<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 3600 and USFW in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78269#M6010</link>
    <description>&lt;P&gt;Mystery resolved &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 14 Mar 2020 04:41:16 GMT</pubDate>
    <dc:creator>HristoGrigorov</dc:creator>
    <dc:date>2020-03-14T04:41:16Z</dc:date>
    <item>
      <title>USFW enablement not clear (SK needed)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77767#M5969</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;any idea why 3600 appliance has USFW enabled by default ?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 16:12:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77767#M5969</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-10T16:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77768#M5970</link>
      <description>I think your question is answered in this post:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/td-p/50058" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/td-p/50058&lt;/A&gt;</description>
      <pubDate>Mon, 09 Mar 2020 17:53:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77768#M5970</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-09T17:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77769#M5971</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680"&gt;@HristoGrigorov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think it is a R80.40 intallation with a 3.10 kernel. In this case&amp;nbsp;UMFW is enabled by default.&lt;/P&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-message-body"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-body-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV id="bodyDisplay_5301e6e623ebad" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;In “Kernel Mode Firewall” KMFW, the maximum number of running cores is limited to 40 because of the Linux/Intel limitation of 2GB kernel memory, and because CoreXL architecture needs to load a large driver (~42MB) dozens of times (according to the CPU number, and up to 40 times). Newer platforms that contain more than 40 cores e.g., 23900 or open server are not fully utilized.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;The solution of the problem is a firewall in the user mode of the Linux operating system.&lt;/P&gt;
&lt;P&gt;USFW “User Space Firewall” or UMFW stands for “User Mode Firewall”, and it is based on proven VSX code. This mode was introduced in R80.10.&lt;/P&gt;
&lt;P&gt;According to SK the UMFW is enabled from R80.30 by default&amp;nbsp;and is customized via the installation process.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="33.33333333333333%"&gt;&lt;STRONG&gt;GAIA version/ Kernel/ Cores&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="33.33333333333333%"&gt;&lt;STRONG&gt;Firewall mode&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="33.33333333333333%"&gt;&lt;STRONG&gt;Check&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;R80.30 kernel 3.10 more then 35* cores&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;UMFW is enabled&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;checked on HP DL 380 G10 2 * Platinum 8180MProcessor 28 cores = 56 cores&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;R80.30 kernel 3.10 less then 35* cores&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;KMFW is enabled&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;checked on HP DL 380 G10 1 * Platinum 8180MProcessor 28 cores&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;R80.30 kernel 2.6&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;KMFW is enabled&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="45px"&gt;checked on VMWare with 30 cores and with 46 cores&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.33333333333333%" height="23px"&gt;R80.40 (default 3.10 kernel)&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="23px"&gt;UMFW is enabled by default&lt;/TD&gt;
&lt;TD width="33.33333333333333%" height="23px"&gt;checked on VMWare with 4 cores&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To make sure that UMFW or KMFW is activated or to switch between modes read this article:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-User-Mode-Firewall-vs-Kernel-Mode/m-p/70759/highlight/true#M14330" target="_self"&gt;R80.x - Performance Tuning Tip – User Mode Firewall vs. Kernel Mode Firewall&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 18:13:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77769#M5971</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-09T18:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77771#M5972</link>
      <description>&lt;P&gt;Thank you for the detailed reply. I however find this in R80.40 release notes kind of strange:&lt;/P&gt;
&lt;H2&gt;Appliance support for User Space &lt;SPAN class="Other_TP_Variablestp_fwcap"&gt;Firewall&lt;/SPAN&gt; (USFW)&lt;/H2&gt;
&lt;P&gt;The following appliances run in USFW mode by default:&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;3600&lt;/STRONG&gt;&lt;/FONT&gt;, 6200, 6600, 6900, 16000T, 26000, 26000T and &lt;SPAN class="Variables_for_Hardware_Models_Cards_and_Featurestp_d3"&gt;23900&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Note"&gt;Note&lt;/SPAN&gt; - All other &lt;SPAN class="Other_TP_Variablestp_cp"&gt;Check Point&lt;/SPAN&gt; appliances will boot in kernel mode by default.&lt;/P&gt;
&lt;P&gt;Open Server / Cloud setup, &lt;SPAN class="Variables_for_CloudGuardtp_vmw"&gt;VMware&lt;/SPAN&gt; will boot in USFW when using 40 cores or more.&lt;/P&gt;
&lt;P&gt;---&lt;/P&gt;
&lt;P&gt;How is 3600 any different to be on this list ? I think there is something specific in the hardware and I am curious to know what it is &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 18:55:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77771#M5972</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-09T18:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77772#M5973</link>
      <description>&lt;P&gt;Ahh, or you mean it is coming with R80.40 pre-installed ?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 18:26:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77772#M5973</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-09T18:26:17Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77777#M5974</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680"&gt;@HristoGrigorov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have described everything in detail in this article for USFW vs KMFW:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-User-Mode-Firewall-vs-Kernel-Mode/m-p/70759/highlight/true#M14330" target="_self"&gt;R80.x - Performance Tuning Tip – User Mode Firewall vs. Kernel Mode Firewall&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;R80.40 3.10 kernel &amp;gt; USFW default&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;R80.30 2.6/ 3.10 kernel with more the 35 cores &amp;gt; USFW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;R80.20 2.6/ 3.10 kernel with more the 35 cores &amp;gt; USFW&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 19:23:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77777#M5974</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-09T19:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77785#M5976</link>
      <description>As these, 3600, 6200, 6600, 6900, 16000T, 26000, 26000T and 23900, are all newer models they come with the 3.10 kernel, even in R80.30 and therefore come with the USFW enabled?</description>
      <pubDate>Mon, 09 Mar 2020 21:18:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77785#M5976</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-09T21:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77802#M5979</link>
      <description>My guess? Hyper-threading.</description>
      <pubDate>Tue, 10 Mar 2020 01:50:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77802#M5979</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-10T01:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77818#M5980</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt; That's very good guess and the only reasonable explanation so far. Thank you.&lt;/P&gt;
&lt;P&gt;I have one of these on its way to me. Can't wait to play with it and will provide some more info later &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 04:27:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77818#M5980</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-10T04:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77826#M5982</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;We have been discussing this topic here in the forum for about 2 months.&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-User-Mode-Firewall-vs-Kernel-Mode/m-p/70759/highlight/true#M14330" target="_self"&gt;R80.x - Performance Tuning Tip – User Mode Firewall vs. Kernel Mode Firewall&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;-&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-during-process-fwk0-dev-0-UMFW-vs-KMFW/m-p/70648/highlight/true#M14307" target="_self"&gt;High CPU utilization during process fwk0_dev_0 (UMFW vs. KMFW)&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;- this article&lt;/P&gt;
&lt;P&gt;Only this&amp;nbsp; information can you found in the KB! I think that is not enough.&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk149973&amp;amp;partition=Advanced&amp;amp;product=Data" target="_blank" rel="noopener"&gt;sk149973: How to enable USFW (User-Space Firewall) on a 23900 appliance&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have also spent some time here at LAB to test this with HP DL360 servers with 28 cores vs 56 cores for R80.20 / R80.30 / R80.40 with kernel 3.10&amp;nbsp; and R80.20 / R80.30 with kernel 2.6.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My request, please write a SK, in which the USFW vs. KMFW are described.&amp;nbsp;&lt;/SPAN&gt;I think that would be very helpful for all of us.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;Heiko&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 06:47:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77826#M5982</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-10T06:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77830#M5983</link>
      <description>&lt;P&gt;I think the 3600 has four cores.&amp;nbsp;Therefore with HT 8 cores.&amp;nbsp;Now the big question, why USFW is enabled with&amp;nbsp; 8&amp;nbsp; (or 4) cores for R80.30.&lt;/P&gt;
&lt;P&gt;On an open server only with more than 35 cores USFW is enabled. (I have checked this in the LAB)?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 07:08:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77830#M5983</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-10T07:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77832#M5984</link>
      <description>&lt;P&gt;Exactly what I am thinking as well. The number of cores on 3600 (4) and 3600-T (8) is just far bellow what's reasonable to enable USFW by default even with HT enabled.&amp;nbsp; So, it is either mistake in release notes or just there is something we are missing or unaware...&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt; I also second Heiko that we need SK about this. &lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 07:18:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77832#M5984</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-10T07:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77833#M5985</link>
      <description>&lt;P&gt;To create some more confusion...&lt;/P&gt;
&lt;P&gt;Last weeks I did new installs of R80.30 on different HP DL 380/360 G9 / G10 hardware. All are with less then 28 cores and all&lt;/P&gt;
&lt;P&gt;had USFW enabled after install.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;I support&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp;request for a knowledgebase article about both modes.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 07:20:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77833#M5985</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-03-10T07:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77865#M5986</link>
      <description>&lt;P&gt;I'd like to also cast my vote for a full disclosure SK specifying exactly under which conditions USFW will be enabled and why. &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&amp;nbsp; While researching the third edition of my book I ran across this same question, and the only answer I could ever get is "it depends".&amp;nbsp; So I had to kind of punt in my book to some degree, show how to determine if USFW was enabled, and say to not change the default without consulting TAC.&lt;/P&gt;
&lt;P&gt;I don't understand why USFW would be enabled by default on a 6900 or lower (16 cores or less), perhaps USFW can take advantage of SMT much more efficiently, but I doubt it.&amp;nbsp; 16000 and higher (32-48 cores), sure USFW makes sense.&amp;nbsp; It looks like the ability to disable SMT via &lt;STRONG&gt;cpconfig&lt;/STRONG&gt; has been removed on certain Check Point appliances as well, thus only enabling TAC to disable it from the BIOS, which I don't understand either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 12:20:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77865#M5986</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-03-10T12:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77891#M5987</link>
      <description>&lt;P&gt;I renamed this thread as it is not only about 3600 appliances.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 16:13:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77891#M5987</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-10T16:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77914#M5989</link>
      <description>&lt;P&gt;Some of the questions in this thread are answered here: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk93000" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk93000&lt;/A&gt;&lt;BR /&gt;This SK is missing all the appliances we announced this year, but they are similar to the 6500/6800 in the sense SMT is enabled by default.&lt;BR /&gt;Further,&amp;nbsp;expect USFW to be enabled by default in the most recent code versions for the newest appliances.&lt;BR /&gt;&lt;BR /&gt;I've also asked the SK team to update sk93000 with the new appliances and to clarify the limitations section as it contradicts the "supported platforms" statements in a few areas.&lt;/P&gt;
&lt;P&gt;(Edited to reflect confirmation from R&amp;amp;D on SMT on newer appliances).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 21:51:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77914#M5989</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-10T21:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77924#M5990</link>
      <description>&lt;P&gt;I hope for a technical explanation from R&amp;amp;D as to why is USFW enabled by default on appliances with low number of CPU cores (even with SMT enabled).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 04:21:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/77924#M5990</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-11T04:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78023#M5992</link>
      <description>I assume it's because it provides for better performance than without, particularly when you're using NGTP/NGTX Software Blades.&lt;BR /&gt;&lt;BR /&gt;In terms of kernel memory utilization, USFW is a significant improvement as we're not having to load a large CoreXL driver for each core (real and virtual).&lt;BR /&gt;Even with a small number of cores, that adds up.</description>
      <pubDate>Wed, 11 Mar 2020 21:45:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78023#M5992</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-11T21:45:30Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78053#M5994</link>
      <description>&lt;P&gt;All right. I think we are getting into some kind of loop here so I will just halt it at this point with not understanding why USFW is enabled by default on one 8 core appliance and disabled on another.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 04:09:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78053#M5994</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-03-12T04:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: 3600 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78151#M6002</link>
      <description>In the Check Point appliances where it is enabled by default, we have newer Intel processors in there.&lt;BR /&gt;There must clearly be a benefit to having SMT enabled by default on these appliances, thus we do it.&lt;BR /&gt;It has nothing to do with the number of cores available in this case.&lt;BR /&gt;&lt;BR /&gt;For systems with older CPUs with more than 40 cores, USFW is required to utilize them all. &lt;BR /&gt;I assume on those appliances, we would also enable USFW by default.&lt;BR /&gt;&lt;BR /&gt;I hope that clears things up.</description>
      <pubDate>Thu, 12 Mar 2020 19:51:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/USFW-enablement-not-clear-SK-needed/m-p/78151#M6002</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-12T19:51:35Z</dc:date>
    </item>
  </channel>
</rss>

