Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Jennifer_Wilson
Contributor

Experience on converting a high load Gateway HA cluster to VSX?

Just wondering what peoples thoughts are on converting a Security Gateway HA cluster that is currently under high load to VSX?

Have a pair of 16200s in HA active/passive cluster running R81.10 latest recommended JHF, with a separate Management/logging server.
It's currently running 60-75% peak loads throughout the day, and is running IPS, Threat Prevention, URL App Control, HTTPS Categorization on most traffic (multi Gigabit loads).

Have been asked as part of an project to have the Checkpoints support VRF by using VSX. 

I've read up on the site on VSX conversions and looked at the documentation but would like to hear any real world experience of what sort of extra load on the Gateway might happen because of VSX itself? 1%? 5%? 10%? etc.
And if their are any No No's? or Gotchas I would need take care of and look out for.
Regards,
Jen.

0 Kudos
4 Replies
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Which major version is the system operating with?

~12% overhead for systems running VSX as a guide.

Note also that there is a maximum amount of cores that you can assign to an individual VS, currently this is less than the total cores that a 16200 has available if you need to configure a large VS.

CCSM R77/R80/ELITE
0 Kudos
Lesley
MVP Gold
MVP Gold

Hi,

Pro would be you can run VSX in VSLS. So example: run 1 VS on one hardware and the other VS on other hardware unit.

Then you have twice the power. BUT if one unit fails all the load will end up on one unit. 

I think it is only worth if you are planning to run a couple of VS system. If there is only one then whats the point 🙂 

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
the_rock
MVP Gold
MVP Gold

Last time I did this was back in R77 versions, not afterwards. One thing to keep in mind is that when it comes to VSX, you can NOT assign same core to more than one VS, plus it would be another core to VS0, which they call management plane, I believe.

Best,

Andy

Best,
Andy
0 Kudos
the_rock
MVP Gold
MVP Gold

Hey Jen,

Forgot to add below, this should help as well.

Best,

Andy

https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_VSX_AdminGuide/Topics-VSXG/C...

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events