![]() VPN features that are disqualified from SecureXL (see below) are disabled.SecureXL acceleration is not disabled by any of the security rules (refer to sk32578).Only "Firewall" and "IPSec VPN" software blades are enabled.All VPN traffic will be handled on the CPU cores running as CoreXL SND under the following conditions: When SecureXL is enabled, Encrypt-Decrypt actions usually take place on SecureXL level (on CPU cores running as CoreXL SND). VPN and SecureXL (relevant to Site-to-Site and IPSec Remote Access) This is relevant only if you have 2 NICs with Multi-Queue enabled, or 4 NICs. If the CPU utilization on the CPU cores running as CoreXL SND is high while the CPU utilization on CPU cores running as CoreXL FW instances is relatively idle, then administrator should consider reducing the amount of CoreXL FW instances from 10 to 8, releasing more CPU cores to run as CoreXL SND. 10 CPU cores are used for CoreXL FW instances, andĮnabling Multi-Queue is recommended when a single interface receives too much traffic for a single CoreXL SND to handle (refer to " Related documentation" section). ![]() 2 CPU cores are used for Secure Network Distributor (SND), and.Configuring interfaces affinity manually is usually not needed.Īs an example, we will use a 12600 appliance with a default CoreXL configuration of "2:10"
0 Comments
Leave a Reply. |