<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.10 User-Mode Firewall and performance impact in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/53447#M10650</link>
    <description>&lt;P&gt;R80.30 w kernel 3.10 which is in EA comes w USFW enabled. Multiple different reasons drive better performance there but it doesnt translate to performing better on R80.10 and gaia. In fact we fixed multiple issues in the release which is why it wasnt the default before.&amp;nbsp;If you are interested, use the EA version as its near GA (consider it release candidate).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are different benefits of USFW that we will document over time. Its specifically performs better w many cores but it has benefits in all platforms&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 May 2019 20:24:05 GMT</pubDate>
    <dc:creator>Dorit_Dor</dc:creator>
    <dc:date>2019-05-14T20:24:05Z</dc:date>
    <item>
      <title>R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/50058#M9852</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A question to the R&amp;amp;D.&lt;/P&gt;
&lt;P&gt;When I switch a firewall from kernel mode to user mode has this a performance impact.&lt;/P&gt;
&lt;P&gt;Is it better for the performance to enable user mode on&amp;nbsp; a firewall or not?&lt;/P&gt;
&lt;P&gt;Does it make sense to enable user mode even for a few cores?&lt;/P&gt;
&lt;P&gt;Enable user mode:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;gt; cpprod_util FwSetUsermode 1&lt;BR /&gt;&amp;gt; reboot&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;More to user mode here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk149973" target="_self"&gt;How to enable USFW (User-Mode Firewall) on a 23900 appliance&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2019 17:06:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/50058#M9852</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-04-07T17:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/50065#M9854</link>
      <description>&lt;P&gt;While there is always a performance penalty for making a transition from kernel space to process/user space, the ability to add cores beyond the kernel memory imposed limit of 40 via CoreXL may mitigate it.&amp;nbsp; Sounds to me like the answer will be "it depends".&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2019 13:48:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/50065#M9854</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-04-07T13:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/50070#M9856</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I have for project several HP DL380 G10 servers in the LAB.&amp;nbsp;I'm run some performance tests in the next days.&lt;/P&gt;
&lt;P&gt;1) I will install package generators on 3 servers with 10GBit network cards and simulate mixed traffic.&lt;BR /&gt;2) And 3 servers as packet destination.&lt;BR /&gt;3) Firewall with two 10 GBit network cards.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Then I can play a little bit in the lab with:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- user mode vs. kenel mode&lt;BR /&gt;- multi queueing on and off&lt;BR /&gt;- rulebase with 20 rules versus 1000 rules&lt;BR /&gt;- SecureXL on and off&lt;BR /&gt;- all blades on vs. fw and ips only&lt;BR /&gt;- 32 bit os vs. 64 bit OS&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I always wanted to do that:-)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2019 16:39:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/50070#M9856</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-04-07T16:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/50078#M9858</link>
      <description>In R80.20, there is only 64bit OS.&lt;BR /&gt;At least from what I was told by R&amp;amp;D, there probably won't be a performance benefit to using usermode firewall on a system with less than 40 cores.</description>
      <pubDate>Sun, 07 Apr 2019 21:24:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/50078#M9858</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-07T21:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/50122#M9869</link>
      <description>&lt;P&gt;Not immediate performance benefits, but capacity should be higher than in Kernel mode, for huge amount of connections, since we are no longer limited by kernel memory for keeping all kernel tables there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2019 09:12:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/50122#M9869</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-04-08T09:12:03Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/53446#M10649</link>
      <description>&lt;P&gt;It appears USFW mode will be enabled by default starting in R80.30 (per &lt;A href="https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk149973" target="_self"&gt;sk149973&lt;/A&gt;).&amp;nbsp; So, it seems that Checkpoint is counting on it performing better than kernel mode.&amp;nbsp; That article is specific to the 23900, but it doesn't say that USFW will only be enabled by default on the 23900.&amp;nbsp; The statement only says it will be the default for R80.30.&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 20:05:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/53446#M10649</guid>
      <dc:creator>phlrnnr</dc:creator>
      <dc:date>2019-05-14T20:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/53447#M10650</link>
      <description>&lt;P&gt;R80.30 w kernel 3.10 which is in EA comes w USFW enabled. Multiple different reasons drive better performance there but it doesnt translate to performing better on R80.10 and gaia. In fact we fixed multiple issues in the release which is why it wasnt the default before.&amp;nbsp;If you are interested, use the EA version as its near GA (consider it release candidate).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are different benefits of USFW that we will document over time. Its specifically performs better w many cores but it has benefits in all platforms&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 May 2019 20:24:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/53447#M10650</guid>
      <dc:creator>Dorit_Dor</dc:creator>
      <dc:date>2019-05-14T20:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/53508#M10672</link>
      <description>&lt;P&gt;So, would you only recommend USFW on R80.30, and leave it disabled on R80.20 and below?&amp;nbsp; If you had to deploy a new 23900 cluster with R80.20 on it running NGTX blades, would you enable USFW to get access to the 'extra' cores?&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 12:25:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/53508#M10672</guid>
      <dc:creator>phlrnnr</dc:creator>
      <dc:date>2019-05-15T12:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/53511#M10673</link>
      <description>&lt;P&gt;My own answer will be:&amp;nbsp;USFW is tested and therefore enabled w R80.30+3.10 - anyone that needs it should use this version. We did fix issues to get there so lets not challenge other versions as we know they will have issues.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We may still decide for practical reasons to enable it in previous releases but it should be isolated, well verified, highly needed use case and I recommend to look at this as exception.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Soon&amp;nbsp;R80.30+3.10 will be GA (potentially this month) so lets look forward and not waste our cycles on things we already solved&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 12:40:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/53511#M10673</guid>
      <dc:creator>Dorit_Dor</dc:creator>
      <dc:date>2019-05-15T12:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54056#M10800</link>
      <description>&lt;P&gt;Hmm. We are running the EA R80.30 w/ 3.10 kernel on our production cluster of 4800s. cpprod_util FwIsUsermode gives a 0, which I am assuming means that USMF isn't enabled.&lt;/P&gt;</description>
      <pubDate>Tue, 21 May 2019 18:02:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54056#M10800</guid>
      <dc:creator>Nicholas_Cuba</dc:creator>
      <dc:date>2019-05-21T18:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54098#M10807</link>
      <description>&lt;P&gt;Run the command &lt;STRONG&gt;lsmod&lt;/STRONG&gt;.&amp;nbsp; If you see a single driver called fwmod in the output, USFW is active.&amp;nbsp; If you see multiple instances of fw_X driver instead USFW is not enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 11:55:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54098#M10807</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-05-22T11:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54123#M10809</link>
      <description>&lt;P&gt;Thanks for the command to know for sure if USFW is enabled.&lt;/P&gt;&lt;P&gt;The lsmod does show the three fw workers, and no fwmod driver,&amp;nbsp; so no USFW on this EA R80.30 build.&lt;/P&gt;&lt;P&gt;&lt;U&gt;lsmod | grep fw&lt;/U&gt;&lt;BR /&gt;fw_2 45566636 54&lt;BR /&gt;fw_1 45566636 58&lt;BR /&gt;fw_0 45566636 110&lt;/P&gt;&lt;P&gt;&lt;U&gt;fw ver&lt;/U&gt;&lt;BR /&gt;This is Check Point's software version R80.30 - Build 022&lt;/P&gt;&lt;P&gt;&lt;U&gt;uname -r&lt;/U&gt;&lt;BR /&gt;3.10.0-693cpx86_64&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 14:50:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54123#M10809</guid>
      <dc:creator>Nicholas_Cuba</dc:creator>
      <dc:date>2019-05-22T14:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54138#M10812</link>
      <description>&lt;P&gt;Interesting, I was under the impression that USFW would be the default for R80.30+ with the 3.10 kernel.&amp;nbsp; Perhaps there needs to be a minimum number of physical cores (like 40) present for it to be enabled by default?&amp;nbsp; You only appear to have 4...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 18:04:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54138#M10812</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-05-22T18:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54140#M10813</link>
      <description>&lt;P&gt;Its “by default” when there are MANY cores - today with less cores there is some benefits but also some “cost”.&lt;/P&gt;
&lt;P&gt;in the future we will enable on less cores...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 18:18:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54140#M10813</guid>
      <dc:creator>Dorit_Dor</dc:creator>
      <dc:date>2019-05-22T18:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54141#M10814</link>
      <description>&lt;P&gt;It's not a problem that our 4800's running the EA program don't have the USFW enabled; we signed up for EA, we'll run the EA code we're given.&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I just wanted to provide a counterpoint showing USFW isn't always enabled by default on R80.30, EA&amp;nbsp; with new kernel 3.10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 18:25:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54141#M10814</guid>
      <dc:creator>Nicholas_Cuba</dc:creator>
      <dc:date>2019-05-22T18:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: R80.10 User-Mode Firewall and performance impact</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54152#M10816</link>
      <description>To clarify, on platforms with 40 or more cores like the 23900, USFW will be enabled by default in R80.30-3.10.&lt;BR /&gt;USFW is required to utilize more than 40 cores.&lt;BR /&gt;You can enable it on other platforms with less cores, but it is not necessary.</description>
      <pubDate>Wed, 22 May 2019 22:51:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-10-User-Mode-Firewall-and-performance-impact/m-p/54152#M10816</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-22T22:51:03Z</dc:date>
    </item>
  </channel>
</rss>

