<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CP latency during policy installation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/225746#M43437</link>
    <description>&lt;P&gt;The SK contains the correct explanation.&lt;/P&gt;
&lt;P&gt;(1)&lt;/P&gt;
&lt;P&gt;0 is the default value. Security Gateway installs the policy on groups of CoreXL Firewall instances, where each group contains from 50% (Total Number / 2) of all CoreXL Firewall instances to a maximum of 35 CoreXL Firewall instances.&lt;/P&gt;
&lt;P&gt;Meaning:&lt;/P&gt;
&lt;P&gt;If there are 10 instances, then the default group size will be 5 (because 10 / 2 &amp;lt; 35)&lt;/P&gt;
&lt;P&gt;If there are 20 instances, then the default group size will be 10 (because 20 / 2 &amp;lt; 35)&lt;/P&gt;
&lt;P&gt;If there are 40 instances, then the default group size will be 20 (because 40 / 2 &amp;lt; 35)&lt;/P&gt;
&lt;P&gt;If there are 72 instances, then the default 3 groups will be 35 + 35 + 2 (because 72 / 2 &amp;gt; 35)&lt;/P&gt;
&lt;P&gt;If there are 100 instances, then the default 3 groups will be 35 + 35 + 30 (because 100 / 2 &amp;gt; 35)&lt;/P&gt;
&lt;P&gt;(2)&lt;/P&gt;
&lt;P&gt;If you configure a non-zero group size value, then:&lt;/P&gt;
&lt;P&gt;If the group size value is 4, and there are 40 instances, then the 10 groups will be&amp;nbsp;4 + 4 + ... + 4&lt;/P&gt;
&lt;P&gt;If the group size value is 10, and there are 40 instances, then the 4 groups will be&amp;nbsp;10 + 10 + 10 + 10&lt;/P&gt;
&lt;P&gt;If the group size value is 50, and there are 100 instances, then the 3 groups will be&amp;nbsp;35 + 35 + 30&lt;/P&gt;</description>
    <pubDate>Thu, 05 Sep 2024 09:27:04 GMT</pubDate>
    <dc:creator>Sergei_Shir</dc:creator>
    <dc:date>2024-09-05T09:27:04Z</dc:date>
    <item>
      <title>CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/131821#M19468</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are experiencing the following issue.&lt;/P&gt;&lt;P&gt;We have a pair of ClusterXL CP5000 series devices that are managed by an external SMS and have a dedicated sync interface.&lt;/P&gt;&lt;P&gt;During the policy deployment procedure we are experiencing high latency issues ie by having a ping running indefinitely from a LAN PC we observe that the RTT towards 8.8.8.8 from 40ms gets as high as 2000ms for quite a few packets (10-20 in total) and we are also experiencing a few packet drops (ICMP request timeouts) 2,3 in total. This behavior occurs either when we ping an Internet site (8.8.8.8) or any other internal subnet / VLAN that is routed by the CP cluster and only when the policy gets deployed.&lt;/P&gt;&lt;P&gt;Also by issuing a ping towards 8.8.8.8 from the firewall , we also get a packet loss only during the policy installation procedure.&lt;/P&gt;&lt;P&gt;When the policy has finished everything goes back to normal ie low RTTs and no packet drop at all.&lt;/P&gt;&lt;P&gt;During the policy installation since I get a lot of CUL (Cluster Under Load) start &amp;amp; stop notifications, the CPU gets as high as 100% which I think is something not to worry about since in many if not all of the policy deployments I have seen so far in my career the CPU gets high enough.&lt;/P&gt;&lt;P&gt;Also we have toggled with all of the connection persistence options (Keep all connections, rematch connections) and the behavior is still the same.&lt;/P&gt;&lt;P&gt;What else could we check ?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 09:36:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/131821#M19468</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2021-10-15T09:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/131869#M19488</link>
      <description>&lt;P&gt;Hi Nikolaos,&lt;/P&gt;
&lt;P&gt;What version &amp;amp; JHF is deployed, have you considered upgrading to R81 (sk169096: &lt;SPAN&gt;Accelerated Install Policy For Access Control Policy&lt;/SPAN&gt;)?&lt;/P&gt;
&lt;P&gt;How's the CPU load normally, can you also provide the output of "fwaccel stat" from Expert mode.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 08:28:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/131869#M19488</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-10-18T08:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/131870#M19489</link>
      <description>&lt;P&gt;Sounds like CPU saturation, the trick will be determining if it is on your SND or Worker/Instance cores.&amp;nbsp; ICMP always goes F2F so it has to go through both types of cores.&amp;nbsp; Policy installation causes heavy CPU on the workers, if you run top do they all max out during policy installation while SNDs are relatively idle?&lt;/P&gt;
&lt;P&gt;Probably will need outputs of Super Seven and enabled_blades to comment further.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/td-p/40528" target="_blank"&gt;https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/td-p/40528&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Oct 2021 15:41:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/131870#M19489</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-10-16T15:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/131871#M19490</link>
      <description>&lt;P&gt;Take 125.&lt;/P&gt;&lt;P&gt;CPU seems to be ok during non-policy installation hours. I have considered doing a fwaccel off and retry to deploy the policy with SecureXL off and see what would be the impact during the process of policy installation. Also I thought maybe doubling the TX buffer of the nics.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Oct 2021 16:40:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/131871#M19490</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2021-10-16T16:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/131874#M19492</link>
      <description>&lt;P&gt;I doubt disabling SecureXL will help improve performance during a policy load on that code version (the full automatic restart of SecureXL every time the policy is installed went away in R80.20), but it is worth a try.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enlarging interface ring buffers is generally a last resort and can actually make thing worse, please provide Super Seven and &lt;STRONG&gt;enabled_blades&lt;/STRONG&gt; output for further recommendations.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 17:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/131874#M19492</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-10-18T17:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/131942#M19508</link>
      <description>&lt;P&gt;Thank you Timothy for the recommendation.&lt;/P&gt;&lt;P&gt;One question though: When do you want me to run the s7 script ?&amp;nbsp; During peaky hours , during policy installation ? The behavior seems to appear only during the policy deployment phase.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 08:25:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/131942#M19508</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2021-10-18T08:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/132003#M19516</link>
      <description>&lt;P&gt;You can run it any time as long as the firewall has been active (i.e. not rebooted) for several days and has undergone several policy installations, the cumulative counters should provide enough info.&amp;nbsp; I may ask you to run it during the slow period if the results are inconclusive, but would prefer not to cause issues in your network with a policy install unless absolutely necessary.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Oct 2021 18:20:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/132003#M19516</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-10-18T18:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/132204#M19561</link>
      <description>&lt;P&gt;There you go: &lt;A href="https://justpaste.it/4yxh4" target="_blank"&gt;https://justpaste.it/4yxh4&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 10:53:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/132204#M19561</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2021-10-20T10:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/132290#M19579</link>
      <description>&lt;P&gt;After looking through your outputs you must have a model 5100-5400 as there are only two cores present which results in a 2/2 CoreXL split with overlap between the cores.&amp;nbsp; Nothing major is jumping out at me other than the firewall is pretty busy with limited core resources.&amp;nbsp; Definitely do NOT recommend turning SecureXL off.&lt;/P&gt;
&lt;P&gt;It would appear that the firewall is undersized for what you are attempting to do, please provide outputs from these commands run anytime:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;enabled_blades&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;free -m&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Depending on how many blades you have enabled more RAM *might* help assuming the model supports being upgraded, as policy installs are a very memory and CPU-intensive process.&amp;nbsp; The fact that setting "keep all connections" (which substantially reduces CPU load during policy install) did not appear to improve the issue implies a shortage of memory during this process.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 18:31:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/132290#M19579</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-10-20T18:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/132375#M19604</link>
      <description>&lt;P&gt;[Expert@ΧΧΧΧΧ_CP1:0]# enabled_blades&lt;/P&gt;&lt;P&gt;fw vpn cvpn urlf av appi ips identityServer anti_bot ThreatEmulation mon&lt;/P&gt;&lt;P&gt;[Expert@ΧΧΧΧΧ_CP1:0]#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The device is CP5400&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 13:41:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/132375#M19604</guid>
      <dc:creator>Nikolaos_Liakop</dc:creator>
      <dc:date>2021-10-21T13:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/132390#M19608</link>
      <description>&lt;P&gt;Almost certainly a memory shortage based on how many blades you have enabled (and possibly CPU saturation during policy load), please provide output of &lt;STRONG&gt;free -m&lt;/STRONG&gt;.&amp;nbsp; The 5400 comes with 8GB of RAM but can be upgraded to 32.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 17:11:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/132390#M19608</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-10-21T17:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/204959#M38644</link>
      <description>&lt;P&gt;I encountered a case similar to yours.&amp;nbsp;It took us almost a month to get R&amp;amp;D involved. After that we must to change a paramater&amp;nbsp;&lt;/P&gt;&lt;P&gt;CP_INSTALL_POLICY_MT_MODE&amp;nbsp;&lt;/P&gt;&lt;P&gt;The default value is 0, we changed to 2 with command:&lt;/P&gt;&lt;P&gt;cpprod_util FwSetParam CP_INSTALL_POLICY_MT_MODE 2&lt;/P&gt;&lt;P&gt;Everything returns to normal with this command. You can find in Jumbo Hotfix take 93 with&amp;nbsp;&lt;SPAN&gt;PRJ-41619,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;PMTR-87160&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 04:18:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/204959#M38644</guid>
      <dc:creator>PhongNN</dc:creator>
      <dc:date>2024-02-04T04:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/204981#M38646</link>
      <description>&lt;P&gt;Did R&amp;amp;D happen to explain what changing this parameter does?&amp;nbsp; I've never seen it before.&amp;nbsp; Does it enable a Multi-Threaded policy install mode?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Edit: Ah I see it now.&amp;nbsp; Interesting.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE id="filter1Table" class="TableStyle-TP_Table_Jumbo_Fixes" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Jumbo_Fixes-Body-White_Background"&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_ID-White_Background"&gt;
&lt;P&gt;PRJ-41619,&lt;BR /&gt;PMTR-87160&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyE-Column_Style_Product-White_Background"&gt;
&lt;P&gt;Security Management&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Jumbo_Fixes-BodyD-Column_Style_Description-White_Background"&gt;
&lt;P&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt;: To reduce policy installation time in large environments (that have many instances), policy can be installed in batches.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Each batch contains&amp;nbsp;several instances that install the policy at the current iteration. By default, the batch size is set to "&lt;EM&gt;0&lt;/EM&gt;" (off).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;To enable it, run a CLI command "&lt;EM&gt;cpprod_util FwSetParam CP_INSTALL_POLICY_MT_LIMIT val&lt;/EM&gt;" and set the value &amp;gt;0.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;</description>
      <pubDate>Sun, 04 Feb 2024 14:29:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/204981#M38646</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-02-04T14:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/225627#M43421</link>
      <description>&lt;P&gt;This parameter "&lt;SPAN&gt;CP_INSTALL_POLICY_MT_MODE&amp;nbsp;" is described in&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk182653" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk182653&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 13:11:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/225627#M43421</guid>
      <dc:creator>Sergei_Shir</dc:creator>
      <dc:date>2024-09-04T13:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/225744#M43436</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2208"&gt;@Sergei_Shir&lt;/a&gt;: Thank you for that sk!&lt;/P&gt;
&lt;P&gt;However, there is a discrepancy between the JHF Release Notes and the sk regarding the default setting 0.&lt;/P&gt;
&lt;P&gt;The JHF Release Notes say:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;When set to "&lt;EM&gt;0&lt;/EM&gt;": the feature is disabled, all non-global instances will be included in the batch.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The SK says:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;0 is the default value. Security Gateway installs the policy on groups of CoreXL Firewall instances, where each group contains from 50% of all CoreXL Firewall instances to a maximum of 35 CoreXL Firewall instances.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;That is not the same.&lt;/P&gt;
&lt;P&gt;Can you explain how it really works with default setting 0? And maybe update documentation so that it matches?&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 08:26:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/225744#M43436</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2024-09-05T08:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/225746#M43437</link>
      <description>&lt;P&gt;The SK contains the correct explanation.&lt;/P&gt;
&lt;P&gt;(1)&lt;/P&gt;
&lt;P&gt;0 is the default value. Security Gateway installs the policy on groups of CoreXL Firewall instances, where each group contains from 50% (Total Number / 2) of all CoreXL Firewall instances to a maximum of 35 CoreXL Firewall instances.&lt;/P&gt;
&lt;P&gt;Meaning:&lt;/P&gt;
&lt;P&gt;If there are 10 instances, then the default group size will be 5 (because 10 / 2 &amp;lt; 35)&lt;/P&gt;
&lt;P&gt;If there are 20 instances, then the default group size will be 10 (because 20 / 2 &amp;lt; 35)&lt;/P&gt;
&lt;P&gt;If there are 40 instances, then the default group size will be 20 (because 40 / 2 &amp;lt; 35)&lt;/P&gt;
&lt;P&gt;If there are 72 instances, then the default 3 groups will be 35 + 35 + 2 (because 72 / 2 &amp;gt; 35)&lt;/P&gt;
&lt;P&gt;If there are 100 instances, then the default 3 groups will be 35 + 35 + 30 (because 100 / 2 &amp;gt; 35)&lt;/P&gt;
&lt;P&gt;(2)&lt;/P&gt;
&lt;P&gt;If you configure a non-zero group size value, then:&lt;/P&gt;
&lt;P&gt;If the group size value is 4, and there are 40 instances, then the 10 groups will be&amp;nbsp;4 + 4 + ... + 4&lt;/P&gt;
&lt;P&gt;If the group size value is 10, and there are 40 instances, then the 4 groups will be&amp;nbsp;10 + 10 + 10 + 10&lt;/P&gt;
&lt;P&gt;If the group size value is 50, and there are 100 instances, then the 3 groups will be&amp;nbsp;35 + 35 + 30&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 09:27:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/225746#M43437</guid>
      <dc:creator>Sergei_Shir</dc:creator>
      <dc:date>2024-09-05T09:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: CP latency during policy installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/225750#M43439</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 09:20:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CP-latency-during-policy-installation/m-p/225750#M43439</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2024-09-05T09:20:43Z</dc:date>
    </item>
  </channel>
</rss>

