We have several 4800 clusters running VSX, with 2 virtual systems (1 for firewall and 1 for VPN). Since it is a 4 core box, I’d like to ask what the optimum setup is.
They are running R77.30 and our SE recommended the following:
• CoreXL is disabled on VS0
• Assign 2 cores to Firewall VS and 1 core to VPN VS, leaving 1 core for interfaces
• 2 virtual system instances assigned to Firewall VS
• 1 virtual system instances assigned to VPN VS
According to top and cpview, Core 0 is getting hammered with high (si). This happens intermittently and when it does there is high latency. From what I have read, CoreXL instances and SND should not share a core. Separating the internal and external interfaces on separate cores makes sense, but how to allocate enough for FWK? What is max virtual instances we should define per VS?