- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: Affinity CPU
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Affinity CPU
We have SMB Appliance 1800 and the customer use a lot of connections SIP, using UDP, so we need make fastaccel to that connections don't make CPU overload. So now I need to balance the CPU, using more CPU to type "others". is that possible?
The CPU is around 50% because we don't put all the traffic into the firewall yet.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would say of course - all fw cores are mostly idle. so i would set more to others. A lot from sk98737: ATRG: CoreXL does apply. There had been a discussion here https://community.checkpoint.com/t5/SMB-Gateways-Spark/SecureXL-amp-CoreXL-on-SMB-devices/m-p/39531 that mentions how to assign an interface to its own core, maybe that can help here.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for reply.
I want to "convert" the CPU 8 and 9 to "Other" but i can't find clear how to. Could you explain the step by step or has some material show how to do that? I trying in sk98737 but I couldn't.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for reply.
That's confuse to me yet how to configure for example CPU 8 and 9 to "other". could you show step by step how to do that?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There are two types of cores:
- FWKs (the CoreXL_FW in your screenshot) -- Used for Layer 7 inspection
- SNDs (the "Other" in your screenshot) -- Used for I/O and Accelerated Layer 3/4 inspection
You cannot change what CPUs do what, only the number of cores allocated to CoreXL FW.
Remaining cores will be allocated as SNDs.
Note you cannot allocate more SNDs than FWKs
The 1800 by default uses a 2/10 mix (2 SNDs, 10 FWK)
To add two additional cores to SND (i.e. Other in your picture), you need to allocate only 8 cores to FWK.
This SK shows you how to change the number of CoreXL Firewall instances: https://support.checkpoint.com/results/sk/sk174423
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks! in my lab it worked, I will make the change in maintenance windows of production appliance and back here to do feedback.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Related to SIP you could check this massive SK, maybe it helps with the issue you have. Not sure what the issue is but maybe it will give you a start:
https://support.checkpoint.com/results/sk/sk95369
Also check all the way down for related SK's URLS
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I can not see that this is relevant here - we see both SNDs overloaded and all fw workers idle, so the solution is clear...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
New SND is also not relevant:
-
It is recommended to allocate an additional CPU core to the SND only if all of the following conditions are met:
- Your platform has at least 8 CPU cores.
- The '
idle
' value (run 'top
' command and press 1 to display all CPU cores) for the CPU core currently running the SND is in the 0%-5% range. - The sum of the '
idle
' values (run the 'top
' command and press 1 to display all CPU cores) for the CPU cores running CoreXL FW instances is significantly higher than 100%.
If any of the above conditions are not met, the default configuration of one processing core allocated to the SND is sufficient, and no further configuration is necessary.
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
While CoreXL/SecureXL exist on SMB appliances, I don't believe you can tune the split of SND/FWK the way you can on regular Gaia.
Perhaps TAC can confirm this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
CoreXL tuning is actually possible on SMB/Spark but the procedure is a bit different (and there isn't nearly as much CPU power to go around); this SK was mentioned briefly in my R81.20 Gateway Performance Optimization Course:
sk174423: Configuring CoreXL Firewall instances on Quantum Spark Appliances
CET (Europe) Timezone Course Scheduled for July 1-2
