 0 0 1697 0 0 0 BMRU&lt;BR /&gt;eth2-02.302 1500 0 0 0 0 0 1697 0 0 0 BMRU&lt;BR /&gt;eth2-02.315 1500 0 0 0 0 0 1697 0 0 0 BMRU&lt;BR /&gt;eth2-02.397 1500 0 1457829243 0 0 0 1431690269 0 0 0 BMRU&lt;BR /&gt;eth2-02.544 1500 0 2876789 0 0 0 2681247 0 0 0 BMRU&lt;BR /&gt;eth2-02.582 1500 0 2082825 0 0 0 3620630 0 0 0 BMRU&lt;BR /&gt;eth2-02.652 1500 0 533620047 0 0 0 781447417 0 0 0 BMRU&lt;BR /&gt;eth2-02.1950 1500 0 602706466 0 830 0 623030146 0 4 0 BMRU&lt;BR /&gt;eth2-03 1500 0 32875317 0 0 0 68723287 0 0 0 BMRU&lt;BR /&gt;eth2-04 1500 0 2984694048 0 0 0 2296906261 0 0 0 BMRU&lt;BR /&gt;lo 65536 0 4407197 0 0 0 4407197 0 0 0 ALPNORU&lt;BR /&gt;vpnt11 1400 0 0 0 0 0 0 0 0 0 MOPRU&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jun 2022 21:21:43 GMT</pubDate>
    <dc:creator>AaronCP</dc:creator>
    <dc:date>2022-06-08T21:21:43Z</dc:date>
    <item>
      <title>SecureXL optimisation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150379#M24410</link>
      <description>&lt;P&gt;Good evening CheckMates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking for some advice on how I can improve the number of accelerated connections on our perimeter gateway. Here is the output from the gateway:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@:0]# fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 2846/16335 (17%)&lt;BR /&gt;Accelerated pkts/Total pkts : 513956107/533355811 (96%)&lt;BR /&gt;F2Fed pkts/Total pkts : 19399704/533355811 (3%)&lt;BR /&gt;F2V pkts/Total pkts : 4110751/533355811 (0%)&lt;BR /&gt;CPASXL pkts/Total pkts : 7421495/533355811 (1%)&lt;BR /&gt;PSLXL pkts/Total pkts : 332024567/533355811 (62%)&lt;BR /&gt;CPAS pipeline pkts/Total pkts : 0/533355811 (0%)&lt;BR /&gt;PSL pipeline pkts/Total pkts : 0/533355811 (0%)&lt;BR /&gt;CPAS inline pkts/Total pkts : 0/533355811 (0%)&lt;BR /&gt;PSL inline pkts/Total pkts : 0/533355811 (0%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/533355811 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/533355811 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/533355811 (0%)&lt;BR /&gt;[Expert@:0]# fwaccel stat&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|0 |SND |enabled |Mgmt,eth1-03,eth2-01, |&lt;BR /&gt;| | | |eth1-06,eth1-07,eth1-08, |&lt;BR /&gt;| | | |eth2-02,eth2-03,eth2-04 |Acceleration,Cryptography |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,NULL,3DES,DES,AES-128, |&lt;BR /&gt;| | | | |AES-256,ESP,LinkSelection, |&lt;BR /&gt;| | | | |DynamicVPN,NatTraversal, |&lt;BR /&gt;| | | | |AES-XCBC,SHA256,SHA384 |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;/P&gt;&lt;P&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;Layer Trust to Walled Garden disables template offloads from rule #9&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Drop Templates : enabled&lt;BR /&gt;NAT Templates : disabled by Firewall&lt;BR /&gt;Layer Trust to Walled Garden disables template offloads from rule #9&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The accelerated packets is at 96%, with the F2F packets at 3% - but I'm wondering if focussing on increasing the number of accelerated connections would improve the performance at all? The second output shows that templates are being offloaded from rule 9, however that isn't entirely accurate. I am using inline layers in the ruleset and the "Trust to Walled Garden" inline layer is right above the clean-up rule. The rule XXX.9 is a rule for our Linux NFS servers and I believe the NFS services are known to impact on SecureXL templating, however I thought with this rule being so close to the bottom of the ruleset that it wouldn't have this impact on the connection templating.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running R80.40 T158 on a 15000 appliance. It is has 32 cores, 4 of which are assigned to SND. Given the gateway is accelerating 96% of the packets, would it be a good idea to increase the number of SND cores?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any advice would be appreciated, as always!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Aaron.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 20:34:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150379#M24410</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-06-07T20:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL optimisation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150382#M24411</link>
      <description>&lt;P&gt;Output of enabled_blades?&lt;BR /&gt;You have stuff in PSLXL, which suggests some level of advanced inspection is being done for access control or threat prevention.&lt;BR /&gt;I assume that would impact templating also.&lt;/P&gt;
&lt;P&gt;That said, 96% of your packets are getting accelerated.&lt;BR /&gt;Unless there's an actual performance issue, I'd say you're already in decent shape.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 22:10:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150382#M24411</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-07T22:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL optimisation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150383#M24412</link>
      <description>&lt;P&gt;I will let&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;respond to this, as he is in my opinion, the guru in secure xl.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jun 2022 23:24:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150383#M24412</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-07T23:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL optimisation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150384#M24413</link>
      <description>&lt;P&gt;Instead of manual CoreXL/SND assignment, it may be worth looking into enabling CoreXL dynamic balancing since your appliances support it and you're on R80.40&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164155" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164155&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 00:06:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150384#M24413</guid>
      <dc:creator>caw001</dc:creator>
      <dc:date>2022-06-08T00:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL optimisation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150414#M24417</link>
      <description>&lt;P&gt;Need to see output of &lt;STRONG&gt;enabled_blades&lt;/STRONG&gt; and &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;The 96% of traffic that is accelerated is only being handled by your 4 SND cores, &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt; will tell if they are able to keep up.&amp;nbsp; You will probably need more SND cores.&lt;/P&gt;
&lt;P&gt;Increasing the templating/conns rate will probably not make a huge difference unless you have a very high new connections rate (you can check this in cpview), due to the use of Column-based matching starting in R80.10.&amp;nbsp; Rulebase lookups are done on the worker/instance cores anyway which I'd imagine are not very busy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 12:09:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150414#M24417</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-06-08T12:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL optimisation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150446#M24419</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the output of&amp;nbsp;&lt;STRONG&gt;enabled_blades&lt;/STRONG&gt; &amp;amp;&amp;nbsp;&lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@:0]# enabled_blades&lt;BR /&gt;fw vpn urlf av appi ips identityServer SSL_INSPECT anti_bot mon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@:0]# netstat -ni&lt;BR /&gt;Kernel Interface table&lt;BR /&gt;Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg&lt;BR /&gt;Mgmt 1500 0 384765362 0 20882 15248 398446895 0 0 0 BMRU&lt;BR /&gt;eth1-03 1500 0 902378366 0 5634 12839 697623630 0 0 0 BMRU&lt;BR /&gt;eth1-03.581 1500 0 900376330 0 226076 0 695448107 0 1712314 0 BMRU&lt;BR /&gt;eth1-03.686 1500 0 361402 0 92 0 722772 0 2 0 BMRU&lt;BR /&gt;eth1-03.687 1500 0 637361 0 22234 0 1168873 0 7 0 BMRU&lt;BR /&gt;eth1-03.743 1500 0 378622 0 0 0 284656 0 10 0 BMRU&lt;BR /&gt;eth1-06 1500 0 107088539 0 3392 0 123824500 0 0 0 BMRU&lt;BR /&gt;eth1-06.245 1500 0 730980 0 24 0 535540 0 6 0 BMRU&lt;BR /&gt;eth1-06.653 1500 0 1258448 0 0 0 5162 0 0 0 BMRU&lt;BR /&gt;eth1-06.714 1500 0 0 0 0 0 1700 0 0 0 BMRU&lt;BR /&gt;eth1-06.1237 1500 0 105047172 0 505 0 123282872 0 382714 0 BMRU&lt;BR /&gt;eth1-07 1500 0 87130863 0 0 0 213715171 0 0 0 BMRU&lt;BR /&gt;eth1-07.883 1500 0 20684965 0 648 0 30742018 0 790 0 BMRU&lt;BR /&gt;eth1-07.1500 1500 0 62166146 0 13 0 180804616 0 556382 0 BMRU&lt;BR /&gt;eth1-07.1919 1500 0 2375698 0 0 0 1790027 0 19 0 BMRU&lt;BR /&gt;eth1-07.1920 1500 0 1907809 0 1898 0 379292 0 4 0 BMRU&lt;BR /&gt;eth1-08 1500 0 16764049 0 10337 0 11586790 0 0 0 BMRU&lt;BR /&gt;eth2-01 1500 0 846477148 0 10176 0 1477009658 0 0 0 BMRU&lt;BR /&gt;eth2-01.10 1500 0 846467807 0 0 0 1477010086 0 4 0 BMRU&lt;BR /&gt;eth2-02 1500 0 2711422160 3 10176 0 2894806629 0 0 0 BMRU&lt;BR /&gt;eth2-02.91 1500 0 30318227 0 0 0 1965481 0 4 0 BMRU&lt;BR /&gt;eth2-02.155 1500 0 39643313 0 0 0 21983075 0 0 0 BMRU&lt;BR /&gt;eth2-02.156 1500 0 40983565 0 0 0 22244626 0 0 0 BMRU&lt;BR /&gt;eth2-02.176 1500 0 17 0 0 0 1699 0 0 0 BMRU&lt;BR /&gt;eth2-02.177 1500 0 31 0 0 0 1706 0 0 0 BMRU&lt;BR /&gt;eth2-02.178 1500 0 24 0 0 0 1706 0 0 0 BMRU&lt;BR /&gt;eth2-02.179 1500 0 1377013 0 0 0 6134425 0 0 0 BMRU&lt;BR /&gt;eth2-02.286 1500 0 17 0 0 0 1697 0 0 0 BMRU&lt;BR /&gt;eth2-02.302 1500 0 0 0 0 0 1697 0 0 0 BMRU&lt;BR /&gt;eth2-02.315 1500 0 0 0 0 0 1697 0 0 0 BMRU&lt;BR /&gt;eth2-02.397 1500 0 1457829243 0 0 0 1431690269 0 0 0 BMRU&lt;BR /&gt;eth2-02.544 1500 0 2876789 0 0 0 2681247 0 0 0 BMRU&lt;BR /&gt;eth2-02.582 1500 0 2082825 0 0 0 3620630 0 0 0 BMRU&lt;BR /&gt;eth2-02.652 1500 0 533620047 0 0 0 781447417 0 0 0 BMRU&lt;BR /&gt;eth2-02.1950 1500 0 602706466 0 830 0 623030146 0 4 0 BMRU&lt;BR /&gt;eth2-03 1500 0 32875317 0 0 0 68723287 0 0 0 BMRU&lt;BR /&gt;eth2-04 1500 0 2984694048 0 0 0 2296906261 0 0 0 BMRU&lt;BR /&gt;lo 65536 0 4407197 0 0 0 4407197 0 0 0 ALPNORU&lt;BR /&gt;vpnt11 1400 0 0 0 0 0 0 0 0 0 MOPRU&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 21:21:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150446#M24419</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-06-08T21:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL optimisation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150447#M24420</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/42699"&gt;@caw001&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the SK! I will definitely be looking into implementing this.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jun 2022 21:23:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150447#M24420</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-06-08T21:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL optimisation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150498#M24453</link>
      <description>&lt;P&gt;If you look at just the stats for the leading non-tagged physical interfaces it appears that your SNDs are keeping up with the handling of packets.&lt;/P&gt;
&lt;P&gt;However the statistics on the tagged subinterfaces are a little strange:&lt;/P&gt;
&lt;P&gt;eth1-03 1500 0 902378366 0 &lt;STRONG&gt;5634&lt;/STRONG&gt; 12839 697623630 0&lt;STRONG&gt; 0&lt;/STRONG&gt; 0 BMRU&lt;BR /&gt;eth1-03.581 1500 0 900376330 0 &lt;STRONG&gt;226076&lt;/STRONG&gt; 0 695448107 0 &lt;STRONG&gt;1712314&lt;/STRONG&gt; 0 BMRU&lt;BR /&gt;eth1-03.686 1500 0 361402 0 &lt;STRONG&gt;92&lt;/STRONG&gt; 0 722772 0 &lt;STRONG&gt;2&lt;/STRONG&gt; 0 BMRU&lt;BR /&gt;eth1-03.687 1500 0 637361 0 &lt;STRONG&gt;22234&lt;/STRONG&gt; 0 1168873 0 &lt;STRONG&gt;7&lt;/STRONG&gt; 0 BMRU&lt;BR /&gt;eth1-03.743 1500 0 378622 0 &lt;STRONG&gt;0&lt;/STRONG&gt; 0 284656 0 &lt;STRONG&gt;10&lt;/STRONG&gt; 0 BMRU&lt;/P&gt;
&lt;P&gt;I've highlighted the RX-DRP and TX-DRP counters.&amp;nbsp; Normally the RX-DRP and TX-DRP counters accumulated on all the subinterfaces should add up to what is displayed on the leading interface, but that isn't happening.&amp;nbsp; As an example if you add up RX-DRP for the four subinterfaces the sum is 248,402 RX-DRPs but the leading interface is only showing 5,634 of them.&amp;nbsp; Also the large number of TX-DRPs on eth1-03.581 is rather concerning as it is pretty rare to see TX-DRPs at all.&amp;nbsp; This may be some kind of change in how the counters are reported in the latest network drivers.&lt;/P&gt;
&lt;P&gt;Please post the following outputs:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ethtool -i eth1-03&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ethtool -S eth1-03&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;mq_mng -o -v -a&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 12:33:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150498#M24453</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-06-09T12:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL optimisation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150515#M24462</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;,&amp;nbsp;as requested:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@:0]# ethtool -i eth1-03&lt;BR /&gt;driver: igb&lt;BR /&gt;version: 5.3.5.20&lt;BR /&gt;firmware-version: 1.63, 0x800009fb&lt;BR /&gt;expansion-rom-version:&lt;BR /&gt;bus-info: 0000:86:00.2&lt;BR /&gt;supports-statistics: yes&lt;BR /&gt;supports-test: yes&lt;BR /&gt;supports-eeprom-access: yes&lt;BR /&gt;supports-register-dump: yes&lt;BR /&gt;supports-priv-flags: no&lt;BR /&gt;[Expert@:0]# ethtool -S eth1-03&lt;BR /&gt;NIC statistics:&lt;BR /&gt;rx_packets: 1723237140&lt;BR /&gt;tx_packets: 1315227525&lt;BR /&gt;rx_bytes: 1156760390227&lt;BR /&gt;tx_bytes: 555185499993&lt;BR /&gt;rx_broadcast: 1884390&lt;BR /&gt;tx_broadcast: 61989&lt;BR /&gt;rx_multicast: 1085635&lt;BR /&gt;tx_multicast: 4&lt;BR /&gt;multicast: 1085635&lt;BR /&gt;collisions: 0&lt;BR /&gt;rx_crc_errors: 0&lt;BR /&gt;rx_no_buffer_count: 0&lt;BR /&gt;rx_missed_errors: 0&lt;BR /&gt;tx_aborted_errors: 0&lt;BR /&gt;tx_carrier_errors: 0&lt;BR /&gt;tx_window_errors: 0&lt;BR /&gt;tx_abort_late_coll: 0&lt;BR /&gt;tx_deferred_ok: 0&lt;BR /&gt;tx_single_coll_ok: 0&lt;BR /&gt;tx_multi_coll_ok: 0&lt;BR /&gt;tx_timeout_count: 0&lt;BR /&gt;rx_long_length_errors: 0&lt;BR /&gt;rx_short_length_errors: 0&lt;BR /&gt;rx_align_errors: 0&lt;BR /&gt;tx_tcp_seg_good: 0&lt;BR /&gt;tx_tcp_seg_failed: 0&lt;BR /&gt;rx_flow_control_xon: 0&lt;BR /&gt;rx_flow_control_xoff: 0&lt;BR /&gt;tx_flow_control_xon: 0&lt;BR /&gt;tx_flow_control_xoff: 0&lt;BR /&gt;rx_long_byte_count: 1156760390227&lt;BR /&gt;tx_dma_out_of_sync: 0&lt;BR /&gt;lro_aggregated: 0&lt;BR /&gt;lro_flushed: 0&lt;BR /&gt;tx_smbus: 0&lt;BR /&gt;rx_smbus: 0&lt;BR /&gt;dropped_smbus: 0&lt;BR /&gt;os2bmc_rx_by_bmc: 0&lt;BR /&gt;os2bmc_tx_by_bmc: 0&lt;BR /&gt;os2bmc_tx_by_host: 0&lt;BR /&gt;os2bmc_rx_by_host: 0&lt;BR /&gt;tx_hwtstamp_timeouts: 0&lt;BR /&gt;rx_hwtstamp_cleared: 0&lt;BR /&gt;rx_errors: 0&lt;BR /&gt;tx_errors: 0&lt;BR /&gt;tx_dropped: 0&lt;BR /&gt;rx_length_errors: 0&lt;BR /&gt;rx_over_errors: 0&lt;BR /&gt;rx_frame_errors: 0&lt;BR /&gt;rx_fifo_errors: 29856&lt;BR /&gt;tx_fifo_errors: 0&lt;BR /&gt;tx_heartbeat_errors: 0&lt;BR /&gt;tx_queue_0_packets: 326309642&lt;BR /&gt;tx_queue_0_bytes: 129405981266&lt;BR /&gt;tx_queue_0_restart: 24602&lt;BR /&gt;tx_queue_1_packets: 312273797&lt;BR /&gt;tx_queue_1_bytes: 128452561252&lt;BR /&gt;tx_queue_1_restart: 29415&lt;BR /&gt;tx_queue_2_packets: 346201163&lt;BR /&gt;tx_queue_2_bytes: 142140083212&lt;BR /&gt;tx_queue_2_restart: 37438&lt;BR /&gt;tx_queue_3_packets: 330442145&lt;BR /&gt;tx_queue_3_bytes: 144269755320&lt;BR /&gt;tx_queue_3_restart: 37282&lt;BR /&gt;rx_queue_0_packets: 425435806&lt;BR /&gt;rx_queue_0_bytes: 289861819616&lt;BR /&gt;rx_queue_0_drops: 6777&lt;BR /&gt;rx_queue_0_csum_err: 0&lt;BR /&gt;rx_queue_0_alloc_failed: 0&lt;BR /&gt;rx_queue_1_packets: 464596030&lt;BR /&gt;rx_queue_1_bytes: 320536125686&lt;BR /&gt;rx_queue_1_drops: 7777&lt;BR /&gt;rx_queue_1_csum_err: 0&lt;BR /&gt;rx_queue_1_alloc_failed: 0&lt;BR /&gt;rx_queue_2_packets: 392166712&lt;BR /&gt;rx_queue_2_bytes: 238191335648&lt;BR /&gt;rx_queue_2_drops: 7731&lt;BR /&gt;rx_queue_2_csum_err: 0&lt;BR /&gt;rx_queue_2_alloc_failed: 0&lt;BR /&gt;rx_queue_3_packets: 441005609&lt;BR /&gt;rx_queue_3_bytes: 294379528280&lt;BR /&gt;rx_queue_3_drops: 7571&lt;BR /&gt;rx_queue_3_csum_err: 0&lt;BR /&gt;rx_queue_3_alloc_failed: 0&lt;BR /&gt;[Expert@:0]# mq_mng -o -v -a&lt;BR /&gt;Total 32 cores. Multiqueue 4 cores: 0,16,1,17&lt;BR /&gt;i/f type state mode cores&lt;BR /&gt;------------------------------------------------------------------------------------------------&lt;BR /&gt;Mgmt igb Up Off 0(58)&lt;BR /&gt;Sync igb Down Auto&lt;BR /&gt;eth1-01 igb Down Auto&lt;BR /&gt;eth1-02 igb Down Auto&lt;BR /&gt;eth1-03 igb Up Auto (4/4) 0(67),16(68),1(69),17(70)&lt;BR /&gt;eth1-04 igb Down Auto&lt;BR /&gt;eth1-05 igb Down Auto&lt;BR /&gt;eth1-06 igb Up Auto (4/4) 0(74),16(75),1(76),17(77)&lt;BR /&gt;eth1-07 igb Up Auto (4/4) 0(79),16(80),1(81),17(85)&lt;BR /&gt;eth1-08 igb Up Auto (4/4) 0(91),16(92),1(93),17(94)&lt;BR /&gt;eth2-01 ixgbe Up Auto (4/4) 0(95),16(96),1(97),17(98)&lt;BR /&gt;eth2-02 ixgbe Up Auto (4/4) 0(100),16(101),1(102),17(103)&lt;BR /&gt;eth2-03 ixgbe Up Auto (4/4) 0(105),16(108),1(109),17(110)&lt;BR /&gt;eth2-04 ixgbe Up Auto (4/4) 0(112),16(113),1(114),17(115)&lt;BR /&gt;eth3-01 ixgbe Down Auto&lt;BR /&gt;eth3-02 ixgbe Down Auto&lt;/P&gt;&lt;P&gt;core interfaces queue irq rx packets tx packets&lt;BR /&gt;------------------------------------------------------------------------------------------------&lt;BR /&gt;0 eth2-01 eth2-01-TxRx-0 95 391755486 526257210&lt;BR /&gt;eth2-03 eth2-03-TxRx-0 105 149460 223506&lt;BR /&gt;eth2-02 eth2-02-TxRx-0 100 1281476432 1352246306&lt;BR /&gt;eth1-08 eth1-08-TxRx-0 91 2030545 10504972&lt;BR /&gt;eth2-04 eth2-04-TxRx-0 112 1046597577 1532525455&lt;BR /&gt;Mgmt Mgmt-TxRx-0 58 630571859 701777770&lt;BR /&gt;eth1-06 eth1-06-TxRx-0 74 34290651 43936538&lt;BR /&gt;eth1-07 eth1-07-TxRx-0 79 43110117 108583315&lt;BR /&gt;eth1-03 eth1-03-TxRx-0 67 425444673 326316946&lt;BR /&gt;1 eth2-01 eth2-01-TxRx-2 97 299676763 1152643147&lt;BR /&gt;eth2-03 eth2-03-TxRx-2 109 5959154 77952&lt;BR /&gt;eth2-02 eth2-02-TxRx-2 102 1195150233 1274034340&lt;BR /&gt;eth1-08 eth1-08-TxRx-2 93 21901068 5635461&lt;BR /&gt;eth2-04 eth2-04-TxRx-2 114 2296817063 835793263&lt;BR /&gt;eth1-06 eth1-06-TxRx-2 76 31729108 51386574&lt;BR /&gt;eth1-07 eth1-07-TxRx-2 81 39356106 93232418&lt;BR /&gt;eth1-03 eth1-03-TxRx-2 69 392179696 346210147&lt;BR /&gt;16 eth2-01 eth2-01-TxRx-1 96 402867786 473040336&lt;BR /&gt;eth2-03 eth2-03-TxRx-1 108 50962712 124307865&lt;BR /&gt;eth2-02 eth2-02-TxRx-1 101 1354595663 1473063739&lt;BR /&gt;eth1-08 eth1-08-TxRx-1 92 2369115 1812140&lt;BR /&gt;eth2-04 eth2-04-TxRx-1 113 1086886130 1014894149&lt;BR /&gt;eth1-06 eth1-06-TxRx-1 75 13455340 49546067&lt;BR /&gt;eth1-07 eth1-07-TxRx-1 80 41770919 92533996&lt;BR /&gt;eth1-03 eth1-03-TxRx-1 68 464611903 312277386&lt;BR /&gt;17 eth2-01 eth2-01-TxRx-3 98 371811514 377583107&lt;BR /&gt;eth2-03 eth2-03-TxRx-3 110 95083 39849&lt;BR /&gt;eth2-02 eth2-02-TxRx-3 103 1287785027 1380370819&lt;BR /&gt;eth1-08 eth1-08-TxRx-3 94 3988027 1514479&lt;BR /&gt;eth2-04 eth2-04-TxRx-3 115 1133430146 960761347&lt;BR /&gt;eth1-06 eth1-06-TxRx-3 77 53846334 61167156&lt;BR /&gt;eth1-07 eth1-07-TxRx-3 85 43126713 103445698&lt;BR /&gt;eth1-03 eth1-03-TxRx-3 70 441012962 330455521&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 18:14:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150515#M24462</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-06-09T18:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL optimisation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150559#M24477</link>
      <description>&lt;P&gt;&lt;EM&gt;tx_queue_0_restart: 24602&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;tx_queue_1_restart: 29415&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;tx_queue_2_restart: 37438&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;tx_queue_3_restart: 37282&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Well that explains the TX-DRPs, it is just odd to bottleneck like that on the TX side of the interface instead of the RX.&amp;nbsp; Almost like there is crapload of traffic flooding into&amp;nbsp;eth1-03.581 from multiple other interfaces and the TX ring buffer is filling up.&amp;nbsp; Recommendations:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1) Change static split from 4/28 to 8/24 or enable Dynamic Balancing/Split which should increase interface queues from 4 to 8 assuming the NIC hardware supports that many, the igb driver supports up to 16.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2) If TX-DRPs/restarts persist after split change consider bonding two physical interfaces with 802.3ad to replace physical interface&amp;nbsp;eth1-03; it looks like you have some unused interfaces available.&amp;nbsp; Also possible that flow control is enabled on the switchport attached to eth1-03 and it is not keeping up and sending pause frames, thus causing the TX queue restarts on the firewall.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3) Also in general make sure that destination is object "Internet" and not "Any" in any rules/layers that are implementing APCL/URLF to keep non-Internet traffic from getting pulled into the Medium Path inappropriately.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Other than those items things look pretty&amp;nbsp;good.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 12:38:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150559#M24477</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-06-10T12:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL optimisation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150682#M24496</link>
      <description>&lt;P&gt;Thanks,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 10:57:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-optimisation/m-p/150682#M24496</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-06-13T10:57:52Z</dc:date>
    </item>
  </channel>
</rss>

