<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Playing with benchmarking tools, is there a preferred direction??? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102344#M8033</link>
    <description>&lt;P&gt;Open a case with TAC to get behind this...&lt;/P&gt;</description>
    <pubDate>Tue, 17 Nov 2020 14:32:49 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2020-11-17T14:32:49Z</dc:date>
    <item>
      <title>Playing with benchmarking tools, is there a preferred direction???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102335#M8031</link>
      <description>&lt;P&gt;Hello Check Pointers,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;i have a question, maybe you can enlighten me with your experience on benchmarking and performance tuning ...&lt;BR /&gt;&lt;BR /&gt;I have an old firewall, OpenServer, 4 CPU´s no blades, just FW enabled. During working hours its totaly overloaded, only SecureXL keeps it alive :-).&lt;BR /&gt;Out of working hours the load is of course very low and we achive 1G wire speed, yes really!&lt;BR /&gt;But during working hours, the speed from LAN to DMZ is horrible, other way is "good"&amp;nbsp;&lt;BR /&gt;Yes sure the firewall has reached its end, a replacement is planned!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When we do a benchmark,&amp;nbsp; we use NetIO, not the best i know, but pretty common in the geman speaking world, we see some connections are ALWAYS much faster then others.&lt;BR /&gt;&lt;BR /&gt;LAN -&amp;gt; DMZ is always SLOW&lt;BR /&gt;DMZ -&amp;gt; LAN is always FAST&lt;BR /&gt;&lt;BR /&gt;i have a quick drawing.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Unbenannt.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9020i17E4982640B9F9EE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Unbenannt.png" alt="Unbenannt.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Overall Question, why is a benchmark from LAN to DMZ bad and a test DMZ to LAN good?&lt;BR /&gt;Is a prefered direction existing?&lt;/STRONG&gt;&lt;BR /&gt;The benchmark tool uses the same SRC &amp;amp; DST Ports for both directions. UDP &amp;amp; TCP&lt;BR /&gt;You see we have different MTU and different Load Sharing Settings on the Interfaces. (Firewall has L3+4 distribution, Switch L2)&lt;BR /&gt;Different port speeds causing different Window Size?&lt;BR /&gt;Bond on LAN interface is Onboard Nic and BroadCom, a double NoGo &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;I know this is way to less information to get a precise answer ...&amp;nbsp;&lt;BR /&gt;But besides of replacing this firewall hardware what are your thoughts on this?&lt;BR /&gt;&lt;BR /&gt;best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thomas.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 13:02:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102335#M8031</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2020-11-17T13:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Playing with benchmarking tools, is there a preferred direction???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102343#M8032</link>
      <description>&lt;P&gt;The answer to your question will be highly dependent on your code level, what is it?&amp;nbsp; If R80.10 or lower, fragmentation due to the differing MTUs is going to kill you as fragmented traffic cannot be accelerated in R80.10 or lower.&amp;nbsp; Other possibility to explain different throughput depending on direction is network interface errors, which will be revealed by &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;.&amp;nbsp; Looks like you may have changed ring buffer sizes from the defaults, almost never a good idea and can easily make things worse.&amp;nbsp; Also Broadcom NICs are terrible and should never be used to carry production traffic.&lt;/P&gt;
&lt;P&gt;Please provide the output of the "Super Seven", ideally taken when the firewall is under heavy load and I can give you a more definitive answer:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Super-Seven-Performance-Assessment-Commands-s7pac/m-p/40528?search-action-id=19001329518&amp;amp;search-result-uid=40528" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/Super-Seven-Performance-Assessment-Commands-s7pac/m-p/40528?search-action-id=19001329518&amp;amp;search-result-uid=40528&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 14:33:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102343#M8032</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-11-17T14:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: Playing with benchmarking tools, is there a preferred direction???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102344#M8033</link>
      <description>&lt;P&gt;Open a case with TAC to get behind this...&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 14:32:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102344#M8033</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-11-17T14:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Playing with benchmarking tools, is there a preferred direction???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102347#M8034</link>
      <description>&lt;P&gt;Hello Timothy,&amp;nbsp;&lt;BR /&gt;as always the story is longer then my first explanation ...&lt;BR /&gt;we did an update from R77.30 to R80.30 Take 155, after some time we encountered a slowness.&amp;nbsp;&lt;BR /&gt;I see NO network interface errors, no Drops at all!&lt;BR /&gt;no indication for fragmentations.&lt;BR /&gt;iam looking forward to get access and run your super7 to provide you with more details!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 14:43:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102347#M8034</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2020-11-17T14:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Playing with benchmarking tools, is there a preferred direction???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102348#M8035</link>
      <description>&lt;P&gt;Hi, yes we have a TAC case running already&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 14:43:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102348#M8035</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2020-11-17T14:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: Playing with benchmarking tools, is there a preferred direction???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102360#M8038</link>
      <description>&lt;P&gt;R80.30 has a known problem where the TLS parser is invoked inappropriately which causes performance issues, fixed in Jumbo HFA Take 219+ and you are running 155...does this apply to your scenario:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166700&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener noreferrer"&gt;sk166700: High CPU after upgrade from R77.x to R80.x when running only Firewall and Monitoring blade...&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 16:31:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102360#M8038</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-11-17T16:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Playing with benchmarking tools, is there a preferred direction???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102534#M8055</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;Hello,&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;so here the Super7 Output ...&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Super Seven Performance Assessment Commands v0.4 (Thanks to Timothy Hall) |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Inspecting your environment: OK |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| This is a firewall....(continuing) |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Referred pagenumbers are to be found in the following book: |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Max Power 2020: Check Point Firewall Performance Optimization - 3rd Edition |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| or when specifically mentioned in |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Max Power: Check Point Firewall Performance Optimization - Second Edition |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Available at &lt;A href="http://www.maxpowerfirewalls.com/" target="_blank"&gt;http://www.maxpowerfirewalls.com/&lt;/A&gt; |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Command #1: fwaccel stat |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Check for : Accelerator Status must be enabled (R77.xx/R80.10 versions) |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Status must be enabled (R80.20 and higher) |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Accept Templates must be enabled |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Message "disabled" from (low rule number) = bad |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 7: SecureXL throughput acceleration &amp;amp; SMT |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 8: Access Control Policy Tuning |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Page 286 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Output: |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;|Id|Name |Status |Interfaces |Features |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;|0 |SND |enabled |eth8,eth9,eth0,eth1,eth3,|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| | | |eth4,eth5,eth7 |Acceleration,Cryptography |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| | | | |SHA1,NULL,3DES,DES,CAST, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| | | | |CAST-40,AES-128,AES-256,ESP, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| | | | |LinkSelection,DynamicVPN, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| | | | |NatTraversal,AES-XCBC,SHA256 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;&lt;STRONG&gt;#### THIS IS NOT THE BEST ... THIS MUST BE FINETUNED I KNOW! ###&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;Accept Templates : disabled by Firewall&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Layer ---Drop Templates : disabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;NAT Templates : disabled by Firewall&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Layer ---&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Command #2: fwaccel stats -s |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Check for : Accelerated conns/Totals conns: &amp;gt;50% desired, &amp;gt;75% ideal |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Accelerated pkts/Total pkts : &amp;gt;50% great |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| PXL pkts/Total pkts : &amp;gt;50% OK |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| F2Fed pkts/Total pkts : &amp;lt;30% good, &amp;lt;10% great |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 7: SecureXL throughput acceleration &amp;amp; SMT |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 8: Access Control Policy Tuning |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Page 288 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Output: |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Accelerated conns/Total conns : 6703/67259 (9%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Accelerated pkts/Total pkts : 30103888360/44020630400 (68%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;F2Fed pkts/Total pkts : 451395237/44020630400 (1%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;F2V pkts/Total pkts : 119988419/44020630400 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPASXL pkts/Total pkts : 0/44020630400 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;PSLXL pkts/Total pkts : 13465346803/44020630400 (30%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;QOS inbound pkts/Total pkts : 0/44020630400 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;QOS outbound pkts/Total pkts : 0/44020630400 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Corrected pkts/Total pkts : 0/44020630400 (0%)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Command #3: grep -c ^processor /proc/cpuinfo &amp;amp;&amp;amp; /sbin/cpuinfo |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Check for : If number of cores is roughly double what you are excpecting, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| hyperthreading may be enabled |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 6: CoreXL &amp;amp; Multi-Queue |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Page 175 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Output: |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;4&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;#### THIS IS AN IBM OBENSERVER NOT AN APPLIANCE! ###&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;HyperThreading=disabled&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Command #4: fw ctl affinity -l -r |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Check for : SND/IRQ/Dispatcher Cores, # of CPU's allocated to interface(s) |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Firewall Workers/INSPECT Cores, # of CPU's allocated to fw_x |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| R77.30: Support processes executed on ALL CPU's |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| R80.xx: Support processes only executed on Firewall Worker Cores|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 6: CoreXL &amp;amp; Multi-Queue |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Page 193 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Output: |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPU 0: eth8 eth9 eth0 eth1 eth3 eth4 eth5 eth7&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPU 1: fw_2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;wsdnsd fwd vpnd mpdaemon lpd in.asessiond rtmd cpd cprid&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPU 2: fw_1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;wsdnsd fwd vpnd mpdaemon lpd in.asessiond rtmd cpd cprid&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPU 3: fw_0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;wsdnsd fwd vpnd mpdaemon lpd in.asessiond rtmd cpd cprid&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;All:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Command #5: netstat -ni |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Check for : RX/TX errors |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| RX-DRP % should be &amp;lt;0.1% calculated by (RX-DRP/RX-OK)*100 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| TX-ERR might indicate Fast Ethernet/100Mbps Duplex Mismatch |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 2: Layers 1&amp;amp;2 Performance Optimization |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Page 68-80 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 6: CoreXL &amp;amp; Multi-Queue |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Page 179 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Output: |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Kernel Interface table&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond0 1500 0 10810656204 0 0 0 9770272262 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond0.1004 1500 0 6090717681 0 0 0 6012406754 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond0.1005 1500 0 4718182186 0 0 0 3836726057 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond0.1006 1500 0 2019 0 0 0 8153 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond0.1007 1500 0 25425 0 0 0 31600 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond0.1030 1500 0 46021 0 0 0 52089 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond0.1031 1500 0 1641519 0 0 0 2037836 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1 1500 0 10840079092 0 159 0 10711067502 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1001 1500 0 3165593126 0 0 0 2920683462 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1002 1500 0 2273374428 0 0 0 2137544956 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1008 1500 0 47222589 0 0 0 45028303 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1010 1500 0 4168233 0 0 0 3964803 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1014 1500 0 18936042 0 0 0 12233215 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1015 1500 0 1676377650 0 0 0 608444189 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1016 1500 0 26136974 0 0 0 27259574 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1017 1500 0 1891577675 0 0 0 2182792432 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1024 1500 0 2736033 0 0 0 2165633 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1025 1500 0 0 0 0 0 5 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1094 1500 0 1096857550 0 0 0 2263968718 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1095 1500 0 344011256 0 0 0 126396012 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1096 1500 0 57293602 0 0 0 59563484 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1097 1500 0 3 0 0 0 8153 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1098 1500 0 3 0 0 0 8153 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.1100 1500 0 111448482 0 0 0 123177644 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.3001 1500 0 2021 0 0 0 8151 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.3002 1500 0 102850256 0 0 0 194671619 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond1.3011 1500 0 21451673 0 0 0 46844978 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond2 1500 0 8794071237 0 26723 0 10068447949 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond2.1013 1500 0 8614527101 0 0 0 9666734887 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond2.1520 1500 0 32077120 0 0 0 26240130 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond2.1521 1500 0 17487131 0 0 0 19886502 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond2.1522 1500 0 7 0 0 0 8151 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond2.1550 1500 0 25819654 0 0 0 24048269 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond2.1580 1500 0 102690997 0 0 0 332519248 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond3 1500 0 430623279 0 0 0 212809864 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond3.1003 1500 0 414118512 0 0 0 157904849 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;bond3.1012 1500 0 16462730 0 0 0 54952999 0 0 0 BMmRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth0 1500 0 2311777931 0 0 0 4927868792 0 0 0 BMsRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth1 1500 0 4142939995 0 9 0 5349009299 0 0 0 BMsRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth3 1500 0 389943270 0 0 0 110072023 0 0 0 BMsRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth4 1500 0 8498878761 0 0 0 4842403951 0 0 0 BMsRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth5 1500 0 6697139520 0 150 0 5362058554 0 0 0 BMsRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth7 1500 0 40680011 0 0 0 102737841 0 0 0 BMsRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth8 1500 0 4456758570 0 0 0 4423256669 0 0 0 BMsRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth9 1500 0 4337312667 0 26723 0 5645191280 0 0 0 BMsRU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;lo 16436 0 156204 0 0 0 156204 0 0 0 LRU&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;interface eth0: There are no RX drops&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;interface eth1: There are no RX drops&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;interface eth3: There are no RX drops&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;interface eth4: There are no RX drops&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;interface eth5: There are no RX drops&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;interface eth7: There are no RX drops&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;interface eth8: There are no RX drops&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;interface eth9: There are no RX drops&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Command #6: fw ctl multik stat |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Check for : Large # of conns on Worker 0 - IPSec VPN/VoIP? |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Large imbalance of connections on a single or multiple Workers |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 6: CoreXL &amp;amp; Multi-Queue |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Page 216 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 9: Site-to-Site VPN Optimization |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Page 329 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Max Power: Check Point Firewall Performance Optimization - Second Edition |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 7: CoreXL Tuning |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Page 241 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 8: CoreXL VPN Optimization |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Page 256 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Output: |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;ID | Active | CPU | Connections | Peak &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;----------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;0 | Yes | 3 | 23101 | 29698&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;1 | Yes | 2 | 21817 | 29293&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2 | Yes | 1 | 23289 | 28789&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Command #7: cpstat os -f multi_cpu -o 1 -c 5 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Check for : High SND/IRQ Core Utilization |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| High Firewall Worker Core Utilization |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Chapter 6: CoreXL &amp;amp; Multi-Queue |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Page 173 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Output: |&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Processors load&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 1| 0| 55| 45| 55| ?| 77859|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 2| 5| 26| 69| 31| ?| 77861|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 3| 4| 28| 69| 31| ?| 77861|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 4| 3| 26| 71| 29| ?| 77863|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Processors load&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 1| 0| 55| 45| 55| ?| 77859|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 2| 5| 26| 69| 31| ?| 77861|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 3| 4| 28| 69| 31| ?| 77861|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 4| 3| 26| 71| 29| ?| 77863|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Processors load&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 1| 0| 56| 44| 56| ?| 71746|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 2| 1| 29| 71| 29| ?| 71751|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 3| 1| 26| 73| 27| ?| 71755|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 4| 1| 25| 74| 26| ?| 71757|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Processors load&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 1| 0| 56| 44| 56| ?| 71746|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 2| 1| 29| 71| 29| ?| 71751|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 3| 1| 26| 73| 27| ?| 71755|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 4| 1| 25| 74| 26| ?| 71757|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Processors load&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 1| 0| 55| 46| 54| ?| 23471|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 2| 2| 23| 75| 25| ?| 23476|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 3| 1| 26| 74| 26| ?| 23479|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| 4| 1| 21| 78| 22| ?| 46966|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;---------------------------------------------------------------------------------&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| Thanks for using s7pac |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+-----------------------------------------------------------------------------+&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;EM&gt;&lt;STRONG&gt;we did run a cpsizeme too of course, a new hardware is on its way, but the replacement will take some time!&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;best regards&lt;BR /&gt;Thomas.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 17:09:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102534#M8055</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2020-11-18T17:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Playing with benchmarking tools, is there a preferred direction???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102544#M8060</link>
      <description>&lt;P&gt;Your policy layer name is too long in the SmartConsole, please shorten it to 31 or less characters, install policy, run &lt;STRONG&gt;fwaccel stat&lt;/STRONG&gt; again, and post the output.&amp;nbsp; Based on the 9% accept templating rate there probably needs to be some optimizations there.&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk145533&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener"&gt;sk145533: "Layer ---" is displayed instead of specific layer name and rule number in output of '&lt;STRONG&gt;fwaccel&lt;/STRONG&gt; &lt;STRONG&gt;stat&lt;/STRONG&gt;'&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Depending on what blades you have enabled that 30% PXL percentage might be OK, or it might be the TLS parser issue I mentioned.&amp;nbsp; Please provide output of &lt;STRONG&gt;enabled_blades&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Everything else including network counters and CoreXL split look fine.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 18:28:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102544#M8060</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-11-18T18:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: Playing with benchmarking tools, is there a preferred direction???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102957#M8108</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;i changed the policy name and here is the output!&lt;BR /&gt;i saw that DHPC relay still used the old legacy protocolls, and stopped accept remplates at rule #11.&lt;BR /&gt;i moved them to the buttom, #924.&lt;BR /&gt;also i will switch to the new services in a maintenance window ...&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NW_Land_Salzburg_Schema2.png" style="width: 902px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9202iE621F0C7E46B349B/image-size/large?v=v2&amp;amp;px=999" role="button" title="NW_Land_Salzburg_Schema2.png" alt="NW_Land_Salzburg_Schema2.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;blades are as followss:&lt;BR /&gt;enabled_blades&lt;BR /&gt;fw mon vpn&lt;BR /&gt;&lt;BR /&gt;so its really not that much!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 11:15:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102957#M8108</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2020-11-23T11:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: Playing with benchmarking tools, is there a preferred direction???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102959#M8109</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;but the main reason of my question ... is still how why is there be a prefence in a certain direction when i do a speed test?&lt;BR /&gt;its clear the firwall is old and has reache its end ... but how to explain that some directions are fast and other are slow?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Speedtest.png" style="width: 546px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9203iF9A74C9EF6A6D422/image-size/large?v=v2&amp;amp;px=999" role="button" title="Speedtest.png" alt="Speedtest.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 11:18:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102959#M8109</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2020-11-23T11:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: Playing with benchmarking tools, is there a preferred direction???</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102991#M8112</link>
      <description>&lt;P&gt;Assuming there is not some kind asymmetry in the network routing, tracking down directional speed differences like that is going to be tough.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try running &lt;STRONG&gt;top&lt;/STRONG&gt; and hit 1 if needed to display all individual cores.&amp;nbsp; Start one of your benchmark tests and watch the individual core utilizations carefully, do any of them drop to around 0% idle?&amp;nbsp; If so that is the bottleneck.&lt;/P&gt;
&lt;P&gt;If none of them drop to near 0% idle, at that point you need to gather a packet capture and pull it into Wireshark for protocol analysis at the TCP level.&amp;nbsp; Wireshark can help with locating TCP zero windows and other network protocol-based conditions that can slow you down; the essential question you need to answer is whether the slower performance is being caused by latency (or jitter) or flat-out packet loss.&amp;nbsp; In general performing that type of advanced analysis directly from the CLI is difficult.&amp;nbsp; You can try running your packet capture through the &lt;STRONG&gt;cpmonitor&lt;/STRONG&gt; tool built into Gaia for some fast statistical analysis (&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk103212&amp;amp;partition=Basic&amp;amp;product=Other" target="_blank"&gt;sk103212: Traffic analysis using the '&lt;STRONG&gt;CPMonitor&lt;/STRONG&gt;' tool&lt;/A&gt;), but I think you'll need the power of Wireshark analysis for this one.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 13:58:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Playing-with-benchmarking-tools-is-there-a-preferred-direction/m-p/102991#M8112</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-11-23T13:58:49Z</dc:date>
    </item>
  </channel>
</rss>

