CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-11
rokudan rokudan is offline
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default So...... What's Your Config/Stats?

Curious about everyone's stats...

Back when I got into managing a CheckPoint system, it was running Firewall-1/VPN-1 version 3.0 on a Windows NT box. Short on money, we put everything into one box... Management Server, Gateway, and Logging... I think it was a Pentium 300 or so, with 256 RAM... We had about 130 users behind it, maybe 20 rules, and a few custom defined objects.. And not too much traffic.. I logged everything in accounting mode... System worked well, never a single crash, except for the time I decided to modify the rules file manually and hosed it... But it typically ran at 60-70% CPU, and 75% memory... Scrolling through the log file was a nightmare, even though I wrote a nice logswitch file, that kept them small... I'll include that at the end for nostalgic purposes...

Anyway, now a days times have changed... And I have a decent setup for our core firewalls...

We have two clusters.

Cluster 1 (Production Firewall)
2 Nokia IP530's

Cluster 2 (Internal Firewall)
2 Nokia IP530's

Both have 512 RAM. And the two do interface together to pass traffic...

Each cluster has it's own policy file, but share , mgmt server, logging and objects. They are currently managed by a single Windows box, and logging to it as well. That Windows box is an out of support Dell Pentium 800 with 1 gig RAM. (Don't worry I am moving to SPLAT on a new box for mgmt, and another new box same for logging.. Both 3GHz and 2 gig RAM)

Total we have about 2000 custom objects, and about 1200 custom services... Each policy has around 200 rules incorporating those objects and services...

We currently run about 5-10% CPU and around 60% memory... On the Gateways... The Mgmt/Logging server runs about 7% except when viewing logs or building/pushing policy, then spikes from 50-100% CPU...

As in the past, they are rock solid, and have yet to let me down... I've some changes to make since taking them over, but that will come in time...

So, what platforms and stats are the rest of you working with?

Last edited by rokudan; 2008-01-20 at 14:14.
Reply With Quote
  #2 (permalink)  
Old 2008-01-12
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 862
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: So...... What's Your Config/Stats?

What version of FW-1 are you using?

I had IP530's for a long time on both R55 and R61. On R55, with just a T-1, the CPU ran consistently between 10% and 15% with 512 MB of RAM. Moving it to R61 caused the CPU to run consistently between 45% and 65% with peaks to 80%.

When we increased the bandwidth to 6 M/bps, the CPU would hit 95%+ regularly. Eliminating all of the Internet Explorer SmartDefense checks, because we were patched against all of them, eliminated the high peaks.

The IP530's are just 721 MHz Pentium III's, so they are really underpowered for today's software. I also figure the newer versions are code-optimized for P-IV's.

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-01-12
rokudan rokudan is offline
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: So...... What's Your Config/Stats?

Currently running 55, but in a couple weeks going to 62... Running 61 on a couple other 530's I have, and have not had CPU spikes like that... So hopefully I wont see that on these...
Reply With Quote
  #4 (permalink)  
Old 2008-01-20
rokudan rokudan is offline
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: So...... What's Your Config/Stats?

Upgraded one of my clusters last night to R62... They are still typically running about the same CPU usage, although every once in a while will spike to 70-80%... But typically under 10%... However since we are off peak usage for our customers, I have about 1/4 the connections.. So Monday will be the true test, well actually Tuesday probably since Monday is a holiday...
Reply With Quote
  #5 (permalink)  
Old 2 Weeks Ago
sisu-up sisu-up is offline
Member
 
Join Date: 2007-03-07
Location: Detroit, Michigan
Posts: 35
Rep Power: 0
sisu-up has an average reputation (10+)
Default Re: So...... What's Your Config/Stats?

I'm running P1 R65 one MDS and one MLM. The upgrade from R61 to 65 was a bit crazy. P1 R61 HFA03 seems better (faster, more stable) then 65. 40 CMA's and 40 CLM's

The P1 is managing 4 VSX clusters, each running 10 VS's with a single EVR per cluster doing the routing (via ospf) for all VS's. I'm running R60 HFA01 VSX with a three special HF's. Lately I've had a series of cluster crashes in, which require a power cycle. Seems to happen every 6 days. Since March of 2008 I've had over 10 total cluster crashes.

I'm trying to move the VSX to R65, but have run into a few show stoppers that requires deveolpement to fix. I wonder if anyone out there is running R65 VSX on SPLAT.

Some of these cluster will process 15 to 20 milliion connections per day.

Everything is running on Dell 2850's.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:05.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0