<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77019#M15664</link>
    <description>&lt;P&gt;This does not work with R80.40.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Mar 2020 18:01:23 GMT</pubDate>
    <dc:creator>uror</dc:creator>
    <dc:date>2020-03-03T18:01:23Z</dc:date>
    <item>
      <title>R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/69105#M14059</link>
      <description>&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;Elephant Flow (Heavy Connections)&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;In computer networking, an elephant flow (heavy connection) is an extremely large in total bytes continuous flow set up by a TCP or other protocol flow measured over a network link. Elephant flows, though not numerous, can occupy a disproportionate share of the total bandwidth over a period of time.&amp;nbsp; When the observations were made that a small number of flows carry the majority of Internet traffic and the remainder consists of a large number of flows that carry very little Internet traffic (mice flows).&lt;/P&gt;
&lt;P&gt;All packets associated with that elephant flow must be handled by the same firewall worker core (CoreXL instance). Packets could be dropped by Firewall when CPU cores, on which Firewall runs, are fully utilized. Such packet loss might occur regardless of the connection's type. &lt;BR /&gt;&lt;BR /&gt;What typically produces heavy connections:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;System backups&lt;/LI&gt;
&lt;LI&gt;Database backups&lt;/LI&gt;
&lt;LI&gt;VMWare sync.&lt;/LI&gt;
&lt;/UL&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;Chapter&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;STRONG&gt;More interesting articles:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Architecture-and-Performance-Tuning-Link-Collection/m-p/47883#M9336" target="_blank" rel="noopener" data-objecttype="102"&gt;- R80.x Architecture and Performance Tuning - Link Collection&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://cp.ankenbrand24.de" target="_blank" rel="noopener nofollow noopener noreferrer noopener noreferrer noopener noreferrer"&gt;- Article list (Heiko Ankenbrand)&lt;/A&gt;&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;Evaluation of heavy connections&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;The big question is, how do you found elephat flows on an R80 gateway?&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#3366FF"&gt;Tip 1&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;Evaluation of heavy connections (epehant flows)&lt;BR /&gt;&lt;BR /&gt;A first indication is a high CPU load on a core if all other cores have a normal CPU load. This can be displayed very nicely with "top". Ok, now a core has 100% CPU usage. What can we do now? For this there is a &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105762&amp;amp;partition=General&amp;amp;product=Security" target="_self"&gt;SK105762&lt;/A&gt; to activate "Firewall Priority Queues".&amp;nbsp; This feature allows the administrator to monitor the heavy connections that consume the most CPU resources without interrupting the normal operation of the Firewall. After enabling this feature, the relevant information is available in CPView Utility. The system saves heavy connection data for the last 24 hours and CPDiag has a matching collector which uploads this data for diagnosis purposes.&lt;/P&gt;
&lt;P&gt;Heavy connection flow system definition on Check Point gateways:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Specific instance CPU is over 60%&lt;/LI&gt;
&lt;LI&gt;Suspected connection lasts more than 10s&lt;/LI&gt;
&lt;LI&gt;Suspected connection utilizes more than 50% of the total work the instance does. In other words, connection CPU utilization must be &amp;gt; 30% &amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;CLI Commands&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#3366FF"&gt;&lt;BR /&gt;Tip 2&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;Enable the monitoring of heavy connections.&lt;/P&gt;
&lt;P&gt;To enable the monitoring of heavy connections that consume high CPU resources:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;# &lt;/STRONG&gt;&lt;STRONG&gt;fw ctl multik prioq 1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;#&lt;/STRONG&gt;&lt;STRONG&gt; reboot&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#3366FF"&gt;Tip 3&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;Found heavy connection on the gateway with „print_heavy connections“&lt;/P&gt;
&lt;P&gt;On the system itself, heavy connection data is accessible using the command: &lt;BR /&gt;&lt;BR /&gt;# &lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pq5.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3461i86D09EC500F48B95/image-size/large?v=v2&amp;amp;px=999" role="button" title="pq5.jpg" alt="pq5.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT color="#3366FF"&gt;Tip 4&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;Found heavy connection on the gateway with cpview&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;# &lt;/EM&gt;&lt;STRONG&gt;cpview&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CPU &amp;gt; Top-Connection &amp;gt; InstancesX&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pq3.png" style="width: 609px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3462iAA72E150064A8A91/image-dimensions/609x320?v=v2" width="609" height="320" role="button" title="pq3.png" alt="pq3.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;Links&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105762&amp;amp;partition=General&amp;amp;product=Security" target="_self"&gt;sk105762 - Firewall Priority Queues in R77.30 / R80.10 and above&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorclipboard_image_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 03 Dec 2019 07:14:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/69105#M14059</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-12-03T07:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/69125#M14064</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Thank you for all the interesting articles about Performance Tuning you wrote.&lt;/P&gt;&lt;P&gt;You could write a book out of this link collection&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Architecture-and-Performance-Tuning-Link-Collection/m-p/47883#M9336" target="_blank" rel="noopener"&gt;R80.x Architecture and Performance Tuning - Link Collection&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 10:09:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/69125#M14064</guid>
      <dc:creator>Josef_Pecher</dc:creator>
      <dc:date>2019-12-03T10:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/69198#M14076</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This article has helped me very well.&lt;/P&gt;&lt;P&gt;I followed the steps and actually found a database backup connection. The connection caused about 70% CPU load on one core. We have now limited the bandwidth of the connection via QoS.&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Dec 2019 16:08:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/69198#M14076</guid>
      <dc:creator>Paul_Erez</dc:creator>
      <dc:date>2019-12-03T16:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/69324#M14096</link>
      <description>&lt;P&gt;We were able to identify a very similar problem.&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2019 14:57:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/69324#M14096</guid>
      <dc:creator>Niroyec_Yerusha</dc:creator>
      <dc:date>2019-12-04T14:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/69436#M14119</link>
      <description>&lt;P&gt;We also had the problem with the elephant flows. This is a good way to find them quickly and easily.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2019 13:47:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/69436#M14119</guid>
      <dc:creator>Patricia_OSulli</dc:creator>
      <dc:date>2019-12-05T13:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/69498#M14130</link>
      <description>&lt;P&gt;In the past years I had always been looking for a solution to find elephant flows. Check Point has built in a good solution.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 07:18:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/69498#M14130</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-12-06T07:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/70016#M14197</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I just tried that. This is a very interesting solution. A way to find elefant flows. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 07:38:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/70016#M14197</guid>
      <dc:creator>Gaurav_B_</dc:creator>
      <dc:date>2019-12-11T07:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/70433#M14270</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":ok_hand:"&gt;👌&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2019 17:55:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/70433#M14270</guid>
      <dc:creator>Delia_Pele</dc:creator>
      <dc:date>2019-12-13T17:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/71822#M14553</link>
      <description>&lt;P&gt;We have several connections with 5-7% utilization.&lt;/P&gt;&lt;P&gt;What can we do here?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 06:40:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/71822#M14553</guid>
      <dc:creator>Dirk_Wisbey</dc:creator>
      <dc:date>2020-01-08T06:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/71853#M14563</link>
      <description>&lt;P&gt;So glad you asked this question.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I will be speaking at CPX New Orleans and Vienna on the CheckMates track with a presentation called "Big Game Hunting: Elephant Flows" that will go through how to track down elephant flows (a.k.a. heavy connections), all the different remediation options, and the pros and cons of each.&amp;nbsp; PhoneBoy will be delivering this presentation for me at CPX Bangkok because I'll be very busy that week, with, uh, something else...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2020 13:48:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/71853#M14563</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-01-08T13:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/72373#M14671</link>
      <description>&lt;P&gt;This is an interesting approach to detect heavy connections.&amp;nbsp;I had checked this after this article and could identify some systems that were causing problems.&amp;nbsp;We have now created QoS rules to limit the bandwidth.&amp;nbsp;That worked well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 20:55:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/72373#M14671</guid>
      <dc:creator>Igor_Szkaradkie</dc:creator>
      <dc:date>2020-01-15T20:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/72408#M14685</link>
      <description>&lt;P&gt;Guys,&lt;/P&gt;&lt;P&gt;if you have a problem with elephant flow you may try this&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SecureXL Fast Accelerator (fw fast_accel) for R80.20 and above -&amp;nbsp;sk156672&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2020 08:50:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/72408#M14685</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2020-01-16T08:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/72896#M14793</link>
      <description>Do we have to enable PrioQ to support the "fw ctl multik print_heavy_conn" command? The article suggests it, but the Tip# list isn't execution step#.&lt;BR /&gt;&lt;BR /&gt;Also is this supported on R77.30 and R76SP.50?</description>
      <pubDate>Tue, 21 Jan 2020 17:16:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/72896#M14793</guid>
      <dc:creator>Josh_Dillig</dc:creator>
      <dc:date>2020-01-21T17:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/72899#M14794</link>
      <description>&lt;P&gt;Priority Queues must be in mode 1 (Eviluator-only) to use that command; mode 1 is the default on a firewall that does not have USFW enabled. I'll be speaking about this very topic in detail at CPX New Orleans and Vienna.&lt;/P&gt;
&lt;P&gt;Support for &lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt; was added in R80.20; I doubt it can be backported into earlier releases since I'm pretty sure it relies on the major changes introduced to SecureXL in R80.20.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 17:26:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/72899#M14794</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-01-21T17:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77019#M15664</link>
      <description>&lt;P&gt;This does not work with R80.40.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 18:01:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77019#M15664</guid>
      <dc:creator>uror</dc:creator>
      <dc:date>2020-03-03T18:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77022#M15665</link>
      <description>&lt;P&gt;R80.40 gateways use USFW by default.&lt;/P&gt;
&lt;P&gt;Unfortunately this is no longer possible with R80.40 in USFW.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp; has already described this well for R80.20.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 18:06:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77022#M15665</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-03T18:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77091#M15675</link>
      <description>&lt;P&gt;Could someone explain why FW was moved from kernel space to user space by default? What is the benefit except alocation more memory when you have more cores? What will be impacted, what is behind? Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 09:13:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77091#M15675</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2020-03-04T09:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77097#M15676</link>
      <description>&lt;P&gt;That was discussed here in several posts, I think.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In a nutshell, with more than 48 cores, kernel mode cannot utilise them all. To allow CoreXL use more cores on high performance boxes, User Mode is the only option. Plus, user mode add stability. If FWK instance crashes, it does not affect the whole machine.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;VSX is running User Mode FWK instances for ages, actually.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 09:31:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77097#M15676</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-03-04T09:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77171#M15691</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/13122"&gt;@Martin_Raska&lt;/a&gt;,&lt;/P&gt;
&lt;DIV class="lia-quilt-row lia-quilt-row-message-body"&gt;
&lt;DIV class="lia-quilt-column lia-quilt-column-24 lia-quilt-column-single lia-quilt-column-message-body-content"&gt;
&lt;DIV class="lia-quilt-column-alley lia-quilt-column-alley-single"&gt;
&lt;DIV id="bodyDisplay_5301e6e623ebad" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;In “Kernel Mode Firewall” KMFW, the maximum number of running cores is limited to 40 because of the Linux/Intel limitation of 2GB kernel memory, and because CoreXL architecture needs to load a large driver (~42MB) dozens of times (according to the CPU number, and up to 40 times). Newer platforms that contain more than 40 cores e.g., 23900 or open server are not fully utilized.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit; color: #2b2b29;"&gt;The solution of the problem is a firewall in the user mode of the Linux operating system.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;STRONG&gt;GAIA version/ Kernel/ Cores&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Firewall mode&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Check&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%" height="45px"&gt;R80.30 kernel 3.10 more then 35* cores&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="45px"&gt;UMFW is enabled&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="45px"&gt;checked on HP DL 380 G10 2 * Platinum 8180MProcessor 28 cores = 56 cores&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%" height="45px"&gt;R80.30 kernel 3.10 less then 35* cores&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="45px"&gt;KMFW is enabled&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="45px"&gt;checked on HP DL 380 G10 1 * Platinum 8180MProcessor 28 cores&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%" height="45px"&gt;R80.30 kernel 2.6&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="45px"&gt;KMFW is enabled&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="45px"&gt;checked on VMWare with 30 cores and with 46 cores&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%" height="23px"&gt;R80.40 (default 3.10 kernel)&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="23px"&gt;UMFW is enabled by default&lt;/TD&gt;
&lt;TD width="33.333333333333336%" height="23px"&gt;checked on VMWare with 4 cores&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To make sure that UMFW is activated, run the following command:&lt;/P&gt;
&lt;P&gt;# cpprod_util FwIsUsermode&lt;/P&gt;
&lt;P&gt;1 = User Mode Firewall&lt;BR /&gt;0 = Kernel Mode Firewall&lt;/P&gt;
&lt;P&gt;For more information or to change the mode, read more in my article here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-User-Mode-Firewall-vs-Kernel-Mode/m-p/70759/highlight/true#M14330" target="_self"&gt;R80.x - Performance Tuning Tip – User Mode Firewall vs. Kernel Mode Firewall&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 18:30:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77171#M15691</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-03-04T18:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning Tip - Elephant Flows (Heavy Connections)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77301#M15732</link>
      <description>Thanks Heiko, I will ask differently, what is a difference when FW code is running in kernel mode or user mode except for memory allocation.</description>
      <pubDate>Thu, 05 Mar 2020 13:58:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-Elephant-Flows-Heavy-Connections/m-p/77301#M15732</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2020-03-05T13:58:23Z</dc:date>
    </item>
  </channel>
</rss>

