
CoreXL joins ClusterXL Load Sharing and SecureXL (Performance Pack) as part of Check Point’s fully complementary family of traffic acceleration technologies. In a CoreXL gateway, the firewall kernel is replicated multiple times. Each replicated copy, or instance, of the firewall kernel runs on one processing core.
What is CoreXL and how does it work?
CoreXL makes it possible for the CPU cores to perform multiple tasks concurrently. This enhances the Security Gateway performance. CoreXL provides almost linear scalability of performance, according to the number of processing cores on a single machine.
How does the CoreXL firewall work on a security gateway?
On a Security Gateway with CoreXL enabled, the Firewall kernel is replicated multiple times. Each replicated copy of the Firewall kernel, or CoreXL Firewall instance, runs on one CPU core. These CoreXL Firewall instances handle traffic concurrently, and each CoreXL Firewall instance is a complete and independent Firewall inspection kernel.
What is the default configuration for CoreXL?
CoreXL Advanced Configuration Guide. In the CoreXL default configuration, the number of kernel instances is one less than the number of processing cores. The SND runs on the remaining core. Upon installation of CoreXL, the number of kernel instances is set to n-1, where n is the total number of processing cores on the platform.
What are the benefits of the CoreXL dynamic dispatcher?
The CoreXL Dynamic Dispatcher allows for better load distribution and helps mitigate connectivity issues during traffic "peaks", as connections opened at a high rate that would have been assigned to the same CoreXL FW instance by a static decision, will now be distributed to several CoreXL FW instances.

What is SecureXL and CoreXL in checkpoint?
SecureXL will accelerate packets from interface to interface for known traffic thus saving CPU usage and CoreXL adds ability to run multiple inspection cores concurrently.
How do I enable multi queue checkpoint?
Multi-QueueMulti-Queue is enabled by default on all interfaces that use the supported drivers.The number of traffic queues on each supported interface is determined automatically, based on: ... Traffic queues are automatically affined to the CPU cores that runs CoreXL SND Instances.More items...
What is dynamic assignment mechanism?
Rather than statically assigning new connections to a CoreXL FW instance based on packet's IP addresses and IP protocol (static hash function), the new dynamic assignment mechanism is based on the utilization of CPU cores, on which the CoreXL FW instances are running.
What is a security gateway with CoreXL?
On a Security Gateway with CoreXL enabled, the Firewall kernel is replicated multiple times. Each replicated copy, or Firewall instance, runs on one processing CPU core. These Firewall instances handle traffic concurrently, and each Firewall instance is a complete and independent Firewall inspection kernel. When CoreXL is enabled, all the Firewall kernel instances in the Security Gateway process traffic through the same interfaces and apply the same security policy.
How is the rank of CoreXL FW calculated?
The rank for each CoreXL FW instance is calculated according to its CPU utilization.
What is CoreXL security?
CoreXL is a performance-enhancing technology for Security Gateways on platforms with multiple CPU cores. CoreXL enhances Security Gateway performance by enabling the processing CPU cores to concurrently perform multiple tasks.
What is a dispatcher in CoreXL?
The dispatcher is executed when a packet should be forwarded to a CoreXL FW instance (in Slow path and Medium path - see sk98737 for details) and is in charge of selecting the Core XL FW instance that will inspects the packet.
What is the traffic distribution in CoreXL?
In R77.20 and lower versions, traffic distribution between CoreXL FW instances is stat ically based on Source IP addresses, Destination IP addresses, and the IP 'Protocol' type. Therefore, there are possible scenarios where one or more CoreXL FW instances would handle more connections, or perform more processing on the packets forwarded to them, than the other CoreXL FW instances.
What mode is Security Gateway?
Security Gateway is configured in VSX mode (not supported on any of the VSs, including VS0), in versions R80.10 and below.