<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Google Searches Odd Behavior in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224657#M43181</link>
    <description>&lt;P&gt;Just word of caution...IF its custom fix, you install it on top of current jumbo, so IF you wish to install latest jumbo at some point, you will need to uninstall custom fix, reboot, then ask TAC to port to new jumbo.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 27 Aug 2024 14:23:55 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-08-27T14:23:55Z</dc:date>
    <item>
      <title>Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223668#M42943</link>
      <description>&lt;P&gt;I wanted to reach out to see if anyone has been experiencing similar issues.&amp;nbsp; We've had several users indicate to us that when they do Google searches and attempt to click on a link, it just hangs and spins.&amp;nbsp; You can click the address bar and hit enter a couple of times or re-click the link a few times and it finally goes to the link.&amp;nbsp; I can take the system out from behind the firewall and everything works seamlessly.&amp;nbsp; I've even put a troubleshooting rule to allow all outbound for myself to test and I still experience the same issue.&amp;nbsp; Strangely enough, if I use firefox, I don't experience the issue.&amp;nbsp; It's in Edge and Chrome which led me to believe a recent update occurred to created a problem.&amp;nbsp; But again, when I take the system out from behind the firewall, everything works fine.&amp;nbsp; So I don't know if there's a component in Chrome/Edge that CheckPoint is struggling with parsing or what.&amp;nbsp; Again, even adding a rule that allows all outbound access doesn't change the behavior.&amp;nbsp; Has anyone else come across this behavior?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 15:55:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223668#M42943</guid>
      <dc:creator>jberg712</dc:creator>
      <dc:date>2024-08-14T15:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223669#M42944</link>
      <description>&lt;P&gt;Never had that issue myself, even in the lab with ssl inspection on. Do you use ssl inspection? Regardless, when did the issue happen? Is it affecting all users?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 15:57:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223669#M42944</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-14T15:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223670#M42945</link>
      <description>&lt;P&gt;Are you using Harmony Browse or Harmony Endpoint products? or only the firewall?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 16:05:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223670#M42945</guid>
      <dc:creator>AdiGH</dc:creator>
      <dc:date>2024-08-14T16:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223674#M42946</link>
      <description>&lt;P&gt;We do use SSL Inspection.&amp;nbsp; It appears to be affecting all users behind the gateway.&amp;nbsp; I know some services with Google are inspected and some are not.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 17:07:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223674#M42946</guid>
      <dc:creator>jberg712</dc:creator>
      <dc:date>2024-08-14T17:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223675#M42947</link>
      <description>&lt;P&gt;We are not using Harmony Endpoint or Browse.&amp;nbsp; It's only Secure Gateway with Firewall, App Cntrl, URL filtering, HTTPS Inspection, along with threat protection like IPS, Antibot, Antivirus.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 17:09:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223675#M42947</guid>
      <dc:creator>jberg712</dc:creator>
      <dc:date>2024-08-14T17:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223679#M42948</link>
      <description>&lt;P&gt;I think this one is the issue:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk111754" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk111754&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 18:06:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223679#M42948</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-14T18:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223693#M42949</link>
      <description>&lt;P&gt;Definitely could be related...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 19:29:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223693#M42949</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-14T19:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223694#M42950</link>
      <description>&lt;P&gt;Is it same behavior no matter what browser they use? I attached a doc with some screenshots of how I have this set up in the lab and works fine.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 19:38:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223694#M42950</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-14T19:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223780#M42951</link>
      <description>&lt;P&gt;You posted this issue in a space for Harmony products, which are Endpoint based.&lt;BR /&gt;This sounds like a gateway issue, so I'm moving this thread to the correct area.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 17:13:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223780#M42951</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-15T17:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223781#M42952</link>
      <description>&lt;P&gt;Please provide version/JHF of gateway as well as any logs that occur during the time this problem is occuring.&lt;BR /&gt;I would explicitly block QUIC in your access policy if you have not already as this is not supported for HTTPS Inspection until R82.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 17:15:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/223781#M42952</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-15T17:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224075#M42993</link>
      <description>&lt;P&gt;I actually did some more digging into this.&amp;nbsp; (We have the QUIC protocol disabled and have for sometime now across the board).&amp;nbsp; What I noticed is that there is some odd correlation between Chrome/Edge and the HTTP2 protocol.&amp;nbsp; When I disable HTTP2 by using the flag on the shortcut --disable-http2, traffic to sites works tremendously better.&amp;nbsp; The logs are indicating when I go to a site like google and do a search, I'm matched properly to the correct rule, however, at some point a Redirect log is generated and the redirect does not match properly and it's being picked up on the a compliance rule.&amp;nbsp; The best example I have so far of this is a user in marketing department who uses facebook to update our facebook page.&amp;nbsp; I'll attach the screenshots.&lt;/P&gt;&lt;P&gt;I've dug around and all I can see when it comes to HTTP2 is to disable strict hold on&amp;nbsp;&lt;SPAN&gt;SK116022 along with SK180257 and SK180673.&amp;nbsp; I'm afraid to disable inspecting of HTTP2 with fear that leads to things being vulnerable during web browsing for the end user.&amp;nbsp; Disabling strict hold didn't help the situation.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have a TAC ticket open about this.&amp;nbsp; Are there any recommendations/best practices when it comes to HTTP2 protocol?&amp;nbsp; It's been out for nearly 10 years now so I can't imagine why there would still be issues with it.&amp;nbsp; Unless Chrome made some update in the latest releases that did something funky with it.&amp;nbsp; I can't find good info on release notes for Chrome/Edge releases.&amp;nbsp; I say that because in one scenario I put on Firefox for another user and his works without issue unlike Chrome/Edge.&amp;nbsp; It's like a perfect mixture of chaos between Chrome, CheckPoint, and HTTP2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are currently on R81.20 Take 76&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 14:17:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224075#M42993</guid>
      <dc:creator>jberg712</dc:creator>
      <dc:date>2024-08-20T14:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224084#M42994</link>
      <description>&lt;P&gt;We support HTTP/2 for HTTPS Inspection as of R81 (though I believe it requires USFW support).&lt;BR /&gt;What hardware is this on?&lt;BR /&gt;HTTP/3 will be supported for HTTPS Inspection in R82.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 15:18:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224084#M42994</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-20T15:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224086#M42995</link>
      <description>&lt;P&gt;It's on a 6600 SGW.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 15:20:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224086#M42995</guid>
      <dc:creator>jberg712</dc:creator>
      <dc:date>2024-08-20T15:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224095#M42998</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Please check bug:&lt;/P&gt;
&lt;TABLE id="filter1Table" class="TableStyle-TP_Table_Jumbo_Fixes" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Jumbo_Fixes-Body-Grey_Background"&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_ID-Grey_Background"&gt;
&lt;P&gt;PRJ-51049,&lt;BR /&gt;PMTR-97496&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_Product-Grey_Background"&gt;
&lt;P&gt;Security Gateway&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyD-Column_Style_Description-Grey_Background"&gt;
&lt;P&gt;In some scenarios, websites that use HTTP2 protocol do not load properly.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is solved in R81.20 take 79 (released yesterday for R81.20 and today for R81.10&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 17:45:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224095#M42998</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-20T17:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224099#M43000</link>
      <description>&lt;P&gt;Thank you for pointing and finding this out Lesley.&amp;nbsp; I'm going to prepare to update my management and gateways with this to see if this resolves the issue.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 18:16:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224099#M43000</guid>
      <dc:creator>jberg712</dc:creator>
      <dc:date>2024-08-20T18:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224100#M43001</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;Question regarding USFW and KSFW.&amp;nbsp; I believe in the past we've always been recommended to use KSFW.&amp;nbsp; I believe when we were running R81.10 on our 6600, we did end up swapping to KSFW because of strange performance issues.&amp;nbsp; It may have reverted back to USFW when we did the upgrade to R81.20.&amp;nbsp; What is usually recommended for overall performance?&amp;nbsp; Should we stay with USFW or consider moving to KSFW?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 18:19:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224100#M43001</guid>
      <dc:creator>jberg712</dc:creator>
      <dc:date>2024-08-20T18:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224101#M43002</link>
      <description>&lt;P&gt;This depends. Sharing below output could help to answer the question.&amp;nbsp;&lt;/P&gt;
&lt;H3 id="TOC04"&gt;Best Practices&lt;/H3&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Use the factors listed below to select the best CoreXL Firewall mode for your Security Gateway - User Space (USFW) or Kernel Space (KSFW):&lt;/P&gt;
&lt;DIV class="table-wrapper"&gt;
&lt;TABLE class="footnote" border="1" width="100%" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR class="SubTitle" bgcolor="#d6dff0"&gt;
&lt;TD width="50%" align="center"&gt;Factor&lt;/TD&gt;
&lt;TD width="25%" align="center"&gt;Testing command&lt;/TD&gt;
&lt;TD width="15%" align="center"&gt;Recommended&lt;BR /&gt;Firewall&lt;BR /&gt;mode&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;80% or more of the traffic undergoes the Fast / Accelerated path&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;fwaccel stats -s&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;KSFW&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;70% or more of the traffic undergoes the Firewall / Slow path&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;fwaccel stats -s&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;KSFW&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;30% or more of the traffic undergoes the PXL / Medium path&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;fwaccel stats -s&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;USFW&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Security Gateway is configured with more CoreXL SND instances than CoreXL Firewall instances,&lt;BR /&gt;or when CoreXL SND instances are the bottleneck&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;fw ctl affinity -l -r&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;KSFW&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;Security Gateway is configured with more than 38 CoreXL Firewall instances&lt;/TD&gt;
&lt;TD&gt;&lt;CODE&gt;fw ctl affinity -l -r&lt;/CODE&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;USFW&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 20 Aug 2024 18:38:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224101#M43002</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-20T18:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224102#M43003</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp; I was looking at that as well Lesley.&amp;nbsp; The part i'm having trouble understanding is the 'fw ctl affinity' results.&lt;/P&gt;&lt;P&gt;Here are the fwaccel stats:&lt;/P&gt;&lt;P&gt;fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 18/14309 (0%)&lt;BR /&gt;LightSpeed conns/Total conns : 0/14309 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 10138306524/10716219296 (94%)&lt;BR /&gt;LightSpeed pkts/Total pkts : 0/10716219296 (0%)&lt;BR /&gt;F2Fed pkts/Total pkts : 577912772/10716219296 (5%)&lt;BR /&gt;F2V pkts/Total pkts : 157378648/10716219296 (1%)&lt;BR /&gt;CPASXL pkts/Total pkts : 7960499954/10716219296 (74%)&lt;BR /&gt;PSLXL pkts/Total pkts : 2176883828/10716219296 (20%)&lt;BR /&gt;CPAS pipeline pkts/Total pkts : 0/10716219296 (0%)&lt;BR /&gt;PSL pipeline pkts/Total pkts : 0/10716219296 (0%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/10716219296 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/10716219296 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/10716219296 (0%)&lt;/P&gt;&lt;P&gt;The 'fw ctl affinity' says this:&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fw ctl affinity -l -r&lt;BR /&gt;CPU 0:&lt;BR /&gt;CPU 1:&lt;BR /&gt;CPU 2: fw_3 (active)&lt;BR /&gt;cprid lpd mta_monitor cp_file_convertd usrchkd mpdaemon fwd wsdnsd rad cserver rtmd pepd watermark_cp_file_convertd in.aftpd in.msd scrubd in.ahclientd scanengine_b in.asessiond scrub_cp_file_convertd core_uploader pdpd in.emaild.mta vpnd in.acapd cprid cpd msgd&lt;BR /&gt;CPU 3: fw_2 (active)&lt;BR /&gt;cprid lpd mta_monitor cp_file_convertd usrchkd mpdaemon fwd wsdnsd rad cserver rtmd pepd watermark_cp_file_convertd in.aftpd in.msd scrubd in.ahclientd scanengine_b in.asessiond scrub_cp_file_convertd core_uploader pdpd in.emaild.mta vpnd in.acapd cprid cpd msgd&lt;BR /&gt;CPU 4: fw_1 (active)&lt;BR /&gt;cprid lpd mta_monitor cp_file_convertd usrchkd mpdaemon fwd wsdnsd rad cserver rtmd pepd watermark_cp_file_convertd in.aftpd in.msd scrubd in.ahclientd scanengine_b in.asessiond scrub_cp_file_convertd core_uploader pdpd in.emaild.mta vpnd in.acapd cprid cpd msgd&lt;BR /&gt;CPU 5: fw_0 (active)&lt;BR /&gt;cprid lpd mta_monitor cp_file_convertd usrchkd mpdaemon fwd wsdnsd rad cserver rtmd pepd watermark_cp_file_convertd in.aftpd in.msd scrubd in.ahclientd scanengine_b in.asessiond scrub_cp_file_convertd core_uploader pdpd in.emaild.mta vpnd in.acapd cprid cpd msgd&lt;BR /&gt;All:&lt;BR /&gt;Interface eth1: has multi queue enabled&lt;BR /&gt;Interface eth5: has multi queue enabled&lt;BR /&gt;Interface eth1-01: has multi queue enabled&lt;BR /&gt;Interface eth1-02: has multi queue enabled&lt;BR /&gt;Interface Mgmt: has multi queue enabled&lt;/P&gt;&lt;P&gt;I'm not sure how to read how many CoreXL instances vs CoreXL SND instances from these results.&amp;nbsp; Are you able to tell?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 18:50:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224102#M43003</guid>
      <dc:creator>jberg712</dc:creator>
      <dc:date>2024-08-20T18:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224104#M43004</link>
      <description>&lt;P&gt;Looks like 2 SND and the res FWK's to be sure verify with cpview -&amp;gt; cpu&lt;/P&gt;
&lt;P&gt;You will see either CoreXL_SND or OTHER. And CoreXL_FW&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 18:53:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224104#M43004</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-20T18:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Google Searches Odd Behavior</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224106#M43005</link>
      <description>&lt;P&gt;CPview indicates 2 CPUs for CoreXL_SND and 4 CPUs for CoreXL_FW&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CoreXLinfo_cpview.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27291i3B259C09BBA3FA56/image-size/medium?v=v2&amp;amp;px=400" role="button" title="CoreXLinfo_cpview.png" alt="CoreXLinfo_cpview.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 18:58:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Google-Searches-Odd-Behavior/m-p/224106#M43005</guid>
      <dc:creator>jberg712</dc:creator>
      <dc:date>2024-08-20T18:58:58Z</dc:date>
    </item>
  </channel>
</rss>

