> Source: [sk180095](https://support.checkpoint.com/results/sk/sk180095)

# sk180095 - Incorrect CPU affinity in Maestro Mix & Match

| Property | Value |
|----------|-------|
| Solution ID | sk180095 |
| Date Created | 2022-10-13 |
| Last Modified | 2025-05-07 |
| Technical Level | General |
| Products | Scalable Platforms |
| Versions | R82.10, R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * If an appliance in a Security Group has more CPU cores than the Single Management Object (SMO), it is assigned the same number of CoreXL (FWK) cores, leaving the other cores to become SecureXL (Secure Network Distributer, or SND).

* If an appliance in a Security Group has fewer CPU cores than the SMO, all cores are assigned to CoreXL (FWK) and SecureXL (SND).

## Cause

### Background

The key point in Mix \& Match is that all appliances in the Security Group must have the same number of CoreXL Firewall instances. One CPU core can be assigned more than one CoreXL Firewall instance ("fw_worker").

When you add an appliance to a Security Group, the new appliance reads the core distribution (how many CoreXL Firewall or SecureXL cores to allocate) from the appliance that has the Single Management Object (SMO) role. Depending on the order in which you add the appliances to the Security Group, there are two possible scenarios.

The examples below apply to a Security Group with two appliances: 7000 (larger) and 5900 (smaller). The default CPU split for these appliance models is:

* 7000 appliance:
  * 28 CoreXL Firewall instances
  * 4 SecureXL instances (that run CoreXL SND instances)
* 5900 appliance:
  * 14 CoreXL Firewall instances
  * 2 SecureXL instances (that run CoreXL SND instances)

In the two scenarios described below, the Maestro Hyperscale Orchestrator (MHO) distributes traffic between Security Group Members based on [SGM weights](https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Maestro_AdminGuide/Topics-Maestro-AG/SGM-Weights.htm1), which are calculated from the **total** amount of CPU cores available. The two scenarios could described below cause unexpected exhaustion of CPU resources.

Legend for the diagrams below:

* **SXL** - a CPU core that runs SecureXL / CoreXL SND instance
* **FW** - a CPU core that runs a CoreXL Firewall instance
* **Both** - a CPU core that runs both SecureXL and a CoreXL Firewall instance

### Scenario 1 - Adding a larger appliance to a Security Group with a smaller appliance SMO

When you add a 7000 appliance to a Security Group in which a 5900 appliance runs as the SMO, the 7000 appliance reads the number of configured CoreXL Firewall instances from the SMO, which is 14 by default, and assigns the remaining CPU cores to SecureXL (CoreXL SND). The 7000 appliance is assigned 14 CoreXL Firewall cores and 18 SecureXL cores.

|---------------------|--------|--------|--------|--------|--------|--------|--------|--------|--------|-------|-------|-------|-------|-------|-------|-------|
| 5900 SMO (16 cores) | 0 SXL  | 1 FW   | 2 FW   | 3 FW   | 4 FW   | 5 FW   | 6 FW   | 7 FW   |        |       |       |       |       |       |       |       |
| 5900 SMO (16 cores) | 8 SXL  | 9 FW   | 10 FW  | 11 FW  | 12 FW  | 12 FW  | 14 FW  | 15 FW  |        |       |       |       |       |       |       |       |
| 7000 New (32 cores) | 0 SXL  | 1 SXL  | 2 SXL  | 3 SXL  | 4 SXL  | 5 SXL  | 6 SXL  | 7 SXL  | 8 SXL  | 9 FW  | 10 FW | 11 FW | 12 FW | 13 FW | 14 FW | 15 FW |
| 7000 New (32 cores) | 16 SXL | 17 SXL | 18 SXL | 19 SXL | 20 SXL | 21 SXL | 22 SXL | 23 SXL | 24 SXL | 25 FW | 26 FW | 27 FW | 28 FW | 29 FW | 30 FW | 31 FW |

### Scenario 2 - Adding a smaller appliance to a Security Group with a larger appliance SMO

When you add a 5900 appliance to a Security Group in which a 7000 appliance runs as the SMO, the 5900 appliance reads the number of configured CoreXL Firewall instances from the SMO, which is 28 by default. The 5900 appliance must have the same number of CoreXL Firewall instances (28), but it has only 16 physical cores. This leads to the allocation of**all** cores to CoreXL. After CoreXL Firewall instances are assigned, SecureXL cores must be assigned, but as no spare cores are available, SecureXL is assigned to **all** existing cores.

|---------------------|--------|--------|---------|---------|---------|---------|---------|---------|-------|-------|-------|-------|-------|-------|-------|-------|
| 7000 SMO (32 cores) | 0 SXL  | 1 SXL  | 2 FW    | 3 FW    | 4 FW    | 5 FW    | 6 FW    | 7 FW    | 8 FW  | 9 FW  | 10 FW | 11 FW | 12 FW | 13 FW | 14 FW | 15 FW |
| 7000 SMO (32 cores) | 16 SXL | 17 SXL | 18 FW   | 19 FW   | 20 FW   | 21 FW   | 22 FW   | 23 FW   | 24 FW | 25 FW | 26 FW | 27 FW | 28 FW | 29 FW | 30 FW | 31 FW |
| 5900 New (16 cores) | 0 Both | 1 Both | 2 Both  | 3 Both  | 4 Both  | 5 Both  | 6 Both  | 7 Both  |       |       |       |       |       |       |       |       |
| 5900 New (16 cores) | 8 Both | 9 Both | 10 Both | 11 Both | 12 Both | 12 Both | 14 Both | 15 Both |       |       |       |       |       |       |       |       |

<br />

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Management Server and Security Gateways / Cluster Members involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).   

**Note** : After you apply the Hotfix, you may need to make some manual CPU affinity changes. See [sk180096 - How to change default CPU affinity in Maestro Mix \& Match](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk180096).
**Related Solution:**   
[sk98737 - ATRG: CoreXL](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98737)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
