<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Performance Tuning Tip – Lightspeed Appliance in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/142376#M25271</link>
    <description>&lt;P&gt;Very interesting information!&lt;/P&gt;</description>
    <pubDate>Thu, 24 Feb 2022 08:00:46 GMT</pubDate>
    <dc:creator>Tobias_L</dc:creator>
    <dc:date>2022-02-24T08:00:46Z</dc:date>
    <item>
      <title>Performance Tuning Tip – Lightspeed Appliance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/141699#M25154</link>
      <description>&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;SPAN&gt;&lt;FONT color="#FFFFFF"&gt;Lightspeed Overview&lt;/FONT&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;The new Quantum Lightspeed firewalls (QLS250, QLS 450, QLS 650, QLS 800) are much better in performance because they use NVIDIA ASIC's on ConnectX NIC’s with accelerated packet processing technology.&lt;/P&gt;
&lt;P&gt;Faster firewall security at line-rate speed&lt;/P&gt;
&lt;P&gt;- 250 to 800 Gbps Hyper-Fast througput&lt;BR /&gt;- Ultra low latency at 3us (10 x faster as GAIA software)&lt;BR /&gt;- Scalability up to 3 Tbps with Maestro (MLS 200, MLS 400 - available Q2/2022)&lt;BR /&gt;- Acceleration of elephant flows&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;SPAN&gt;&lt;FONT color="#FFFFFF"&gt;Lightspeed Design&lt;/FONT&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;Only traffic on the same &lt;SPAN&gt;NVIDIA&lt;/SPAN&gt; network card can be accelerated by Lightspeed.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LS_Picture_1.jpg" style="width: 383px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15425i660906A9FDAD643C/image-dimensions/383x180?v=v2" width="383" height="180" role="button" title="LS_Picture_1.jpg" alt="LS_Picture_1.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Network traffic between different network cards cannot be accelerated by Lightspeed (uses regular flow and speed).&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LS_Picture_2.jpg" style="width: 382px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15426iF98A9D701B64AA9D/image-dimensions/382x180?v=v2" width="382" height="180" role="button" title="LS_Picture_2.jpg" alt="LS_Picture_2.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;An important point at the moment is that &lt;STRONG&gt;only&lt;/STRONG&gt; &lt;STRONG&gt;firewall traffic&lt;/STRONG&gt; can be optimised via Lightspeed &lt;STRONG&gt;on the same network card&lt;/STRONG&gt;. As soon as traffic has to be analysed by F2F path or PSLXL path - for example by the IPS blade - the connection is not optimised by Lightspeed.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Security Gateway&lt;/SPAN&gt; does &lt;STRONG&gt;not&lt;/STRONG&gt; support these features when you install a &lt;SPAN&gt;NVIDIA 2-port 100G Card&lt;/SPAN&gt;:&lt;/P&gt;
&lt;P&gt;- &lt;SPAN&gt;ClusterXL&lt;/SPAN&gt; in the &lt;SPAN&gt;Load Sharing&lt;/SPAN&gt; mode or &lt;SPAN&gt;Active-Active&lt;/SPAN&gt; mode.&lt;BR /&gt;- &lt;SPAN&gt;VSX&lt;/SPAN&gt; mode&lt;BR /&gt;- &lt;SPAN&gt;SecureXL&lt;/SPAN&gt; Drop Templates (see &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk153832" target="_blank" rel="noopener"&gt;sk153832&lt;/A&gt;).&lt;BR /&gt;- VRRP Cluster.&lt;BR /&gt;- Rate Limiting rules for DoS Mitigation configured with the commands 'fwaccel dos deny' and 'fwaccel dos allow' (see &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112454" target="_blank" rel="noopener"&gt;sk112454&lt;/A&gt;).&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;SPAN&gt;&lt;FONT color="#FFFFFF"&gt;How does it work?&lt;/FONT&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;1) First packet in every connection validated by security policy check in the CoreXL instance.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LS_Picture_3.jpg" style="width: 425px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15427i371D488A94D40A54/image-dimensions/425x266?v=v2" width="425" height="266" role="button" title="LS_Picture_3.jpg" alt="LS_Picture_3.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;2) Approved traffic flow offloaded to Quantum Lightspeed ASIC via rte_flow API&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LS_Picture_4.jpg" style="width: 426px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15428i4A72D7569AD4592A/image-dimensions/426x266?v=v2" width="426" height="266" role="button" title="LS_Picture_4.jpg" alt="LS_Picture_4.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;3) Subsequent packetes are secured by accelerated packet processing via NVIDIA ASIC&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LS_Picture_5.jpg" style="width: 426px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15429i6AF07AB603D7D735/image-dimensions/426x265?v=v2" width="426" height="265" role="button" title="LS_Picture_5.jpg" alt="LS_Picture_5.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;NVIDIA accelerated packet processing supports the following features on ASIC:&lt;BR /&gt;- TCP state validation&lt;BR /&gt;- Tunneling and NAT support&lt;BR /&gt;- Header validation&lt;BR /&gt;- Accelerated firewall packet flow&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 08:02:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/141699#M25154</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-02-17T08:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Performance Tuning Tip – Lightspeed Appliance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/141729#M25162</link>
      <description>&lt;P&gt;We plan to use Lightspeed applications in the data centre in the future. Can the traffic also be accelerated between two NVIDIA network cards through Lightspeed?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 05:26:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/141729#M25162</guid>
      <dc:creator>Rasputin</dc:creator>
      <dc:date>2022-02-17T05:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Performance Tuning Tip – Lightspeed Appliance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/141736#M25164</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/69535"&gt;@Rasputin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Lightspeed optimization is not possible between two NVIDIA network cards. &lt;BR /&gt;For acceleration, both 100Gbps interfaces must be on one network card.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 07:30:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/141736#M25164</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-02-17T07:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Performance Tuning Tip – Lightspeed Appliance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/141841#M25177</link>
      <description>&lt;P&gt;When will the QLS applications be available from the distribution?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 07:32:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/141841#M25177</guid>
      <dc:creator>Joschua_M</dc:creator>
      <dc:date>2022-02-18T07:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: Performance Tuning Tip – Lightspeed Appliance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/142004#M25217</link>
      <description>&lt;P&gt;According to the price list, the QLS appliances should be available from 01 February 2022.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Feb 2022 07:09:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/142004#M25217</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-02-21T07:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Performance Tuning Tip – Lightspeed Appliance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/142376#M25271</link>
      <description>&lt;P&gt;Very interesting information!&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 08:00:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/142376#M25271</guid>
      <dc:creator>Tobias_L</dc:creator>
      <dc:date>2022-02-24T08:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Performance Tuning Tip – Lightspeed Appliance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/142378#M25272</link>
      <description>&lt;P&gt;Very nice summary. Thank you.&lt;/P&gt;&lt;P&gt;I would also add (from what I have learned on a presentation):&lt;/P&gt;&lt;P&gt;- Header validation is currently up to L4&lt;/P&gt;&lt;P&gt;- In development there is acceleration of inspection layers above L4.&lt;/P&gt;&lt;P&gt;- size of the card - The card is double width and occupies two slots (though careful reader will notice this on the pictures).&lt;/P&gt;&lt;P&gt;- Interface bonding between two cards will not guarantee the acceleration. - Currently there is no mechanism implemented to ensure that the inbound and outbound frames of one connection will be on the same card but it is in preparation (smart bonding).&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 08:59:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Performance-Tuning-Tip-Lightspeed-Appliance/m-p/142378#M25272</guid>
      <dc:creator>Václav_Brožík</dc:creator>
      <dc:date>2022-02-24T08:59:22Z</dc:date>
    </item>
  </channel>
</rss>

