As I stated in my book, 2-core firewalls are between a bit of a rock and a hard place. The only documentation I've seen for variable fwmultik_sync_processing_enabled being set to 0 states that "This limits the CPU to handle fewer stack functions simultaneously.. ". The other related kernel parameters are:
- fwmultik_sync_processing_limited = 0
- fwmultik_sync_processing_max = 2048
I guess setting fwmultik_sync_processing_enabled to 0 limits parallel processing or CPU monopolization by a Firewall Worker? Not really sure...
Here are the relevant pages from my book covering how to handle 2-core firewalls:
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com