sk164155
CoreXL Dynamic Balancing
Product: Check Point Appliances, CoreXL, ElasticXL, Maestro HyperScale Firewall, Scalable Chassis, Security Gateways, VSNext, VSX (Traditional)
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Last Modified: 2026-06-14
Solution
Table of Contents
- Introduction
- Key Features
- System Requirements
- CLI Syntax
- Advanced Configuration Parameters
- Monitoring
- SmartConsole Extension
- Super Instance Feature
- Turbo Boost Feature
- "Green" Feature
- HyperFlow Resource Allocation
- FAQ
- Notes
- Known Limitations
Introduction
Security Gateway R80.40 and higher contains the CoreXL Dynamic Balancing (formerly, Dynamic Split) feature - a performance-enhancing daemon that balances the load between CoreXL SND instances and CoreXL Firewall instances. It dynamically changes the split between CoreXL SND instances and CoreXL Firewall instances and does not require a reboot or cause an outage.
Each Check Point Security Gateway's CPU belongs to one of two groups, each of which performs a different task:
- CoreXL Firewall Instance
- CoreXL SND (with the exception of a single CPU running FWD in large User-Space appliances).
The distribution of jobs across a Security Gateway's CPU cores is referred to as the Security Gateway's split. As the distribution of work across these groups depends on your security policy and traffic, we highly recommend that you configure your split to fit your specific needs.
CoreXL's Out-of-the-Box Dynamic Balancing performs a dynamic change of the split. It monitors the Security Gateway performance and makes changes as needed.
Default State:
- CoreXL Dynamic Balancing is enabled by default in the versions R81 and higher.
- CoreXL Dynamic Balancing is disabled by default in the R80.40 version.
| Important Note: The CoreXL Dynamic Balancing feature applies to IPv4 and IPv6 CoreXL Firewall instances. To balance the load between IPv6 CoreXL instances, you can manually increase the number of IPv6 CoreXL Firewall instances with the " cpconfig" command (in the menu, select the Check Point CoreXL option > configure the applicable number of IPv6 CoreXL Firewall instances > reboot). |
Key Features
- Out-of-the-box optimization
- A flexible split to suit your profile
System Requirements
| Category | Information |
| Supported Platforms | CoreXL Dynamic Balancing is supported only on Check Point Appliances. (CoreXL Dynamic Balancing is not supported on Virtual Machines or Open Servers.) |
| Supported Appliance Models | CoreXL Dynamic Balancing is supported on these models (non-Maestro configuration): - All models in these series: 7000, 9000, 15000, 16000, 19000, 23000, 26000, 28000, 29000 - 5000 series: 5600, 5800, 5900 - 6000 series: 6200T, 6400, 6500, 6600, 6700, 6800, 6900 - 3900 series: 3920, 3950, 3970, 3980 - 3000 series: 3100, 3200, 3600, 3800 - Quantum LightSpeed QLS and MLS Appliances with SecureXL in the KPPAK mode - Quantum LightSpeed QLS and MLS Appliances with SecureXL in the UPPAK mode (starting in the R81.20 Jumbo Hotfix Take 38). Notes: - On appliance models with fewer than 8 CPU cores, you must enable the GNAT port allocation feature as described in sk165153. Note: On the 3920 appliance, GNAT port allocation and dynamic split are enabled by default. If CoreXL Dynamic Balancing was enabled before or is enabled by default, then after you enable GNAT and reboot, CoreXL Dynamic Balancing starts running automatically. - R80.40 is the last supported version for the 2200 / 4000 / 12000 / 13000 / 21000 appliances. |
| Supported Configurations and Versions |
- Security Gateway (Kernel FW mode and User Space FW mode): - R81 and higher - Starting in R81, the CoreXL Dynamic Balancing feature is enabled by default - R80.40 Jumbo Hotfix, Take 25 and higher - StandAlone Server: - R81 and higher - Starting in R81, the CoreXL Dynamic Balancing feature is enabled by default - R80.40 Jumbo Hotfix, Take 25 and higher - VSX - R81.10 and higher versions - Starting in R81.20, the VSX support is enabled by default - Starting in R81.10, the CoreXL Dynamic Balancing feature is enabled by default - R81 Jumbo Hotfix, Take 58 and higher - R80.40 Jumbo Hotfix, Take 126 and higher - ElasticXL Security Group - R82 and higher - The CoreXL Dynamic Balancing feature is enabled by default - Maestro Security Group - R81.20 and higher - Starting in R81.20, the CoreXL Dynamic Balancing feature is enabled by default - Including Security Groups with mixed appliance models - Security Group on Scalable Chassis 44000 / 64000 (only with SGM440) - R81.20 and higher - Starting in R81.20, the CoreXL Dynamic Balancing feature is enabled by default |
| Supported Features | - Only IPv4 CoreXL instances are balanced automatically. Balancing of IPv6 CoreXL instances requires manual configuration with the " fw6 ctl affinity -s" command.- Management Data Plane Separation (MDPS, sk138672) is supported. - Bridge mode is supported. |
CLI Syntax
For the complete procedures, refer to the Performance Tuning Administration Guide for your version > Chapter " CoreXL" > Section " Performance Tuning" > Section " Dynamic Balancing of CoreXL Instances".
Important - In ClusterXL, you must configure all cluster members in the same way. In High Availability mode, start with the Standby members.
Syntax
| Shell | Security Gateway (each Cluster Member) | Scalable Platform Security Group |
| Gaia Clish | ||
| --- | --- | |
<br>set dynamic-balancing<br> config <Parameter> value <Value><br> state<br> disable<br> enable<br> reset<br> start<br> stop<br> |
||
<br>show dynamic-balancing state<br> |
N / A | |
| Gaia gClish | N / A | |
| --- | --- | |
<br>set dynamic-balancing<br> config <Parameter> value <Value><br> state<br> disable<br> enable<br> reset<br> start<br> stop<br> |
||
<br>show dynamic-balancing state<br> |
||
| Expert Mode | ||
| --- | ||
<br>dynamic_balancing<br> -h<br> -o disable<br> -o enable<br> -o start<br> -o stop<br> -p<br> -r<br> -v <Parameter> <Value><br> |
||
| --- | ||
<br>g_dynamic_balancing<br> -h<br> -o disable<br> -o enable<br> -o start [member_ids <Member IDs>]<br> -o stop [member_ids <Member IDs>]<br> -p<br> -r<br> -v <Parameter> <Value><br> |
Advanced Configuration Parameters
CoreXL Dynamic Balancing has various configuration parameters that you can change during the run-time.
CLI Syntax:
| Configuration | Gaia Clish / Gaia gClish | Expert Mode |
| Security Gateway (each Cluster Member) |
1. set dynamic-balancing config <Parameter> value <Value>2. save config |
dynamic_balancing -v <Parameter> <Value> |
| Scalable Platform Security Group |
set dynamic-balancing config <Parameter> value <Value> |
g_dynamic_balancing -v <Parameter> <Value> |
Availability:
- R81.20 and higher
- R81.10 Jumbo Hotfix, Take 79 or higher
- R81 Jumbo Hotfix, Take 77 or higher
- R80.40 Jumbo Hotfix, Take 180 or higher
Monitoring
You can see the CoreXL Dynamic Balancing status in CPView ( sk101878) > SysInfo tab.
You can monitor the CoreXL Dynamic Balancing performance in CPView > CPU tab.
You can monitor the CoreXL Dynamic Balancing actions in these log files on the Security Gateway / Scalable Platform Security Group:
$FWDIR/log/dynamic_split.elg$FWDIR/log/dsd.elg
SmartConsole Extension
You install the SmartConsole Extension " CoreXL Dynamic Balancing" to monitor and control CoreXL Dynamic Balancing.
In SmartConsole:
- From the left navigation panel, click Manage & Settings.
- Click Preferences.
- In the SmartConsole Extensions section, click [+] ( Import).
- Paste this URL and click OK:
https://dannyjung.de/ds.json
Super Instance Feature
The Super Instance feature is supported in these versions ( not supported in the VSX mode):
- R81.20 and higher
- R81.10 Jumbo Hotfix Take 79 or higher
- R81 Jumbo Hotfix Take 77 or higher
- R80.40 Jumbo Hotfix Take 180 or higher
Turbo Boost Feature
Only these software versions support Intel Turbo Boost:
- R82.10 and higher: Turbo Boost is enabled by default.
- R82 Jumbo Hotfix Take 25 or higher: Turbo Boost is supported.
"Green" Feature
The "Green" feature reduces power consumption on Check Point Appliances during low-load conditions by dynamically applying power-saving optimizations. See sk184700.
HyperFlow Resource Allocation
In R81.20 and higher, alongside the regular CoreXL split decisions, CoreXL Dynamic Balancing is responsible for activation of HyperFlow cores (refer to sk178070 - HyperFlow in R81.20 and higher).
FAQ
- Who should use Dynamic Balancing?
Dynamic Balancing is especially beneficial for:
- Customers who use non-default splits
- Customers with environment bottle-necks by Secure Network Distributors (SNDs)
- Customers with environments that may change usage over time - you can "auto tune" your Security Gateway with no outages, no reboots, no need for any skills!
- Why don't I get more Secure Network Distributors (SNDs)?
There are few possible reasons:
- Average utilization of CoreXL SND instances vs. CoreXL Firewall instances is relatively close (the default required difference is 10%).
- CoreXL Firewalls are utilized more than 50%. ( This is done to prevent a situation where more than one heavily utilized CoreXL Firewall instance works on a single CPU.
- All eligible SND CPU cores are already used as CoreXL SND instances.
- Why don't I get more Firewalls?
There are few possible reasons:
- Average utilization of CoreXL SND instances vs. CoreXL Firewall instances is relatively close (the default required difference is 10%).
- All loaded CoreXL Firewall instances are already active.
- How does it work with Cluster?
In Cluster High Availability mode, changes the Active cluster member makes are synchronized to the Standby cluster members. This does not apply to VRRP clusters.
- Can excessive split changes impact production environment?
CoreXL Dynamic Balancing has mechanisms within its logic aimed to prevent unwanted changes.
Notes
CoreXL Dynamic Balancing manages network card ports that have Multi-Queue enabled.
Known Limitations
| Issue ID | Description |
| PMTR-114499 | This is the behavior when you upgrade VSX Gateways / VSX Cluster Members R80.40 - R81.10, on which CoreXL Dynamic Balancing was not disabled explicitly, to R81.20 (or higher) and then install a Jumbo Hotfix Accumulator. |
| VSECPC-10367 | Dynamic Balancing / Dynamic Split is not supported on CloudGuard Network public cloud. |
| PRJ-15874 | In R80.40, CoreXL Dynamic Balancing is supported only in R80.40 Jumbo Hotfix Take 25 (or higher). |