- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Open server cores limit
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Open server cores limit
Hi
Is there a limit of cores usage in open server? Can i use up to 48 cores with corexl on open server?
Im asking both technically and also from license perspective. Is there a license up to 48 cores?
Thanks
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Amir_Arama a 48core license for open server is available
"CPSG-48C-NGTX" Security Gateway software for 48 cores with Next Generation Threat Prevention & SandBlast(NGTX) Package
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Amir_Arama a 48core license for open server is available
"CPSG-48C-NGTX" Security Gateway software for 48 cores with Next Generation Threat Prevention & SandBlast(NGTX) Package
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In addition to what Wolfgang said, SMT/Hyperthreading and also Dynamic Balancing (a.k.a. Dynamic Split) are not supported on open hardware and neither is hardware counter/sensor monitoring. Actually these limitations should probably be added to the following SK, so I have just messaged the owner of the SK and referenced this thread:
sk168335: Open Server Recommendations and Known Limitations
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you Timothy (and everyone)
by the way, i just wanted to say i'm reading your max power book, now in page 440. i have really no words to describe the Huge worth of all the information you put there. and i can't wait to finish it and start implementing it on our GWs.
so Thank you!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Glad you are enjoying the book however it was written for R80.30/Gaia 3.10 and as such is getting a bit outdated, although there was an addendum released in August of 2020 for version R80.40 available at maxpowerfirewalls.com.
Lots has changed since that book was published with the introduction of CoreXL Dynamic Balancing/Split, CPU Spike Detective, Elephant/Heavy Flow handing via the pipeline paths and HyperFlow, higher ARP table size limits, the ClusterXL Correction Layer, TLS parser optimizations, GNAT/NAT Exhaustion handing & NAT Hit Counts, TailoredSafe/Autonomous Threat Prevention, USFW, Remote Access VPN/Harmony/Visitor Mode enhancements, Maestro, continuing cpview statistics enhancements, and of course the resurrection of hardware-based acceleration via NVidia and Lightspeed.
Performance improvement was clearly a very high priority for Check Point R&D over the last few years and they have done a fantastic job of automatically optimizing performance in the later gateway releases. It's almost like every time I published a book the smart people in Check Point R&D thumbed through it and said "how can we replace all this analysis and manual tuning with software?" and then they proceeded to do it, solving some very tough problems and pushing through some thorny longstanding implementation limits in the process. I have been essentially replaced with a shell script. 😀
I get asked all the time if there will be a fourth edition of Max Power, and I believe it to be unlikely as my ultimate recommendation to optimize performance is to just upgrade to R81+ and don't touch the default settings. That's it. Not very exciting reading to be sure. In fact if there was a fourth edition it would probably be much shorter than the previous books, and should probably be bundled with a small but ferocious dog which is trained to bite the firewall administrator any time they try to tamper with any default settings involving gateway performance!
However I will share that there is a new independently-produced book being written right now covering Check Point; I am not involved with writing the book but have provided some informal advice to the author. I can't say any more at this time but hopefully it will be available later this year, so keep an eye out for it!
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you.
I hope you will write more books. I'm sure gonna read it.
And thank you for the tip.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The new resource I mentioned in my post above but could not disclose details for was @Vladimir's book which was recently announced here: Announcement – Check Point Firewall Administration R81.10+ book release
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Further the above the hardware must also be listed on the HCL.
https://www.checkpoint.com/support-services/hcl/
