CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > QoS (Quality of Service) (Formerly FloodGate-1)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-19
Bikky Bikky is offline
Junior Member
 
Join Date: 2005-10-18
Location: Newcastle - UK
Posts: 14
Rep Power: 0
Bikky has an average reputation (10+)
Default CP slowing down net connection

Hi.

I'm running CP-FW1 NG fp5 with floodgate module. Initially we had an 8mb internet connection and had floodgate setup for this. Since then we've moved to an 80mb connection and noticed that we're still only getting about 75Kb download speed.

I've adjusted the interface speeds and floodgate to allow for the new connection but still getting really slow throughput. If i plug in outside the firewall, i see upto 2Meg download speed, but inside the firewall i see less than 100K.

Any ideas anyone?


Thanks.
__________________
OOO - Look.....

a Hole......
Reply With Quote
  #2 (permalink)  
Old 2007-10-19
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: CP slowing down net connection

FP5? Do you mean NG-AI R55?

It sounds like you have too much SmartDefence turned on for the hardware its running on.

First thing I would suggest is upgrading to NGX R65 and reading the SmartDefense guide, use only the features you need.
Reply With Quote
  #3 (permalink)  
Old 2007-10-21
Thorpuse Thorpuse is offline
Senior Member
 
Join Date: 2007-07-16
Posts: 323
Rep Power: 1
Thorpuse has an average reputation (10+)
Default Re: CP slowing down net connection

Also... try turning off FloodGate and/or Smartdefense to see whether either makes a difference. TBH, I can't understand why you would want or need Floodgate with a link of that size. Floodgate only kicks in when the link is at full utilisation, and if you have an 80Mb link at full utilisation I'd be more interested at what traffic is causing the saturation that trying to rate-limit it.
Reply With Quote
  #4 (permalink)  
Old 2007-10-22
Bikky Bikky is offline
Junior Member
 
Join Date: 2005-10-18
Location: Newcastle - UK
Posts: 14
Rep Power: 0
Bikky has an average reputation (10+)
Default Re: CP slowing down net connection

Well all smart defense is off, and still no improvement (there were only about 12-15 SD rules)

Floodgate was there when we had an 8Mb connection (we have over 3000 staff).

Trying floodgate next (fingers X)
__________________
OOO - Look.....

a Hole......
Reply With Quote
  #5 (permalink)  
Old 2007-10-22
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 346
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: CP slowing down net connection

As said before, I would try to disable as much stuff as possible and check.

Also, monitor the firewall, how is the CPU, RAM, Disk space, etc... maybe you are running short on resources (and if that is the case FG/SmartDefence won't help at all).
Reply With Quote
  #6 (permalink)  
Old 2007-10-22
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 131
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: CP slowing down net connection

Have you adjusted the per interface settings?

[gateway] -> [Topology] -> [interface] -> [QOS tab]

disable in/outbound weight push qos rule and test again.

With R65 I note that the rules are in Kb even the global properties is set to MB (with R60-R62 this was not the case maybe R65_HFA2 solves this;)
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 09:14.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0