CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Crossbeam
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-09
Junior Member
 
Join Date: 2007-07-17
Posts: 10
Rep Power: 0
underattack has an average reputation (10+)
Default Crossbeam : maximum NAT connections on AMP in X-serie

Hello,

Does anyone know what is the maximum concurrent NAT connections per AMP on a X-serie Crossbeam ?

Regards,
Reply With Quote
  #2 (permalink)  
Old 2007-12-10
Junior Member
 
Join Date: 2007-07-17
Posts: 10
Rep Power: 0
underattack has an average reputation (10+)
Default Re: Crossbeam : maximum NAT connections on APM in X-serie

Hi,
Obviously it is APM and not AMP...
Regards,
Reply With Quote
  #3 (permalink)  
Old 2007-12-10
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Re: Crossbeam : maximum NAT connections on AMP in X-serie

it depends...

How many memory on the APMs?
Reply With Quote
  #4 (permalink)  
Old 2007-12-11
Junior Member
 
Join Date: 2007-07-17
Posts: 10
Rep Power: 0
underattack has an average reputation (10+)
Default Re: Crossbeam : maximum NAT connections on AMP in X-serie

Hello,

I don't have the specification yet. Would you have this info for different kind of APM ?

Regards
Reply With Quote
  #5 (permalink)  
Old 2007-12-11
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Re: Crossbeam : maximum NAT connections on AMP in X-serie

You should ask Crossbeam support for the details.

From my experience, assume you have 512m memory, with NAT, it should be around 40-50k.
Reply With Quote
  #6 (permalink)  
Old 2007-12-17
Junior Member
 
Join Date: 2007-07-17
Posts: 10
Rep Power: 0
underattack has an average reputation (10+)
Default Re: Crossbeam : maximum NAT connections on APM in X-serie

The APM should be : CROSSBEAM APM-8400 Single P-IV Xeon with 4 GB DRAM (4x1 GB) APM-8400-1P4-4G-2

Regards,
Reply With Quote
  #7 (permalink)  
Old 2007-12-17
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Re: Crossbeam : maximum NAT connections on AMP in X-serie

should be more or less than half meg
Reply With Quote
  #8 (permalink)  
Old 2008-01-07
Junior Member
 
Join Date: 2006-03-13
Posts: 13
Rep Power: 0
cjbischoff has an average reputation (10+)
Default Re: Crossbeam : maximum NAT connections on AMP in X-serie

Depending on the type of NAT (many-to-one or one-to-one) you might have additional resources that are used (HIDE NAT tracking is done via ports).

Per SecureKnowledge
Solution ID: sk618
What are some of the per connection memory statistics for FireWall-1 4.1?

Here are some of the averages per connection:
FireWall hash memory (fwhmem):
~70 bytes per simple connection
+100 bytes per connection using NAT
+170 bytes per connection using Security Servers
Kernel memory:
+50 bytes per VPN connection
+3 KB per VPN key exchange
+8 KB per connection using Security Servers for the TCP/IP stack
On average, a simple connection will use approximately 70 bytes of FireWall hash memory (fwhmem).

Just add the total RAM from the APM(s) then divide by the worse case scenario (+170) and that should give you a rough idea.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:02.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0