<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Details and risks about Dynamic Balancing on Maestro in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/283202#M4437</link>
    <description>&lt;P&gt;Hi everyone.&lt;/P&gt;
&lt;P&gt;In case anyone else is/will go through a similar procedure, I'll briefly write down the steps we took. It worked for us, hope it works others as well.&lt;/P&gt;
&lt;P&gt;Assume Chassis 1 is active and Chassis 2 is standby.&lt;/P&gt;
&lt;P&gt;1. Checked overall health with usual diagnostic commands, like &lt;FONT face="courier new,courier"&gt;asg diag verify&lt;/FONT&gt;, &lt;FONT face="courier new,courier"&gt;hcp -r all&lt;/FONT&gt; etc.&lt;/P&gt;
&lt;P&gt;2. We took Chassis 2 DOWN.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;asg_chassis_admin -c 2 down&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;3. We set the default number of FW instances not on cpview, but using the dynamic split command in gclish:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;set dynamic-balancing state enable set_default_fw_instances&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;4. We enabled the parameter &lt;EM&gt;fwha_allow_different_corexl_instances&lt;/EM&gt; so that ClusterXL allows us to do failovers even when there are different FW/SND distributions among sites.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;g_fw ctl set -f int fwha_allow_different_corexl_instances 1&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;5. Rebooted all SGMs in Chassis 2, and waited until all of them got back together with ACTIVE (!) state, while Chassis 2 still was DOWN.&lt;/P&gt;
&lt;P&gt;6. Brought Chassis 2 up, did a failover from Chassis 1 to Chassis 2. Chassis 2 became ACTIVE.&lt;/P&gt;
&lt;P&gt;7. Took Chassis 1 DOWN.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;asg_chassis_admin -c 1 down&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;8. Rebooted all SGMs in Chassis 1, and waited until all of them got back together with ACTIVE (!) state, while Chassis 1 still was DOWN.&lt;/P&gt;
&lt;P&gt;9. Brought Chassis 1 back up, did a failover from Chassis 2 to Chassis 1. Chassis 1 became ACTIVE.&lt;/P&gt;
&lt;P&gt;Now at this stage you might expect everything to get back to normal, but it didn't in our case, probably because we had auto-clone disabled (we had a Mix &amp;amp; Match on this SG).&lt;/P&gt;
&lt;P&gt;10. As a last step we restarted Dynamic Balancing a couple of times until everything showed desired outputs.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;g_dynamic_balancing -r&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;11. We reverted the&amp;nbsp;fwha_allow_different_corexl_instances parameter back to 0.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;sed -i '/^fwha_allow_different_corexl_instances=1$/d'&amp;nbsp;$FWDIR/boot/modules/fwkern.conf&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;12. Ran system diagnostics again, just in case.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;As you may or may not have noticed, &lt;U&gt;&lt;EM&gt;we didn't touch MQ settings at all&lt;/EM&gt;&lt;/U&gt;. In the beginning it was globally in Manual mode, and in the end it was globally Dynamic. So turns out that you don't need to manually set it to Auto if you're making these changes both on MQ and DB.&lt;/P&gt;
&lt;P&gt;What increased our adrenaline during the procedure:&lt;/P&gt;
&lt;P&gt;- There was still a bit of traffic going through the gateways during the whole operation, and we received occasional connection loss complaints. Could be some long living TCP sessions, but I've got no detailed information from customer's infra.&lt;/P&gt;
&lt;P&gt;- We monitored the system constantly using commands below.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;asg stat -v&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;g_allc "fw ctl affinity -l -v -a | grep fw_"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;g_allc "mq_mng -o | grep -v igb"&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;And sometimes the outputs didn't make sense. But we.. ahem.. rawdogged it, because we were told both by TAC and PS that those weird outputs will be expected. In the end, after resetting Dynamic Balancing a couple of times on both sites, everything automatically got resolved. Again, it may be because we didn't have auto-clone enabled.&lt;/P&gt;
&lt;P&gt;Thank you all for providing ideas, that helped us help TAC to come up with a proper plan of actions.&lt;/P&gt;
&lt;P&gt;Hope it'll be useful for someone in the future.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
    <pubDate>Mon, 05 Oct 2026 09:10:26 GMT</pubDate>
    <dc:creator>kamilazat</dc:creator>
    <dc:date>2026-10-05T09:10:26Z</dc:date>
    <item>
      <title>Details and risks about Dynamic Balancing on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281863#M4398</link>
      <description>&lt;P&gt;Hello everyone.&lt;/P&gt;
&lt;P&gt;- Maestro Dual Site (HA), R81.20, JHF Take 146&lt;BR /&gt;- 4x 9200 appliances on each site.&lt;/P&gt;
&lt;P&gt;We've noticed that Dynamic Balancing (Dynamic Split) is disabled on the gateways, so we want to enable it. As far as I remember, the gateways come with DS enabled by default, and we don't know why it's disabled. So we need to try to understand why it's disabled, and how to re-enable it on a production setup with preferably no traffic loss.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;As per&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk164155" target="_self"&gt;CoreXL Dynamic Balancing&lt;/A&gt; we checked the requirements:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- CoreXL enabled&lt;/P&gt;
&lt;P&gt;- 9200 (part of supported 9000 appliances)&lt;/P&gt;
&lt;P&gt;- Firewall is User mode, SecureXL KPPAK&lt;/P&gt;
&lt;P&gt;- No VSX, MDPS, ElasticXL etc.&lt;/P&gt;
&lt;P&gt;- GNAT enabled:&amp;nbsp;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[Expert@Hostname-ch02-01:0]# g_fw ctl get int fwx_gnat_enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;-*- 8 blades: 1_01 1_02 1_03 1_04 2_01 2_02 2_03 2_04 -*-&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;fwx_gnat_enabled = 1&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;- fwkern.conf has these values on all SGMs:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;fwha_ssm_type=16&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;fwha_ch_arp_forwarding=1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;fwha_mbs_mixed_appliance=0&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;- DS config file:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[Expert@Hostname-ch02-01:0]# cat $FWDIR/conf/dynamic_split.conf&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;ALPHA=10&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;EMERGENCY_CPU_HANDLING_THRESHOLD=40&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;LOG_LEVEL=0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;STD_DIV_MULTIPLAYER=1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;DEFAULT_BOOT_STATUS=1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;MACHINE_CONFIG_OK=0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;VERBOSE_DEBUG=0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;STATE_VRIFICATION_FAILURE_DETECTED=0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;MONITOR_MODE=0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CLUSTER_MODE=1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;AUTOMATION_MODE=0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;INITIALIZATION=0&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;- fwaffinity.conf set to auto and contains "&lt;FONT face="courier new,courier"&gt;i default auto&lt;/FONT&gt;", and Multi-Queue untouched.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;- No custom weight distributions:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[Global] Hostname-ch02-01&amp;gt; show smo security-group sgm-weight current&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Chassis: Blade: State: Distribution:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;1 1 Active 25.0% 128/512&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;1 2 Active 25.0% 128/512&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;1 3 Active 25.0% 128/512&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;1 4 Active 25.0% 128/512&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2 1 Active 25.0% 128/512&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2 2 Active 25.0% 128/512&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2 3 Active 25.0% 128/512&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2 4 Active 25.0% 128/512&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;And there are some weird indications that we don't quite understand:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;- SMT status unknown.&amp;nbsp;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Expert@Hostname-ch02-01:0]# cat /proc/smt_status&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cat: /proc/smt_status: No such file or directory&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;- &lt;EM&gt;cpconfig&lt;/EM&gt; shows us that FW cores are supposed to be 6:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;This machine has 8 CPUs.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Note: All cluster members must have the same number of firewall instances enabled.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;How many IPv4 firewall instances would you like to enable (2 to 8)&lt;/img&gt; &lt;U&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;[6]&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/U&gt; ?&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;- CPVIEW shows a weird distribution:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPVIEW.CPU&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Overview SysInfo Network CPU I/O software-blades Hardware-Health Advanced&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Overview Top-Protocols Top-Connections Spikes Processes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Host&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Overview:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;CPU type CPUs Avg utilization&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CoreXL_SND 4 24%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;BOTH 3 71%&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CoreXL_FW 1 62%&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;CPU:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;CPU Type User System Idle I/O wait Interrupts&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;0 &lt;STRONG&gt;CoreXL_SND&lt;/STRONG&gt; 0% 28% 72% 0% 690,262&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;1 &lt;STRONG&gt;CoreXL_SND&lt;/STRONG&gt; 0% 27% 73% 0% 690,298&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2 &lt;STRONG&gt;CoreXL_SND&lt;/STRONG&gt; 0% 20% 80% 0% 690,298&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;3 &lt;STRONG&gt;CoreXL_SND&lt;/STRONG&gt; 0% 20% 80% 0% 690,302&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;4 &lt;STRONG&gt;BOTH&lt;/STRONG&gt; 16% 49% 35% 0% 345,160&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;5 &lt;STRONG&gt;BOTH&lt;/STRONG&gt; 22% 50% 28% 0% 345,159&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;6 &lt;STRONG&gt;CoreXL_FW&lt;/STRONG&gt; 34% 28% 38% 0% 345,159&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;7 &lt;STRONG&gt;BOTH&lt;/STRONG&gt; 21% 55% 24% 0% 345,164&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;- And again in CPVIEW we see "CoreXL instances" value as 4.&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPVIEW. SysInfo&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Overview SysInfo Network CPU I/O Software-blades Hardware-Health Advanced&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Configuration Information:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Platform Gaia 64Bit&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Configuration Check Point Security Gateway&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CoreXL Status On&lt;/FONT&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;CoreXL instances 4&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Dynamic Balancing Status off&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;SecureXL Status On&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;USFW Status On&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;UPPAK Status off&lt;/FONT&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorkamilazat_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, we want to clean this situation up. But first I need to understand why we see such discrepancies. And then I want to use your experience to avoid unwanted scenarios and risks.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After settling with the question marks above, I'm thinking about enabling DS in this order:&lt;/P&gt;
&lt;P&gt;1. Enable DS globally&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;g_dynamic_balancing -o enable&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;2. Reboot all SGMs on the Standby chassis (say, chassis 2).&lt;/P&gt;
&lt;P&gt;3. Failover to chassis 2.&lt;/P&gt;
&lt;P&gt;4. Reboot all SGMs on the new Standby chassis (now chassis 1).&lt;/P&gt;
&lt;P&gt;5. Failover back to chassis 1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do you think about the procedure and why do you think we have DS disabled in the first place? Any issues that you've encountered in a similar situation?&lt;/P&gt;
&lt;P&gt;I'd heavily appreciate all opinions &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2026 15:46:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281863#M4398</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2026-09-04T15:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Details and risks about Dynamic Balancing on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281868#M4399</link>
      <description>&lt;P&gt;If you have ever configured a custom static CoreXL split on your firewall (including before upgrading to R81.20, when it was first supported on Maestro), Dynamic Split (DS) will be off.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also, any custom changes to Multi-Queue can inhibit DS from starting.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To get DS going:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1) Run &lt;STRONG&gt;mq_mng --show&lt;/STRONG&gt;, make sure all interfaces are showing "Auto". This changes to "Dynamic" once DS is successfully started.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;2)&amp;nbsp;Undo the custom split and revert to the default number of instances (6 for an 8-core firewall), reboot, and Dynamic Split should be enabled.&amp;nbsp; The&amp;nbsp;&lt;STRONG&gt;dynamic_balancing -o enable&lt;/STRONG&gt; command can also accomplish setting the split back to default for you.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If it is still not working, check the following two files for error messages; the issue will probably be something like&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk184372" target="_blank" rel="noopener"&gt;sk184372: Dynamic Balancing stays in the "Initializing" stage,&lt;/A&gt;&amp;nbsp;or this&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk163815" target="_blank" rel="noopener"&gt;sk163815: "Dynamic Balancing was disabled due to state verification failure" log error&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;$FWDIR/log/dynamic_split.elg&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;$FWDIR/log/dsd.elg&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2026 20:45:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281868#M4399</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-09-04T20:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Details and risks about Dynamic Balancing on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281889#M4400</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, I forgot to check the MQ configuration, since it's almost always in Auto. And we see that it's in Manual mode right now:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Affinity of Multi-Queue IRQs&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Note: 'cpmq' is deprecated and no longer supported. For multiqueue management, please use 'mq_mng'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Current multiqueue status:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;Total 8 cores. Available for MQ 4 cores&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;i/f driver driver mode state mode (queues) cores &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;actual/avail &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;------------------------------------------------------------------------------------------------&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ethsBP1 igb Kernel Up Manual (4/4) 0,1,2,3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ethsBP1-01 ice Kernel Up Manual (7/7) 0,1,2,3,4,5,7&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ethsBP1-02 ice Kernel Up Manual (7/7) 0,1,2,3,4,5,7&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ethsBP1-03 ice Kernel Up Manual (7/7) 0,1,2,3,4,5,7&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ethsBP1-04 ice Kernel Up Manual (7/7) 0,1,2,3,4,5,7&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ethsBP2 igb Kernel Up Manual (4/4) 0,1,2,3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ethsBP3 igb Kernel Up Manual (4/4) 0,1,2,3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ethsBP4 igb Kernel Up Manual (4/4) 0,1,2,3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ethsBP5 igb Kernel Up Manual (4/4) 0,1,2,3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ethsBP6 igb Kernel Up Manual (4/4) 0,1,2,3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ethsBP7 igb Kernel Up Manual (4/4) 0,1,2,3&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;ethsBP8 igb Kernel Up Manual (4/4) 0,1,2,3&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;So next steps will be to;&lt;/P&gt;
&lt;P&gt;1. Enable Multi-Queue&lt;BR /&gt;&lt;EM&gt;mq_mng --set-mode auto&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;2. Enable Dynamic Balancing&lt;BR /&gt;&lt;EM&gt;dynamic_balancing -o enable&lt;/EM&gt; &lt;/P&gt;
&lt;P&gt;Now onto the second phase, implementation. Since this is a Maestro environment, and I don't have a Maestro lab at my disposal to test things, I believe we need to tread carefully to avoid traffic issues.&lt;/P&gt;
&lt;P&gt;- Do you think we can enable both guys and finish the job in one reboot?&lt;/P&gt;
&lt;P&gt;- What do you think about the procedure for minimum (preferably zero) downtime?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;1. Enable DS globally&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;FONT face="courier new,courier"&gt;g_dynamic_balancing -o enable&lt;BR /&gt;&lt;/FONT&gt;2. Reboot all SGMs on the Standby chassis (say, chassis 2).&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;3. Failover to chassis 2.&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;4. Reboot all SGMs on the new Standby chassis (now chassis 1).&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;5. Failover back to chassis 1.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2026 07:42:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281889#M4400</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2026-09-07T07:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Details and risks about Dynamic Balancing on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281915#M4402</link>
      <description>&lt;P&gt;I'd suggest making the MQ changes from clish (followed by a save config, reboot, and recheck of MQ state for Auto mode) to ensure that the changes stick.&amp;nbsp; Once that's complete, you can enable Dynamic Split globally and start rebooting. I wouldn't try to make both the MQ and DS changes for a single reboot, although it may work.&lt;/P&gt;
&lt;P&gt;Also, because these changes are similar to doing a code upgrade (or static CoreXL split adjustment) to one SGM at a time, I'd recommend reviewing the&amp;nbsp;&lt;SPAN&gt;PMTR-74532 section of Known Limitations in &lt;A href="https://support.checkpoint.com/results/sk/sk164155" target="_blank"&gt;sk164155: CoreXL Dynamic Balancing&lt;/A&gt;&lt;/SPAN&gt;, to avoid any possible traffic handling issues as you may see some alarms in the Security Group until all members have been modified.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2026 14:48:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281915#M4402</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-09-07T14:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Details and risks about Dynamic Balancing on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281923#M4403</link>
      <description>&lt;P&gt;Reboot one stand-by SGM before you make the changes to mq. After reboot make sure it is auto.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you do all changes at once you cannot know if it goes wrong, what the cause was.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it all looks good you can change the dynamic balancing and after that make it active.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also checked the latest bugs and I dont see any at the moment for dynamic balancing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2026 19:15:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281923#M4403</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-09-07T19:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Details and risks about Dynamic Balancing on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281974#M4404</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;Is there a way to do &lt;EM&gt;mq_mng --set-mode auto&amp;nbsp;&lt;/EM&gt;for all interfaces using clish? I have failed to find such a command in the documentation. Is there a difference in how mg_mng and clish commands work?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 08:23:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281974#M4404</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2026-09-09T08:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: Details and risks about Dynamic Balancing on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281975#M4405</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;Fair point. At this point what concerns me more is that even during a MW we cannot shut all traffic down to reduce the load on the SMO.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you think making changes and reboots on the chassis 2 (standby), and then doing a failover from ch1 -&amp;gt; ch2 can at least allow us to keep processing whatever traffic is there during the MW?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These gateways are located at a very critical position, where stopping all traffic is simply not possible. So we're afraid that we'll lose access to the SMO when it stays the only gateway if we follow&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk164155" target="_self"&gt;PMTR-74532&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 08:32:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/281975#M4405</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2026-09-09T08:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Details and risks about Dynamic Balancing on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/282084#M4406</link>
      <description>&lt;P&gt;Not that I can think of.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;I suppose&amp;nbsp;&lt;EM&gt;mq_mng --set-mode auto&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;might actually update the clish startup config, although things done like that in expert mode normally&amp;nbsp;&lt;/SPAN&gt;don't survive a boot.&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;I'd try the&amp;nbsp;&lt;/SPAN&gt;&lt;EM style="background-color: #ffffff; font-size: 18px;"&gt;mq_mng&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;command, then check MQ config of all interfaces in clish.&amp;nbsp; If it looks good do a &lt;EM&gt;save config&lt;/EM&gt; just before rebooting to be sure.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 16:44:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/282084#M4406</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-09-09T16:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: Details and risks about Dynamic Balancing on Maestro</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/283202#M4437</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;
&lt;P&gt;In case anyone else is/will go through a similar procedure, I'll briefly write down the steps we took. It worked for us, hope it works others as well.&lt;/P&gt;
&lt;P&gt;Assume Chassis 1 is active and Chassis 2 is standby.&lt;/P&gt;
&lt;P&gt;1. Checked overall health with usual diagnostic commands, like &lt;FONT face="courier new,courier"&gt;asg diag verify&lt;/FONT&gt;, &lt;FONT face="courier new,courier"&gt;hcp -r all&lt;/FONT&gt; etc.&lt;/P&gt;
&lt;P&gt;2. We took Chassis 2 DOWN.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;asg_chassis_admin -c 2 down&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;3. We set the default number of FW instances not on cpview, but using the dynamic split command in gclish:&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;set dynamic-balancing state enable set_default_fw_instances&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;4. We enabled the parameter &lt;EM&gt;fwha_allow_different_corexl_instances&lt;/EM&gt; so that ClusterXL allows us to do failovers even when there are different FW/SND distributions among sites.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;g_fw ctl set -f int fwha_allow_different_corexl_instances 1&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;5. Rebooted all SGMs in Chassis 2, and waited until all of them got back together with ACTIVE (!) state, while Chassis 2 still was DOWN.&lt;/P&gt;
&lt;P&gt;6. Brought Chassis 2 up, did a failover from Chassis 1 to Chassis 2. Chassis 2 became ACTIVE.&lt;/P&gt;
&lt;P&gt;7. Took Chassis 1 DOWN.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;asg_chassis_admin -c 1 down&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;8. Rebooted all SGMs in Chassis 1, and waited until all of them got back together with ACTIVE (!) state, while Chassis 1 still was DOWN.&lt;/P&gt;
&lt;P&gt;9. Brought Chassis 1 back up, did a failover from Chassis 2 to Chassis 1. Chassis 1 became ACTIVE.&lt;/P&gt;
&lt;P&gt;Now at this stage you might expect everything to get back to normal, but it didn't in our case, probably because we had auto-clone disabled (we had a Mix &amp;amp; Match on this SG).&lt;/P&gt;
&lt;P&gt;10. As a last step we restarted Dynamic Balancing a couple of times until everything showed desired outputs.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;g_dynamic_balancing -r&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;11. We reverted the&amp;nbsp;fwha_allow_different_corexl_instances parameter back to 0.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;sed -i '/^fwha_allow_different_corexl_instances=1$/d'&amp;nbsp;$FWDIR/boot/modules/fwkern.conf&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;12. Ran system diagnostics again, just in case.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;As you may or may not have noticed, &lt;U&gt;&lt;EM&gt;we didn't touch MQ settings at all&lt;/EM&gt;&lt;/U&gt;. In the beginning it was globally in Manual mode, and in the end it was globally Dynamic. So turns out that you don't need to manually set it to Auto if you're making these changes both on MQ and DB.&lt;/P&gt;
&lt;P&gt;What increased our adrenaline during the procedure:&lt;/P&gt;
&lt;P&gt;- There was still a bit of traffic going through the gateways during the whole operation, and we received occasional connection loss complaints. Could be some long living TCP sessions, but I've got no detailed information from customer's infra.&lt;/P&gt;
&lt;P&gt;- We monitored the system constantly using commands below.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;asg stat -v&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;g_allc "fw ctl affinity -l -v -a | grep fw_"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;g_allc "mq_mng -o | grep -v igb"&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;And sometimes the outputs didn't make sense. But we.. ahem.. rawdogged it, because we were told both by TAC and PS that those weird outputs will be expected. In the end, after resetting Dynamic Balancing a couple of times on both sites, everything automatically got resolved. Again, it may be because we didn't have auto-clone enabled.&lt;/P&gt;
&lt;P&gt;Thank you all for providing ideas, that helped us help TAC to come up with a proper plan of actions.&lt;/P&gt;
&lt;P&gt;Hope it'll be useful for someone in the future.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2026 09:10:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Details-and-risks-about-Dynamic-Balancing-on-Maestro/m-p/283202#M4437</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2026-10-05T09:10:26Z</dc:date>
    </item>
  </channel>
</rss>

