CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-07-11
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default Maximum number of connections ??

What is the maximum number of connections I can have through a firewall using NAT. CP says 50000, does that mean 50000 per destination server or total connections, including all the destinations servers.

e.g is it 50000 conections to google and 50000 to yahoo or yahoo + google = 50000.
Reply With Quote
  #2 (permalink)  
Old 2006-07-11
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Maximum number of connections ??

What version do you use? You can find parameter nat_limit by guidbedit. For NGX this value is 0 (unlimit I think).
About limit, imho there are concurrent connections. Exactly not concurrent, but this number is number of connections which keeps in cp tables. These tables refresh after fixed time-out.
Reply With Quote
  #3 (permalink)  
Old 2006-07-11
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: Maximum number of connections ??

Hi KVA

I am using NG AI 54. I havegot firewall and smartcenter server installed on win 2000 server plateform. guidbedit is not working from command prompt.
Reply With Quote
  #4 (permalink)  
Old 2006-07-12
Senior Member
 
Join Date: 2006-01-26
Location: Moscow, Russia
Posts: 706
Rep Power: 3
kva.kva has an average reputation (10+)
Default Re: Maximum number of connections ??

Really, I didn't work a lot with R54, but guidbedit is smartclient. For R55 and later you can find it in directory with other SmartClients (SmartDashboard, etc) ...\CheckPoint\SmartConsole\R55\PROGRAM (for R55).
Reply With Quote
  #5 (permalink)  
Old 2006-07-14
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: Maximum number of connections ??

Sorry, this is not about nat, but anyway

You can set a Max Concurrent connections individually per gateway: "Right Click on Check Point Gateway Cluster object > Edit > Capacity Optimization"

Checkpoint Firewall will reserve memory and prepare connection hash tables based on this value. Gui prompts that the value should be between 1.000 and 10.000.000. You can see automatically calculated memory size needed.
Reply With Quote
  #6 (permalink)  
Old 2006-07-14
Senior Member
 
Join Date: 2005-11-21
Location: Europe, Lithuania
Posts: 291
Rep Power: 4
Sergej has an average reputation (10+)
Default Re: Maximum number of connections ??

For the nat there is the formula:
(some guidbedit can be set here) Global Properties > SmartDashboard Customization > Advanced Configuration > Firewall-1 > NAT

hide_max_high_port (def) 60.000
hide_min_high_port (def) 10.000

Looks like it is the upper and lover ports to use for HideNAT. That mean that Checkpoint can HideNAT (PAT) 60.000-10.000=50.000 TCP sessions behind 1 IP address (I guess the same settings applied for TCP)

Do not forget that the same NAT sessions should by stored in hash tables (my earlier post)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:54.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0