<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint 5900 VSX Cluster High CPU in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34063#M2771</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great, we can rule that out. CIFS should take PXL not F2F. Check actual IPs&amp;nbsp; and see if it leads somewhere &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Oct 2018 05:43:47 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2018-10-18T05:43:47Z</dc:date>
    <item>
      <title>CheckPoint 5900 VSX Cluster High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34054#M2762</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a strange issue, we have CP 5900 VSX VSLS cluster with 3 virtual firewalls, only one is active on node-1 and others are active node-2.&lt;/P&gt;&lt;P&gt;We have coreXL and SecureXL enabled with only IPS blade enabled, strangely on node 1 there is one firewall worker taking lot of CPU&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also strangely ~70% traffic takes F2F path without any explanation. If it would have being IPS it should take PXL path for the most of the traffic?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone has any idea what is wrong with this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71310_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71312_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71314_pastedImage_5.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71315_pastedImage_6.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-5 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71316_pastedImage_7.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-6 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71317_pastedImage_8.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2018 01:21:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34054#M2762</guid>
      <dc:creator>Demith_Samaraw2</dc:creator>
      <dc:date>2018-10-10T01:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 5900 VSX Cluster High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34055#M2763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should see connections that are not accelerated with&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fwaccel conns -f F&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;might help you to identify root cause&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2018 07:16:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34055#M2763</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-10-10T07:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 5900 VSX Cluster High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34056#M2764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Kaspars&lt;/P&gt;&lt;P&gt;I will have a look at that command&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2018 05:25:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34056#M2764</guid>
      <dc:creator>Demith_Samaraw2</dc:creator>
      <dc:date>2018-10-11T05:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 5900 VSX Cluster High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34057#M2765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;VSX is not my specialty but I'll take a shot here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as the high F2F, try applying IPS profile "Optimized" to your gateway and see if it improves the situation with high F2F.&amp;nbsp; If it does not, try running these commands in your VS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ips off&lt;/P&gt;&lt;P&gt;fwaccel stats -r&lt;/P&gt;&lt;P&gt;(wait 60 seconds)&lt;/P&gt;&lt;P&gt;fwaccel stats -s&lt;/P&gt;&lt;P&gt;ips on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did F2F go way down in "fwaccel stats -s"?&amp;nbsp; If so it is definitely something in your IPS profile config, probably an active signature with a&amp;nbsp;performance rating of "Critical" handling a lot of traffic.&amp;nbsp; Make sure you run "ips on" at the end!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If F2F is still stubbornly high you could have fragmentation or some other kind of issue interfering with SecureXL.&amp;nbsp; Please post the output of the following command to this thread:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fwaccel stats -p&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Second Edition of my "Max Power" Firewall Book&lt;BR /&gt;&lt;SPAN&gt;Now Available at &lt;/SPAN&gt;&lt;A href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2018 22:56:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34057#M2765</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-10-12T22:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 5900 VSX Cluster High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34058#M2766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Tim,&lt;/P&gt;&lt;P&gt;I will do this test tomorrow&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Oct 2018 23:47:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34058#M2766</guid>
      <dc:creator>Demith_Samaraw2</dc:creator>
      <dc:date>2018-10-14T23:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 5900 VSX Cluster High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34059#M2767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually disabling IPS did not fix the issue much,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="71644" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71644_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fwaccel stats -p gives this output&lt;/P&gt;&lt;P&gt;biggest culprits here are TCP conn is F2Fed, UDP miss conn, TCP state viol, and TCP-SYN miss conn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71646_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea what kind of traffic is causing this,&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2018 03:54:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34059#M2767</guid>
      <dc:creator>Demith_Samaraw2</dc:creator>
      <dc:date>2018-10-18T03:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 5900 VSX Cluster High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34060#M2768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As said before, look at the actual traffic that's not being accelerated, might give some clues&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;fwaccel conns -f F&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2018 05:24:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34060#M2768</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-10-18T05:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 5900 VSX Cluster High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34061#M2769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also I noticed that there's not a lot of traffic there - 40000 packets in 60secs.. That's ~700pps, almost nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you looking at VS0 stats? It is quite normal to see 100% F2F on VS0 as most traffic will be either CP management (18192) or logs (257) and that cannot be accelerated as it originates from gateway itself&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here's my VS0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71647_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And fwaccel conns -f F shows connections&amp;nbsp;originating or terminating on GW itself&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2018 05:32:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34061#M2769</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-10-18T05:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 5900 VSX Cluster High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34062#M2770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kaspars&lt;/P&gt;&lt;P&gt;Nope, this is run on VS1, actually this is run very late in the night, when there were not much traffic, I guess I kind of have an idea what is causing this, I have done some packet captures on the day and based on the Wireshark, most of the traffic going through this firewall microsoft-ds/CIFS and I guess CP still send all of that traffic to F2F path, but I will get a&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;fwaccel conns -f F output to compare the list of actuall connections.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2018 05:38:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34062#M2770</guid>
      <dc:creator>Demith_Samaraw2</dc:creator>
      <dc:date>2018-10-18T05:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 5900 VSX Cluster High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34063#M2771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great, we can rule that out. CIFS should take PXL not F2F. Check actual IPs&amp;nbsp; and see if it leads somewhere &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2018 05:43:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34063#M2771</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-10-18T05:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint 5900 VSX Cluster High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34064#M2772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check with cpview, advanced and network, this shows the heaviest connections and the path.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2018 20:52:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-5900-VSX-Cluster-High-CPU/m-p/34064#M2772</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-10-18T20:52:42Z</dc:date>
    </item>
  </channel>
</rss>

