CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-09
Junior Member
 
Join Date: 2008-04-07
Posts: 15
Rep Power: 0
santa has an average reputation (10+)
Default I upgraded R61 to R65 after internet slowly

Hello,

We upgraded SPLAT ver R61 to R65. But I have a problem internet speed. I think my internet connection is more slowly then before. (my internet connection is Leased Line).

Old Checkpoint (R61) works normaly.

Yourself, what happen it?
Reply With Quote
  #2 (permalink)  
Old 2008-05-09
Senior Member
 
Join Date: 2007-06-04
Posts: 1,097
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

I have personally found that each version of NGX is getting more resource hungry, so do get a slight performance decrease on older hardware.

Not sure if a real difference or just feels slower though.
Reply With Quote
  #3 (permalink)  
Old 2008-05-09
Junior Member
 
Join Date: 2008-04-07
Posts: 15
Rep Power: 0
santa has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Quote:
Originally Posted by mcnallym View Post
I have personally found that each version of NGX is getting more resource hungry, so do get a slight performance decrease on older hardware.

Not sure if a real difference or just feels slower though.
I'm sure for real difference.

We old system (R61) devices P4 1.6 1GB RAM IBM PC and other machine (I use Eventia Reporter) P4 1.6 1GBRAM IBM PC. Our firewall and logging solution provide by both machine.

Now, I bought IBM x3250 Server. You know, this machine Intel Xeon Dual and 3GB RAM, finaly server system. That is to say it's machine better then before.

(Everybody feeling slow surf)
Reply With Quote
  #4 (permalink)  
Old 2008-05-09
Senior Member
 
Join Date: 2006-09-26
Posts: 856
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Did you check to see that the interface setting matches with what you
have on the layer-2 switchport.

When in doubt, use "ethtool" to check your interface setting.
Reply With Quote
  #5 (permalink)  
Old 2008-05-09
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: I upgraded R61 to R65 after internet slowly

Also check to see that nothing in SmartDefense got turned on that you don't want (epically if you don't have SMDF updates).

R65 in general should be faster than R61.
Reply With Quote
  #6 (permalink)  
Old 2008-05-12
Junior Member
 
Join Date: 2008-04-07
Posts: 15
Rep Power: 0
santa has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Hi chillyjim,

I'm using Smart Defense, and it's updated last version. Anything else?

Hi cciesec2006,

Where I look to ethtool? Which I use command to ethtool?
Examples:

[Expert@korozogw]# ethtool -a eth0
Pause parameters for eth0:
Autonegotiate: on
RX: on
TX: on

[Expert@korozogw]# ethtool -i eth0
driver: tg3
version: 3.66f
firmware-version: 5721-v3.65
bus-info: 01:00.0
Reply With Quote
  #7 (permalink)  
Old 2008-05-12
Junior Member
 
Join Date: 2008-04-07
Posts: 15
Rep Power: 0
santa has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Hello again my friends,

Do you mind if you look my another post? Maybe it's interest with this case..

a strange log in Eventia?? (have a pictures)

Last edited by santa; 2008-05-12 at 01:31.
Reply With Quote
  #8 (permalink)  
Old 2008-05-12
Member
 
Join Date: 2007-08-04
Posts: 72
Rep Power: 2
eduardw has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Try ethtool eth0
and netstat -i
check for duplex mismatches and for interfaces errors. Did you allready check the settings of the switch ports.
Reply With Quote
  #9 (permalink)  
Old 2008-05-12
Junior Member
 
Join Date: 2008-04-07
Posts: 15
Rep Power: 0
santa has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Everthing is a normal?

Settings for eth0:
Supported ports: [ MII ]
Supported link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
1000baseT/Half 1000baseT/Full
Supports auto-negotiation: Yes
Advertised link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
1000baseT/Half 1000baseT/Full
Advertised auto-negotiation: Yes
Speed: 100Mb/s
Duplex: Full
Port: Twisted Pair
PHYAD: 1
Transceiver: internal
Auto-negotiation: on
Supports Wake-on: g
Wake-on: d
Current message level: 0x000000ff (255)
Link detected: yes


Settings for eth1:
Supported ports: [ MII ]
Supported link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
1000baseT/Half 1000baseT/Full
Supports auto-negotiation: Yes
Advertised link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
1000baseT/Half 1000baseT/Full
Advertised auto-negotiation: Yes
Speed: 1000Mb/s
Duplex: Full
Port: Twisted Pair
PHYAD: 1
Transceiver: internal
Auto-negotiation: on
Supports Wake-on: g
Wake-on: d
Current message level: 0x000000ff (255)
Link detected: yes

Settings for eth2:
Supported ports: [ MII ]
Supported link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
1000baseT/Half 1000baseT/Full
Supports auto-negotiation: Yes
Advertised link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
1000baseT/Half 1000baseT/Full
Advertised auto-negotiation: Yes
Speed: 100Mb/s
Duplex: Full
Port: Twisted Pair
PHYAD: 1
Transceiver: internal
Auto-negotiation: on
Supports Wake-on: g
Wake-on: d
Current message level: 0x000000ff (255)
Link detected: yes



----------- and netstat -i results is below: ------------

Kernel Interface table
Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg
eth0 1500 0 12350421 0 0 0 9823472 0 0 0 BMRU
eth1 1500 0 11971189 0 0 0 13096018 0 0 0 BMRU
eth2 1500 0 2751242 10 0 0 2920810 0 0 0 BMRU
lo 16436 0 1367041 0 0 0 1367041 0 0 0 LRU
Reply With Quote
  #10 (permalink)  
Old 2008-05-13
Junior Member
 
Join Date: 2008-02-21
Posts: 1
Rep Power: 0
wilsonck has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Even though you have a bigger, newer server, R65 doesn't use the other cores unless you buy corexl. on the gateway, run TOP and then look at the processor loads over the cores. I bet most load is on cpu0. This is what I found and now I am going back to R60 to try it out.
Reply With Quote
  #11 (permalink)  
Old 2008-05-13
Junior Member
 
Join Date: 2008-05-11
Posts: 28
Rep Power: 0
jaskaran224 has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

can it be related to the compatibility issue between the new Network adapters with R65?
Reply With Quote
  #12 (permalink)  
Old 2008-05-13
Junior Member
 
Join Date: 2008-04-07
Posts: 15
Rep Power: 0
santa has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Quote:
Originally Posted by wilsonck View Post
Even though you have a bigger, newer server, R65 doesn't use the other cores unless you buy corexl. on the gateway, run TOP and then look at the processor loads over the cores. I bet most load is on cpu0. This is what I found and now I am going back to R60 to try it out.
Hello willsonck

I did check it CPU in TOP, and results is below... I think so it's normal?? idle is higher


CPU states: cpu user nice system irq softirq iowait idle
total 2.6% 0.0% 1.6% 0.4% 15.2% 0.2% 179.8%
cpu00 1.6% 0.0% 1.2% 0.4% 14.1% 0.0% 82.6%
cpu01 1.0% 0.0% 0.4% 0.0% 1.2% 0.2% 97.1%
Mem: 3081156k av, 2785640k used, 295516k free, 0k shrd, 110308k buff
1096284k actv, 943196k in_d, 46500k in_c
Reply With Quote
  #13 (permalink)  
Old 2008-05-14
Junior Member
 
Join Date: 2008-04-07
Posts: 15
Rep Power: 0
santa has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Quote:
Originally Posted by jaskaran224 View Post
can it be related to the compatibility issue between the new Network adapters with R65?
Yes, I think.

My using server and devices (x3250) certified by Check Point and are recommened for use with Secure Platform... you can look at this web site:

Check Point Software: IBM System x3250

(Note: Network Adapter : Broadcom Netextreme. It was come with server onboard)
Reply With Quote
  #14 (permalink)  
Old 2008-05-14
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: I upgraded R61 to R65 after internet slowly

Quote:
Originally Posted by santa View Post
(Note: Network Adapter : Broadcom Netextreme. It was come with server onboard)
There have been several reports that the Broadcom adapters do not perform well under load. In general it's recommended that you use the on-board adaptors for your management and sync interfaces only.
Reply With Quote
  #15 (permalink)  
Old 2008-05-14
Junior Member
 
Join Date: 2008-04-07
Posts: 15
Rep Power: 0
santa has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Quote:
Originally Posted by chillyjim View Post
There have been several reports that the Broadcom adapters do not perform well under load. In general it's recommended that you use the on-board adaptors for your management and sync interfaces only.
Hey,

Yes, you'r right. I agree with you but I wrote upside "Broadcom Netextreme" NIC is my server onboard NIC. My server model is x3250 PN:
4364 42G. I mean, this PN owner with IBM Server use onboard Broadcom Ethernet..

2 x Broadcom Netextreme Onboard
1 x Broadmcom Netextreme PCI-E
Reply With Quote
  #16 (permalink)  
Old 2008-05-15
Junior Member
 
Join Date: 2005-12-01
Posts: 9
Rep Power: 0
larstr has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Not sure what specific models you have, but VMware has the following statement regarding two Broadcom models: "Do not use Broadcom 5700 Rev 14 or 5701 Rev 15 for heavy traffic"

It seems that these nics might stop transmitting data if the load becomes high.

Don't know if the issue could be the same on SPLAT, but I'm not surprised if it is.

Lars
Reply With Quote
  #17 (permalink)  
Old 2008-05-15
Junior Member
 
Join Date: 2008-04-07
Posts: 15
Rep Power: 0
santa has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Quote:
Originally Posted by larstr View Post
Not sure what specific models you have, but VMware has the following statement regarding two Broadcom models: "Do not use Broadcom 5700 Rev 14 or 5701 Rev 15 for heavy traffic"

It seems that these nics might stop transmitting data if the load becomes high.

Don't know if the issue could be the same on SPLAT, but I'm not surprised if it is.

Lars
Hello,

Yes I saw that, bu my Broadcom NIC model is:
01:00.0 Ethernet controller: Broadcom Corporation NetXtreme BCM5721 Gigabit Ethernet PCI Express (rev 21)

and that's not seen in the list.

But you said to me; " It seems that these nics might stop transmitting data if the load becomes high." it's good idea. Maybe it idea is possible valid for my problem.
Reply With Quote
  #18 (permalink)  
Old 2008-05-16
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: I upgraded R61 to R65 after internet slowly

Do not use Broadcom NICs in any application that will receive high traffic levels. They will work as management interfaces and as sync interfaces but not for main traffic interfaces. It is a problem with the NIC.
Reply With Quote
  #19 (permalink)  
Old 2008-05-20
Junior Member
 
Join Date: 2008-04-07
Posts: 15
Rep Power: 0
santa has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Quote:
Originally Posted by chillyjim View Post
Do not use Broadcom NICs in any application that will receive high traffic levels. They will work as management interfaces and as sync interfaces but not for main traffic interfaces. It is a problem with the NIC.

What will I do? :( unfortunatelly it's NIC onboard and I think I don't change server. If I upgrade NIC driver version, haven't to be useful??

Can I try this, yourself? and also how in secureplatform?

+1

Meanwhile, I want to upgrade my NIC driver version on Secure Platform R65. How can I check driver version now and how can I install new (I searched driver, last version is 3.81c) driver? I think it maybe should to be useful

Last edited by santa; 2008-05-21 at 00:59.
Reply With Quote
  #20 (permalink)  
Old 2008-05-27
Junior Member
 
Join Date: 2008-04-07
Posts: 15
Rep Power: 0
santa has an average reputation (10+)
Default Re: I upgraded R61 to R65 after internet slowly

Hello My Friends,

Is this devices to be useful for my slowly problem? Solution?

INN-PWLA8494GTBLK ETH Pro/1000MT Quad Port Server Adptr

Last edited by santa; 2008-05-27 at 01:28.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:14.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0