CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-08
Coronabeer Coronabeer is offline
Junior Member
 
Join Date: 2006-07-23
Posts: 23
Rep Power: 0
Coronabeer has an average reputation (10+)
Default Preformance Issue

Hello,

I am having some internet preformance issue when I apply my smart defense and web intelligence polices.

I have a NGX60 with high aval 2 Nokia 350's.

Any clue?
Reply With Quote
  #2 (permalink)  
Old 2007-01-08
Coronabeer Coronabeer is offline
Junior Member
 
Join Date: 2006-07-23
Posts: 23
Rep Power: 0
Coronabeer has an average reputation (10+)
Default Re: Preformance Issue

More info sorry..


When they are applied my internet becomes very sluggish. When I remove them, the connection is normal.
Reply With Quote
  #3 (permalink)  
Old 2007-01-08
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Preformance Issue

Aren't 350's kind of old?

Anyway there are several protections that really eat your CPU. They should warn you before you activate them. They also should tell you in the desriptions which ones are hogs.
Reply With Quote
  #4 (permalink)  
Old 2007-01-08
Coronabeer Coronabeer is offline
Junior Member
 
Join Date: 2006-07-23
Posts: 23
Rep Power: 0
Coronabeer has an average reputation (10+)
Default Re: Preformance Issue

IP 350's ....

But my cpu sits at 7 - 10 % when the rules are applied. I dont beleive its CPU realted. Concurrent connections sit at around 727.
Reply With Quote
  #5 (permalink)  
Old 2007-01-09
northlandboy northlandboy is offline
Senior Member
 
Join Date: 2006-07-28
Location: New Zealand
Posts: 787
Rep Power: 3
northlandboy has an average reputation (10+)
Default Re: Preformance Issue

IP350s are getting on a bit, but they're still OK platforms, for that sort of number of connections.

SD/Web Intelligence covers a lot of things. Which ones are you turning on? Did you enable specific checks, or just turn on everything?

You're probably going to have to go through them slowly, enabling different checks, comparing performance.

Worm catcher can be intensive on CPU, not sure about the others.

May also pay to check HFA & IPSO versions.
Reply With Quote
  #6 (permalink)  
Old 2007-01-11
rayden69 rayden69 is offline
Junior Member
 
Join Date: 2006-09-18
Posts: 19
Rep Power: 0
rayden69 has an average reputation (10+)
Default Re: Preformance Issue

I have found this one to be a big help and generally the one that really slows down smart defense! this is SK31200 in the checkpoint knowledge portal!


In web security, put <HTTP Protocol Inspection> | <ASCI Only Response
Headers> to monitor only AND set the "protection Scope" to < Apply to
connections related to URI resources>.

SK31200
1. High CPU use caused by configuration applying to many
connections

Symptoms:

Traffic through the Security Gateway may be
connections>slower than expected, particularly HTTP traffic.

Traffic through VPNs may also run slower than expected.

Traffic performance increases and CPU use drops significantly, after setting SmartDefense HTTP Protocol Inspection to apply only to connections related to resources.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 13:36.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0