CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-20
benhabing benhabing is offline
Junior Member
 
Join Date: 2007-12-18
Posts: 3
Rep Power: 0
benhabing has an average reputation (10+)
Default Crazy recurring Problem

I am fairly new to the checkpoint line (cisco background) We are having a VERY strange issue happen randomly. Hoping someone might be able to tell me what could possibly cause this.

We are on NGX R65 HFA02, new installation on CP UTM-1 2050. We're running BGP on our external interface, have multiple subnets behind internal interface, web dmz interface, client network, etc...

First occurred about 2 weeks ago... Get a call about our customer support department can't connect into our client hosting network (different subnet routed through CP). I try to access vpn and terminal server from outside (of course it's a saturday) can't connect to either, they are on different subnets behind the internal interface. grab my laptop, jump in the car, race downtown, get into the office start running some diagnostics and figure out all of our VPN tunnels are working, but we can't get to any subnet routed via the CP box. After about 2.5 hours everything returns to normal on it's own. ??? I call Checkpoint support, run cpinfo, fw monitor, etc... the think it's related to a memory leak BTW there's a fix for it. We go ahead and install hotfixes CP tech recommends. So far so good, with the exception of losing our BGP config during one of the reboots. Everything runs fine for about 2 weeks, then about 2:30am the box decides to do the same thing again for about 3 hours this time. About 40 hours later it does it again, this time for 4.5 hours. Each time the box comes back up just as quickly as it goes down. (Note: during these "outages" can't connect to WebUI or SmartDashboard, etc...) I was out of the office, and started to do some ping tests to our two internal hosts, notice that I'm getting about 19% packet loss and avg latency of about 800ms.

Last time it occured was about on Monday and it was down for 6 hours!!! They crazy thing about all of this is that NONE, I repeat, NONE of our VPN tunnels are affected.

We've checked cables, ISPs, traffic on network, done a dozen CPINFOs, top, vmstat, df, etc..., talked to CP support multiple times, they are scratching their heads as well. The only thing we've found is ksoftirqd has about 6x the CPU time as anything else.
We're about ready to take the box up to the 24th floor............

For any of you checkpoint experts, what could cause the network to go to crap, but the vpn tunnels, and traffic to our web dmz interface be unaffected???

Any ideas are greatly appreaciated.

Thanks,
Bald in Canada
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:48.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0