CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-06-27
Junior Member
 
Join Date: 2006-06-27
Posts: 3
Rep Power: 0
jabberw0cky has an average reputation (10+)
Default High CPU Utilization--dropped fwchain_frag; dropped fwconn_memory_check

I have a customer experiencing high CPU utilization and need to pinpoint the problem. I noticed these mesages in the log.

fw_log_drop: Packet proto=17 x.x.x.x:10000 -> x.x.x.x:6275 dropped by fwchain_frag Reason: wait for more fragments

Is this due to the following:

Cause

The problem occurs because the server & client are using SACK TCP options. When using "SACK options", this may result in big
gaps between the sent packets. TCP Streaming, in its term, performs sanity checks on the gaps and TCP window. It may drop the packets that
are out of the "10k" pre-defined window default size.

Solution

To increase the window size from the command line run:

"fw ctl set int fwtcpstr_max_window 65536"

I am also seeing these messages:

fw_log_drop: Packet proto=6 x.x.x.x:44559 -> x.x.x.x:80 dropped by fwconn_memory_check Reason: no memory available

Is this caused be reaching the maximum number of connections in the connections table.

Will increasing the size of the connection table alleviate the problem.

Last edited by jabberw0cky; 2006-06-27 at 16:38.
Reply With Quote
  #2 (permalink)  
Old 2006-11-15
Junior Member
 
Join Date: 2006-10-23
Posts: 2
Rep Power: 0
cpcat has an average reputation (10+)
Default Re: High CPU Utilization

Hi,

Did you manage to resolve the below problem? I don't understand, why UDP protocol have defragmentation problem. Thanks

fw_log_drop: Packet proto=17 x.x.x.x:10000 -> x.x.x.x:6275 dropped by fwchain_frag Reason: wait for more fragments
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:28.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0