> Source: [sk157692](https://support.checkpoint.com/results/sk/sk157692)

# sk157692 - Latency in userspace firewall or VSX due to System Kernel Memory allocation

| Property | Value |
|----------|-------|
| Solution ID | sk157692 |
| Date Created | 2019-07-07 |
| Last Modified | 2021-06-02 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * After enabling IPS, latency in increased by \~150ms, due to System Kernel Memory allocation.
* Latency is visible between incoming interface (in 'tcpdump') and the lower 'i' in 'fw monitor'.
* The traffic is going through the firewall medium path (PXL)

## Cause

In Userspace Firewall ( USFW / VSX ) allocating System Kernel Memory (over Hash Kernel Memory) is more resources demanding.  
If high number of SMEM allocations are required in a high rate, system latency may be experienced.

The mostly known to cause this behavior is GZIP infrastructure.

## Solution

HTTP traffic performance enhancement on VSX and USFW environment when Gzip enforcement is used under "**ws_gzip_filter_alloc** " memory allocation.   

This problem was fixed. The fix is included in:

* **[Check Point R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160736&partition=Basic&product=All) since GA**
* **[Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) since Take 107**
* **[Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) since Take 134**
* **[Jumbo Hotfix Accumulator for R80.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116380&partition=Basic&product=Endpoint) since take 270**

Check Point recommends to always upgrade to the most recent version.  

For lower versions, [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.   
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.  

In order to verify if the cause is indeed GZIP, one may disable the GZIP mechanism.

1. Under "Gzip enforcment"-\> Advanced, make sure the "Inspect compressed HTTP traffic" is NOT checked
2. On the VSX Gateway disable Gzip with kernel parameter "ips_gzip_disable", and set it to "1"

**Note:**   
GZIP mechanism can be enabled by multiple software blades, we currently have a way to disable it only for IPS. **If other software blades are enabled - the mechanism will NOT be disabled.**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
