- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi
I have been trying to find info about VS resource allocation in a VSX VSLS cluster.
To be more specific, has every VS access to same resources (cpu/mem) on the VSX gateway ?
And how much can a VS use, all cores and max memory or is some resources spared for VS0 ?
Thanks
On a multi-core system, VSX is using CoreXL. Amount of cores per VS is set on per VS object. If total amount of cores for all VSs is higher than the number of FWK cores available on the system than yes, some VSs may share the same CPU core, or even several.
You can check CPU allocation by running fw ctl affinily -l command.
Amount of FWKs depends on a number of physical cores on the platform, minus amount of SNDs. By default, in a system with 4 cores, just one of them is SND, with 6 to 20 cores - 2, with more than 20 cores, 4 of them are assigned to SND roles.
Now, for the memory. VSX is running in a User Space mode, meaning VSs are using the regular RAM and not kernel memory space. There is usually lots of memory available there. Memory usage depends on the size of the VS, or, in other words, on a maximum amount of connections VS is defined to handle. Also controllable from SmartConsole.
There is no reservation of resources, all VSs are equal, including VS0.
Now, why do you ask? Are you facing an actual issue?
On a multi-core system, VSX is using CoreXL. Amount of cores per VS is set on per VS object. If total amount of cores for all VSs is higher than the number of FWK cores available on the system than yes, some VSs may share the same CPU core, or even several.
You can check CPU allocation by running fw ctl affinily -l command.
Amount of FWKs depends on a number of physical cores on the platform, minus amount of SNDs. By default, in a system with 4 cores, just one of them is SND, with 6 to 20 cores - 2, with more than 20 cores, 4 of them are assigned to SND roles.
Now, for the memory. VSX is running in a User Space mode, meaning VSs are using the regular RAM and not kernel memory space. There is usually lots of memory available there. Memory usage depends on the size of the VS, or, in other words, on a maximum amount of connections VS is defined to handle. Also controllable from SmartConsole.
There is no reservation of resources, all VSs are equal, including VS0.
Now, why do you ask? Are you facing an actual issue?
Hi,
Thanks for reply.
So for each VS the resource is controlled by using corexl (in that perticular VS context?)
The reason i am asking is because one VS is running IPS, and now it seems it has used more cpu than it had available so it was bypassed.
Correct. I suspect that VS is running just a single core. Add more 🙂
add more "vs instances" aka cores 😄 , when it comes to vsx you also need to keep track of the connections 🙂
Don - is there a way to monitor the memory utilisation on a per VS basis using SNMP v3?
Have a look at this thread:
https://community.checkpoint.com/t5/Management/VSX-Monitor-Virtual-Memory-of-VS/td-p/32664
Other references:
Search:
vsxStatusMemoryUsageTable
Thanks Don,
Unable to access:
https://dl3.checkpoint.com/paid/3a/3a7f7303d86eaabace8923ad195f017f/chkpnt.mib?HashKey=1638127098_c9...
I'll take a look at the other links, been many years since you where my SE 😉
Me neither, and I have all the rights 🙂
Something is wrong with the link.
Cool.
It is the R81 Product MIB (.mib) file from SK90470
Sorry, I assumed the link would work.
Probably should've posted that link (the download link)
Thanks Don.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
13 | |
12 | |
11 | |
10 | |
9 | |
8 | |
7 | |
6 | |
5 | |
5 |
Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY