<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unusual high CPU after migration VSX R77.30 to R80.30 jumbo take 215 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unusual-high-CPU-after-migration-VSX-R77-30-to-R80-30-jumbo-take/m-p/96771#M8780</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am just wonder, if you observe similar behavior. We are running VSX cluster Check point&amp;nbsp;12200, 4CPUs, 8G of memory,&amp;nbsp;CPAC-4-10 line card.&lt;/P&gt;&lt;P&gt;Prior migration from R77.30 to R80.30 hfa 215 we had CPU utilization:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:2]#top&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;top - 15:08:42 up 541 days, 13:07,&amp;nbsp; 2 users,&amp;nbsp; load average: 0.96, 1.04, 0.95&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Tasks: 151 total,&amp;nbsp;&amp;nbsp; 1 running, 150 sleeping,&amp;nbsp;&amp;nbsp; 0 stopped,&amp;nbsp;&amp;nbsp; 0 zombie&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Cpu(s):&amp;nbsp; 4.6%us,&amp;nbsp; 2.3%sy,&amp;nbsp; 0.0%ni, 87.2%id,&amp;nbsp; 0.1%wa,&amp;nbsp; 0.2%hi,&amp;nbsp; 5.5%si,&amp;nbsp; 0.0%st&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Mem:&amp;nbsp;&amp;nbsp; 8029532k total,&amp;nbsp; 7977484k used,&amp;nbsp;&amp;nbsp;&amp;nbsp; 52048k free,&amp;nbsp;&amp;nbsp; 419772k buffers&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Swap: 18908408k total,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 544k used, 18907864k free,&amp;nbsp; 2963120k cached&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; PID USER&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PR&amp;nbsp; NI&amp;nbsp; VIRT&amp;nbsp; RES&amp;nbsp; SHR S %CPU %MEM&amp;nbsp;&amp;nbsp;&amp;nbsp; TIME+&amp;nbsp; COMMAND&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;16043 admin&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 -20&amp;nbsp; 818m 278m&amp;nbsp; 21m S&amp;nbsp;&amp;nbsp; 52&amp;nbsp; 3.6 120937:59 fwk2_dev&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;9718 admin&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15&amp;nbsp;&amp;nbsp; 0&amp;nbsp; 448m&amp;nbsp; 73m&amp;nbsp; 25m S&amp;nbsp;&amp;nbsp; 16&amp;nbsp; 0.9 &amp;nbsp;&amp;nbsp;9965:41 fw_full&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;16026 admin&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 -20&amp;nbsp; 649m 109m&amp;nbsp; 21m S&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; 1.4&amp;nbsp; 31184:29 fwk1_dev&amp;nbsp;&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Virtual system had only 1 virtual instance (CPU) and was working just fine.&lt;/P&gt;&lt;P&gt;But with the very same rulebase and configuration we are having CPUs through the roof.&lt;/P&gt;&lt;P&gt;[&lt;FONT face="courier new,courier"&gt;Expert@FW01:2]# top&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;top - 09:45:29 up 2 days, 6:48, 5 users, load average: 4.04, 4.22, 4.39&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Tasks: 163 total, 1 running, 162 sleeping, 0 stopped, 0 zombie&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Cpu0 : 0.0%us, 0.0%sy, 0.0%ni, 21.3%id, 0.0%wa, 0.3%hi, 78.3%si, 0.0%st&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Cpu1 : 56.1%us, 10.0%sy, 0.0%ni, 27.6%id, 0.0%wa, 0.0%hi, 6.3%si, 0.0%st&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Cpu2 : 64.3%us, 10.3%sy, 0.0%ni, 18.3%id, 0.0%wa, 0.0%hi, 7.0%si, 0.0%st&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Cpu3 : 62.1%us, 12.0%sy, 0.0%ni, 19.9%id, 0.0%wa, 0.0%hi, 6.0%si, 0.0%st&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Mem: 8029492k total, 4010952k used, 4018540k free, 284872k buffers&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Swap: 18908408k total, 0k used, 18908408k free, 1106088k cached&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;26699 admin 0 -20 1741m 1.0g 110m S 203 13.6 653:26.79 fwk2_dev_0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;27524 admin 15 0 595m 95m 39m S 12 1.2 32:44.97 fw_full&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10245 admin 15 0 0 0 0 S 4 0.0 11:56.26 cphwd_q_init_ke&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;18641 admin 0 -20 809m 194m 46m S 3 2.5 32:04.54 fwk1_dev_0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I have added to virtual system three virtual instances (CPUs), But still not enough. Also I am observing quite high CPU0 where is dispatcher.&lt;/P&gt;&lt;P&gt;I have checked SIM affinity, looks fine for me:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:0]# sim affinity -l -r -v&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth1-02 : 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth1-03 : 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth1-01 : 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Mgmt : 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:0]# fw ctl affinity -l -a -v&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface eth1 (irq 234): CPU 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface eth7 (irq 115): CPU 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface Mgmt (irq 99): CPU 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface eth1-01 (irq 226): CPU 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface eth1-02 (irq 234): CPU 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface eth1-03 (irq 67): CPU 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;VS_0 fwk: CPU 1 2 3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;VS_1 fwk: CPU 1 2 3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;VS_2 fwk: CPU 1 2 3&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;In affected virtual system I can observe surprisingly high amount of PSLXL traffic, but I could not compare it prior upgrade.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:2]# fwaccel stats -s&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Accelerated conns/Total conns : 26754/115454 (23%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Accelerated pkts/Total pkts : 5344525154/10554405196 (50%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;F2Fed pkts/Total pkts : 5629452/10554405196 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;F2V pkts/Total pkts : 21331262/10554405196 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPASXL pkts/Total pkts : 0/10554405196 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;PSLXL pkts/Total pkts : 5204250590/10554405196 (49%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;QOS inbound pkts/Total pkts : 0/10554405196 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;QOS outbound pkts/Total pkts : 0/10554405196 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Corrected pkts/Total pkts : 0/10554405196 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Tried also turn off IPS, also no help:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:2]# ips stat&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;IPS Status: Manually disabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;IPS Update Version: 635158746&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Global Detect: Off&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Bypass Under Load: Off&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:2]# enabled_blades&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;fw ips&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:0]# vsx stat -l&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;VSID: 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;VRID: 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Type: Virtual System&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Name: ntra&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Security Policy: Standard&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Installed at: 14Sep2020 20:03:55&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SIC Status: Trust&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Connections number: 118972&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Connections peak: 119651&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Connections limit: 549900&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I have also observed in "fw ctl zdebug + drop" logs, it disappeared after adding virtual instance.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;@;166488350;[kern];[tid_0];[fw4_0];fw_log_drop_ex: Packet proto=6 10.20.30.40:50057 -&amp;gt; 15.114.24.198:443 dropped by cphwd_pslglue_handle_packet_cb_do Reason: F2P: Instance 0 is currently fully utilized;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I do have opened support case for it, but so far nothing really helpful. Am I missing something?&lt;/P&gt;&lt;P&gt;Thank your for opinion and advice.&lt;/P&gt;</description>
    <pubDate>Tue, 15 Sep 2020 07:16:25 GMT</pubDate>
    <dc:creator>Martin_Oles</dc:creator>
    <dc:date>2020-09-15T07:16:25Z</dc:date>
    <item>
      <title>Unusual high CPU after migration VSX R77.30 to R80.30 jumbo take 215</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unusual-high-CPU-after-migration-VSX-R77-30-to-R80-30-jumbo-take/m-p/96771#M8780</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am just wonder, if you observe similar behavior. We are running VSX cluster Check point&amp;nbsp;12200, 4CPUs, 8G of memory,&amp;nbsp;CPAC-4-10 line card.&lt;/P&gt;&lt;P&gt;Prior migration from R77.30 to R80.30 hfa 215 we had CPU utilization:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:2]#top&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;top - 15:08:42 up 541 days, 13:07,&amp;nbsp; 2 users,&amp;nbsp; load average: 0.96, 1.04, 0.95&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Tasks: 151 total,&amp;nbsp;&amp;nbsp; 1 running, 150 sleeping,&amp;nbsp;&amp;nbsp; 0 stopped,&amp;nbsp;&amp;nbsp; 0 zombie&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Cpu(s):&amp;nbsp; 4.6%us,&amp;nbsp; 2.3%sy,&amp;nbsp; 0.0%ni, 87.2%id,&amp;nbsp; 0.1%wa,&amp;nbsp; 0.2%hi,&amp;nbsp; 5.5%si,&amp;nbsp; 0.0%st&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Mem:&amp;nbsp;&amp;nbsp; 8029532k total,&amp;nbsp; 7977484k used,&amp;nbsp;&amp;nbsp;&amp;nbsp; 52048k free,&amp;nbsp;&amp;nbsp; 419772k buffers&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Swap: 18908408k total,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 544k used, 18907864k free,&amp;nbsp; 2963120k cached&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp; PID USER&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PR&amp;nbsp; NI&amp;nbsp; VIRT&amp;nbsp; RES&amp;nbsp; SHR S %CPU %MEM&amp;nbsp;&amp;nbsp;&amp;nbsp; TIME+&amp;nbsp; COMMAND&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;16043 admin&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 -20&amp;nbsp; 818m 278m&amp;nbsp; 21m S&amp;nbsp;&amp;nbsp; 52&amp;nbsp; 3.6 120937:59 fwk2_dev&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;nbsp;9718 admin&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15&amp;nbsp;&amp;nbsp; 0&amp;nbsp; 448m&amp;nbsp; 73m&amp;nbsp; 25m S&amp;nbsp;&amp;nbsp; 16&amp;nbsp; 0.9 &amp;nbsp;&amp;nbsp;9965:41 fw_full&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;16026 admin&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 -20&amp;nbsp; 649m 109m&amp;nbsp; 21m S&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp; 1.4&amp;nbsp; 31184:29 fwk1_dev&amp;nbsp;&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Virtual system had only 1 virtual instance (CPU) and was working just fine.&lt;/P&gt;&lt;P&gt;But with the very same rulebase and configuration we are having CPUs through the roof.&lt;/P&gt;&lt;P&gt;[&lt;FONT face="courier new,courier"&gt;Expert@FW01:2]# top&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;top - 09:45:29 up 2 days, 6:48, 5 users, load average: 4.04, 4.22, 4.39&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Tasks: 163 total, 1 running, 162 sleeping, 0 stopped, 0 zombie&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Cpu0 : 0.0%us, 0.0%sy, 0.0%ni, 21.3%id, 0.0%wa, 0.3%hi, 78.3%si, 0.0%st&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Cpu1 : 56.1%us, 10.0%sy, 0.0%ni, 27.6%id, 0.0%wa, 0.0%hi, 6.3%si, 0.0%st&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Cpu2 : 64.3%us, 10.3%sy, 0.0%ni, 18.3%id, 0.0%wa, 0.0%hi, 7.0%si, 0.0%st&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Cpu3 : 62.1%us, 12.0%sy, 0.0%ni, 19.9%id, 0.0%wa, 0.0%hi, 6.0%si, 0.0%st&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Mem: 8029492k total, 4010952k used, 4018540k free, 284872k buffers&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Swap: 18908408k total, 0k used, 18908408k free, 1106088k cached&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;26699 admin 0 -20 1741m 1.0g 110m S 203 13.6 653:26.79 fwk2_dev_0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;27524 admin 15 0 595m 95m 39m S 12 1.2 32:44.97 fw_full&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;10245 admin 15 0 0 0 0 S 4 0.0 11:56.26 cphwd_q_init_ke&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;18641 admin 0 -20 809m 194m 46m S 3 2.5 32:04.54 fwk1_dev_0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I have added to virtual system three virtual instances (CPUs), But still not enough. Also I am observing quite high CPU0 where is dispatcher.&lt;/P&gt;&lt;P&gt;I have checked SIM affinity, looks fine for me:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:0]# sim affinity -l -r -v&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth1-02 : 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth1-03 : 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;eth1-01 : 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Mgmt : 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:0]# fw ctl affinity -l -a -v&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface eth1 (irq 234): CPU 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface eth7 (irq 115): CPU 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface Mgmt (irq 99): CPU 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface eth1-01 (irq 226): CPU 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface eth1-02 (irq 234): CPU 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface eth1-03 (irq 67): CPU 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;VS_0 fwk: CPU 1 2 3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;VS_1 fwk: CPU 1 2 3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;VS_2 fwk: CPU 1 2 3&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;In affected virtual system I can observe surprisingly high amount of PSLXL traffic, but I could not compare it prior upgrade.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:2]# fwaccel stats -s&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Accelerated conns/Total conns : 26754/115454 (23%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Accelerated pkts/Total pkts : 5344525154/10554405196 (50%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;F2Fed pkts/Total pkts : 5629452/10554405196 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;F2V pkts/Total pkts : 21331262/10554405196 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPASXL pkts/Total pkts : 0/10554405196 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;PSLXL pkts/Total pkts : 5204250590/10554405196 (49%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;QOS inbound pkts/Total pkts : 0/10554405196 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;QOS outbound pkts/Total pkts : 0/10554405196 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Corrected pkts/Total pkts : 0/10554405196 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Tried also turn off IPS, also no help:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:2]# ips stat&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;IPS Status: Manually disabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;IPS Update Version: 635158746&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Global Detect: Off&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Bypass Under Load: Off&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:2]# enabled_blades&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;fw ips&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:0]# vsx stat -l&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;VSID: 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;VRID: 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Type: Virtual System&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Name: ntra&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Security Policy: Standard&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Installed at: 14Sep2020 20:03:55&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SIC Status: Trust&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Connections number: 118972&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Connections peak: 119651&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Connections limit: 549900&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I have also observed in "fw ctl zdebug + drop" logs, it disappeared after adding virtual instance.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;@;166488350;[kern];[tid_0];[fw4_0];fw_log_drop_ex: Packet proto=6 10.20.30.40:50057 -&amp;gt; 15.114.24.198:443 dropped by cphwd_pslglue_handle_packet_cb_do Reason: F2P: Instance 0 is currently fully utilized;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I do have opened support case for it, but so far nothing really helpful. Am I missing something?&lt;/P&gt;&lt;P&gt;Thank your for opinion and advice.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 07:16:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unusual-high-CPU-after-migration-VSX-R77-30-to-R80-30-jumbo-take/m-p/96771#M8780</guid>
      <dc:creator>Martin_Oles</dc:creator>
      <dc:date>2020-09-15T07:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unusual high CPU after migration VSX R77.30 to R80.30 jumbo take 215</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unusual-high-CPU-after-migration-VSX-R77-30-to-R80-30-jumbo-take/m-p/96773#M8781</link>
      <description>&lt;P&gt;Output from fwaccel stats -s prior upgrade:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:2]# fwaccel stats -s&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Accelerated conns/Total conns : 146685/233205 (62%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Delayed conns/(Accelerated conns + PXL conns) : 3527/151585 (2%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Accelerated pkts/Total pkts : 15054685273/15274541182 (98%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;F2Fed pkts/Total pkts : 81148412/15274541182 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;PXL pkts/Total pkts : 138707497/15274541182 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;QXL pkts/Total pkts : 0/15274541182 (0%)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;and after upgrade:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:2]# fwaccel stats -s&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Accelerated conns/Total conns : 26476/118159 (22%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Accelerated pkts/Total pkts : 6035857883/11882865662 (50%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;F2Fed pkts/Total pkts : 6149406/11882865662 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;F2V pkts/Total pkts : 23685230/11882865662 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPASXL pkts/Total pkts : 0/11882865662 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;PSLXL pkts/Total pkts : 5840858373/11882865662 (49%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;QOS inbound pkts/Total pkts : 0/11882865662 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;QOS outbound pkts/Total pkts : 0/11882865662 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Corrected pkts/Total pkts : 0/11882865662 (0%)&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 07:33:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unusual-high-CPU-after-migration-VSX-R77-30-to-R80-30-jumbo-take/m-p/96773#M8781</guid>
      <dc:creator>Martin_Oles</dc:creator>
      <dc:date>2020-09-15T07:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Unusual high CPU after migration VSX R77.30 to R80.30 jumbo take 215</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unusual-high-CPU-after-migration-VSX-R77-30-to-R80-30-jumbo-take/m-p/96786#M8782</link>
      <description>&lt;P&gt;Almost certainly this issue, which is the TLS parser being invoked inappropriately causing high PSLXL:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166700&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener"&gt;sk166700: High CPU after upgrade from R77.x to R80.x when running only Firewall and Monitoring blades&lt;/A&gt;. This was also mentioned in the R80.40 addendum for my book.&lt;/P&gt;
&lt;P&gt;You can try manually disabling the TLS parser as mentioned in the SK just to verify this is indeed your issue, but the best way to deal with this is load a Jumbo HFA that has the fix.&amp;nbsp; For your release R80.30 the fix for this was added just two days ago in&amp;nbsp;&lt;STRONG&gt;R80.30 Jumbo HotFix - Ongoing Take 219.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 14:30:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unusual-high-CPU-after-migration-VSX-R77-30-to-R80-30-jumbo-take/m-p/96786#M8782</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-09-15T14:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unusual high CPU after migration VSX R77.30 to R80.30 jumbo take 215</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unusual-high-CPU-after-migration-VSX-R77-30-to-R80-30-jumbo-take/m-p/96797#M8783</link>
      <description>&lt;P&gt;I have patched that cluster on Saturday Sept 12, and new Jumbo HotFix has been added on Sunday&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":unamused_face:"&gt;😒&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[Expert@FW01:2]# enabled_blades&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;fw&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;On firewall (or MultiDomain management) monitoring blade is not enabled.&lt;/P&gt;&lt;P&gt;When checking traffic which is send to&amp;nbsp;&lt;SPAN&gt;PSLXL (fwaccel conns -f S) I have found around 10000 connections on HTTPS going to PSLXL. So, very likely issue with TLS parser.&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 13:05:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unusual-high-CPU-after-migration-VSX-R77-30-to-R80-30-jumbo-take/m-p/96797#M8783</guid>
      <dc:creator>Martin_Oles</dc:creator>
      <dc:date>2020-09-15T13:05:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unusual high CPU after migration VSX R77.30 to R80.30 jumbo take 215</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unusual-high-CPU-after-migration-VSX-R77-30-to-R80-30-jumbo-take/m-p/103386#M8784</link>
      <description>&lt;P&gt;So, update about this issue.&lt;/P&gt;&lt;P&gt;You were right, TLS parser has caused traffic to go via PSLXL, issue has disappeared after installation of&amp;nbsp;R80.30 Jumbo HotFix - Ongoing Take 219.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@FW01:2]# fwaccel stats -s
Accelerated conns/Total conns : 116807/120869 (96%)
Accelerated pkts/Total pkts : 4853922830/5213520449 (93%)
F2Fed pkts/Total pkts : 6874512/5213520449 (0%)
F2V pkts/Total pkts : 18827387/5213520449 (0%)
CPASXL pkts/Total pkts : 0/5213520449 (0%)
PSLXL pkts/Total pkts : 352723107/5213520449 (6%)
QOS inbound pkts/Total pkts : 0/5213520449 (0%)
QOS outbound pkts/Total pkts : 0/5213520449 (0%)
Corrected pkts/Total pkts : 0/5213520449 (0%)&lt;/LI-CODE&gt;&lt;P&gt;Via PSLSL goes only a bit of&amp;nbsp;&lt;SPAN&gt;NetBIOS&amp;nbsp;&lt;/SPAN&gt;traffic on port 445 .&lt;/P&gt;&lt;P&gt;I have adjusted also affinity, majority of traffic goes via eth1-01 and eth1-02:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@FW01:0]# fw ctl affinity -l -a -v
Interface eth7 (irq 115): CPU 0
Interface Mgmt (irq 99): CPU 0
Interface eth1-01 (irq 226): CPU 0
Interface eth1-02 (irq 234): CPU 1
Interface eth1-03 (irq 67): CPU 0
VS_0 fwk: CPU 1 2 3
VS_1 fwk: CPU 1 2 3
VS_2 fwk: CPU 1 2 3&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@FW01:0]# cat $FWDIR/conf/fwaffinity.conf
#
i eth1-02 1
i default auto&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;[Expert@FW01:0]# top
top - 10:06:44 up 13:02, 4 users, load average: 2.34, 2.56, 2.44
Tasks: 156 total, 2 running, 154 sleeping, 0 stopped, 0 zombie
Cpu0 : 0.0%us, 0.3%sy, 0.0%ni, 57.2%id, 0.0%wa, 0.7%hi, 41.8%si, 0.0%st
Cpu1 : 28.9%us, 4.4%sy, 0.0%ni, 14.1%id, 0.0%wa, 0.0%hi, 52.7%si, 0.0%st
Cpu2 : 18.8%us, 9.4%sy, 0.0%ni, 71.1%id, 0.0%wa, 0.0%hi, 0.7%si, 0.0%st
Cpu3 : 16.4%us, 5.7%sy, 0.0%ni, 76.6%id, 0.0%wa, 0.0%hi, 1.3%si, 0.0%st
Mem: 8029492k total, 4256544k used, 3772948k free, 160128k buffers
Swap: 18908408k total, 0k used, 18908408k free, 1440248k cached

PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
19167 admin 0 -20 1465m 787m 142m S 97 10.0 233:15.40 fwk2_dev_0
3422 admin 15 0 604m 92m 39m R 11 1.2 31:37.59 fw_full&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No it is much better, but still having CPU 1 above 80% of usage (50% SND + 30% FW worker virtual system 2). So I am wonder, how exactly to set affinity in safe way and preferably on the fly, to use for virtual system 2 only CPU 2 and CPU 3?&lt;/P&gt;&lt;P&gt;I might be wrong, but turning on&amp;nbsp;Multi-Queue should not have so much effect in this case.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 08:28:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unusual-high-CPU-after-migration-VSX-R77-30-to-R80-30-jumbo-take/m-p/103386#M8784</guid>
      <dc:creator>Martin_Oles</dc:creator>
      <dc:date>2020-11-26T08:28:01Z</dc:date>
    </item>
  </channel>
</rss>

