> Source: [sk182000](https://support.checkpoint.com/results/sk/sk182000)

# sk182000 - Check Point appliances - Hybrid Architecture combining CPU P-Cores and E-Cores

| Property | Value |
|----------|-------|
| Solution ID | sk182000 |
| Date Created | 2024-02-06 |
| Last Modified | 2024-09-11 |
| Technical Level | General |
| Products | Hardware |
| Versions | Not Version-Specific |
| OS | Gaia |
| Platform | 9000 |

## Solution

### (1) Introduction

Starting with Quantum Force appliances, Check Point is taking advantage of a new Intel's Performance Hybrid Architecture combining CPU P-Cores and E-Cores to enhance overall system performance. The P-cores are designed for heavy work and tuned for high frequency. The E-cores are designed to maximize CPU efficiency and are ideal to run background tasks. Check Point optimized the use of P-Cores / E-Cores to maximize both performance and power consumption.

**Note** - Customers do not need to configure anything. Quantum Security Gateway automatically adjusts the traffic distribution between these CPU cores.

### (2) Availability

* Check Point 9300 model.
* Check Point 9400 model.

### (3) Terms

Check Point specifications for CPUs use the Intel terms "P-Core" and "E-Core":

|------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Term       | Description                                                                                                                                                                                                                                                |
| **P-Core** | Performance CPU core - designed for heavy work, tuned for high frequency. P-Cores support the Hyper-Threading technology, and these CPU core siblings are ordered sequentially. For example, CPU ID 0 and CPU ID 1 are siblings on the same physical core. |
| **E-Core** | Efficient CPU core - designed to maximize CPU efficiency, optimized to run background tasks. E-Cores do not support the Hyper-Threading technology.                                                                                                        |

### (4) Mapping of CPU Cores

**Note** - You cannot change this hardware configuration.

|-----------|--------------------------------------|--------------------------------|
| Appliance | CPU IDs of Logical P-Cores           | CPU IDs of E-Cores             |
| 9300      | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11 | 12, 13, 14, 15                 |
| 9400      | 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11 | 12, 13, 14, 15, 16, 17, 18, 19 |

### (5) CoreXL and Multi-Queue Configuration

**The recommended CoreXL configuration is:**

* CPU E-Cores should run only IPv4 and IPv6 CoreXL Firewall instances.

* CPU P-Cores can run IPv4 and IPv6 CoreXL Firewall instances or CoreXL SND instances.

**CoreXL configuration on the 9300 Model:**

On the 9300 model, the default CoreXL configuration is **2** SND instances and **14** FW instances:

|----------------|--------|--------|-------|-------|-------|-------|-------|-------|-------|-------|-------|-------|--------|--------|--------|--------|
|                | P-Cores                                                                              |||||||||||| E-Cores                        ||||
| Physical Cores | 0              || 1            || 2            || 3            || 4            || 5            || 6      | 7      | 8      | 9      |
| Logical Cores  | 0      | 1      | 2     | 3     | 4     | 5     | 6     | 7     | 8     | 9     | 10    | 11    | 12     | 13     | 14     | 15     |
| CoreXL Roles   | SND~0~ | SND~1~ | FW~0~ | FW~1~ | FW~2~ | FW~3~ | FW~4~ | FW~5~ | FW~6~ | FW~7~ | FW~8~ | FW~9~ | FW~10~ | FW~11~ | FW~12~ | FW~13~ |

On the 9300 model, the minimum supported CoreXL configuration is **6** IPv4 CoreXL Firewall instances (and 10 SND instances):

|----------------|--------|--------|--------|--------|--------|--------|--------|--------|--------|--------|-------|-------|-------|-------|-------|-------|
|                | P-Cores                                                                                      |||||||||||| E-Cores                    ||||
| Physical Cores | 0              || 1              || 2              || 3              || 4              || 5            || 6     | 7     | 8     | 9     |
| Logical Cores  | 0      | 1      | 2      | 3      | 4      | 5      | 6      | 7      | 8      | 9      | 10    | 11    | 12    | 13    | 14    | 15    |
| CoreXL Roles   | SND~0~ | SND~1~ | SND~2~ | SND~3~ | SND~4~ | SND~5~ | SND~6~ | SND~7~ | SND~8~ | SND~9~ | FW~0~ | FW~1~ | FW~2~ | FW~3~ | FW~4~ | FW~5~ |

**CoreXL configuration on the 9400 Model:**

On the 9400 model, the default CoreXL configuration is **2** SND instances and **18** FW instances:

|----------------|--------|--------|-------|-------|-------|-------|-------|-------|-------|-------|-------|-------|--------|--------|--------|--------|--------|--------|--------|--------|
|                | P-Cores                                                                              |||||||||||| E-Cores                                                        ||||||||
| Physical Cores | 0              || 1            || 2            || 3            || 4            || 5            || 6      | 7      | 8      | 9      | 10     | 11     | 12     | 13     |
| Logical Cores  | 0      | 1      | 2     | 3     | 4     | 5     | 6     | 7     | 8     | 9     | 10    | 11    | 12     | 13     | 14     | 15     | 16     | 17     | 18     | 19     |
| CoreXL Roles   | SND~0~ | SND~1~ | FW~0~ | FW~1~ | FW~2~ | FW~3~ | FW~4~ | FW~5~ | FW~6~ | FW~7~ | FW~8~ | FW~9~ | FW~10~ | FW~11~ | FW~12~ | FW~13~ | FW~14~ | FW~15~ | FW~16~ | FW~17~ |

On the 9400 model, the minimum supported CoreXL configuration is **10** IPv4 CoreXL Firewall instances (and 10 SND instances):

|----------------|--------|--------|--------|--------|--------|--------|--------|--------|--------|--------|-------|-------|-------|-------|-------|-------|-------|-------|-------|-------|
|                | P-Cores                                                                                      |||||||||||| E-Cores                                                ||||||||
| Physical Cores | 0              || 1              || 2              || 3              || 4              || 5            || 6     | 7     | 8     | 9     | 10    | 11    | 12    | 13    |
| Logical Cores  | 0      | 1      | 2      | 3      | 4      | 5      | 6      | 7      | 8      | 9      | 10    | 11    | 12    | 13    | 14    | 15    | 16    | 17    | 18    | 19    |
| CoreXL Roles   | SND~0~ | SND~1~ | SND~2~ | SND~3~ | SND~4~ | SND~5~ | SND~6~ | SND~7~ | SND~8~ | SND~9~ | FW~0~ | FW~1~ | FW~2~ | FW~3~ | FW~4~ | FW~5~ | FW~6~ | FW~7~ | FW~8~ | FW~9~ |

**Notes about CoreXL behavior:**

When the CoreXL Dynamic Balancing feature is enabled (this is the default), CoreXL SND instances and HyperFlow PPE instances are never assigned to E-Cores.

The CoreXL Dynamic Dispatcher assigns a greater number of connections to CoreXL Firewall instances that run on P-Cores (because these cores work faster) than it assigns to CoreXL Firewall instances that run on E-Cores (because these cores work slower).

The **traffic load is balanced** between CoreXL Firewall instances that run on P-Cores and on E-Cores. Because traffic is dispatched to CoreXL Firewall instances with respect to their traffic queue availability and CPU utilization, the CoreXL Firewall instances that run on E-Cores will handle less connections than the CoreXL Firewall instances that run on P-Cores. As a result, the overall traffic load is balanced.
The **CPU load may be imbalanced** between CoreXL Firewall instances that run on P-Cores and on E-Cores. This is an expected behavior.  

### (6) Documentation

For information about the Check Point appliances, refer to [sk96246: Documentation For Check Point Appliances](https://support.checkpoint.com/results/sk/sk96246) - to the applicable section.

For information about CoreXL and Multi-Queue, refer to the [Performance Tuning Administration Guide](https://support.checkpoint.com/product/73#f-commonsource=C.%20Documentation) for your version.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
