CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Clustering (Security Gateway HA and ClusterXL)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-04
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default ClusterXL Active/Active multicast and Unicast mode

I have a question regarding ClusterXL Active/Active in
Unicast mode with 30% on the Pivot node and 70% on the
other node. I have a pair of Sun X4200-M2 dual Opteron,
dual-core with 4GB RAM, runningin ClusterXL Active/Actve
Unicat Mode in NGx R65 2.6 kernel. This cluster is
managed by a CMA inside a Provider-1 NGx R65 with
HFA_02 SPLAT. I have about 200 rules in the security
policy with about 10k objects (network and services),
and that the Iperf rule is at the bottom of the
security policy, just above the clean-up rule.

Everything is connected to a Cisco Catalyst capable
of easily handling 10GB throughput without issues.

I have 6 Dell 2950-III servers outside of the
firewalls, 3 Iperf clients and 3 Iperf servers. I also
have 6 Dell 2850 servers inside the firewall, with 3
Iperf servers and 3 Iperf clients.

When I fired off 3 Iperf clients from outside the firewall
to connect to 3 Iperf servers inside the firewall, I
see that my throughput on the Pivot node is about 980Mbps
receiving and 600Mbps transmitting. That 600Mbps transmitting
is going from the Pivot node over to the other node in
the cluster. I can NOT go above 980Mpbs in Active/Active
Unicast mode.

Therefore I have the following question:

1- In order to go >1Gbps throughput, I have to use
Cluster Active/Active Multicast mode. Because in muticast
mode, there is NO pivot node, the traffics will hit all of the
firewall thus 50% load on each firewall is expected.
Is that correct?

2- In term of throughput alone, there is NO difference
between Active/Active Unicast mode and Active/Standby because
the "pivot" node has to handle the initial connection and then
forward it to the "non" pivot node. Is that correct?


Thanks guys
Reply With Quote
  #2 (permalink)  
Old 2008-05-04
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: ClusterXL Active/Active multicast and Unicast mode

Please note the following is my simplistic understanding/translation from Developer (Smart guy) to SE (Not so smart me)...

Active/Active mode is not designed to get you better network throughput, it is designed to gain performance in a (FW's) CPU intensive environment.

With a 1 Gbps connection, you will not see better than a 1 Gbps (less overhead, etc) even in multicast mode (as all packets go to all members). Multicast is a little more effecent from a failover & packet processing standpoint than unicast but that's it.

If you want higher bandwidth, then you need higher speed links. If you do increase your link speed, say with 10Gps interfaces, remember to also increase the speed of the sync network, or at least tweak the sync delay and the like or you will saturate the sync network (This leading to the "Why am I only getting 12% of my bandwidth when using HTTP!?!? questions).
Reply With Quote
  #3 (permalink)  
Old 2008-05-05
cciesec2006 cciesec2006 is offline
Senior Member
 
Join Date: 2006-09-26
Posts: 596
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: ClusterXL Active/Active multicast and Unicast mode

Thank you Jim.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:30.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0