CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Eventia Analyzer/Reporter/SmartView Reporter
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-31
Fulvio Fulvio is offline
Junior Member
 
Join Date: 2006-05-04
Posts: 15
Rep Power: 0
Fulvio has an average reputation (10+)
Default Eventia Network Activity Reports - How Reliable?

Hi all,

I have been running network activity reports to try and understand what is going through the firewall and if I can relate that to CPU utilization.

One thing you get out from the network activity reports is the number of connections. When I tried to look closely at the number of connections during an high CPU utilization period and I had some "strange" results.

between 12:00 and 12:59 121K connections in agreement with the daily report
but when I looked at smaller interval I was concerned about the reliability of the results, this is what I got from the reports:
12:00 and 12:05 65K
12:05 and 12:55 53K
12:55 and 12:59 4K
The total is exactly 121K but is the distribution of connection I am concerned about.
How can I confirm that the data reported by Eventia are correct and I did have 65K connections in 5 minutes and 53K connections in 50?
Also between 12:00 and 13:00 it reported 177K connections, in 1 minute 56K connections more. Again, could that be normal?
Reply With Quote
  #2 (permalink)  
Old 2007-02-04
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,603
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Eventia Network Activity Reports - How Reliable?

The date from EVR on a 5+ minute resolution should be very good, less than 5 minutes, well that can get a little off depending on load, latency and the like.

As to normal, There is no normal except your own, every place is different.

Try just running the report with 5 minute resolution for a few days and see if it tracks.
Reply With Quote
  #3 (permalink)  
Old 2007-02-05
Fulvio Fulvio is offline
Junior Member
 
Join Date: 2006-05-04
Posts: 15
Rep Power: 0
Fulvio has an average reputation (10+)
Default Re: Eventia Network Activity Reports - How Reliable?

Thanks chillyjim
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:21.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0