<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: looking for detailed information to cpview in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212288#M40283</link>
    <description>&lt;P&gt;Any idea what traffic is being matched?&lt;BR /&gt;I suspect it's something that makes heavy use of Medium and/or Slow path.&lt;/P&gt;</description>
    <pubDate>Thu, 25 Apr 2024 14:17:26 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-04-25T14:17:26Z</dc:date>
    <item>
      <title>looking for detailed information to cpview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212257#M40275</link>
      <description>&lt;P&gt;sometimes the my FW has high CPU usage and it seams caused by special traffic.&lt;/P&gt;&lt;P&gt;If I load the CPViewCB in&amp;nbsp; DB Viewer of Diagostic View I see in the timeframe high Host Streaming_Overall_Connection&lt;/P&gt;&lt;P&gt;Have someone a short explanation what Host Streaming mean in this case ?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 09:44:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212257#M40275</guid>
      <dc:creator>Steffen_Matouse</dc:creator>
      <dc:date>2024-04-25T09:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: looking for detailed information to cpview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212288#M40283</link>
      <description>&lt;P&gt;Any idea what traffic is being matched?&lt;BR /&gt;I suspect it's something that makes heavy use of Medium and/or Slow path.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 14:17:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212288#M40283</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-04-25T14:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: looking for detailed information to cpview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212382#M40314</link>
      <description>&lt;P&gt;currenly not. Is&amp;nbsp; host streaming an indicator for special traffic or for special path in FW ?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 13:47:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212382#M40314</guid>
      <dc:creator>Steffen_Matouse</dc:creator>
      <dc:date>2024-04-26T13:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: looking for detailed information to cpview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212389#M40315</link>
      <description>&lt;P&gt;That is probably Medium Path streaming in passive and active mode.&amp;nbsp; It is not unusual for most CPU to be consumed here on a modern gateway with the typical blades enabled.&amp;nbsp; Please provide the outputs of the &lt;STRONG&gt;enabled_blades&lt;/STRONG&gt; and &lt;STRONG&gt;fwaccel&lt;/STRONG&gt; &lt;STRONG&gt;stats&lt;/STRONG&gt; -&lt;STRONG&gt;s&lt;/STRONG&gt;&amp;nbsp;for further analysis.&amp;nbsp; If you have a cluster, make sure these commands are run on the active member.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Apr 2024 14:47:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212389#M40315</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-04-26T14:47:09Z</dc:date>
    </item>
    <item>
      <title>Re: looking for detailed information to cpview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212532#M40361</link>
      <description>&lt;P&gt;enabled blades&lt;/P&gt;&lt;P&gt;fw vpn urlf av appi ips identityServer anti_bot ThreatEmulation qos mon Scrub&lt;/P&gt;&lt;P&gt;fwaccel stats -s&lt;BR /&gt;----------------------&lt;BR /&gt;Accelerated conns/Total conns : 0/2211 (0%)&lt;BR /&gt;LightSpeed conns/Total conns : 0/2211 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 84797454270/95272799005 (89%)&lt;BR /&gt;LightSpeed pkts/Total pkts : 0/95272799005 (0%)&lt;BR /&gt;F2Fed pkts/Total pkts : 10475344735/95272799005 (10%)&lt;BR /&gt;F2V pkts/Total pkts : 18299159379/95272799005 (19%)&lt;BR /&gt;CPASXL pkts/Total pkts : 375428925/95272799005 (0%)&lt;BR /&gt;PSLXL pkts/Total pkts : 80604241319/95272799005 (84%)&lt;BR /&gt;CPAS pipeline pkts/Total pkts : 0/95272799005 (0%)&lt;BR /&gt;PSL pipeline pkts/Total pkts : 0/95272799005 (0%)&lt;BR /&gt;CPAS inline pkts/Total pkts : 0/95272799005 (0%)&lt;BR /&gt;PSL inline pkts/Total pkts : 0/95272799005 (0%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 22484053775/95272799005 (23%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 26954068758/95272799005 (28%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/95272799005 (0%)&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 12:19:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212532#M40361</guid>
      <dc:creator>Steffen_Matouse</dc:creator>
      <dc:date>2024-04-29T12:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: looking for detailed information to cpview</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212537#M40362</link>
      <description>&lt;P&gt;First off you have no SecureXL templating happening (Accelerated conns), which means higher CPU overhead for a fresh rulebase lookup every time for new connections.&amp;nbsp; Most likely cause is having any blade other than Firewall enabled in your top/parent layer of your policy (&lt;A href="https://support.checkpoint.com/results/sk/sk180633" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk180633: Security Gateway accelerates 99% of traffic through the PSLXL&lt;/SPAN&gt;&lt;/A&gt;) and/or specifying applications/content in that top/first layer, or use of services with Protocol Signature set.&amp;nbsp; Please provide outputs of &lt;STRONG&gt;fwaccel stat&lt;/STRONG&gt; and &lt;STRONG&gt;fwaccel templates -R&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Looks like you are utilizing the QoS blade as well which will increase overhead (but not nearly as badly as in R80.10 and earlier), keep in mind if all you want to do is shared rule-based bandwidth limits, this can be accomplished directly in the Action field of your APCL/URLF without needing the QoS blade.&amp;nbsp; The QoS blade will be needed if you want to do per-connection limits, shared or per-connection guarantees, Weighted Fair Queueing, LLQ, ToS/DiffServ preferences etc.&lt;/P&gt;
&lt;P&gt;Other than that you just have a lot of features enabled and a busy firewall.&amp;nbsp; One other thing that can spike the CPU is elephant flows, try running &lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt; to see all elephant flows in the last 24 hours.&amp;nbsp; The Spike Detective (&lt;A href="https://support.checkpoint.com/results/sk/sk166454" target="_blank" rel="noopener"&gt;sk166454: CPU&amp;nbsp;Spike&amp;nbsp;Detective&lt;/A&gt;) can also be helpful for tracking down excessive CPU usage.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 13:21:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/looking-for-detailed-information-to-cpview/m-p/212537#M40362</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-04-29T13:21:02Z</dc:date>
    </item>
  </channel>
</rss>

