<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 3600 and USFW in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78173#M6003</link>
    <description>&lt;P&gt;My knowledge of computer architectures is may be a bit rusty already but last I remember is that HT/SMT helps when you have multi-threaded program. If USFW is realized as such it definitely benefits from HT. My understanding however was it is separate processes in the operating system and if so task switching will kind of kill performance gain from HT if any.&lt;/P&gt;
&lt;P&gt;As to why it is enabled on one and disabled on another appliances then yes, your answer clears it.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Mar 2020 04:13:54 GMT</pubDate>
    <dc:creator>HristoGrigorov</dc:creator>
    <dc:date>2020-03-13T04:13:54Z</dc:date>
    <item>
      <title>USFW enablement not clear (SK needed)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77767#M5969</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;any idea why 3600 appliance has USFW enabled by default ?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 16:12:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77767#M5969</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-10T16:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77768#M5970</link>
      <description>I think your question is answered in this post:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/td-p/50058" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/td-p/50058&lt;/A&gt;</description>
      <pubDate>Mon, 09 Mar 2020 17:53:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77768#M5970</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-09T17:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77769#M5971</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680"&gt;@HristoGrigorov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think it is a R80.40 intallation with a 3.10 kernel. In this case&amp;nbsp;UMFW is enabled by default.&lt;/P&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-message-body"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-body-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV id="bodyDisplay_5301e6e623ebad" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;In “Kernel Mode Firewall” KMFW, the maximum number of running cores is limited to 40 because of the Linux/Intel limitation of 2GB kernel memory, and because CoreXL architecture needs to load a large driver (~42MB) dozens of times (according to the CPU number, and up to 40 times). Newer platforms that contain more than 40 cores e.g., 23900 or open server are not fully utilized.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;The solution of the problem is a firewall in the user mode of the Linux operating system.&lt;/P&gt;
&lt;P&gt;USFW “User Space Firewall” or UMFW stands for “User Mode Firewall”, and it is based on proven VSX code. This mode was introduced in R80.10.&lt;/P&gt;
&lt;P&gt;According to SK the UMFW is enabled from R80.30 by default&amp;nbsp;and is customized via the installation process.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="33.33333333333333%"&gt;&lt;STRONG&gt;GAIA version/ Kernel/ Cores&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="33.33333333333333%"&gt;&lt;STRONG&gt;Firewall mode&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="33.33333333333333%"&gt;&lt;STRONG&gt;Check&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;R80.30 kernel 3.10 more then 35* cores&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;UMFW is enabled&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;checked on HP DL 380 G10 2 * Platinum 8180MProcessor 28 cores = 56 cores&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;R80.30 kernel 3.10 less then 35* cores&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;KMFW is enabled&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;checked on HP DL 380 G10 1 * Platinum 8180MProcessor 28 cores&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;R80.30 kernel 2.6&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;KMFW is enabled&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;checked on VMWare with 30 cores and with 46 cores&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.33333333333333%" height="23px"&gt;R80.40 (default 3.10 kernel)&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="23px"&gt;UMFW is enabled by default&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="23px"&gt;checked on VMWare with 4 cores&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To make sure that UMFW or KMFW is activated or to switch between modes read this article:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-User-Mode-Firewall-vs-Kernel-Mode/m-p/70759/highlight/true#M14330" target="_self"&gt;R80.x - Performance Tuning Tip – User Mode Firewall vs. Kernel Mode Firewall&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 18:13:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77769#M5971</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-09T18:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77771#M5972</link>
      <description>&lt;P&gt;Thank you for the detailed reply. I however find this in R80.40 release notes kind of strange:&lt;/P&gt;
&lt;H2&gt;Appliance support for User Space &lt;SPAN class="Other_TP_Variablestp_fwcap"&gt;Firewall&lt;/SPAN&gt; (USFW)&lt;/H2&gt;
&lt;P&gt;The following appliances run in USFW mode by default:&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;3600&lt;/STRONG&gt;&lt;/FONT&gt;, 6200, 6600, 6900, 16000T, 26000, 26000T and &lt;SPAN class="Variables_for_Hardware_Models_Cards_and_Featurestp_d3"&gt;23900&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Note"&gt;Note&lt;/SPAN&gt; - All other &lt;SPAN class="Other_TP_Variablestp_cp"&gt;Check Point&lt;/SPAN&gt; appliances will boot in kernel mode by default.&lt;/P&gt;
&lt;P&gt;Open Server / Cloud setup, &lt;SPAN class="Variables_for_CloudGuardtp_vmw"&gt;VMware&lt;/SPAN&gt; will boot in USFW when using 40 cores or more.&lt;/P&gt;
&lt;P&gt;---&lt;/P&gt;
&lt;P&gt;How is 3600 any different to be on this list ? I think there is something specific in the hardware and I am curious to know what it is &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 18:55:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77771#M5972</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-09T18:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77772#M5973</link>
      <description>&lt;P&gt;Ahh, or you mean it is coming with R80.40 pre-installed ?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 18:26:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77772#M5973</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-09T18:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77777#M5974</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680"&gt;@HristoGrigorov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have described everything in detail in this article for USFW vs KMFW:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-User-Mode-Firewall-vs-Kernel-Mode/m-p/70759/highlight/true#M14330" target="_self"&gt;R80.x - Performance Tuning Tip – User Mode Firewall vs. Kernel Mode Firewall&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;R80.40 3.10 kernel &amp;gt; USFW default&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;R80.30 2.6/ 3.10 kernel with more the 35 cores &amp;gt; USFW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;R80.20 2.6/ 3.10 kernel with more the 35 cores &amp;gt; USFW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 19:23:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77777#M5974</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-09T19:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77785#M5976</link>
      <description>As these, 3600, 6200, 6600, 6900, 16000T, 26000, 26000T and 23900, are all newer models they come with the 3.10 kernel, even in R80.30 and therefore come with the USFW enabled?</description>
      <pubDate>Mon, 09 Mar 2020 21:18:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77785#M5976</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-09T21:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77802#M5979</link>
      <description>My guess? Hyper-threading.</description>
      <pubDate>Tue, 10 Mar 2020 01:50:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77802#M5979</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-10T01:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77818#M5980</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt; That's very good guess and the only reasonable explanation so far. Thank you.&lt;/P&gt;
&lt;P&gt;I have one of these on its way to me. Can't wait to play with it and will provide some more info later &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 04:27:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77818#M5980</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-10T04:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77826#M5982</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;We have been discussing this topic here in the forum for about 2 months.&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-User-Mode-Firewall-vs-Kernel-Mode/m-p/70759/highlight/true#M14330" target="_self"&gt;R80.x - Performance Tuning Tip – User Mode Firewall vs. Kernel Mode Firewall&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;-&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-during-process-fwk0-dev-0-UMFW-vs-KMFW/m-p/70648/highlight/true#M14307" target="_self"&gt;High CPU utilization during process fwk0_dev_0 (UMFW vs. KMFW)&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;- this article&lt;/P&gt;
&lt;P&gt;Only this&amp;nbsp; information can you found in the KB! I think that is not enough.&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk149973&amp;amp;partition=Advanced&amp;amp;product=Data" target="_blank" rel="noopener"&gt;sk149973: How to enable USFW (User-Space Firewall) on a 23900 appliance&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have also spent some time here at LAB to test this with HP DL360 servers with 28 cores vs 56 cores for R80.20 / R80.30 / R80.40 with kernel 3.10&amp;nbsp; and R80.20 / R80.30 with kernel 2.6.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My request, please write a SK, in which the USFW vs. KMFW are described.&amp;nbsp;&lt;/SPAN&gt;I think that would be very helpful for all of us.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;Heiko&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 06:47:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77826#M5982</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-10T06:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77830#M5983</link>
      <description>&lt;P&gt;I think the 3600 has four cores.&amp;nbsp;Therefore with HT 8 cores.&amp;nbsp;Now the big question, why USFW is enabled with&amp;nbsp; 8&amp;nbsp; (or 4) cores for R80.30.&lt;/P&gt;
&lt;P&gt;On an open server only with more than 35 cores USFW is enabled. (I have checked this in the LAB)?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 07:08:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77830#M5983</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-10T07:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77832#M5984</link>
      <description>&lt;P&gt;Exactly what I am thinking as well. The number of cores on 3600 (4) and 3600-T (8) is just far bellow what's reasonable to enable USFW by default even with HT enabled.&amp;nbsp; So, it is either mistake in release notes or just there is something we are missing or unaware...&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt; I also second Heiko that we need SK about this. &lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 07:18:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77832#M5984</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-10T07:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77833#M5985</link>
      <description>&lt;P&gt;To create some more confusion...&lt;/P&gt;
&lt;P&gt;Last weeks I did new installs of R80.30 on different HP DL 380/360 G9 / G10 hardware. All are with less then 28 cores and all&lt;/P&gt;
&lt;P&gt;had USFW enabled after install.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;I support&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp;request for a knowledgebase article about both modes.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 07:20:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77833#M5985</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-03-10T07:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77865#M5986</link>
      <description>&lt;P&gt;I'd like to also cast my vote for a full disclosure SK specifying exactly under which conditions USFW will be enabled and why. &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&amp;nbsp; While researching the third edition of my book I ran across this same question, and the only answer I could ever get is "it depends".&amp;nbsp; So I had to kind of punt in my book to some degree, show how to determine if USFW was enabled, and say to not change the default without consulting TAC.&lt;/P&gt;
&lt;P&gt;I don't understand why USFW would be enabled by default on a 6900 or lower (16 cores or less), perhaps USFW can take advantage of SMT much more efficiently, but I doubt it.&amp;nbsp; 16000 and higher (32-48 cores), sure USFW makes sense.&amp;nbsp; It looks like the ability to disable SMT via &lt;STRONG&gt;cpconfig&lt;/STRONG&gt; has been removed on certain Check Point appliances as well, thus only enabling TAC to disable it from the BIOS, which I don't understand either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 12:20:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77865#M5986</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-03-10T12:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77891#M5987</link>
      <description>&lt;P&gt;I renamed this thread as it is not only about 3600 appliances.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 16:13:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77891#M5987</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-10T16:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77914#M5989</link>
      <description>&lt;P&gt;Some of the questions in this thread are answered here: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk93000" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk93000&lt;/A&gt;&lt;BR /&gt;This SK is missing all the appliances we announced this year, but they are similar to the 6500/6800 in the sense SMT is enabled by default.&lt;BR /&gt;Further,&amp;nbsp;expect USFW to be enabled by default in the most recent code versions for the newest appliances.&lt;BR /&gt;&lt;BR /&gt;I've also asked the SK team to update sk93000 with the new appliances and to clarify the limitations section as it contradicts the "supported platforms" statements in a few areas.&lt;/P&gt;
&lt;P&gt;(Edited to reflect confirmation from R&amp;amp;D on SMT on newer appliances).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 21:51:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77914#M5989</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-10T21:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77924#M5990</link>
      <description>&lt;P&gt;I hope for a technical explanation from R&amp;amp;D as to why is USFW enabled by default on appliances with low number of CPU cores (even with SMT enabled).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 04:21:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77924#M5990</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-11T04:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78023#M5992</link>
      <description>I assume it's because it provides for better performance than without, particularly when you're using NGTP/NGTX Software Blades.&lt;BR /&gt;&lt;BR /&gt;In terms of kernel memory utilization, USFW is a significant improvement as we're not having to load a large CoreXL driver for each core (real and virtual).&lt;BR /&gt;Even with a small number of cores, that adds up.</description>
      <pubDate>Wed, 11 Mar 2020 21:45:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78023#M5992</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-11T21:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78053#M5994</link>
      <description>&lt;P&gt;All right. I think we are getting into some kind of loop here so I will just halt it at this point with not understanding why USFW is enabled by default on one 8 core appliance and disabled on another.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 04:09:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78053#M5994</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-12T04:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78151#M6002</link>
      <description>In the Check Point appliances where it is enabled by default, we have newer Intel processors in there.&lt;BR /&gt;There must clearly be a benefit to having SMT enabled by default on these appliances, thus we do it.&lt;BR /&gt;It has nothing to do with the number of cores available in this case.&lt;BR /&gt;&lt;BR /&gt;For systems with older CPUs with more than 40 cores, USFW is required to utilize them all. &lt;BR /&gt;I assume on those appliances, we would also enable USFW by default.&lt;BR /&gt;&lt;BR /&gt;I hope that clears things up.</description>
      <pubDate>Thu, 12 Mar 2020 19:51:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78151#M6002</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-12T19:51:35Z</dc:date>
    </item>
  </channel>
</rss>

