<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: High CPU Spikes on 5100 Cluster in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172051#M28713</link>
    <description>&lt;P&gt;How many routes do you see via BGP, a handful or thousands, more?&lt;/P&gt;</description>
    <pubDate>Mon, 20 Feb 2023 13:17:35 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-02-20T13:17:35Z</dc:date>
    <item>
      <title>High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/171963#M28694</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We've been having trouble with high CPU usage spikes on a 5100 cluster at one of our offices - on and off for a few months. These issues typically happen in the weekend (it so happens that this office is mostly used during the weekend) and the events generally only last for a few minutes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When such issues occur, we typically notice the following:&lt;/P&gt;&lt;P&gt;- High CPU can be observed on CPView (see attached screenshot) on both cores.&lt;/P&gt;&lt;P&gt;- Generally network protocols seem to be affected - for example ISP redundancy is disturbed (to the extent that we've had to disable this as it was causing a snowball effect of issues) and BGP sessions dropped.&lt;/P&gt;&lt;P&gt;- There is nothing in the logs leading up to the event that would indicate any problem. I've checked /var/log/messages, dmesg, routed.log and routed_messages (the latter shows the dropped BGP sessions and ISP redundancy flaps but these are an effect of the high CPU, not a cause).&lt;/P&gt;&lt;P&gt;- Whilst the issues generally happen in the weekend in the afternoon, there is no exact/repeatable timestamp at which they occur (which means we cannot link what's happening to any specific process kicking off).&lt;/P&gt;&lt;P&gt;- Leading up to and after such events, the CPU generally sits somewhere between 40-60% so there's no indication of any impending issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would you be able to help me troubleshoot this further as I'm at a bit of a loss as to what I could look at next?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;</description>
      <pubDate>Sat, 18 Feb 2023 13:21:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/171963#M28694</guid>
      <dc:creator>joeborg</dc:creator>
      <dc:date>2023-02-18T13:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/171970#M28697</link>
      <description>&lt;P&gt;What about the regular FW logs? The first thing to look for is an abnormal number of drop logs just before and during the issue.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Feb 2023 21:28:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/171970#M28697</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-02-18T21:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/171971#M28698</link>
      <description>&lt;P&gt;Which version &amp;amp; JHF is this gateway deployed with?&lt;/P&gt;
&lt;P&gt;If BFD is enabled for the BGP session is it configured in the PriorityQ settings per&amp;nbsp;&lt;SPAN&gt;sk105762?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Additionally it may also be worthwhile reviewing the S7 commands output per:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/td-p/40528" target="_blank"&gt;https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/td-p/40528&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Feb 2023 02:50:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/171971#M28698</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-02-19T02:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172025#M28707</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thank you both for the prompt replies and for the insightful questions. To answer them:&lt;/P&gt;&lt;P&gt;1. Regular FW logs don't seem to show anything abnormal. We've combed through them a few times but, other than drops which we see during normal operation, there's nothing that caught our eye (e.g. nothing that would suggest a DOS attack or anything of the sort).&lt;/P&gt;&lt;P&gt;2. Version R81.10:&lt;/P&gt;&lt;P&gt;Product version Check Point Gaia R81.10 Take 78&lt;BR /&gt;OS build 335&lt;BR /&gt;OS kernel version 3.10.0-957.21.3cpx86_64&lt;BR /&gt;OS edition 64-bit&lt;/P&gt;&lt;P&gt;3. We're not running BFD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for your assistance on this.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 08:58:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172025#M28707</guid>
      <dc:creator>joeborg</dc:creator>
      <dc:date>2023-02-20T08:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172037#M28709</link>
      <description>&lt;P&gt;Look into the spike logs: &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166454&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank"&gt;sk166454: CPU &lt;STRONG&gt;Spike&lt;/STRONG&gt; Detective&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 10:15:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172037#M28709</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-20T10:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172050#M28712</link>
      <description>&lt;P&gt;Nothing in there corresponding to these two events :-(. The last log is from the 3rd of February. These events happened on the 18th.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 13:14:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172050#M28712</guid>
      <dc:creator>joeborg</dc:creator>
      <dc:date>2023-02-20T13:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172051#M28713</link>
      <description>&lt;P&gt;How many routes do you see via BGP, a handful or thousands, more?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 13:17:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172051#M28713</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-02-20T13:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172055#M28715</link>
      <description>&lt;P&gt;83 BGP routes installed in the route table. Around 472 in total received from all BGP peers.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 13:33:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172055#M28715</guid>
      <dc:creator>joeborg</dc:creator>
      <dc:date>2023-02-20T13:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172071#M28720</link>
      <description>&lt;P&gt;At this stage I can only recommend the following further actions.&lt;/P&gt;
&lt;P&gt;1. Update to JHF T87 which will address / eliminate the following (listed resolved from T82):&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PRJ-41504,&lt;/SPAN&gt;&lt;SPAN&gt;PMTR-75250&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Routing -&amp;nbsp;&lt;SPAN&gt;Some invalid nexthop and destination addresses from remote BGP peers may be incorrectly handled, causing lost BGP connection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. If the problem persist investigate further with TAC&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;3. Provide the S7 output mentioned in a previous post above.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 15:21:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172071#M28720</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-02-20T15:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172074#M28722</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks for this. s7 output attached though this is taken today so not sure it's still relevant. Unfortunately these incidents generally only last a few minutes and have usually resolved themselves by the time I'm called and login so it's near impossible for me to run this command whilst the issue is underway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Noted re BGP - I doubt it as most routes are our internal routes over MPLS and don't change often. Moreover, other sites recieve them too without issues.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 15:46:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172074#M28722</guid>
      <dc:creator>joeborg</dc:creator>
      <dc:date>2023-02-20T15:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172083#M28728</link>
      <description>&lt;P&gt;You've got some slight overruns on your NICs that are a very low percentage of overall traffic, but other than that your box appears to be well-tuned but is simply not powerful enough to do all that you are asking of it.&amp;nbsp; You only have 2 cores so both cores are pulling double duty in a 2/2 split, when the CPUs get saturated BGP will destabilize as there simply aren't enough processing resources to go around.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Spike Detective is not logging anything as the CPUs are generally so busy that there is no single outlier that is consuming an inordinate amount of CPU compared to everything else.&amp;nbsp; Try running &lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt;&amp;nbsp;to see if there are any detected elephant flows in the last 24 hours, but it will almost certainly have the same issue as the Spike Detective and not show anything.&amp;nbsp; In my opinion there is not much you can do other than get a more powerful box, as the 2-core&amp;nbsp;Celeron G1820 in your 5100 isn't cutting it and you are getting all you will get out of that box.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 17:50:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172083#M28728</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-02-20T17:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172136#M28734</link>
      <description>&lt;P&gt;Hi Timothy,&lt;/P&gt;&lt;P&gt;Many thanks for taking the time to look into it, I very much appreciate it. I'm also in agreement with you that the box is underdimensioned at this stage and probably needs replacement with something more powerful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the meantime, we've enabled Fast Acceleration on some flows as per &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk156672&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk156672&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22&lt;/A&gt;. We're getting around 30% traffic being fast accelerated during peak and this has lowered CPU by some 20% or so; I'm hoping this buys us some respite until we figure out a replacement plan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All this being said, the only nagging doubt I still have is due to sequence of events that occurs. When this issue happens, CPU goes from 50-60% (not low but hardly alarming) to being maxed out for a few minutes and then things go back dow to 50-60%. Had the cause been solely due to load, I would have expected a far more linear behaviour by way of CPU usage (e.g. 60 -&amp;gt; 70 -&amp;gt; 80 -&amp;gt; 90 over our peak usage hours). In my ignorance, what we're experiencing is more indicative of some event suddenly maxing out the CPU. The problem I have is that I've got no clue what this event might be...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 08:29:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172136#M28734</guid>
      <dc:creator>joeborg</dc:creator>
      <dc:date>2023-02-21T08:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172143#M28735</link>
      <description>&lt;P&gt;Watch out for policy installation tasks. I have a cluster of 5200 running R81.10 Take 87 that have the same CPU than the 5100 and even an accelerated policy installation with no changes creates a surge of 30% on the CPU usage. I've seen non-accelerated policy installation on that cluster increase CPU by 40% even.&lt;/P&gt;&lt;P&gt;That cluster sees very low usage with CPU at 5% most of the time so it decreases rather quickly after policy installation, but in your active setup such an increase might have a more lasting impact.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 09:47:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172143#M28735</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-02-21T09:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU Spikes on 5100 Cluster</title>
      <link>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172168#M28737</link>
      <description>&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;Many thanks for this. The issues happen over the weekend asthis particular office works in the weekend. During the weekend we don't install any policies. Nonetheless, I've gone back and checked and can confirm there is no policy installation going on during the time frame.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm with you that these process tend to cause a spike in CPU usage;the software update check process is one such other one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This being said, during these events,the logs show no such process coinciding.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 13:20:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/High-CPU-Spikes-on-5100-Cluster/m-p/172168#M28737</guid>
      <dc:creator>joeborg</dc:creator>
      <dc:date>2023-02-21T13:20:28Z</dc:date>
    </item>
  </channel>
</rss>

