<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Affinity and Bridge Mode in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Affinity-and-Bridge-Mode/m-p/17712#M3021</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a situation were we implemented a checkpoint with IPS in a bridged interface scenario, on 10Gbps interfaces. The the default Checkpoint affinity for the cpu's were to assign the mgmt and 1 of the bridged interfaces to 1 CPU and the Sync and the other bridged interface to a second CPU. We then hit a problem of traffic throughput that caused both CPU's to run between 90 and 100%. This effectively locked us out of the device and caused major latency problems. The device is currently bypassed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have changed the affinity to combine the mgmt and sync on 1 cpu and am looking to assign 2 cpu's to each of the bridged interfaces. Leaving 11 cpu's for firewall workers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So noting the above is there any experience out there that can comment on whether the 2 x cpu per bridged interface "should be" sufficient or whether it would be advisable to increase them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running r77.30 with dynamic dispatching enable and only 6 firewall rules. Because we were locked out of the device I could not gather any meaningful stats.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Nov 2018 11:20:52 GMT</pubDate>
    <dc:creator>Petrus_Rossouw</dc:creator>
    <dc:date>2018-11-19T11:20:52Z</dc:date>
    <item>
      <title>Affinity and Bridge Mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Affinity-and-Bridge-Mode/m-p/17712#M3021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a situation were we implemented a checkpoint with IPS in a bridged interface scenario, on 10Gbps interfaces. The the default Checkpoint affinity for the cpu's were to assign the mgmt and 1 of the bridged interfaces to 1 CPU and the Sync and the other bridged interface to a second CPU. We then hit a problem of traffic throughput that caused both CPU's to run between 90 and 100%. This effectively locked us out of the device and caused major latency problems. The device is currently bypassed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have changed the affinity to combine the mgmt and sync on 1 cpu and am looking to assign 2 cpu's to each of the bridged interfaces. Leaving 11 cpu's for firewall workers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So noting the above is there any experience out there that can comment on whether the 2 x cpu per bridged interface "should be" sufficient or whether it would be advisable to increase them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running r77.30 with dynamic dispatching enable and only 6 firewall rules. Because we were locked out of the device I could not gather any meaningful stats.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Nov 2018 11:20:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Affinity-and-Bridge-Mode/m-p/17712#M3021</guid>
      <dc:creator>Petrus_Rossouw</dc:creator>
      <dc:date>2018-11-19T11:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Affinity and Bridge Mode</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Affinity-and-Bridge-Mode/m-p/17713#M3022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With the right traffic flows and utilization, a single CPU would have been enough &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;Two CPUs will certainly be better, but you will need to monitor to see if it will be enough and adjust accordingly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Nov 2018 06:34:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Affinity-and-Bridge-Mode/m-p/17713#M3022</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-22T06:34:58Z</dc:date>
    </item>
  </channel>
</rss>

