| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| I work an an ISP. We are seeing an issue where people cannot check their mail (pop or smtp) on any mail server when we have a high volume of smtp traffic flowing. Is there some sort of optimization that needs to be done on the firewall to help with this? We are running NGX R60 HFA02 on SPLAT. SmartDefense is not enabled on the mail features. Concurrent connections around 80k seems to be the threashold. We seem to run fine under 70k. Thanks in advance for any assistance. DeShark |
| |||
| You might need to increase the state table. Edit your firewall object and go to "Capacity Optimization" tab. Tweak the Maximum Connections as needed... and remember to have plenty of RAM. |
| |||
| You should be able to get in the neighborhood of 150K sessions without problems with a gig of RAM. You do have to adjust the number of connections allowed in firewall object as MarioL pointed out. |
| |||
| Are you using the SMTP security server or trying to run the anti-virus on it? I didn't think of asking before, because I'd be really surprised if you got 10K sessions but... |
| |||
| I added a gig to the box bringing it up to 1.5 GB. No difference. The memory utilization is the same. The new gig is available. We are still seeing the intermittent issue where people cannot pop or send email on occasion. No we are not using the SMTP security server. We have no problem with the number of concurrent connections when it gets high.. 85k is seen on occasion on the high side. Config is set to 250k. Just this issue where people cannot pop or smtp to ANY mail server on our network. Very odd and very critical! Any ideas? DeShark |
![]() |
| Thread Tools | |
| Display Modes | |
| |