<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;out of the box performance tool&amp;quot; in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/93022#M7185</link>
    <description>&lt;P&gt;Dynamic Split is not enabled by default in R80.40, have you enabled it?&lt;/P&gt;
&lt;P&gt;Your output looks correct, the management interface traffic can only be handled on core 0 but there are 8 SND/IRQ cores so the line of zeroes is expected.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dynamic Split will have to work with the out of the box performance tool (which is what seems to be happening) so I don't see an issue here.&lt;/P&gt;</description>
    <pubDate>Fri, 31 Jul 2020 14:47:03 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2020-07-31T14:47:03Z</dc:date>
    <item>
      <title>"out of the box performance tool"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/92538#M7132</link>
      <description>&lt;P&gt;Hello Check Point Gurus.&lt;/P&gt;&lt;P&gt;Has anyone heard about (or used) the "out of the box performance tool" that exists in the R80.30&amp;nbsp; code based on the 3.10 kernel as well as R80.40? There is a single reference to this in the whole SK database,&amp;nbsp;&lt;STRONG&gt;sk153373, &lt;/STRONG&gt;dealing with the automatic management of interfaces multi-queue associations...&lt;/P&gt;&lt;P&gt;I hit a problem with&amp;nbsp; a new 16200 cluster deployed where one of the 10G interfaces is a production interface, carrying a lot of traffic but is also defined as the Management interface fro the appliance... As such (being the management interface) that is left out of the multi-queue configuration and gets a single SND core assigned. That core gets into 70 - 80 % usage with 150 remote users tunneling into the cluster... The end-user plan was to have 2000 concurrent users... Without getting multi-queue enabled on that that interface this will be impossible to achieve...&lt;/P&gt;&lt;P&gt;Any hints / ideas will be much appreciated...&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Valeriu&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 15:02:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/92538#M7132</guid>
      <dc:creator>Valeriu_Cioara1</dc:creator>
      <dc:date>2020-07-27T15:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: "out of the box performance tool"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/92805#M7164</link>
      <description>&lt;P&gt;Which version are you actually using?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 02:53:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/92805#M7164</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-30T02:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: "out of the box performance tool"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/92846#M7167</link>
      <description>&lt;P&gt;R80.40 With JHF 65 installed on top...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 10:19:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/92846#M7167</guid>
      <dc:creator>Valeriu_Cioara1</dc:creator>
      <dc:date>2020-07-30T10:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: "out of the box performance tool"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/92874#M7170</link>
      <description>&lt;P&gt;why not change the Management interface ? IN WebGUI or like in&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108333&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;sk108333: "NMSETH0029 &lt;STRONG&gt;Management&lt;/STRONG&gt; &lt;STRONG&gt;interface&lt;/STRONG&gt; must have an IP address" error in Gaia Clish when trying to assign an IP address?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 14:34:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/92874#M7170</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-07-30T14:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: "out of the box performance tool"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/92877#M7172</link>
      <description>&lt;P&gt;My interpretation of the "out-of-the-box performance tool" is that it is the replacement for Automatic Interface Affinity that was employed in prior versions.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under the old scheme, Automatic Interface Affinity would check network interface utilization every 60 seconds and potentially shift SoftIRQ processing around on the different SND/IRQ cores in an attempt to keep them roughly balanced.&amp;nbsp; But only one SND/IRQ core could empty a single interface's ring buffer via SoftIRQ unless Multi-Queue was manually enabled by an administrator, and no more than 5 physical interfaces could have Multi-Queue enabled at a time.&amp;nbsp; There were also various driver-based queue limits that kept all SND/IRQ cores from being able to empty a single interface's ring buffer, even if Multi-Queue was enabled for that interface.&lt;/P&gt;
&lt;P&gt;When Gaia 3.10 is in use on a gateway (some R80.30 or R80.40), the out-of-the-box performance tool automatically enables Multi-Queue on all interfaces except the management interface and the 5 interface limit is no longer present; the various driver-based queue limits were also substantially increased for some types of interfaces.&amp;nbsp; The expert mode &lt;STRONG&gt;mq_mng&lt;/STRONG&gt; command is used to query and configure this new tool, although in R80.40 there have been new clish commands added for managing Multi-Queue instead.&amp;nbsp; Here is an example of &lt;STRONG&gt;mq_mng&lt;/STRONG&gt; in action:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vmxnet3_MQ.png" style="width: 967px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7429i90E1E56C2E5D09FB/image-size/large?v=v2&amp;amp;px=999" role="button" title="Vmxnet3_MQ.png" alt="Vmxnet3_MQ.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The reason that the Gaia management interface is excluded from Multi-Queue by the tool is to ensure that the box can still be remotely managed and interacted with even if this mechanism somehow fails.&amp;nbsp; In general you want to leave the tool alone and not try to make changes (especially to number of queues in use), lest the tool stop ensuring that Multi-Queue is enabled on all interfaces but the management one.&lt;/P&gt;
&lt;P&gt;So to&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7076"&gt;@Valeriu_Cioara1&lt;/a&gt;'s specific situation, I would recommend the following:&lt;/P&gt;
&lt;P&gt;Change the management interface in Gaia to some other interface that you can reach for SSH/WebUI management.&amp;nbsp; Note however that Multi-Queue will not be automatically enabled on the prior management interface, see the supported steps needed to force this here:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167200&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener"&gt;sk167200: Multi-queue state is "off" when changing the management interface&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It does not appear possible to force the existing management interface to use Multi-Queue, at least that I can see.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;mq_mng --set-mode manual --interface eth0 -c 0-7&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;error: Management interface 'eth0' cannot be configured&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 18:12:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/92877#M7172</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-07-30T18:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: "out of the box performance tool"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/93007#M7183</link>
      <description>&lt;P&gt;Thanks guys, much appreciated... To give you an update, I changed the management interface on the appliance to one of the copper interfaces that are less used... That allowed us to have multi-queue enabled on the 10G production interface, which in turn appeared to have resolved the bottleneck of having a single core assigned to that interface...&lt;/P&gt;&lt;P&gt;There are still a number of questions about this new multi-queue operation and how it interacts with the SND / CoreXL dynamic split introduced in R80.40...&lt;/P&gt;&lt;P&gt;The output of mq_mng -o commands shows the production interfaces as "dynamic" and the management interface as "auto", with 8 times core 0 associated to it... See screenshot below...&amp;nbsp; I was expecting "auto" and "off" respectively...&lt;/P&gt;&lt;P&gt;Total 48 cores. Multiqueue 8 cores&lt;BR /&gt;i/f type state mode cores&lt;BR /&gt;------------------------------------------------------------------------------------------------&lt;BR /&gt;eth1-02 igb Up Dynamic (8/8) 0,24,12,36,1,25,13,37&lt;BR /&gt;eth1-03 igb Up Dynamic (8/8) 0,24,12,36,1,25,13,37&lt;BR /&gt;eth1-04 igb Up Dynamic (8/8) 0,24,12,36,1,25,13,37&lt;BR /&gt;eth1-05 igb Up Dynamic (8/8) 0,24,12,36,1,25,13,37&lt;BR /&gt;eth1-06 igb Up Auto (8/8)* 0,0,0,0,0,0,0,0&lt;BR /&gt;eth2-01 i40e Up Dynamic (8/8) 24,12,36,1,25,13,37,0&lt;BR /&gt;eth2-02 i40e Up Dynamic (8/8) 24,12,36,1,25,13,37,0&lt;BR /&gt;* Management interface&lt;/P&gt;&lt;P&gt;Should I stop or disable the dynamic split, in order to have multi-queue behave as described in the R80.40 Admin guides and SKs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 12:11:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/93007#M7183</guid>
      <dc:creator>Valeriu_Cioara1</dc:creator>
      <dc:date>2020-07-31T12:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: "out of the box performance tool"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/93022#M7185</link>
      <description>&lt;P&gt;Dynamic Split is not enabled by default in R80.40, have you enabled it?&lt;/P&gt;
&lt;P&gt;Your output looks correct, the management interface traffic can only be handled on core 0 but there are 8 SND/IRQ cores so the line of zeroes is expected.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dynamic Split will have to work with the out of the box performance tool (which is what seems to be happening) so I don't see an issue here.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2020 14:47:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/quot-out-of-the-box-performance-tool-quot/m-p/93022#M7185</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-07-31T14:47:03Z</dc:date>
    </item>
  </channel>
</rss>

