<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS VM-100 (2 VCPU limit) on M4/M5.xlarge (4 VCPU onboard) - wasted VCP in VM-Series in the Public Cloud</title>
    <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/348571#M960</link>
    <description>&lt;P&gt;You may see a nominal performance increase by running the bigger instance size due some of the underlying AWS hashing to hardware. &amp;nbsp;The increase will be no where close to the performance of running a VM-300 on the same instance types.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Sep 2020 12:36:11 GMT</pubDate>
    <dc:creator>jmeurer</dc:creator>
    <dc:date>2020-09-11T12:36:11Z</dc:date>
    <item>
      <title>AWS VM-100 (2 VCPU limit) on M4/M5.xlarge (4 VCPU onboard) - wasted VCPU?</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/348557#M959</link>
      <description>&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help to understand what happens when one runs AWS VM-100 (2 VCPU limit) on M4.xlarge or M5.xlarge (4 VCPU onboard).&lt;/P&gt;&lt;P&gt;It works fine. But it seems like two of four VCPUs are staying idle in such setup. Would you agree?&lt;/P&gt;&lt;P&gt;I tried to use CloudWatch to see core specific CPU utilization, it is only display overall stats and does not show per VCPU stats&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please see some bits from my research below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sergg&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details about VM-100 virtual hardware support&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-performance-capacity/vm-series-performance-capacity/vm-series-on-aws-performance-and-capacity.html" target="_blank" rel="noopener"&gt;VM-Series on Amazon Web Services Performance and Capacity&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Details about amount of the resources supported by VM license type from &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClDCCA0" target="_blank" rel="noopener"&gt;VM-Series for AWS Sizing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Please note – VM-100 does only support &lt;STRONG&gt;2 VCPU&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SergGur_0-1599826668014.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27715i1E0E34C10DA431DA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SergGur_0-1599826668014.png" alt="SergGur_0-1599826668014.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details about AWS EC2 types&lt;/P&gt;&lt;P&gt;Details about EC2 instances from &lt;A href="https://aws.amazon.com/ec2/instance-types/" target="_blank" rel="noopener"&gt;https://aws.amazon.com/ec2/instance-types/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Please note xlarge instances provide 4 VCPU (while VM-100 can only consume 2 VCPU)&lt;/P&gt;&lt;P&gt;M4 options:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SergGur_1-1599826668018.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27713i30354CD96444CB2E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SergGur_1-1599826668018.png" alt="SergGur_1-1599826668018.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;M5 options:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SergGur_2-1599826668020.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27714iACC54A1B914F3552/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SergGur_2-1599826668020.png" alt="SergGur_2-1599826668020.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Details about declared VM throughput&lt;/P&gt;&lt;P&gt;From &lt;A href="https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-performance-capacity/vm-series-performance-capacity/vm-series-on-aws-performance-and-capacity.html" target="_blank" rel="noopener"&gt;VM-Series on Amazon Web Services Performance and Capacity&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SergGur_3-1599826668025.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27716i966E11F29D45CFBC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SergGur_3-1599826668025.png" alt="SergGur_3-1599826668025.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 21:04:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/348557#M959</guid>
      <dc:creator>SergGur</dc:creator>
      <dc:date>2020-11-23T21:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM-100 (2 VCPU limit) on M4/M5.xlarge (4 VCPU onboard) - wasted VCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/348571#M960</link>
      <description>&lt;P&gt;You may see a nominal performance increase by running the bigger instance size due some of the underlying AWS hashing to hardware. &amp;nbsp;The increase will be no where close to the performance of running a VM-300 on the same instance types.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 12:36:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/348571#M960</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2020-09-11T12:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM-100 (2 VCPU limit) on M4/M5.xlarge (4 VCPU onboard) - wasted VCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/348574#M961</link>
      <description>&lt;P&gt;Update: I discovered that SNMP monitoring does indeed only report 2 CPU and does individual graphs got each.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I'm suspecting AWS CloudWatch graphs does not represent true AWS VA firewall load. This is because AWS combines the load of 4 VCPUs (2 busy and 2 totally idle) and therefore in this situation, AWS CloadWatch results need to be multiplied by two (to compensate for CPUs provided by AWS but not used by firewall software)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My sample data for a firewall I'm examining (24 hours - but it can not be compared because in a massive difference in polling frequency and methods)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AWS CloudWatch:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SergGur_0-1599828528873.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27717iC3A5EA9182C10FD4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SergGur_0-1599828528873.png" alt="SergGur_0-1599828528873.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SNMP monitoring:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SergGur_1-1599828579561.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/27718i6270FC99865E584A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="SergGur_1-1599828579561.png" alt="SergGur_1-1599828579561.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 12:55:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/348574#M961</guid>
      <dc:creator>SergGur</dc:creator>
      <dc:date>2020-09-11T12:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM-100 (2 VCPU limit) on M4/M5.xlarge (4 VCPU onboard) - wasted VCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/348577#M962</link>
      <description>&lt;P&gt;Similar to physical firewalls there is the management and data plane separation. And there is (at least one) dedicated CPU assigned to the management. I'm getting there but still confused. In one hand there is a document (see below) telling unlicensed CPUs allocated to management. In the other hand, my SNMP monitoring only reports two CPUs back.&lt;/P&gt;&lt;P&gt;Does my VM-100 in AWS effectively only has 1 VCPU for traffic?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From &lt;A href="https://docs.paloaltonetworks.com/vm-series/9-1/vm-series-deployment/about-the-vm-series-firewall/vm-series-models/vm-series-system-requirements.html" target="_self"&gt;VM-Series System Requirements&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The number of vCPUs assigned to the management plane and those assigned to the dataplane differs depending on the total number of vCPUs assigned to the VM-Series firewall. &lt;STRONG&gt;If you assign more vCPUs than those officially supported by the license, any additional vCPUs are assigned to the management plane&lt;/STRONG&gt;.&lt;/P&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="40px"&gt;Total vCPUs&lt;/TD&gt;&lt;TD width="40px"&gt;Management Plane vCPUs&lt;/TD&gt;&lt;TD width="40px"&gt;Dataplane vCPUs&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;2&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="40px"&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;1&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="40px"&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;1&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;4&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="40px"&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;2&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="40px"&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;2&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;8&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="40px"&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;2&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="40px"&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;6&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="40px"&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;16&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="40px"&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;4&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;TD width="40px"&gt;&lt;DIV&gt;&lt;DIV class="p"&gt;&lt;DIV&gt;12&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Fri, 11 Sep 2020 13:07:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/348577#M962</guid>
      <dc:creator>SergGur</dc:creator>
      <dc:date>2020-09-11T13:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM-100 (2 VCPU limit) on M4/M5.xlarge (4 VCPU onboard) - wasted VCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/348692#M965</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70475"&gt;@jmeurer&lt;/a&gt;with regards to your statement&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;You may see a nominal performance increase by running the bigger instance size due some of the underlying AWS hashing to hardware.  The increase will be no where close to the performance of running a VM-300 on the same instance types.&lt;/LI-CODE&gt;&lt;P&gt;Thank you for sharing the first-hand experience with running VM-100 and VM-300 on the same instance type. Perhaps the difference is due to the number of VCPUs used by bata plane.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 21:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/348692#M965</guid>
      <dc:creator>SergGur</dc:creator>
      <dc:date>2020-09-11T21:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM-100 (2 VCPU limit) on M4/M5.xlarge (4 VCPU onboard) - wasted VCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/365018#M1052</link>
      <description>&lt;P&gt;You are correct, the VM-100 will only utilize 2 vCPU for data plane.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 21:10:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/365018#M1052</guid>
      <dc:creator>jmeurer</dc:creator>
      <dc:date>2020-11-23T21:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM-100 (2 VCPU limit) on M4/M5.xlarge (4 VCPU onboard) - wasted VCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/365026#M1053</link>
      <description>&lt;P&gt;I tested this inside out. Here is final take:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;VM-100 is limited to 2 VCPU all together&lt;/LI&gt;&lt;LI&gt;Out of 2 VCPU at least one is dedicated to management&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;One 1 VCPU is left for DP (data plane)&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;On the AWS M4 type machine with 4 VCPUs only half is used.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 23 Nov 2020 21:42:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/365026#M1053</guid>
      <dc:creator>SergGur</dc:creator>
      <dc:date>2020-11-23T21:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: AWS VM-100 (2 VCPU limit) on M4/M5.xlarge (4 VCPU onboard) - wasted VCP</title>
      <link>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/366148#M1059</link>
      <description>&lt;P&gt;What OIDs are you using in SNMP monitoring?&lt;/P&gt;&lt;P&gt;If you are monitoring hrProcessorLoad, you will only see two objects, no matter what model of Palo Alto FW you are using.&lt;BR /&gt;It corresponds to the utilization of the data plane and the management plane.&lt;/P&gt;&lt;P&gt;Also, these values correspond to the values of the system resource wedge in the dashboard.&lt;/P&gt;&lt;P&gt;You can find it at &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaSCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClaSCAS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If you want to see the utilization per VCPU, you need a little trick.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please press "1" after running "show system resources follow" to toggle view to show separate states.&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLZZCA4" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PLZZCA4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I do not know the REST API that corresponds to this idea. Naturally, I don't know the corresponding SNMP objects either.&lt;BR /&gt;Therefore, I don't believe there is an elegant means of continuous monitoring.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In the VM-Series and PA-850, for example, the management plane and the data plane are not physically separated, and the data plane is run as a process called pan_task.&lt;/P&gt;&lt;P&gt;The number of pan_task processes increases or decreases according to the capacity of the Palo Alto FW and is allocated to logical cores from CPU1 onwards using CPU affinity (a feature of the Linux kernel).&lt;/P&gt;&lt;P&gt;I remember that the CPU utilization of the pan_task process, which can be checked with the above command, behaved a little differently depending on whether SR-IOV was enabled or not.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Nov 2020 05:28:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/vm-series-in-the-public-cloud/aws-vm-100-2-vcpu-limit-on-m4-m5-xlarge-4-vcpu-onboard-wasted/m-p/366148#M1059</guid>
      <dc:creator>nanasin</dc:creator>
      <dc:date>2020-11-30T05:28:31Z</dc:date>
    </item>
  </channel>
</rss>

