- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I assume it's because the interfaces associated with the SND/FWK processes are processing the majority of the traffic.
Super Seven command output, please?
https://community.checkpoint.com/t5/General-Topics/Super-Seven-Performance-Assessment-Commands-s7pac...
Output of Super Seven Performance Assessment Commands.
Command 1: fwaccel stat
Command 2: fwaccel stats -s
1% --> Accelerated conns/Total conns is very low?
Command 3: grep -c ^processor /proc/cpuinfo
/sbin/cpuinfo:
Command 4: fw ctl affinity -l -r
Command 5: netstat -ni
A lot RX-DRP frames on Mgmt interface? 0,25% (should be <0,1%)?
Command 6: fw ctl multik stat
Command 7: cpstat os -f multi_cpu -o 1
Command 7: cpstat os -f multi_cpu -o 1
I've seen an odd distribution of Interrupts like that before and it doesn't indicate a problem. I suspect the Linux OS has allocated these processors to handle hardware interrupts (hi% in top output) from the NICs and other devices, which are separate from soft interrupts (si% in top - SoftIRQ among others) that are processed only by SND cores.
Yes the number of RX-DRPs on your Mgmt interface is too high, because Multi-Queue is not allowed on the defined management interface in R80.40; there is no way to enable it on the Mgmt interface other than to move your management interface out of the way. I recently ran into this and just posted this update to the Max Power 2020 addendum thread:
p. 221: If possible, do not set an R80.40's firewall’s management interface to a NIC that is carrying a heavy amount of production traffic to avoid possible frame loss (RX-DRP as shown by command netstat -ni) caused by the lack of Multi-Queue on that interface. If the management interface has been changed from a busy production interface and Multi-Queue is still not active on that busy interface (use the expert mode mq_mng –o –vv command to check this) see this SK: sk167200: Multi-queue state is "off" when changing the management interface. It appears that the restriction blocking the activation Multi-Queue on the firewall's management interface has been lifted in R81.
Don't worry about the low Accelerated Conns percentage, it just means that connection rule matches are not being cached/templated by SecureXL. Many blades can cause this effect including Anti-bot.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY