CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-12-28
sys0p sys0p is offline
Junior Member
 
Join Date: 2005-12-28
Posts: 1
Rep Power: 0
sys0p has an average reputation (10+)
Default SPLAT excessive memory usage?

Hello all - I wasnt sure where to post this question since I couldnt find the appropriate forum but -

Has anyone noticed a tendency of SPLAT to use excessive amounts of memory under any specific circumstances? Such as a long, over complicated and heavily used rulebase or something?

Heres the situation: The box is an Intel based 1U rackmount system running SPLAT, with a very diverse and (and perhaps) over complicated rule base. This is a production firewall serving many, many purposes and clients. It is pretty stable and doesnt seem to have any functionality issues - it has been up for quite some time now. The box has 1GB of memory, which is 99% used constantly, and I do mean ALL the time. Yet load averages show 0.00, CPUs are 99% idle, and TOP doesnt show any particular process using the memory. Any thoughts?

Thanks in advance for the input.
Reply With Quote
  #2 (permalink)  
Old 2005-12-28
alienbaby alienbaby is offline
Junior Member
 
Join Date: 2005-11-25
Posts: 17
Rep Power: 0
alienbaby has an average reputation (10+)
Default Re: SPLAT excessive memory usage?

Memory usage on a linux/unix/bsd only becomes a problem if the system begins to use swap.
*nix's use unused physical RAM as a Read/Write cache for the filesystems.


Use the 'free' command. 'swapinfo' on Nokia.


High memory utilization on a *nix system is common. Begin to worry when the usage pours over to the swap files/partitions.
Reply With Quote
  #3 (permalink)  
Old 2005-12-29
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,627
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SPLAT excessive memory usage?

As alianbaby said, if you're not swaping/paging and load adverage is down, don't worry about it.

From a product standpoint, you might want to look at VSX & P1. VSX provides virtual firewalls and is good in the isp-like space and for data centers. It can be a big help in simplifing your rulebase.

-jlh
Reply With Quote
  #4 (permalink)  
Old 2006-01-10
tedesco tedesco is offline
Junior Member
 
Join Date: 2005-09-27
Posts: 5
Rep Power: 0
tedesco has an average reputation (10+)
Default Re: SPLAT excessive memory usage?

This answer might be a little late, but it still might be usefull to some one:

I also noticed a excessive memory usage specially when the VSX has been logging locally for a while.

The solution is to switch the logs on the VSX/VS. (it it not the same than to switch on the CMA/MDS.)

You can check the size of your file by loging on the vsx and doing:
[Expert@vsxxxx]# cd /var/opt/CPfw1-V25/CTX/
[Expert@vsxxxx]# du -sk */log | sort -n
...
3708 CTX00074/log
3724 CTX00072/log
3760 CTX00096/log
...

Then you can list the local logs:
[Expert@vsxxxx]# vrfctl -s 96
[Expert@vsxxxx]# fw -vs 96 lslogs
Size Log file name
2152KB 2005-11-04_142611.log
1529KB fw.log

Finally you can switch the logs, using the command line or the Smartview tracker for the corresponding cma/VS. (Tools/Remote Files Management)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:47.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0