<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High latency after Checkpoint firewall from R77.30 to R80.10 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37204#M3003</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Almost sounds like firewall under load. Have you checked CPU/ram/throughput? How do you run your ping from FW to switch or vice versa?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Mar 2018 16:00:49 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2018-03-21T16:00:49Z</dc:date>
    <item>
      <title>High latency after Check Point firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37201#M3000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As before we are running on CP R77.30 hardware model is 13500 with cluster appliance with smooth and normal performance. But after upgrade to R80.10 all network performance to slow down, for example,&amp;nbsp;we have PRTG monitor (network via checkpoint)&amp;nbsp;have monitor our website performance, on R77.30 the loading time around 5x-1xx ms, after R80.10 drop to 5xx - 4xxxx ms. The second case is we have ping test under our core switch, the interface plug into Checkpoint firewall directly. The R77.30 ping time is below 5ms, after R80.10 over 1x - 5x ms.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that's very&amp;nbsp;simple evidence and test result. But how to be next step? Hope I can get more advice, Tks guys&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 14:53:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37201#M3000</guid>
      <dc:creator>Ben_Fung</dc:creator>
      <dc:date>2018-03-21T14:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37202#M3001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you verify that the cluster and the network interfaces&amp;nbsp;are in a good state using cli?&lt;/P&gt;&lt;P&gt;the ICMP echo from adjacent switch should not be taking that long.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the cluster members connected to the HSRP pair of switches?&lt;/P&gt;&lt;P&gt;Do you have a vMAC enabled on the cluster?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 15:13:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37202#M3001</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-03-21T15:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37203#M3002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems no packet lost when I check in cli.&lt;/P&gt;&lt;P&gt;Our core switch is H3C, i remember it's using VRRP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for vMAC, are you said the Checkpoint cluster enable vMAC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tks&amp;nbsp;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 15:16:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37203#M3002</guid>
      <dc:creator>Ben_Fung</dc:creator>
      <dc:date>2018-03-21T15:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37204#M3003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Almost sounds like firewall under load. Have you checked CPU/ram/throughput? How do you run your ping from FW to switch or vice versa?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 16:00:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37204#M3003</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-21T16:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37205#M3004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does the speed and duplex look good on all interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As to vMAC, you have option of enabling it:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63990_pastedImage_1.png" style="width: 620px; height: 315px;" /&gt;&lt;/P&gt;&lt;P&gt;Depending on topology of your network, use of STP, etc., it may make sense to enable it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can, do the "&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;tcpdump -tttt -ne host &amp;lt;IP of the cluster&amp;gt;" on your switch and check if the replies are coming from the expected interface of the active cluster member or vMAC.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 16:22:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37205#M3004</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-03-21T16:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37206#M3005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tough to say but it sounds like you may have cluster-related issues if latency has spiked that much after the upgrade.&amp;nbsp; Easy way to determine that is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Power off the standby cluster member.&amp;nbsp; Does the latency situation improve?&amp;nbsp; If it does, your problem is cluster-related and you need to have a look at logs with the "type:Control" log filter to see what is going on.&amp;nbsp; If the cluster is not stable and constantly failing over you may need to set broadcast mode for CCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Next step is to ensure the network is running cleanly.&amp;nbsp; Are all firewall interfaces running at 1Gbps or higher speed?&amp;nbsp; Any Fast Ethernet (100Mbps) interfaces need to be checked for a duplex mismatch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Was the firewall upgrade in-place (i.e. upgraded the same hardware directly from R77.30 to R80.10 with CPUSE) or forklift (new firewall hardware scratch-loaded and dropped into place).&amp;nbsp; If it is the latter you may have lost some local adjustments in fwkern.conf or /etc/rc.local, or may be running with the default CoreXL split of 2/14 which almost always needs to be adjusted on a 13500 in the real world.&amp;nbsp; You can check the CoreXL split with &lt;STRONG&gt;fw ctl affinity -l -r&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failing all of those, please post the output from the following "Super Seven" commands run in expert mode on the primary/active cluster member during an observed period of high latency and I can advise further:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fwaccel stat&lt;/P&gt;&lt;P&gt;fwaccel stats -s&lt;/P&gt;&lt;P&gt;grep -c ^processor /proc/cpuinfo&lt;/P&gt;&lt;P&gt;fw ctl affinity -l -r&lt;/P&gt;&lt;P&gt;netstat -ni&lt;/P&gt;&lt;P&gt;fw ctl multik stat&lt;/P&gt;&lt;P&gt;cpstat os -f multi_cpu -o 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 16:46:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37206#M3005</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-03-21T16:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37207#M3006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As checked the speed and duplex look good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for vMAC, we haven't enable on ClusterXL. But it will make network down when enable this function? Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 01:29:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37207#M3006</guid>
      <dc:creator>Ben_Fung</dc:creator>
      <dc:date>2018-03-22T01:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37208#M3007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can give some ping test result as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CPU loading&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63997_pastedImage_3.png" style="width: 620px; height: 633px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping Result&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63995_pastedImage_1.png" style="width: 620px; height: 683px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 04:02:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37208#M3007</guid>
      <dc:creator>Ben_Fung</dc:creator>
      <dc:date>2018-03-22T04:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37209#M3008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about other commands that Tim asked for? Acceleration, interface stats, CoreXL?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 05:02:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37209#M3008</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-22T05:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37210#M3009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also what interface speed is set on the interface you run ping on and what is the throughput there?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 05:04:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37210#M3009</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-22T05:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37211#M3010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ben,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you contact our support ? &lt;BR /&gt;if so, Please share SR#....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eyal Rashelbach&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; color: gray;"&gt;R80 Desk Manager | Solution Center | Check Point Software Technologies&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 08:09:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37211#M3010</guid>
      <dc:creator>Eyal_Rashelbach</dc:creator>
      <dc:date>2018-03-22T08:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37212#M3011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is infromation follow your "Super Serven" command, Tks for your help, and know new terms of checkpoint&amp;nbsp;&lt;SPAN&gt;"Super Serven".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@LMPRCPFW01:0]# fwaccel stat&lt;BR /&gt;Accelerator Status : on&lt;BR /&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;Layer PDC_CP_Firewall Security disables template offloads from rule #116&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Drop Templates : disabled&lt;BR /&gt;NAT Templates : disabled by user&lt;BR /&gt;NMR Templates : enabled&lt;BR /&gt;NMT Templates : enabled&lt;/P&gt;&lt;P&gt;Accelerator Features : Accounting, NAT, Cryptography, Routing,&lt;BR /&gt;HasClock, Templates, Synchronous, IdleDetection,&lt;BR /&gt;Sequencing, TcpStateDetect, AutoExpire,&lt;BR /&gt;DelayedNotif, TcpStateDetectV2, CPLS, McastRouting,&lt;BR /&gt;WireMode, DropTemplates, NatTemplates,&lt;BR /&gt;Streaming, MultiFW, AntiSpoofing, Nac,&lt;BR /&gt;ViolationStats, AsychronicNotif, ERDOS,&lt;BR /&gt;McastRoutingV2, NMR, NMT, NAT64, GTPAcceleration,&lt;BR /&gt;SCTPAcceleration&lt;BR /&gt;Cryptography Features : Tunnel, UDPEncapsulation, MD5, SHA1, NULL,&lt;BR /&gt;3DES, DES, CAST, CAST-40, AES-128, AES-256,&lt;BR /&gt;ESP, LinkSelection, DynamicVPN, NatTraversal,&lt;BR /&gt;EncRouting, AES-XCBC, SHA256&lt;BR /&gt;[Expert@LMPRCPFW01:0]# fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 0/94 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 0/6854226 (0%)&lt;BR /&gt;F2Fed pkts/Total pkts : 6854226/6854226 (100%)&lt;BR /&gt;PXL pkts/Total pkts : 0/6854226 (0%)&lt;BR /&gt;QXL pkts/Total pkts : 0/6854226 (0%)&lt;BR /&gt;[Expert@LMPRCPFW01:0]# grep -c ^processor /proc/cpuinfo&lt;BR /&gt;16&lt;BR /&gt;[Expert@LMPRCPFW01:0]# fw ctl affinity -l -r&lt;BR /&gt;CPU 0: eth2-01 eth2-02 eth1-07 eth1-08 eth2-04 Mgmt Sync&lt;BR /&gt;CPU 1: eth1-01 eth1-02 eth1-03 eth1-04 eth1-05 eth1-06 eth2-03&lt;BR /&gt;CPU 2: fw_13&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 3: fw_12&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 4: fw_11&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 5: fw_10&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 6: fw_9&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 7: fw_8&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 8: fw_7&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 9: fw_6&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 10: fw_5&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 11: fw_4&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 12: fw_3&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 13: fw_2&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 14: fw_1&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;CPU 15: fw_0&lt;BR /&gt;fwd pepd lpd usrchkd in.msd mpdaemon pdpd vpnd fwucd rad in.emaild.mta in.acapd cpd cprid&lt;BR /&gt;All:&lt;BR /&gt;[Expert@LMPRCPFW01:0]# netstat -ni&lt;BR /&gt;Kernel Interface table&lt;BR /&gt;Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg&lt;BR /&gt;Mgmt 1500 0 13702966 0 0 0 15962552 0 0 0 BMRU&lt;BR /&gt;Sync 1500 0 333650207 0 0 0 121769745 0 0 0 BMRU&lt;BR /&gt;bond2 1500 0 1441565252 1 0 0 1627548069 0 0 0 BMmRU&lt;BR /&gt;bond2.10 1500 0 238388484 0 0 0 147686142 0 0 0 BMmRU&lt;BR /&gt;bond2.163 1500 0 818903388 0 0 0 341775356 0 0 0 BMmRU&lt;BR /&gt;bond2.700 1500 0 384199869 0 0 0 214359826 0 0 0 BMmRU&lt;BR /&gt;bond3 1500 0 12815465 0 0 0 23478665 0 0 0 BMmRU&lt;BR /&gt;bond3.801 1500 0 4692593 0 0 0 4421277 0 0 0 BMmRU&lt;BR /&gt;bond3.1014 1500 0 1162293 0 0 0 595678 0 0 0 BMmRU&lt;BR /&gt;bond3.1209 1500 0 2280454 0 0 0 668717 0 0 0 BMmRU&lt;BR /&gt;bond3.1688 1500 0 4643707 0 0 0 4425602 0 0 0 BMmRU&lt;BR /&gt;eth1-01 1500 0 81281889 0 472 472 83202416 0 0 0 BMRU&lt;BR /&gt;eth1-02 1500 0 199227419 0 111 111 146528821 0 0 0 BMRU&lt;BR /&gt;eth1-03 1500 0 390331603 0 0 0 882904179 0 0 0 BMRU&lt;BR /&gt;eth1-04 1500 0 66707804 0 0 0 19987560 0 0 0 BMRU&lt;BR /&gt;eth1-04.210 1500 0 66707804 0 0 0 8818908 0 0 0 BMRU&lt;BR /&gt;eth1-05 1500 0 1012244443 0 0 0 443288453 0 0 0 BMRU&lt;BR /&gt;eth1-06 1500 0 4077432 0 0 0 4185548 0 0 0 BMRU&lt;BR /&gt;eth1-07 1500 0 8568255 0 0 0 11757975 0 0 0 BMRU&lt;BR /&gt;eth1-08 1500 0 333934975 0 0 0 122084202 0 0 0 BMRU&lt;BR /&gt;eth2-01 1500 0 724739031 1 0 0 508740663 0 0 0 BMsRU&lt;BR /&gt;eth2-02 1500 0 716826232 0 0 0 1118807427 0 0 0 BMsRU&lt;BR /&gt;eth2-03 1500 0 11301424 0 0 0 11329734 0 0 0 BMsRU&lt;BR /&gt;eth2-04 1500 0 1514041 0 0 0 12148931 0 0 0 BMsRU&lt;BR /&gt;lo 16436 0 2623169 0 0 0 2623169 0 0 0 LRU&lt;BR /&gt;[Expert@LMPRCPFW01:0]# fw ctl multik stat&lt;BR /&gt;ID | Active | CPU | Connections | Peak&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;0 | Yes | 15 | 6753 | 8506&lt;BR /&gt;1 | Yes | 14 | 3750 | 5886&lt;BR /&gt;2 | Yes | 13 | 1529 | 6240&lt;BR /&gt;3 | Yes | 12 | 3078 | 6010&lt;BR /&gt;4 | Yes | 11 | 5029 | 6191&lt;BR /&gt;5 | Yes | 10 | 4485 | 6400&lt;BR /&gt;6 | Yes | 9 | 4878 | 6110&lt;BR /&gt;7 | Yes | 8 | 4577 | 6070&lt;BR /&gt;8 | Yes | 7 | 4711 | 5961&lt;BR /&gt;9 | Yes | 6 | 3953 | 6203&lt;BR /&gt;10 | Yes | 5 | 4908 | 6233&lt;BR /&gt;11 | Yes | 4 | 3546 | 6288&lt;BR /&gt;12 | Yes | 3 | 4134 | 5883&lt;BR /&gt;13 | Yes | 2 | 3878 | 6141&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert@LMPRCPFW01:0]#cpstat os -f multi_cpu -o 1&lt;BR /&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 2| 99| 1| ?| 3313|&lt;BR /&gt;| 2| 0| 0| 100| 0| ?| 3313|&lt;BR /&gt;| 3| 1| 1| 98| 2| ?| 3313|&lt;BR /&gt;| 4| 2| 3| 96| 4| ?| 3313|&lt;BR /&gt;| 5| 1| 1| 98| 2| ?| 3313|&lt;BR /&gt;| 6| 0| 1| 98| 2| ?| 3313|&lt;BR /&gt;| 7| 0| 0| 100| 0| ?| 3314|&lt;BR /&gt;| 8| 0| 1| 100| 0| ?| 3315|&lt;BR /&gt;| 9| 0| 1| 99| 1| ?| 3315|&lt;BR /&gt;| 10| 2| 2| 96| 4| ?| 3315|&lt;BR /&gt;| 11| 0| 1| 98| 2| ?| 3315|&lt;BR /&gt;| 12| 0| 1| 98| 2| ?| 3315|&lt;BR /&gt;| 13| 0| 1| 100| 0| ?| 3315|&lt;BR /&gt;| 14| 0| 1| 99| 1| ?| 3315|&lt;BR /&gt;| 15| 0| 1| 99| 1| ?| 3315|&lt;BR /&gt;| 16| 0| 1| 99| 1| ?| 3315|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 01:21:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37212#M3011</guid>
      <dc:creator>Ben_Fung</dc:creator>
      <dc:date>2018-03-23T01:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37213#M3012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The case now handle by the local distributor, I think they haven't created SR at this moment. &lt;SPAN&gt;the local distributor has arrange the local / remote&amp;nbsp;session but no finding. So I want to find&amp;nbsp;another channel to help this case.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, on remote session yesterday, I very strange that why the local distributor TAC said ping high latency is normal at CheckPoint firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 01:25:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37213#M3012</guid>
      <dc:creator>Ben_Fung</dc:creator>
      <dc:date>2018-03-23T01:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37214#M3013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All interface speed is 1G&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 01:27:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37214#M3013</guid>
      <dc:creator>Ben_Fung</dc:creator>
      <dc:date>2018-03-23T01:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37215#M3014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;one more test. on Checkpoint firewall active node ping the local interface, seems lager ping time suddenly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64021_pastedImage_1.png" style="width: 620px; height: 392px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 01:32:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37215#M3014</guid>
      <dc:creator>Ben_Fung</dc:creator>
      <dc:date>2018-03-23T01:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37216#M3015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ben&lt;/P&gt;&lt;P&gt;Do you ever try to check ring buffer size issue?&lt;/P&gt;&lt;P style="font-size: 12px;"&gt;sk42181&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 02:53:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37216#M3015</guid>
      <dc:creator>RickLin</dc:creator>
      <dc:date>2018-03-23T02:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37217#M3016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Acceleration is not working at all (neither fast path nor medium) so you need to dig into that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;F2Fed pkts/Total pkts : 6854226/6854226 (100%)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;Pls add full stats&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;faccel stats&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 05:35:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37217#M3016</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-23T05:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37218#M3017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may read and try yourself advance guide for SecureXL&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98722" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98722"&gt;ATRG: SecureXL&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But good start would be cpview tool and&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL style="color: #000000; background-color: #ffffff; font-size: 14px;" type="square"&gt;&lt;LI&gt;On the '&lt;CODE&gt;SysInfo&lt;/CODE&gt;' tab, refer to '&lt;CODE&gt;Configuration Information:&lt;/CODE&gt;' section - look at '&lt;CODE&gt;PPack Status&lt;/CODE&gt;'&lt;/LI&gt;&lt;LI&gt;On the '&lt;CODE&gt;Traffic&lt;/CODE&gt;' tab, go to '&lt;CODE&gt;Overview&lt;/CODE&gt;' menu - refer to section '&lt;CODE&gt;Templates:&lt;/CODE&gt;'&lt;/LI&gt;&lt;LI&gt;On the '&lt;CODE&gt;I/S&lt;/CODE&gt;' tab, go to '&lt;CODE&gt;SXL&lt;/CODE&gt;' menu - go to '&lt;CODE&gt;Overview&lt;/CODE&gt;' menu&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 06:11:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37218#M3017</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-23T06:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37219#M3018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Send a screenshot of rule 116 btw&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 06:14:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37219#M3018</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-23T06:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: High latency after Checkpoint firewall from R77.30 to R80.10</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37220#M3019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest to consult &lt;STRONG&gt;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98348" rel="nofollow"&gt;sk98348&lt;/A&gt;&lt;/STRONG&gt;:&lt;STRONG&gt; Best Practices - Security Gateway Performance - &lt;/STRONG&gt;Including some useful tips for SecureXL, CoreXL, HyperThreading, Multi-Queue, and some references to other very good SKs about ClusterXL or VPN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 10:50:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/High-latency-after-Check-Point-firewall-from-R77-30-to-R80-10/m-p/37220#M3019</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-23T10:50:43Z</dc:date>
    </item>
  </channel>
</rss>

