CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-13
switzer switzer is offline
Junior Member
 
Join Date: 2006-12-21
Posts: 27
Rep Power: 0
switzer has an average reputation (10+)
Default Capacity Optimization

We currently have a problem with our firewall having to be reset every few hours - while awaiting an engineer we have looked at the logs and have increased capacity optimization to 50000 from 25000 this seems to help as
it lasted about 5 hours instead of 2.
1 Are there any issues we should be aware of when we try this ?
2. Cant see anything else we can do -
We are looking at recently installed rules etc .....
This is what we saw on the logs -
FW-1: WARNING: The connections table is 80% full.
Sep 6 13:03:42 CRUK-1 [LOG_CRIT] kernel: New connections will be dropped once the connection table reaches
Sep 6 13:03:42 CRUK-1 [LOG_CRIT] kernel: full capacity. Please consider increasing the connections table limit.
Any other ideas to increase the time between fall overs while we get
a CP engineer in.
Reply With Quote
  #2 (permalink)  
Old 2007-09-13
Robby Cauwerts Robby Cauwerts is offline
Senior Member
 
Join Date: 2006-10-05
Location: Belgium
Posts: 108
Rep Power: 2
Robby Cauwerts has an average reputation (10+)
Default Re: Capacity Optimization

Something is setting up a lot of connections.

1)In the SmartView Tracker select the "Active" tab.
Monitor the new connections that are being setup.
See if you can find if they have something in common (same source).

2)If you have an SmartView Monitor license you can easily track the host that is causing the problem using the build in queries.
If you don't have the license request a demo license.

Might be a broken application on your network, ...

Br.
Robby
Reply With Quote
  #3 (permalink)  
Old 2007-09-13
cpcpc cpcpc is offline
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Re: Capacity Optimization

Use this to check the limit you set is actually working on the modules:
fw tab -t connections | grep limit

You can check the traffic using this:
fw tab -t connections -s -f

If you properly set up Max concurrent connection, it can prevent "out of memory". This is a protection.
Reply With Quote
  #4 (permalink)  
Old 2007-09-14
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 434
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Capacity Optimization

check connections, is it legit traffic?
use network quota in smartdefense if applicable
increase max connections if step above doesnt help (take memory in consideration)
Reply With Quote
  #5 (permalink)  
Old 2007-09-16
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Capacity Optimization

After you go through all of the above to figure out the cause, if it turns out you are just being attacked OR its legal traffic, upgrade to R65 and enable "Aggressive Aging" (See the release notes for details).
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:43.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0