- Products
- Learn
- Local User Groups
- Partners
- More
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
Hi
I have been trying to find info about VS resource allocation in a VSX VSLS cluster.
To be more specific, has every VS access to same resources (cpu/mem) on the VSX gateway ?
And how much can a VS use, all cores and max memory or is some resources spared for VS0 ?
Thanks
On a multi-core system, VSX is using CoreXL. Amount of cores per VS is set on per VS object. If total amount of cores for all VSs is higher than the number of FWK cores available on the system than yes, some VSs may share the same CPU core, or even several.
You can check CPU allocation by running fw ctl affinily -l command.
Amount of FWKs depends on a number of physical cores on the platform, minus amount of SNDs. By default, in a system with 4 cores, just one of them is SND, with 6 to 20 cores - 2, with more than 20 cores, 4 of them are assigned to SND roles.
Now, for the memory. VSX is running in a User Space mode, meaning VSs are using the regular RAM and not kernel memory space. There is usually lots of memory available there. Memory usage depends on the size of the VS, or, in other words, on a maximum amount of connections VS is defined to handle. Also controllable from SmartConsole.
There is no reservation of resources, all VSs are equal, including VS0.
Now, why do you ask? Are you facing an actual issue?
On a multi-core system, VSX is using CoreXL. Amount of cores per VS is set on per VS object. If total amount of cores for all VSs is higher than the number of FWK cores available on the system than yes, some VSs may share the same CPU core, or even several.
You can check CPU allocation by running fw ctl affinily -l command.
Amount of FWKs depends on a number of physical cores on the platform, minus amount of SNDs. By default, in a system with 4 cores, just one of them is SND, with 6 to 20 cores - 2, with more than 20 cores, 4 of them are assigned to SND roles.
Now, for the memory. VSX is running in a User Space mode, meaning VSs are using the regular RAM and not kernel memory space. There is usually lots of memory available there. Memory usage depends on the size of the VS, or, in other words, on a maximum amount of connections VS is defined to handle. Also controllable from SmartConsole.
There is no reservation of resources, all VSs are equal, including VS0.
Now, why do you ask? Are you facing an actual issue?
Hi,
Thanks for reply.
So for each VS the resource is controlled by using corexl (in that perticular VS context?)
The reason i am asking is because one VS is running IPS, and now it seems it has used more cpu than it had available so it was bypassed.
Correct. I suspect that VS is running just a single core. Add more 🙂
add more "vs instances" aka cores 😄 , when it comes to vsx you also need to keep track of the connections 🙂
Don - is there a way to monitor the memory utilisation on a per VS basis using SNMP v3?
Have a look at this thread:
https://community.checkpoint.com/t5/Management/VSX-Monitor-Virtual-Memory-of-VS/td-p/32664
Other references:
Search:
vsxStatusMemoryUsageTable
Thanks Don,
Unable to access:
https://dl3.checkpoint.com/paid/3a/3a7f7303d86eaabace8923ad195f017f/chkpnt.mib?HashKey=1638127098_c9...
I'll take a look at the other links, been many years since you where my SE 😉
Me neither, and I have all the rights 🙂
Something is wrong with the link.
Cool.
It is the R81 Product MIB (.mib) file from SK90470
Sorry, I assumed the link would work.
Probably should've posted that link (the download link)
Thanks Don.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Tue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 03:00 PM (EDT)
Maestro Masters Americas: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 03:00 PM (EDT)
Maestro Masters Americas: Hyperscale Firewall Architectures and OptimizationTue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY