CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > High-End Security > Firewall-1 GX
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-07-13
Junior Member
 
Join Date: 2005-09-06
Location: Singapore
Posts: 16
Rep Power: 0
srikrishnak has an average reputation (10+)
Default Any Feedback on GX

Hi,
Any feedback on Gx. We are thinking of it. Wondering whether any body used it before or any feedback on the performance.
Reply With Quote
  #2 (permalink)  
Old 2006-07-28
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 857
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Any Feedback on GX

I used it quite a bit with version 1.5 and 2 (if I'm remembering the versions correctly here).

In general it was pretty good - you had full visibility of the GTP traffic, and what was going on inside it. Check out the predefined GX view in Tracker - you can see MSISDNs, APN, SGSN, GGSN info. Pretty good, as you could filter on all of that.

Performance-wise I can't say for sure - we didn't have huge volumes of traffic, so it was never really an issue. I do know of another telco that was having performance issues, but they were doing massive amounts of traffic - and this was a couple of years ago, so things will be different now.

The problems we came across were related to vendor interoperability. It turns out that various vendors had implemented things slightly differently. Check Point made their own assumptions about what was "proper" traffic. Things would be working fine for us, then a new partner would come along, and we would run into odd issues. Or, an existing partner would change their vendor/settings, and cause us some pain. Some of the things that different vendors do can make life difficult - like respond to PDP context requests with a different IP to the one the request was made to.

Sometimes you needed to reject GTPv1 with some partners, and make them fall back to GTPv0. Sometimes when we were having major hassles, you might even need to turn off GTP inspection (i.e. just filter on ports) for some partners, to get things working.

Check Point support for the issues we had was in general very good. If you look at the hotfixes for version 2, I can point to several which were implemented specifically for us. Turnaround time was generally pretty quick.

I don't work with it any more, but I imagine the NGX version has got most of the issues sorted out. Certainly the wider uptake by now should have identified many of the interoperability problems.

HTH
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 07:08.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0