<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint Gateway Physical cores and fw workers in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58928#M4473</link>
    <description>That looks like you only have two workers (also referred to as firewall instances) and no SNDs, which does not seem right.&lt;BR /&gt;If you check via cpconfig and choose the CoreXL option, what does it say you have allocated?&lt;BR /&gt;On my VM with 4 cores, it says: CoreXL is currently enabled with 3 IPv4 firewall instances and 2 IPv6 firewall instances.&lt;BR /&gt;&lt;BR /&gt;[Expert@gateway:0]# fw ctl affinity -l -r&lt;BR /&gt;CPU 0:	eth0 eth2&lt;BR /&gt;CPU 1:	fw_2&lt;BR /&gt;	mpdaemon lpd rad in.acapd fwd cp_file_convertd pepd vpnd in.asessiond pdpd usrchkd cpd cprid&lt;BR /&gt;CPU 2:	fw_1&lt;BR /&gt;	mpdaemon lpd rad in.acapd fwd cp_file_convertd pepd vpnd in.asessiond pdpd usrchkd cpd cprid&lt;BR /&gt;CPU 3:	fw_0&lt;BR /&gt;	mpdaemon lpd rad in.acapd fwd cp_file_convertd pepd vpnd in.asessiond pdpd usrchkd cpd cprid&lt;BR /&gt;All:&lt;BR /&gt;&lt;BR /&gt;Unless you know for absolute certain you need a different setting for optimal performance, I recommend starting with the default setting (6 firewall instances).</description>
    <pubDate>Wed, 24 Jul 2019 22:06:24 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-07-24T22:06:24Z</dc:date>
    <item>
      <title>Check Point Gateway Cores and FW Workers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58848#M4468</link>
      <description>&lt;P&gt;Hi Checkpoint experts,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I got a question regarding Checkpoint license cores,, we have this license to allow to use 8 cores in a gateway ,&amp;nbsp; I understand that is for CoreXL allocation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.) Would this also means that we are allowed to use 8 physical cores in Checkpoint VM? Does the license had an effect on physical or hardware cpu core limitations?&lt;/P&gt;
&lt;P&gt;2.) And if we only have 3 firewall workers activated , does that mean we are not utilizing the other 5 cores? or those cores were used in some processes?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert]# fw ctl multik stat&lt;BR /&gt;ID | Active | CPU | Connections | Peak&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;0 | Yes | 7 | 192 | 1473&lt;BR /&gt;1 | Yes | 3 | 211 | 1369&lt;BR /&gt;2 | Yes | 6 | 215 | 1387&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert]# fw ctl affinity -l&lt;BR /&gt;Kernel fw_0: CPU 7&lt;BR /&gt;Kernel fw_1: CPU 3&lt;BR /&gt;Kernel fw_2: CPU 6&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert]# fw ctl get int fwlic_num_of_allowed_cores&lt;BR /&gt;fwlic_num_of_allowed_cores = 8&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; Total VM hardware Cores = 8&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jul 2019 00:38:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58848#M4468</guid>
      <dc:creator>Neil_ARZ</dc:creator>
      <dc:date>2019-07-27T00:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Physical cores and fw workers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58851#M4469</link>
      <description>In a VM, the license applies to the number of virtual cores allocated to the VM.&lt;BR /&gt;The cores on the physical hardware is not relevant.&lt;BR /&gt;&lt;BR /&gt;The cores are split between SND and Worker.&lt;BR /&gt;If you allocate 3 workers, then that means 5 cores are being used for SND.&lt;BR /&gt;In R80.30+, you can also allocate a core for management traffic if you have 8 or more cores licensed, but this is not the default.&lt;BR /&gt;</description>
      <pubDate>Tue, 23 Jul 2019 23:15:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58851#M4469</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-23T23:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Physical cores and fw workers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58903#M4470</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Hi Phoneboy ,&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yeah , sorry I was really referring to Virtual cores of the VM...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The cores are split between SND and Worker.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Thanks . I will research more on SND.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If you allocate 3 workers, then that means 5 cores are being used for SND.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;gt; Is there a command to view how many cores were assigned to SND?&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;In R80.30+, you can also allocate a core for management traffic if you have 8 or more cores licensed, but this is not the default.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Is there a default core assignment between the Firewall worker and SND?&amp;nbsp; For example like in our environment with 8 core&amp;nbsp; &amp;nbsp; &amp;nbsp;gateway .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 13:37:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58903#M4470</guid>
      <dc:creator>Neil_ARZ</dc:creator>
      <dc:date>2019-07-24T13:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Physical cores and fw workers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58913#M4471</link>
      <description>You can only directly control the number of workers, SNDs are allocated from the remaining (licensed) cores.&lt;BR /&gt;The default allocation for 8 cores is 6/2 (6 workers, 2 SND).&lt;BR /&gt;You can see the list of defaults here:&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98737" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98737&lt;/A&gt;</description>
      <pubDate>Wed, 24 Jul 2019 17:42:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58913#M4471</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-24T17:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Physical cores and fw workers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58926#M4472</link>
      <description>&lt;P&gt;Hi Phoneboy ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the info . i am learning from it ...&amp;nbsp;&lt;/P&gt;&lt;P&gt;so I would say that we have no SND active for interfaces... only firewall workers running on CPU 3 and CPU 7 that are helping to process traffics..&amp;nbsp;&lt;/P&gt;&lt;P&gt;I far as i can see with those details , we are not utilizing all CPU cores right ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or these unallocated CPU's&amp;nbsp; could be running other&amp;nbsp;&lt;SPAN&gt;processes?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert]# cpmq get -a&lt;/P&gt;&lt;P&gt;Active virtio_net interfaces:&lt;BR /&gt;eth0 [Off]&lt;BR /&gt;eth1 [Off]&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert]# fw ctl affinity -l -r&lt;BR /&gt;CPU 0:&lt;BR /&gt;CPU 1:&lt;BR /&gt;CPU 2:&lt;BR /&gt;CPU 3: fw_1&lt;BR /&gt;cp_file_convertd fwd usrchkd rad pepd in.geod in.msd mpdaemon lpd vpnd pdpd in.acapd in.asessiond gcpd wsdnsd cpd cprid&lt;BR /&gt;CPU 4:&lt;BR /&gt;CPU 5:&lt;BR /&gt;CPU 6:&lt;BR /&gt;CPU 7: fw_0&lt;BR /&gt;cp_file_convertd fwd usrchkd rad pepd in.geod in.msd mpdaemon lpd vpnd pdpd in.acapd in.asessiond gcpd wsdnsd cpd cprid&lt;BR /&gt;All:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[Expert]# fw ctl affinity -l&lt;BR /&gt;Kernel fw_0: CPU 7&lt;BR /&gt;Kernel fw_1: CPU 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tasks: 163 total, 2 running, 161 sleeping, 0 stopped, 0 zombie&lt;BR /&gt;Cpu0 : 0.0%us, 0.0%sy, 0.0%ni, 97.0%id, 0.0%wa, 0.0%hi, 3.0%si, 0.0%st&lt;BR /&gt;Cpu1 : 0.0%us, 0.0%sy, 0.0%ni, 98.3%id, 0.0%wa, 0.3%hi, 1.3%si, 0.0%st&lt;BR /&gt;Cpu2 : 0.0%us, 0.0%sy, 0.0%ni,100.0%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st&lt;BR /&gt;Cpu3 : 9.3%us, 3.3%sy, 0.0%ni, 84.7%id, 0.0%wa, 0.0%hi, 2.7%si, 0.0%st&lt;BR /&gt;Cpu4 : 0.0%us, 0.0%sy, 0.0%ni,100.0%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st&lt;BR /&gt;Cpu5 : 0.0%us, 0.0%sy, 0.0%ni,100.0%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st&lt;BR /&gt;Cpu6 : 0.0%us, 0.0%sy, 0.0%ni,100.0%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st&lt;BR /&gt;Cpu7 : 9.3%us, 3.7%sy, 0.0%ni, 83.7%id, 0.0%wa, 0.0%hi, 3.3%si, 0.0%st&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 19:45:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58926#M4472</guid>
      <dc:creator>Neil_ARZ</dc:creator>
      <dc:date>2019-07-24T19:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Physical cores and fw workers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58928#M4473</link>
      <description>That looks like you only have two workers (also referred to as firewall instances) and no SNDs, which does not seem right.&lt;BR /&gt;If you check via cpconfig and choose the CoreXL option, what does it say you have allocated?&lt;BR /&gt;On my VM with 4 cores, it says: CoreXL is currently enabled with 3 IPv4 firewall instances and 2 IPv6 firewall instances.&lt;BR /&gt;&lt;BR /&gt;[Expert@gateway:0]# fw ctl affinity -l -r&lt;BR /&gt;CPU 0:	eth0 eth2&lt;BR /&gt;CPU 1:	fw_2&lt;BR /&gt;	mpdaemon lpd rad in.acapd fwd cp_file_convertd pepd vpnd in.asessiond pdpd usrchkd cpd cprid&lt;BR /&gt;CPU 2:	fw_1&lt;BR /&gt;	mpdaemon lpd rad in.acapd fwd cp_file_convertd pepd vpnd in.asessiond pdpd usrchkd cpd cprid&lt;BR /&gt;CPU 3:	fw_0&lt;BR /&gt;	mpdaemon lpd rad in.acapd fwd cp_file_convertd pepd vpnd in.asessiond pdpd usrchkd cpd cprid&lt;BR /&gt;All:&lt;BR /&gt;&lt;BR /&gt;Unless you know for absolute certain you need a different setting for optimal performance, I recommend starting with the default setting (6 firewall instances).</description>
      <pubDate>Wed, 24 Jul 2019 22:06:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58928#M4473</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-24T22:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Physical cores and fw workers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58961#M4474</link>
      <description>Thanks , Thats what i thought we are not utilizing all cores and I am looking to go down to 4 cores thats why I am studying this process. ... So the default or recommended will be 3 firewall workers?&lt;BR /&gt;&lt;BR /&gt;I noticed that all of our VM does have a configured SND , its running for more than a year .. is it recommended to assign SNDs in a core?&lt;BR /&gt;&lt;BR /&gt;What if we dont assign a processing core in a worker or SND? Does it means that will be use in other process?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 25 Jul 2019 13:33:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/58961#M4474</guid>
      <dc:creator>Neil_ARZ</dc:creator>
      <dc:date>2019-07-25T13:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint Gateway Physical cores and fw workers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/59066#M4475</link>
      <description>The default is 3 Workers / 1 SND for a 4 core system.&lt;BR /&gt;&lt;BR /&gt;As for assignment, the only thing you can directly control is the number of workers assigned.&lt;BR /&gt;If you have more than 8 cores in R80.30, you can optionally assign one core for management-related functions.&lt;BR /&gt;All other cores should be assigned to SND automatically.</description>
      <pubDate>Sat, 27 Jul 2019 00:36:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Gateway-Cores-and-FW-Workers/m-p/59066#M4475</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-27T00:36:44Z</dc:date>
    </item>
  </channel>
</rss>

