<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High CPU in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159603#M27979</link>
    <description>&lt;P&gt;once added should it be effective immediatly or just on new connections?&lt;/P&gt;</description>
    <pubDate>Fri, 14 Oct 2022 18:15:32 GMT</pubDate>
    <dc:creator>flachance</dc:creator>
    <dc:date>2022-10-14T18:15:32Z</dc:date>
    <item>
      <title>High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159570#M27961</link>
      <description>&lt;P&gt;Hi, we're experiencing some high cpu usage and to be honest I'm not sure what to make of the cpview results. What is PM tier 1? Is it related to IPS?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cpu5.JPG" style="width: 693px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18129i42C0030D93CDA120/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cpu5.JPG" alt="Cpu5.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cpu4.JPG" style="width: 659px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18126iC7152CDB98F0CA0D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cpu4.JPG" alt="Cpu4.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cpu3.JPG" style="width: 560px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18127i93CFF9D0C2C07289/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cpu3.JPG" alt="Cpu3.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cpu2.JPG" style="width: 637px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18128iF45FA9D7366F9D2B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cpu2.JPG" alt="Cpu2.JPG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cpu1.JPG" style="width: 639px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18130iBBBFAE05A82E1F84/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cpu1.JPG" alt="Cpu1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 15:23:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159570#M27961</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-10-14T15:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159579#M27968</link>
      <description>&lt;P&gt;I tried turning off ips but it didn't help&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 15:58:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159579#M27968</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-10-14T15:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159581#M27969</link>
      <description>&lt;P&gt;Pattern Matcher is used with any blade that is not Firewall and VPN.&lt;BR /&gt;That would include but isn't necessarily caused by IPS.&lt;BR /&gt;Please provide the output of the Super 7 Commands:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/m-p/40528#M703" target="_blank"&gt;https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/m-p/40528#M703&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 16:17:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159581#M27969</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-14T16:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159590#M27972</link>
      <description>&lt;P&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Super Seven Performance Assessment Commands v0.5 (Thanks to Timothy Hall) |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Inspecting your environment: &amp;#27;[32mOK&amp;#27;(B&amp;#27;[m |&lt;BR /&gt;| This is a firewall....(continuing) |&lt;BR /&gt;| |&lt;BR /&gt;| Referred pagenumbers are to be found in the following book: |&lt;BR /&gt;| Max Power: Check Point Firewall Performance Optimization - Second Edition |&lt;BR /&gt;| |&lt;BR /&gt;| Available at &lt;A href="http://www.maxpowerfirewalls.com/" target="_blank"&gt;http://www.maxpowerfirewalls.com/&lt;/A&gt; |&lt;BR /&gt;| |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Command #1: fwaccel stat |&lt;BR /&gt;| |&lt;BR /&gt;| Check for : Accelerator Status must be enabled (R77.xx/R80.10 versions) |&lt;BR /&gt;| Status must be enabled (R80.20 and higher) |&lt;BR /&gt;| Accept Templates must be enabled |&lt;BR /&gt;| Message "disabled" from (low rule number) = bad |&lt;BR /&gt;| |&lt;BR /&gt;| Chapter 9: SecureXL throughput acceleration |&lt;BR /&gt;| Page 278 |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Output: |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|0 |SND |enabled |eth1,eth2,eth3,eth8,eth9 |Acceleration,Cryptography |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,NULL,3DES,DES,AES-128, |&lt;BR /&gt;| | | | |AES-256,ESP,LinkSelection, |&lt;BR /&gt;| | | | |DynamicVPN,NatTraversal, |&lt;BR /&gt;| | | | |AES-XCBC,SHA256,SHA384 |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;/P&gt;&lt;P&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;Layer CIRB incoming disables template offloads from rule #3&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Layer RZ Inbound disables template offloads from rule #1&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Layer OnPrem2AzureInfrastructure disables template offloads from rule #2&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Layer Mtl2OnPremRZ disables template offloads from rule #1&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Layer Azure2OnPrem RZ disables template offloads from rule #1&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Layer RZ-OnPrem&amp;amp;Azure disables template offloads from rule #8&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Drop Templates : enabled&lt;BR /&gt;NAT Templates : disabled by Firewall&lt;BR /&gt;Layer CIRB incoming disables template offloads from rule #3&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Layer RZ Inbound disables template offloads from rule #1&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Layer OnPrem2AzureInfrastructure disables template offloads from rule #2&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Layer Mtl2OnPremRZ disables template offloads from rule #1&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Layer Azure2OnPrem RZ disables template offloads from rule #1&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Layer RZ-OnPrem&amp;amp;Azure disables template offloads from rule #8&lt;BR /&gt;Throughput acceleration still enabled.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Command #2: fwaccel stats -s |&lt;BR /&gt;| |&lt;BR /&gt;| Check for : Accelerated conns/Totals conns: &amp;gt;25% good, &amp;gt;50% great |&lt;BR /&gt;| Accelerated pkts/Total pkts : &amp;gt;50% great |&lt;BR /&gt;| PXL pkts/Total pkts : &amp;gt;50% OK |&lt;BR /&gt;| F2Fed pkts/Total pkts : &amp;lt;30% good, &amp;lt;10% great |&lt;BR /&gt;| |&lt;BR /&gt;| Chapter 9: SecureXL throughput acceleration |&lt;BR /&gt;| Page 287, Packet/Throughput Acceleration: The Three Kernel Paths |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Output: |&lt;BR /&gt;Accelerated conns/Total conns : 46/31721 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 171313823924/173420969516 (98%)&lt;BR /&gt;F2Fed pkts/Total pkts : 2107145592/173420969516 (1%)&lt;BR /&gt;F2V pkts/Total pkts : 347523193/173420969516 (0%)&lt;BR /&gt;CPASXL pkts/Total pkts : 51117776512/173420969516 (29%)&lt;BR /&gt;PSLXL pkts/Total pkts : 118964632574/173420969516 (68%)&lt;BR /&gt;CPAS pipeline pkts/Total pkts : 0/173420969516 (0%)&lt;BR /&gt;PSL pipeline pkts/Total pkts : 0/173420969516 (0%)&lt;BR /&gt;CPAS inline pkts/Total pkts : 0/173420969516 (0%)&lt;BR /&gt;PSL inline pkts/Total pkts : 0/173420969516 (0%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/173420969516 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/173420969516 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/173420969516 (0%)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Command #3: grep -c ^processor /proc/cpuinfo &amp;amp;&amp;amp; /sbin/cpuinfo |&lt;BR /&gt;| |&lt;BR /&gt;| Check for : If number of cores is roughly double what you are excpecting, |&lt;BR /&gt;| hyperthreading may be enabled |&lt;BR /&gt;| |&lt;BR /&gt;| Chapter 7: CoreXL Tuning |&lt;BR /&gt;| Page 239 |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Output: |&lt;BR /&gt;8&lt;BR /&gt;HyperThreading=disabled&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Command #4: fw ctl affinity -l -r |&lt;BR /&gt;| |&lt;BR /&gt;| Check for : SND/IRQ/Dispatcher Cores, # of CPU's allocated to interface(s) |&lt;BR /&gt;| Firewall Workers/INSPECT Cores, # of CPU's allocated to fw_x |&lt;BR /&gt;| R77.30: Support processes executed on ALL CPU's |&lt;BR /&gt;| R80.xx: Support processes only executed on Firewall Worker Cores|&lt;BR /&gt;| |&lt;BR /&gt;| Chapter 7: CoreXL Tuning |&lt;BR /&gt;| Page 221 |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Output: |&lt;BR /&gt;CPU 0: eth1 eth2 eth3&lt;BR /&gt;CPU 1: fw_5&lt;BR /&gt;fwd lpd in.acapd mta_monitor in.asessiond usrchkd dtpsd pepd mpdaemon vpnd wsdnsd rtmd cprid fwpushd in.emaild.mta rad dtlsd core_uploader pdpd in.geod cpd cprid&lt;BR /&gt;CPU 2: fw_3&lt;BR /&gt;fwd lpd in.acapd mta_monitor in.asessiond usrchkd dtpsd pepd mpdaemon vpnd wsdnsd rtmd cprid fwpushd in.emaild.mta rad dtlsd core_uploader pdpd in.geod cpd cprid&lt;BR /&gt;CPU 3: fw_1&lt;BR /&gt;fwd lpd in.acapd mta_monitor in.asessiond usrchkd dtpsd pepd mpdaemon vpnd wsdnsd rtmd cprid fwpushd in.emaild.mta rad dtlsd core_uploader pdpd in.geod cpd cprid&lt;BR /&gt;CPU 4:&lt;BR /&gt;CPU 5: fw_4&lt;BR /&gt;fwd lpd in.acapd mta_monitor in.asessiond usrchkd dtpsd pepd mpdaemon vpnd wsdnsd rtmd cprid fwpushd in.emaild.mta rad dtlsd core_uploader pdpd in.geod cpd cprid&lt;BR /&gt;CPU 6: fw_2&lt;BR /&gt;fwd lpd in.acapd mta_monitor in.asessiond usrchkd dtpsd pepd mpdaemon vpnd wsdnsd rtmd cprid fwpushd in.emaild.mta rad dtlsd core_uploader pdpd in.geod cpd cprid&lt;BR /&gt;CPU 7: fw_0&lt;BR /&gt;fwd lpd in.acapd mta_monitor in.asessiond usrchkd dtpsd pepd mpdaemon vpnd wsdnsd rtmd cprid fwpushd in.emaild.mta rad dtlsd core_uploader pdpd in.geod cpd cprid&lt;BR /&gt;All:&lt;BR /&gt;Interface eth8: has multi queue enabled&lt;BR /&gt;Interface eth9: has multi queue enabled&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Command #5: netstat -ni |&lt;BR /&gt;| |&lt;BR /&gt;| Check for : RX/TX errors |&lt;BR /&gt;| RX-DRP % should be &amp;lt;0.1% calculated by (RX-DRP/RX-OK)*100 |&lt;BR /&gt;| TX-ERR might indicate Fast Ethernet/100Mbps Duplex Mismatch |&lt;BR /&gt;| |&lt;BR /&gt;| Chapter 2: Layers 1&amp;amp;2 Performance Optimization |&lt;BR /&gt;| Page 28-35 |&lt;BR /&gt;| |&lt;BR /&gt;| Chapter 7: CoreXL Tuning |&lt;BR /&gt;| Page 204 |&lt;BR /&gt;| Page 206 (Network Buffering Misses) |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Output: |&lt;BR /&gt;Kernel Interface table&lt;BR /&gt;Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg&lt;BR /&gt;bond1 1500 0 131205881921 0 0 0 98197788926 0 0 0 BMmRU&lt;BR /&gt;bond1.2 1500 0 11075878 0 49750 0 19263187 0 0 0 BMRU&lt;BR /&gt;bond1.11 1500 0 10190083 0 156 0 9717573 0 0 0 BMRU&lt;BR /&gt;bond1.100 1500 0 77510858121 0 1307019 0 78822159513 0 0 0 BMRU&lt;BR /&gt;bond1.106 1500 0 4380993 0 379761 0 235075028 0 0 0 BMRU&lt;BR /&gt;bond1.108 1500 0 17092053715 0 183806 0 5674536270 0 0 0 BMRU&lt;BR /&gt;bond1.112 1500 0 21332727560 0 823 0 5877593652 0 0 0 BMRU&lt;BR /&gt;bond1.140 1500 0 2742324 0 917 0 2677623 0 0 0 BMRU&lt;BR /&gt;bond1.150 1500 0 3164913167 0 59 0 642979284 0 0 0 BMRU&lt;BR /&gt;bond1.152 1500 0 192985 0 0 0 149949 0 0 0 BMRU&lt;BR /&gt;bond1.160 1500 0 827531034 0 24259 0 229120864 0 0 0 BMRU&lt;BR /&gt;bond1.170 1500 0 13975269 0 31 0 12763680 0 0 0 BMRU&lt;BR /&gt;bond1.171 1500 0 19 0 0 0 42795 0 0 0 BMRU&lt;BR /&gt;bond1.355 1500 0 5484716373 0 0 0 4311281028 0 0 0 BMRU&lt;BR /&gt;bond1.500 1500 0 3778665907 0 2438 0 1726948704 0 0 0 BMRU&lt;BR /&gt;bond1.550 1500 0 565614091 0 17 0 192662881 0 0 0 BMRU&lt;BR /&gt;bond1.560 1500 0 585068115 0 202 0 215526710 0 0 0 BMRU&lt;BR /&gt;bond1.570 1500 0 815696026 0 358 0 238497128 0 0 0 BMRU&lt;BR /&gt;bond1.804 1500 0 5303533 0 0 0 9059566 0 0 0 BMRU&lt;BR /&gt;eth1 1500 0 7191113 0 6 0 8530266 0 0 0 BMRU&lt;BR /&gt;eth2 1500 0 42402513961 0 321122427 0 114851655091 0 0 0 BMRU&lt;BR /&gt;eth3 1500 0 559319557 0 333462 0 546147561 0 0 0 BMRU&lt;BR /&gt;eth8 1500 0 63152389162 0 0 0 13837171475 0 0 0 BMsRU&lt;BR /&gt;eth9 1500 0 68053487950 0 0 0 84360614272 0 0 0 BMsRU&lt;BR /&gt;lo 65536 0 81592231 0 0 0 81592231 0 0 0 ALMPRU&lt;/P&gt;&lt;P&gt;interface eth1: &amp;#27;[32mThere were no RX drops in the past 0.5 seconds&amp;#27;(B&amp;#27;[m&lt;BR /&gt;interface eth1 rx_missed_errors :&lt;BR /&gt;interface eth1 rx_fifo_errors :&lt;BR /&gt;interface eth1 rx_no_buffer_count:&lt;/P&gt;&lt;P&gt;interface eth2: &amp;#27;[32mThere were no RX drops in the past 0.5 seconds&amp;#27;(B&amp;#27;[m&lt;BR /&gt;interface eth2 rx_missed_errors :&lt;BR /&gt;interface eth2 rx_fifo_errors :&lt;BR /&gt;interface eth2 rx_no_buffer_count:&lt;/P&gt;&lt;P&gt;interface eth3: &amp;#27;[32mThere were no RX drops in the past 0.5 seconds&amp;#27;(B&amp;#27;[m&lt;BR /&gt;interface eth3 rx_missed_errors :&lt;BR /&gt;interface eth3 rx_fifo_errors :&lt;BR /&gt;interface eth3 rx_no_buffer_count:&lt;/P&gt;&lt;P&gt;interface eth8: &amp;#27;[32mThere were no RX drops in the past 0.5 seconds&amp;#27;(B&amp;#27;[m&lt;BR /&gt;interface eth8 rx_missed_errors : 0&lt;BR /&gt;interface eth8 rx_fifo_errors : 0&lt;BR /&gt;interface eth8 rx_no_buffer_count: 0&lt;/P&gt;&lt;P&gt;interface eth9: &amp;#27;[32mThere were no RX drops in the past 0.5 seconds&amp;#27;(B&amp;#27;[m&lt;BR /&gt;interface eth9 rx_missed_errors : 0&lt;BR /&gt;interface eth9 rx_fifo_errors : 0&lt;BR /&gt;interface eth9 rx_no_buffer_count: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Command #6: fw ctl multik stat |&lt;BR /&gt;| |&lt;BR /&gt;| Check for : Large # of conns on Worker 0 - IPSec VPN/VoIP? |&lt;BR /&gt;| Large imbalance of connections on a single or multiple Workers |&lt;BR /&gt;| |&lt;BR /&gt;| Chapter 7: CoreXL Tuning |&lt;BR /&gt;| Page 241 |&lt;BR /&gt;| |&lt;BR /&gt;| Chapter 8: CoreXL VPN Optimization |&lt;BR /&gt;| Page 256 |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Output: |&lt;BR /&gt;ID | Active | CPU | Connections | Peak&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;0 | Yes | 7 | 8073 | 11972&lt;BR /&gt;1 | Yes | 3 | 2891 | 9650&lt;BR /&gt;2 | Yes | 6 | 7990 | 10876&lt;BR /&gt;3 | Yes | 2 | 7732 | 10735&lt;BR /&gt;4 | Yes | 5 | 2764 | 8529&lt;BR /&gt;5 | Yes | 1 | 4610 | 9798&lt;/P&gt;&lt;P&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Command #7: cpstat os -f multi_cpu -o 1 -c 5 |&lt;BR /&gt;| |&lt;BR /&gt;| Check for : High SND/IRQ Core Utilization |&lt;BR /&gt;| High Firewall Worker Core Utilization |&lt;BR /&gt;| |&lt;BR /&gt;| Chapter 6: CoreXL &amp;amp; Multi-Queue |&lt;BR /&gt;| Page 173 |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Output: |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 76| 24| 76| ?| 42582|&lt;BR /&gt;| 2| 1| 99| 1| 99| ?| 42582|&lt;BR /&gt;| 3| 7| 58| 35| 65| ?| 42582|&lt;BR /&gt;| 4| 0| 100| 0| 100| ?| 42582|&lt;BR /&gt;| 5| 0| 8| 92| 8| ?| 42582|&lt;BR /&gt;| 6| 0| 100| 0| 100| ?| 42582|&lt;BR /&gt;| 7| 5| 62| 33| 67| ?| 42582|&lt;BR /&gt;| 8| 4| 70| 26| 74| ?| 42582|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 76| 24| 76| ?| 42582|&lt;BR /&gt;| 2| 1| 99| 1| 99| ?| 42582|&lt;BR /&gt;| 3| 7| 58| 35| 65| ?| 42582|&lt;BR /&gt;| 4| 0| 100| 0| 100| ?| 42582|&lt;BR /&gt;| 5| 0| 8| 92| 8| ?| 42582|&lt;BR /&gt;| 6| 0| 100| 0| 100| ?| 42582|&lt;BR /&gt;| 7| 5| 62| 33| 67| ?| 42582|&lt;BR /&gt;| 8| 4| 70| 26| 74| ?| 42582|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 78| 22| 78| ?| 87287|&lt;BR /&gt;| 2| 0| 100| 0| 100| ?| 43644|&lt;BR /&gt;| 3| 12| 49| 39| 61| ?| 87290|&lt;BR /&gt;| 4| 0| 100| 0| 100| ?| 43646|&lt;BR /&gt;| 5| 0| 7| 93| 7| ?| 87296|&lt;BR /&gt;| 6| 0| 100| 0| 100| ?| 43648|&lt;BR /&gt;| 7| 2| 79| 19| 81| ?| 87299|&lt;BR /&gt;| 8| 3| 67| 30| 70| ?| 87303|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 78| 22| 78| ?| 87287|&lt;BR /&gt;| 2| 0| 100| 0| 100| ?| 43644|&lt;BR /&gt;| 3| 12| 49| 39| 61| ?| 87290|&lt;BR /&gt;| 4| 0| 100| 0| 100| ?| 43646|&lt;BR /&gt;| 5| 0| 7| 93| 7| ?| 87296|&lt;BR /&gt;| 6| 0| 100| 0| 100| ?| 43648|&lt;BR /&gt;| 7| 2| 79| 19| 81| ?| 87299|&lt;BR /&gt;| 8| 3| 67| 30| 70| ?| 87303|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 78| 22| 78| ?| 84875|&lt;BR /&gt;| 2| 0| 100| 0| 100| ?| 42437|&lt;BR /&gt;| 3| 7| 55| 38| 62| ?| 84873|&lt;BR /&gt;| 4| 0| 100| 0| 100| ?| 42438|&lt;BR /&gt;| 5| 0| 7| 93| 7| ?| 84875|&lt;BR /&gt;| 6| 0| 100| 0| 100| ?| 42437|&lt;BR /&gt;| 7| 1| 79| 20| 80| ?| 84883|&lt;BR /&gt;| 8| 3| 60| 37| 63| ?| 84882|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;| Thanks for using s7pac |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 16:38:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159590#M27972</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-10-14T16:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159592#M27974</link>
      <description />
      <pubDate>Fri, 14 Oct 2022 16:56:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159592#M27974</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-10-14T16:56:06Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159600#M27976</link>
      <description>&lt;P&gt;This is a bit concerning:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Accept Templates : disabled by Firewall
                   Layer CIRB incoming disables template offloads from rule #3
                   Throughput acceleration still enabled.
                   Layer RZ Inbound disables template offloads from rule #1
                   Throughput acceleration still enabled.
                   Layer OnPrem2AzureInfrastructure disables template offloads from rule #2
                   Throughput acceleration still enabled.
                   Layer Mtl2OnPremRZ disables template offloads from rule #1
                   Throughput acceleration still enabled.
                   Layer Azure2OnPrem RZ disables template offloads from rule #1
                   Throughput acceleration still enabled.
                   Layer RZ-OnPrem&amp;amp;Azure disables template offloads from rule #8
                   Throughput acceleration still enabled.&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;BR /&gt;That said, most of your packets are accelerated, so this may not be a big deal.&lt;BR /&gt;You do have a large number of receive drops on your bond interface and on eth2, which might be something worth investigating.&lt;/P&gt;
&lt;P&gt;What version/JHF are we working with here on what precise hardware?&lt;BR /&gt;output of enabled_blades would also be helpful to further contextualize this.&lt;/P&gt;
&lt;P&gt;Also, you have 10 connections that are taking 92% of the CPU.&lt;BR /&gt;What precisely are these connections for and what precise policies relate to them?&lt;BR /&gt;Depending on what they are (and if they are trusted), we can fully accelerate them using fast_accel to reduce the overall CPU load.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 17:54:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159600#M27976</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-14T17:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159601#M27977</link>
      <description>&lt;P&gt;I looked at the mentioned layers and rule numbers where it says disables template offload but I don't see/notice anything particular about them.&lt;/P&gt;&lt;P&gt;We're running R80.40 JHF 173 on a pair of HP Proliant servers. The connections taking all that CPU are from the backup server so they would be trusted. Maybe it's always been like that and I just happened to notice it today but I don't think so. Is it easy to fully accelerate the connections from that server?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 18:03:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159601#M27977</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-10-14T18:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159602#M27978</link>
      <description>&lt;P&gt;Yes, using fw ctl fast_accel.&lt;BR /&gt;Refer to:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk156672&amp;amp;partition=Advanced&amp;amp;product=SecureXL" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk156672&amp;amp;partition=Advanced&amp;amp;product=SecureXL&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 18:08:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159602#M27978</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-14T18:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159603#M27979</link>
      <description>&lt;P&gt;once added should it be effective immediatly or just on new connections?&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 18:15:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159603#M27979</guid>
      <dc:creator>flachance</dc:creator>
      <dc:date>2022-10-14T18:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159605#M27981</link>
      <description>&lt;P&gt;Given how SecureXL works in R80.20 and above, I believe it should be effective immediately.&lt;BR /&gt;However, it might require a new connection to be established.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 18:23:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-CPU/m-p/159605#M27981</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-14T18:23:27Z</dc:date>
    </item>
  </channel>
</rss>

