<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dmd_mgmt process using several CPUs 100% in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220592#M2737</link>
    <description>&lt;P&gt;dmd_mgmt is related to Hyperflow (a gateway-side feature):&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk178070" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk178070&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jul 2024 18:41:38 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-07-12T18:41:38Z</dc:date>
    <item>
      <title>dmd_mgmt process using several CPUs 100%</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220471#M2729</link>
      <description>&lt;P&gt;Lately I see on an 16000 appliance running as a SGM several CPUs used to 100 % for a longer period of time (sometimes 3 or 4 hours).&lt;/P&gt;&lt;P&gt;Using top the most consuming process is dmd_mgmt.&lt;/P&gt;&lt;P&gt;I did not observe a similar behaviour on other systems and was not able to find out what this process is actually doing.&lt;/P&gt;&lt;P&gt;Can you guys give me a hint?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 06:15:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220471#M2729</guid>
      <dc:creator>roethlein</dc:creator>
      <dc:date>2024-07-12T06:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: dmd_mgmt process using several CPUs 100%</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220505#M2731</link>
      <description>&lt;P&gt;Which JHF is the environment running and anything relevant in the Hyperflow log&amp;nbsp;&lt;EM&gt;$FWDIR/log/dmd.elg ?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 06:15:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220505#M2731</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-07-15T06:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: dmd_mgmt process using several CPUs 100%</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220509#M2732</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;this is R81.20 JHF 41.&lt;/P&gt;&lt;P&gt;In dmd.elg I am not sure what relevant information there may be hidden. The log right now without this high load seems very similar to the one yesterday afternoon.&lt;/P&gt;&lt;P&gt;Anything I should look for in special?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 11:36:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220509#M2732</guid>
      <dc:creator>roethlein</dc:creator>
      <dc:date>2024-07-12T11:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: dmd_mgmt process using several CPUs 100%</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220592#M2737</link>
      <description>&lt;P&gt;dmd_mgmt is related to Hyperflow (a gateway-side feature):&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk178070" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk178070&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 18:41:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220592#M2737</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-12T18:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: dmd_mgmt process using several CPUs 100%</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220646#M2738</link>
      <description>&lt;P&gt;From the &lt;A href="https://support.checkpoint.com/results/sk/sk178070" target="_self"&gt;HyperFlow SK&lt;/A&gt;:&lt;/P&gt;
&lt;P&gt;When an elephant connection triggers HyperFlow, the output of the "&lt;CODE&gt;top&lt;/CODE&gt;" and "&lt;CODE&gt;ps&lt;/CODE&gt;" commands can show that HyperFlow user space processes consume the CPU at 100%.&lt;/P&gt;
&lt;P&gt;This occurs because HyperFlow constantly polls its queues to handle incoming jobs. After the elephant connection closes, the output of these commands shows that the user space "&lt;CODE&gt;us&lt;/CODE&gt;" consumption returns to usual levels because Hyperflow goes down and stops processing jobs.&lt;/P&gt;
&lt;P&gt;To see the actual load on the CPU, use one of these:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;CPView (&lt;STRONG&gt;CPU&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Overview&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Host&lt;/STRONG&gt;)&lt;/LI&gt;
&lt;LI&gt;SNMP (the OID tree 1.3.6.1.4.1.2620.1.6.7.5)&lt;/LI&gt;
&lt;LI&gt;SmartConsole (right-click the Security Gateway object &amp;gt; click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Monitor&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt; from the left, open&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;System Counters&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;System&lt;/STRONG&gt;).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This does&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;trigger inspection bypass because of a high CPU load.&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 15:13:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220646#M2738</guid>
      <dc:creator>AmitShmuel</dc:creator>
      <dc:date>2024-07-13T15:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: dmd_mgmt process using several CPUs 100%</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220648#M2739</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/46744"&gt;@AmitShmuel&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I thought that when Hyperflow becomes active and reallocates former Firewall Worker instances to PPE_MGR or PPE_WT, that the reallocated cores were not allowed to be driven beyond 60% utilization by PPE, to ensure that the "mice" connections still remaining on the reallocated cores do not get squashed by PPE before they decay away.&amp;nbsp; Questions:&lt;/P&gt;
&lt;P&gt;1) So when you say that Hyperflow processes consume CPU at 100% I assume that load is spread across multiple cores to avoid violating the 60% per-core utilization rule to respect the existing mice connections?&lt;/P&gt;
&lt;P&gt;2) I thought that poll mode (instead of interrupt mode) which drives the CPU to 100% was only employed if UPPAK is enabled on a Lightspeed/9000/19000/29000.&amp;nbsp; Is that not correct?&lt;/P&gt;
&lt;P&gt;3) Are the CPAS and PXL "pipeline" paths displayed by &lt;STRONG&gt;fwaccel stats -s&lt;/STRONG&gt; just Hyperflow by another name?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 15:31:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220648#M2739</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-07-13T15:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: dmd_mgmt process using several CPUs 100%</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220650#M2740</link>
      <description>&lt;P&gt;Hi Tim,&lt;/P&gt;
&lt;P&gt;The 60% utilization enforcement refers only to the non-HyperFlow cores.&lt;/P&gt;
&lt;P&gt;Let's examine the following 4 cores example, for simplicity:&lt;/P&gt;
&lt;P&gt;CPU 0: SND&lt;BR /&gt;CPU 1: PPE_MGR&lt;BR /&gt;CPU 2: PPE_WT&lt;BR /&gt;CPU 3: FW_0 FW_1 FW_2&lt;/P&gt;
&lt;P&gt;- FW_1 &amp;amp; FW_2 are both stopped FW workers (new connections will not be dispatched to them), that continue to handle existing mice connections, whos cores been reallocated for HyperFlow/PPE threads&lt;/P&gt;
&lt;P&gt;- Looking at top, CPU 1 &amp;amp; 2 will show 100% utilization, as they constantly polling for MD5 and Hash jobs, similar to how UPPAK is polling for packets - both UPPAK (usim_x86) and HyperFlow (dmd_run) processes are running in poll-mode, and considered "PMD". We can see their real utilization in CPView.&lt;/P&gt;
&lt;P&gt;- Yes, the "pipeline" paths refer to HyperFlow&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 15:59:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220650#M2740</guid>
      <dc:creator>AmitShmuel</dc:creator>
      <dc:date>2024-07-13T15:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: dmd_mgmt process using several CPUs 100%</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220666#M2742</link>
      <description>&lt;P&gt;Thank you for the clarifications.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2024 13:03:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220666#M2742</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-07-14T13:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: dmd_mgmt process using several CPUs 100%</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220721#M2743</link>
      <description>&lt;P&gt;Thank you, this really helped me understanding the situation better.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I understand the behaviour is pretty normal and we should find out which connections are the elephants.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 06:10:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/dmd-mgmt-process-using-several-CPUs-100/m-p/220721#M2743</guid>
      <dc:creator>roethlein</dc:creator>
      <dc:date>2024-07-15T06:10:44Z</dc:date>
    </item>
  </channel>
</rss>

