CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-01-11
Junior Member
 
Join Date: 2005-12-20
Posts: 24
Rep Power: 0
Westy has an average reputation (10+)
Default NGX Problems, who's having them?

I was looking at the posts and caught a couple about NGX problems. Some requiring a reinstall. I'm wondering who out there is experiencing what?
We have a small setup. Single firewall, 40 rules, 100 objects are so. Nothing big and complicated.

Here's my stories.
In mid November, we had a consultant come in and help us with upgrading from SPLAT R54 to SPLAT R60. All was fine, until we applied the patch and rebooted. After the reboot, policy wouldn't load, etc. We had to reinstall from scratch and reimport the exported file. We left the patch off. All was well, firewall back online doing what it's supposed to do and we're on R60.

Last week, I was in the Web Gui when it hung up. I couldn't exit out of it.
After hours, I went to the console, issued cpstop and cpstart, all was fine, tried to get in via the Web Gui, couldn't do it. So I rebooted thinking this will solve the problem. CPD would not start. I wound up calling Check Point Tech support. After trying a few things they decided the cpd file was corrupted. They walked me through running the backup command that created a .tgz file. And, I wound up reinstalling from cd and importing the .tgz file. Again, the firewall is back online doing what it's supposed to be doing.

But this now, twice that I would say we've had major problems with R60. The hardware is a Compaq DL320, that ran R54 for 3 years without a hitch.
What else is going on out there with SPLAT R60?
Reply With Quote
  #2 (permalink)  
Old 2006-01-17
Junior Member
 
Join Date: 2005-09-02
Posts: 19
Rep Power: 0
jobroco has an average reputation (10+)
Default Re: NGX Problems, who's having them?

I also have an HP DL320 that I have experienced some issues with, when installing NGx running Splat R60 (and hotfixes). After everything was installed, imported, etc..., all seems fine (SIC, policy install, etc...), then after a period of time weird things just seem to happen (memory utilization exceeded, arp table size exceeded, or other lockup). Does the system health indicator light ever go red on your DL320? I haven't quite figured out yet what is so different in this version of Splat from R54 or R55 that could cause these problems. I'm working with some CP techs in hopes of resolving the quirks. Maybe it's something in particular with the DL320, or the nics. I also have an Intel Pro/1000 Quad card installed.
-jj
Reply With Quote
  #3 (permalink)  
Old 2006-01-18
Junior Member
 
Join Date: 2005-12-20
Posts: 24
Rep Power: 0
Westy has an average reputation (10+)
Default Re: NGX Problems, who's having them?

No, the health indicator light has never come on. We have an Intel Pro 100 card with two ports on it. I've seen a couple of posts regarding problems with the Intel drivers and SPLAT. I've been running for the past 6 days without a problem. So far, so good. I'm just gonna let it ride and see what shakes. I'm just wondering who else is having problems. How many packets a day are you logging. I average about 1.5 million per day. And, I have 512 mb of ram in the server. How much ram do you have installed?
Reply With Quote
  #4 (permalink)  
Old 2006-01-18
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,662
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: NGX Problems, who's having them?

If by patch you mean HFA1, there was a fix/new HFA1 that came out that fixed something with HFA1.

FWIW HFA2 is available now as well
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:11.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0