CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-11-01
zarcoff zarcoff is offline
Member
 
Join Date: 2006-07-06
Posts: 70
Rep Power: 3
zarcoff has an average reputation (10+)
Default CPU issue

cpu issue with Smartdefence and the 'general http worm catcher' option which is the only option that is selected in Smartdefence.

When it's not ticked cpu at K/w is around 35% When it is selected the cpu goes to around 90%.
We are running r55ng, ipso 3.8, hfa_18, hotfix 771-build 11.

I will be checking to logs later on any ideas have you come across this befor.

Cheers
Zarcoff
Reply With Quote
  #2 (permalink)  
Old 2006-11-01
betski betski is offline
Member
 
Join Date: 2006-07-05
Location: Yorkshire, UK
Posts: 42
Rep Power: 0
betski has an average reputation (10+)
Default Re: CPU issue

I think 35% CPU utilization is about the most you want to average anyway, without adding more defense features. When you hit peak times the firewall will really suffer.

Have you tried checking the 'Monitor only' box to see what affect this has?

Are you protecting web servers or all HTTP traffic?
Reply With Quote
  #3 (permalink)  
Old 2006-11-01
zarcoff zarcoff is offline
Member
 
Join Date: 2006-07-06
Posts: 70
Rep Power: 3
zarcoff has an average reputation (10+)
Default Re: CPU issue

Do you mean set it to log only
Reply With Quote
  #4 (permalink)  
Old 2006-11-01
betski betski is offline
Member
 
Join Date: 2006-07-05
Location: Yorkshire, UK
Posts: 42
Rep Power: 0
betski has an average reputation (10+)
Default Re: CPU issue

no, i mean 'Monitor only'. which version are you using?

i think 'monitor only' option is new to NGX. worm catcher comes under the 'web intelligence tab' not the smart defense tab as it used to.
Reply With Quote
  #5 (permalink)  
Old 2006-11-01
zarcoff zarcoff is offline
Member
 
Join Date: 2006-07-06
Posts: 70
Rep Power: 3
zarcoff has an average reputation (10+)
Default Re: CPU issue

Using Checkpoint NG R55
Reply With Quote
  #6 (permalink)  
Old 2006-11-01
betski betski is offline
Member
 
Join Date: 2006-07-05
Location: Yorkshire, UK
Posts: 42
Rep Power: 0
betski has an average reputation (10+)
Default Re: CPU issue

I found this on Check Point knowledge base which appears to be a related to R54 but may affect your version of IPSO.

Symptoms

CPU jumps to 100 percent when redirecting HTTP to port 80, and using SmartDefense Worm Catcher.

Environment Changes

SmartDefense HTTP parameters are set to Level 7: Cross-Site Scripting, HTTP Format Sizes, ASCII Only Response Headers, ASCII Only Request Headers, Peer to Peer, and HTTP Worm Catcher.

Cause

IPSO 3.8 will support enabling Flows with SmartDefense. IPSO 3.7 has a known issue with Flows and SmartDefense affecting performance.

Solution

This issue is resolved in NG with Application Intelligence R55. Upgrade to the current version.
Reply With Quote
  #7 (permalink)  
Old 2006-11-01
zarcoff zarcoff is offline
Member
 
Join Date: 2006-07-06
Posts: 70
Rep Power: 3
zarcoff has an average reputation (10+)
Default Re: CPU issue

Thanks Betski I will have a look.
Reply With Quote
  #8 (permalink)  
Old 2006-11-01
zarcoff zarcoff is offline
Member
 
Join Date: 2006-07-06
Posts: 70
Rep Power: 3
zarcoff has an average reputation (10+)
Default Re: CPU issue

Where using IPSO 3.8 34
Reply With Quote
  #9 (permalink)  
Old 2006-11-01
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,627
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: CPU issue

NGX (R60-2) has a lot of SMDF improvements, esp R62. I would strongly recomend going to that.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:28.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0