- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
if enable VSX on security gateway or Maestro architecture, how many percentage of performance degradations?
Small addendum:
For example, if you have 20 VS, there are 20 instances of this fwk0_dev_x process.
A calculation sample for the utilization of VS process fwk0_dev_X:
max_CoreXL_number max_CoreXL_number
fwkX_dev_0 = ∑ fwkX_0 + ∑ fwkX_dev_0 + fwk0_kissd + fwk0_hp
x=0 x=0
- fwk0_X -> fw instance thread that takes care for the packet processing
- fwk0_dev_X -> the thread that takes care for communication between fw instances and other CP daemons
- fwk0_kissd -> legacy Kernel Infrastructure (obsolete)
- fwk0_hp -> (high priority) cluster thread
More read here:
- R8x - Performance Tuning Tip – User Mode Firewall vs. Kernel Mode Firewall
It depends on which blades you activate in the vs. You can't really make a general statement.
For the VS own VSX processes I see in practice about 1%-3% pervormance loss per instance.
If you use a large applinace, e.g. a 26000, this should not be a problem.
If you use a large applinace, e.g. a 26000, this should not be a problem.
For example, with 48 cores (48*100% = 4800% CPU performance) and 20 VS (2%*20 VS = 40% CPU performance) you lose 40% of 4800%. Is normally no problem.
It is similar with Maestro.
Small addendum:
For example, if you have 20 VS, there are 20 instances of this fwk0_dev_x process.
A calculation sample for the utilization of VS process fwk0_dev_X:
max_CoreXL_number max_CoreXL_number
fwkX_dev_0 = ∑ fwkX_0 + ∑ fwkX_dev_0 + fwk0_kissd + fwk0_hp
x=0 x=0
- fwk0_X -> fw instance thread that takes care for the packet processing
- fwk0_dev_X -> the thread that takes care for communication between fw instances and other CP daemons
- fwk0_kissd -> legacy Kernel Infrastructure (obsolete)
- fwk0_hp -> (high priority) cluster thread
More read here:
- R8x - Performance Tuning Tip – User Mode Firewall vs. Kernel Mode Firewall
Link @HeikoAnkenbrand sent is 100% your best reference. Not sure if you guys have anything better over there internally, but this is pretty good.
Cheers,
Andy
As a guide ~12% overhead for VSX itself then the rest is very much configuration & version dependent.
This is a VSX environment in the LAB with 2 VS instances and without blades enabled. At the moment, no traffic is going through the VS instancen.
I think each VS uses about 2% CPU performance when idle.
I actually spun up VSX in the lab today and saw pretty much the same thing. I gave it 32 GB of ram and also 2 VSs and shows 4% utilization. Not sure if yours was R81.20, but thats what I created.
I used R81.20 for the test.
With
-> R80.40 approx. 4%
-> R81.10 approx. 3%
per VS instance.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 36 | |
| 18 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY