<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High CPU utilization and affinity in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104329#M20043</link>
    <description>&lt;P&gt;You didn't say which kind of core was saturated (SND vs. Firewall Worker) after the JHFA application but I am assuming it is an SND core due to this fix included in your JHFA level which makes much more traffic eligible for full acceleration by SecureXL in some circumstances:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166700&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener"&gt;sk166700: High CPU after upgrade from R77.x to R80.x when running only Firewall and Monitoring blades&lt;/A&gt;&amp;nbsp; &amp;nbsp;This is a great problem to have.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Generally you should avoid static CPU allocations for SoftIRQ via &lt;STRONG&gt;sim affinity&lt;/STRONG&gt; wherever possible and enable Multi-Queue on your 10Gbps interfaces; one CPU core (even if dedicated to only one 10Gbps interface) will start getting saturated around 4-5Gbps and start losing frames (RX-DRP as shown by &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;).&amp;nbsp; What I would recommend:&lt;/P&gt;
&lt;P&gt;1) If more than 70% of your traffic is fully-accelerated (Accelerated pkts [not conns] shown by &lt;STRONG&gt;fwaccel stats -s&lt;/STRONG&gt;) configure a 4/4 split with cpconfig.&amp;nbsp; Otherwise your 3/5 split should be fine for now.&lt;/P&gt;
&lt;P&gt;2) Run &lt;STRONG&gt;sim affinity -a&lt;/STRONG&gt; to set all interface affinities back to auto mode.&amp;nbsp; You may need to reboot after doing this, can't remember.&lt;/P&gt;
&lt;P&gt;3) Enable Multi-Queue on your 10Gbps interfaces; Multi-Queue can only be active on a maximum of 5 physical interfaces in your kernel version.&amp;nbsp; You will most definitely need to reboot after making this change.&lt;/P&gt;
&lt;P&gt;4) After reboot all SND/IRQ cores will be able to service the 10Gbps interfaces, thus spreading the load out more evenly among them and hopefully avoiding excessive RX-DRP frame loss.&lt;/P&gt;
&lt;P&gt;As far as having 12 cores but only being licensed for 8, I have seen some strange effects happen when there is this kind of mismatch but based on your command outputs I think your firewall is handling this situation fine.&amp;nbsp; You taskset core allocations as you have them configured are OK, be sure to update them if you change the number of SND cores to avoid wayward processes from grabbing CPU time on the SND cores and trashing their CPU fast cache.&lt;/P&gt;</description>
    <pubDate>Fri, 04 Dec 2020 14:56:15 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2020-12-04T14:56:15Z</dc:date>
    <item>
      <title>High CPU utilization and affinity</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104238#M20034</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In one of our R80.20 firewalls the CPU utilization on one core is very high, while the other cores are almost idle. This started after the installation on JHA 183 on the firewall cluster.&lt;/P&gt;&lt;P&gt;While perhaps not related to the upgrade itself, the CPU affinity is now in an undesirable state as eth6 and eth7 are 10 Gbps interfaces while eth0, eth2 and eth3 are 1 Gbps interfaces.&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;firewall&amp;gt; fw ctl affinity -l -r&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;CPU 0: eth6 eth7 eth0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;CPU 1: eth2 eth3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;CPU 2: fw_5&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;lpd rtmd fwd wsdnsd mpdaemon in.asessiond cpd cprid&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;CPU 3: fw_4&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;lpd rtmd fwd wsdnsd mpdaemon in.asessiond cpd cprid&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;CPU 4: fw_3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;lpd rtmd fwd wsdnsd mpdaemon in.asessiond cpd cprid&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;CPU 5: fw_2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;lpd rtmd fwd wsdnsd mpdaemon in.asessiond cpd cprid&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;CPU 6: fw_1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;lpd rtmd fwd wsdnsd mpdaemon in.asessiond cpd cprid&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;CPU 7: fw_0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;lpd rtmd fwd wsdnsd mpdaemon in.asessiond cpd cprid&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;CPU 8:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;CPU 9:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;CPU 10:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;CPU 11:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;All:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;The current license permits the use of CPUs 0, 1, 2, 3, 4, 5, 6, 7 only.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We previously used the following procedure to change affinity and improve utilization across cores&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Use “cpconfig” to change CoreXL to use 3 cores for SND/IRQ and 5 cores for Firewall worker (previously 2 cores were used for SND/IRQ and 6 for Firewall worker)&lt;/LI&gt;&lt;LI&gt;Use “sim affinity -s” to allocate 1 SND/IRQ to each 10 Gbps interface and a separate to the other interfaces (eth6 to CPU 1,&amp;nbsp;eth7 to CPU 2 and&amp;nbsp;all other interfaces to CPU0)&lt;/LI&gt;&lt;LI&gt;Use “taskset_us_all” to assign user space processes to only firewall worker cores:&lt;/LI&gt;&lt;LI&gt;taskset_us_all -l 3-7&lt;/LI&gt;&lt;LI&gt;Update /etc/rc.local with the “taskset_us_all” command to make it survive reboot&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;BR /&gt;I have a few questions that I hope you could answer:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Does this procedure look correct or should something be changed? For example:&lt;/LI&gt;&lt;LI&gt;Is it correct to allocate one SND/IRQ to each 10 Gbps interface and another to the 1 Gbps interfaces?&lt;/LI&gt;&lt;LI&gt;The server has 12 cores, but we only have a license for 8. If I understand correctly it is recommended to modify BIOS so only 8 are seen by the OS, but what are the advantage compared to just specifying 8 cores in CoreXL?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;BR /&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Harry&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 17:00:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104238#M20034</guid>
      <dc:creator>net-harry</dc:creator>
      <dc:date>2020-12-03T17:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization and affinity</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104286#M20042</link>
      <description>&lt;P&gt;To me, that looks right.&lt;BR /&gt;You might consider licensing those additional cores so you can leverage all the cores (and potentially use multiqueue).&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 04:09:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104286#M20042</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-04T04:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization and affinity</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104329#M20043</link>
      <description>&lt;P&gt;You didn't say which kind of core was saturated (SND vs. Firewall Worker) after the JHFA application but I am assuming it is an SND core due to this fix included in your JHFA level which makes much more traffic eligible for full acceleration by SecureXL in some circumstances:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166700&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank" rel="noopener"&gt;sk166700: High CPU after upgrade from R77.x to R80.x when running only Firewall and Monitoring blades&lt;/A&gt;&amp;nbsp; &amp;nbsp;This is a great problem to have.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Generally you should avoid static CPU allocations for SoftIRQ via &lt;STRONG&gt;sim affinity&lt;/STRONG&gt; wherever possible and enable Multi-Queue on your 10Gbps interfaces; one CPU core (even if dedicated to only one 10Gbps interface) will start getting saturated around 4-5Gbps and start losing frames (RX-DRP as shown by &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;).&amp;nbsp; What I would recommend:&lt;/P&gt;
&lt;P&gt;1) If more than 70% of your traffic is fully-accelerated (Accelerated pkts [not conns] shown by &lt;STRONG&gt;fwaccel stats -s&lt;/STRONG&gt;) configure a 4/4 split with cpconfig.&amp;nbsp; Otherwise your 3/5 split should be fine for now.&lt;/P&gt;
&lt;P&gt;2) Run &lt;STRONG&gt;sim affinity -a&lt;/STRONG&gt; to set all interface affinities back to auto mode.&amp;nbsp; You may need to reboot after doing this, can't remember.&lt;/P&gt;
&lt;P&gt;3) Enable Multi-Queue on your 10Gbps interfaces; Multi-Queue can only be active on a maximum of 5 physical interfaces in your kernel version.&amp;nbsp; You will most definitely need to reboot after making this change.&lt;/P&gt;
&lt;P&gt;4) After reboot all SND/IRQ cores will be able to service the 10Gbps interfaces, thus spreading the load out more evenly among them and hopefully avoiding excessive RX-DRP frame loss.&lt;/P&gt;
&lt;P&gt;As far as having 12 cores but only being licensed for 8, I have seen some strange effects happen when there is this kind of mismatch but based on your command outputs I think your firewall is handling this situation fine.&amp;nbsp; You taskset core allocations as you have them configured are OK, be sure to update them if you change the number of SND cores to avoid wayward processes from grabbing CPU time on the SND cores and trashing their CPU fast cache.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 14:56:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104329#M20043</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-12-04T14:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization and affinity</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104340#M20044</link>
      <description>&lt;P&gt;I will share very simple way I fixed this with customers few times (cant guarantee it would work)&lt;/P&gt;&lt;P&gt;cpconfig -&amp;gt; disable corexl -&amp;gt; reboot -&amp;gt; cpconfig -&amp;gt; re-enable corexl -&amp;gt; reboot again -&amp;gt; check (make sure you do it on both fws if its a cluster_&lt;/P&gt;&lt;P&gt;I never figured out why this worked, but I guess like with anything else, it probably "resets" the corexl config and starts fresh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let us know if you tried that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 17:36:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104340#M20044</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-04T17:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization and affinity</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104341#M20045</link>
      <description>&lt;P&gt;However, if what I suggested above fails, I would try below article to debug it and send to TAC:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sk43443&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 17:37:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104341#M20045</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-04T17:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization and affinity</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104396#M20056</link>
      <description>&lt;P&gt;Thank you very much&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;for your suggestions!&lt;/P&gt;&lt;P&gt;In the end I used my initial plan with sim affinity since we are (unfortunately) running&amp;nbsp;tg3 and be2net drivers that from what I understand do not allow multi-queue.&lt;/P&gt;&lt;P&gt;Will try to ensure that we use better NICs when we refresh the hardware on the open servers.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Harry&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2020 11:22:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104396#M20056</guid>
      <dc:creator>net-harry</dc:creator>
      <dc:date>2020-12-06T11:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization and affinity</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104404#M20058</link>
      <description>&lt;P&gt;tg3 and be2net in use on your firewall?&amp;nbsp; My condolences...&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2020 13:53:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104404#M20058</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-12-06T13:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization and affinity</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104405#M20059</link>
      <description>&lt;P&gt;@&amp;nbsp;&lt;SPAN&gt;tg3 and be2net in use on your firewall?&amp;nbsp; My condolences...that made me laugh LOL&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2020 13:58:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-utilization-and-affinity/m-p/104405#M20059</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2020-12-06T13:58:43Z</dc:date>
    </item>
  </channel>
</rss>

