<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gaia partition misalignment in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160817#M70652</link>
    <description>&lt;P&gt;I have asked R&amp;amp;D owners to comment here, please give them a bit of time to do that.&lt;/P&gt;
&lt;P&gt;Spoiler alert: AFAIK, R81.20 clean install should resolve the issue.&lt;/P&gt;</description>
    <pubDate>Mon, 31 Oct 2022 12:07:54 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-10-31T12:07:54Z</dc:date>
    <item>
      <title>Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160677#M70648</link>
      <description>&lt;P&gt;During Gaia installation (appliance/open server), partitions are NOT aligned on a 1MB boundary, but are instead cylinder-aligned, in a MS-DOS compatible way.&lt;/P&gt;&lt;P&gt;This alignment turns to a real performance problem with today's RAID, SSDs and AF HDDs.&lt;BR /&gt;Filesystem blocks being misaligned with storage blocks leads to read-before-write operations, which can incur a severe performance hit.&lt;BR /&gt;My own measurements showed storage performance being more than halved on some specific workload.&lt;BR /&gt;(The worst case scenario probably is heavy SmartEvent activity.)&lt;/P&gt;&lt;P&gt;This issue was fixed in WS 2008 and RHEL 6, when the performance hit first became obvious.&lt;BR /&gt;Gaia should have inherited the fix from RHEL, but this did not happen due to the use of a custom installer.&lt;BR /&gt;The packaged fdisk utility was fixed, the installer was not.&lt;/P&gt;&lt;P&gt;Fixing an installed Check Point system is almost impossible and requires LVM wizardry.&lt;/P&gt;&lt;P&gt;Please fix the installer and make sure partitions are 1MB-aligned at installation time.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2022 14:32:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160677#M70648</guid>
      <dc:creator>nmelay</dc:creator>
      <dc:date>2022-10-28T14:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160678#M70649</link>
      <description>&lt;P&gt;The above was posted as an RFE to &lt;A href="https://usercenter.checkpoint.com/ucapps/rfe/" target="_blank"&gt;https://usercenter.checkpoint.com/ucapps/rfe/&lt;/A&gt; (reference number: lH5U9X43H), and I'm bringing it here to raise general awareness.&lt;/P&gt;&lt;P&gt;I know this has been reported before, and wrongly dismissed as an issue of the past.&lt;BR /&gt;The issue is very real, and very current on Check Point software.&lt;BR /&gt;I really want this to get ironed out now, there's no excuse for this 10-15 years after it was fixed by everyone else.&lt;BR /&gt;Sadly, this is probably too late for R81.20.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2022 14:34:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160678#M70649</guid>
      <dc:creator>nmelay</dc:creator>
      <dc:date>2022-10-28T14:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160768#M70650</link>
      <description>&lt;P&gt;R81.20 has a newer installer—might be worth checking the Public EA to see if it has the same issue.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 02:15:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160768#M70650</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-31T02:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160796#M70651</link>
      <description>&lt;P&gt;How to check for that in a simple way ?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 09:19:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160796#M70651</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-10-31T09:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160817#M70652</link>
      <description>&lt;P&gt;I have asked R&amp;amp;D owners to comment here, please give them a bit of time to do that.&lt;/P&gt;
&lt;P&gt;Spoiler alert: AFAIK, R81.20 clean install should resolve the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 12:07:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160817#M70652</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-31T12:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160834#M70653</link>
      <description>&lt;P&gt;I did not get to play with the R81.20 ISO, only the upgrade package.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 14:19:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160834#M70653</guid>
      <dc:creator>nmelay</dc:creator>
      <dc:date>2022-10-31T14:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160836#M70654</link>
      <description>&lt;P&gt;When you are upgrading, you get stuck with your "old" file system anyway&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 14:21:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160836#M70654</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-31T14:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160837#M70655</link>
      <description>&lt;P&gt;fdisk -l /dev/sda&lt;/P&gt;&lt;P&gt;Every partition's first sector (Start) should be a multiple of 2048.&lt;BR /&gt;That's especially true for the LVM PVs.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 14:21:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160837#M70655</guid>
      <dc:creator>nmelay</dc:creator>
      <dc:date>2022-10-31T14:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160838#M70656</link>
      <description>&lt;P&gt;Thanks Val for the good news.&lt;BR /&gt;I'm delighted to hear this topic is getting the attention it deserves.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 14:22:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160838#M70656</guid>
      <dc:creator>nmelay</dc:creator>
      <dc:date>2022-10-31T14:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160839#M70657</link>
      <description>&lt;P&gt;Sure thing. I can promise you, this particular issue is addressed very seriously.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 14:28:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160839#M70657</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-31T14:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160841#M70658</link>
      <description>&lt;P&gt;Indeed.&lt;/P&gt;&lt;P&gt;The "easiest" way to fix the alignment on an existing system is to create a new LVM PV, move LVs to the new PV, recreate the original PV correctly aligned, and move everything back.&lt;BR /&gt;That's something you can manage on a VM with enough available storage.&lt;BR /&gt;(Also, the misalignment/realignment will break deduplication on smart NAS/SAN storage, so you won't benefit from this.)&lt;/P&gt;&lt;P&gt;On a physical server or Smart-1 appliance, you need to shrink the existing PV, resize the hosting partition, create a new partition/PV, move LVs...&lt;/P&gt;&lt;P&gt;Anyway, you need to know what you're doing and make sure solid backups are not too far away.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 15:00:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160841#M70658</guid>
      <dc:creator>nmelay</dc:creator>
      <dc:date>2022-10-31T15:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160846#M70659</link>
      <description>&lt;P&gt;Indeed as mentioned above, R81.20 release will have a new installer (with new fdisk of course) so clean installation will align the partitions to a 1MB boundary.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2022 15:43:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/160846#M70659</guid>
      <dc:creator>itzhakd</dc:creator>
      <dc:date>2022-10-31T15:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161019#M70660</link>
      <description>&lt;P&gt;OK, I did so, and verified that R81.20 EA correctly aligns partitions.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 11:15:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161019#M70660</guid>
      <dc:creator>nmelay</dc:creator>
      <dc:date>2022-11-02T11:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161024#M70661</link>
      <description>&lt;P&gt;Thanks Itzhak for your confirmation.&lt;/P&gt;&lt;P&gt;It will be a while before R81.20 is widely adopted.&lt;BR /&gt;Do you know if there will there be an updated R81.10 ISO?&amp;nbsp; And fix instructions for existing setups?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 11:40:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161024#M70661</guid>
      <dc:creator>nmelay</dc:creator>
      <dc:date>2022-11-02T11:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161028#M70662</link>
      <description>&lt;P&gt;I hope you are happy now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 13:21:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161028#M70662</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-02T13:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161034#M70663</link>
      <description>&lt;P&gt;Yes I am!&lt;BR /&gt;Problem was fixed before I even got to report it, that's quite a feat!&lt;/P&gt;&lt;P&gt;Still I'd like to know where Check Point stands on this issue regarding current releases and upgrades.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 14:52:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161034#M70663</guid>
      <dc:creator>nmelay</dc:creator>
      <dc:date>2022-11-02T14:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161035#M70664</link>
      <description>&lt;P&gt;I will let R&amp;amp;D answer the question about clean install, although I find it very unlike that we will be able to change that, too many moving parts for the released version: production lines, install tolls, Blink images, etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For the upgrades, you are stuck with your pre-existing file system, unless you perform a clean install.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 14:58:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161035#M70664</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-02T14:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161040#M70665</link>
      <description>&lt;P&gt;Okay, after some internal chatter, it seems we will not be fixing the alignment with the previous versions.&lt;BR /&gt;&lt;BR /&gt;Also, a personal note, in my 24 years with CP, I have never seen that being an actual issue. Any reason?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 15:28:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161040#M70665</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-02T15:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161058#M70666</link>
      <description>&lt;P&gt;Thanks for your time Val, I really appreciate this.&lt;/P&gt;&lt;P&gt;I take note that previous/existing versions won't be updated, I can understand this.&lt;BR /&gt;I'm really glad the fix is part of the R81.20 release, whether is was intentional or a side effect of the new installer. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I wish the issue was clearly documented -- maybe this will happen once R81.20 is released.&lt;BR /&gt;Right now, Best practices for running SMS on VMware (sk104848) states you should&amp;nbsp;"make sure the disk partitions within the guest are aligned"... but omits to say Gaia installer (up to R81.10) will forbid you from doing so.&lt;/P&gt;&lt;P&gt;What brought the issue back to my attention recently was a customer with abysmal SmartEvent performance.&lt;BR /&gt;A colleague of mine spent days relocating the log server to a new hosting infrastructure and reindexing everything, only to get a minor performance improvement.&lt;BR /&gt;When I had a look at it, the misalignment issue was obvious to me. With a few decades of systems/storage experience, misaligned partitions bring back old memories of poorly performing database workloads, wrongly designed/poorly documented storage vendor fixes (I'm looking at you, NetApp!) and so on.&lt;BR /&gt;I knew I saw it before on Check Point installs, but only then realized ALL of them are affected: old and new appliances, open servers, even CloudGuard IaaS Azure instances.&lt;BR /&gt;We did NOT spend more days fixing this for this specific customer -- we probably won't until he brings it back and we get an officially supported procedure for this. But I did run some tests on my own and it did not look good.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 18:23:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161058#M70666</guid>
      <dc:creator>nmelay</dc:creator>
      <dc:date>2022-11-02T18:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia partition misalignment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161060#M70667</link>
      <description>&lt;P&gt;Thanks for the thorough write-up.&lt;/P&gt;
&lt;P&gt;However, I will ask again, what were the issues you experienced with Check Point, related to the&amp;nbsp;&lt;SPAN&gt;cylinder-aligned partitions?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2022 18:49:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-partition-misalignment/m-p/161060#M70667</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-02T18:49:34Z</dc:date>
    </item>
  </channel>
</rss>

