<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fifo errors in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171708#M31151</link>
    <description>&lt;P&gt;Honestly, since reading all your answers, it suggests to me this is concerning, and I would be as well if I were you, I would open TAC support case and have them verify everything.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Feb 2023 14:06:35 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-02-16T14:06:35Z</dc:date>
    <item>
      <title>Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171696#M31141</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;i am having an issue with increasing rx drops on the Internet interface.&lt;BR /&gt;the Security Gateway is brand new and installed only a week, the appliance is 6900 Plus model (not clustered) who replaced a 7 years old 6600 gateway which not present this kind of errors. (configurations are exactly the same)&lt;BR /&gt;version of SMS and the Gateway is R80.40 take 180.&lt;/P&gt;&lt;P&gt;netstat -i shows RX-DRP errors on the interface&lt;BR /&gt;eth7 1500 0 329723032 0 16865 16865 247209762 0 0 0 BMRU&lt;/P&gt;&lt;P&gt;ethtool -S eth7 | grep error shows the number of RX-DRP (16865) on&lt;BR /&gt;rx_missed_errors: 16865&lt;BR /&gt;rx_fifo_errors: 16865&lt;/P&gt;&lt;P&gt;i will love to get some help on investigate this issue.&lt;/P&gt;&lt;P&gt;Thank you in advance, Yossi.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 13:29:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171696#M31141</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2023-02-16T13:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171699#M31142</link>
      <description>&lt;P&gt;Can you send the output of cpconfig and corexl info section?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 13:40:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171699#M31142</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-16T13:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171700#M31143</link>
      <description>&lt;P&gt;Hi, thank you for the fast response.&lt;/P&gt;&lt;P&gt;Configuring Check Point CoreXL...&lt;BR /&gt;=================================&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;CoreXL is currently enabled with 14 IPv4 firewall instances.&lt;/P&gt;&lt;P&gt;(1) Change the number of firewall instances&lt;BR /&gt;(2) Disable Check Point CoreXL&lt;/P&gt;&lt;P&gt;(3) Exit&lt;BR /&gt;Enter your choice (1-3) :&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 13:42:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171700#M31143</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2023-02-16T13:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171701#M31144</link>
      <description>&lt;P&gt;K, so that seems to be the default I believe, if it says 14, thats fine. What is eth7 used for? You can also run below and see what you get:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;cat $FWDIR/conf/fwaffinity.conf&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;fw ctl affinity -l -r -v -a&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Reference links:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Automatic-sim-affinity-deprecated-in-R80-40/m-p/114698#M21438" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Automatic-sim-affinity-deprecated-in-R80-40/m-p/114698#M21438&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Scalable-Chassis/File-edit-FWDIR-conf-fwaffinity-conf/m-p/153237#M315" target="_blank"&gt;https://community.checkpoint.com/t5/Scalable-Chassis/File-edit-FWDIR-conf-fwaffinity-conf/m-p/153237#M315&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 13:45:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171701#M31144</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-16T13:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171702#M31145</link>
      <description>&lt;P&gt;Forgot to mention, can you also run ethtool -i eth7 and under cpconfig, when you press corexl, if you do option 1, do NOT change anything, just curious, what is max number it lets you set firewals instances to? I am pretty sure its 16...&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 13:48:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171702#M31145</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-16T13:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171703#M31146</link>
      <description>&lt;P&gt;cat $FWDIR/conf/fwaffinity.conf&lt;/P&gt;&lt;P&gt;looks like all interfaces have multi queue enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 13:58:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171703#M31146</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2023-02-16T13:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171704#M31147</link>
      <description>&lt;P&gt;driver: igb&lt;BR /&gt;version: 5.3.5.18&lt;BR /&gt;firmware-version: 1.63, 0x800009f9&lt;BR /&gt;expansion-rom-version:&lt;BR /&gt;bus-info: 0000:04:00.1&lt;BR /&gt;supports-statistics: yes&lt;BR /&gt;supports-test: yes&lt;BR /&gt;supports-eeprom-access: yes&lt;BR /&gt;supports-register-dump: yes&lt;BR /&gt;supports-priv-flags: no&lt;/P&gt;&lt;P&gt;you are right i am actually can increase to 16 CoreXL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 13:58:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171704#M31147</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2023-02-16T13:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171705#M31148</link>
      <description>&lt;P&gt;Which versions were each appliances running?&lt;/P&gt;
&lt;P&gt;In some scenarios additional RX-DRPs are expected but perhaps not here e.g.&lt;/P&gt;
&lt;P&gt;sk166424: Number of RX packet drops on interfaces increases on a Security Gateway R80.30 and higher with Gaia kernel 3.10&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 13:59:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171705#M31148</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-02-16T13:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171706#M31149</link>
      <description>&lt;P&gt;R80.40 Take 180&lt;/P&gt;&lt;P&gt;both old and new firewalls with the same version. this issue was not present in the old firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 14:04:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171706#M31149</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2023-02-16T14:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171707#M31150</link>
      <description>&lt;P&gt;Can you run&amp;nbsp;&lt;STRONG&gt;mq_mng&amp;nbsp; -vv&amp;nbsp; --show&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;Tim Hall gave in one of the links I posted and see what it shows? I also did below in my lab, but of course it wont work, as its just esxi server in the lab, but yours would 100%&lt;/P&gt;
&lt;P&gt;quantum-firewall&amp;gt; set interface eth0 multi-queue auto&lt;BR /&gt;No multiqueue supported interfaces available&lt;/P&gt;
&lt;P&gt;quantum-firewall&amp;gt;&lt;/P&gt;
&lt;P&gt;Also, as Chris mentioned, that sk is good reference.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 14:04:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171707#M31150</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-16T14:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171708#M31151</link>
      <description>&lt;P&gt;Honestly, since reading all your answers, it suggests to me this is concerning, and I would be as well if I were you, I would open TAC support case and have them verify everything.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 14:06:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171708#M31151</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-16T14:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171710#M31153</link>
      <description>&lt;P&gt;thank you, i opened an SR.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 14:10:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171710#M31153</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2023-02-16T14:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171711#M31154</link>
      <description>&lt;P&gt;Please keep us posted how this gets solved, as we like to post those things...just the spirit of the community, as it helps others. As my good friend says, we are all brothers from different mothers helping each other out : - )&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 14:15:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171711#M31154</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-16T14:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171712#M31155</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Of course I will update as soon as I find a solution&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 14:17:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171712#M31155</guid>
      <dc:creator>gm446</dc:creator>
      <dc:date>2023-02-16T14:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171718#M31159</link>
      <description>&lt;P&gt;FIFO errors shown by ethtool matching the RX-DRP counter indicate legitimate full ring buffer drops, and not unknown protocols arriving on the interface and being dropped as mentioned in&amp;nbsp;&lt;SPAN&gt;sk166424&lt;/SPAN&gt;.&amp;nbsp; You almost certainly need to adjust your default static CoreXL split from 2/14 to 4/12 or something like that due to a probably large amount of fully-accelerated traffic and limited number of blades enabled as shown by &lt;STRONG&gt;enabled_blades&lt;/STRONG&gt;.&amp;nbsp; Will need to see &lt;A href="https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/m-p/40528" target="_self"&gt;Super Seven&lt;/A&gt; outputs to be sure.&amp;nbsp; However your drop rate is 0.005% which is well below the &amp;lt;0.1% threshold where you need to worry about it; these probably piled up during a period of high load such as a policy installation and are not a constant ongoing concern.&amp;nbsp; Use &lt;STRONG&gt;sar -n EDEV&lt;/STRONG&gt; to see when the RX-DRP counter is being incremented.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 14:57:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171718#M31159</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-02-16T14:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171728#M31168</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/84973"&gt;@gm446&lt;/a&gt;&amp;nbsp;...what Tim suggested is an excellent idea, superseven would definitely give us much better idea, for sure.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 15:17:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171728#M31168</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-16T15:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Fifo errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171729#M31169</link>
      <description>&lt;P&gt;RX Drops mean that your NIC is dropping frames on the receiving side. Check the interface settings and the buffer side, plus multi-queue, then drill further based on the results&lt;/P&gt;</description>
      <pubDate>Thu, 16 Feb 2023 15:27:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Fifo-errors/m-p/171729#M31169</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-02-16T15:27:11Z</dc:date>
    </item>
  </channel>
</rss>

