CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-08-20
gavvys gavvys is offline
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 141
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Issue with pushing policy in R65

Hi
I have recently insalled R65 on NOKIA 380,on latest IPSO image, I am facing the issue with pushing the policy, when I push the policy it takes lot of time, near about 10 mins, let me know if anybody facing the issue.
Another issue is that if I enable the smartdefence the CPU usage goes very high, it goes near about 80% and makes the system slow.
One more question has anbody faced the issue with licences, I mean to say if we have less checkpoint user licences and having more machines in the network, does it make any issue with the performance of the system, because I have read somewhere that if the number of users exceeds then the licence then it makes the system slow.

Regards
Ranjit
Reply With Quote
  #2 (permalink)  
Old 2007-08-20
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,027
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Issue with pushing policy in R65

Yep SmartDefense will use up CPU. At our last Nokia update then Nokia were saying that really unless you have a multicore or multiple CPU system then SMARTDefense and UTM functionallity on the appliances will be a big performance hit on the unit. There newest appliances are coming out with Dual Core or more and awaiting the IPSO 6.0 update to allow multicore to work properly on them and should resolve some of these options.

Talking with some Check point people last week and they said that even there new UTM appliances start to struggle when you have the SMARTDefense enabled or start doing the UTM AV or URL filtering.

I have found that progressively over NGX then the policy install time has got worse and takes longer and longer with each release. I don't really suggest less then 512Mb for an NGX box these days.

I personally haven't seen anything regarding license count and going slower if exceed the license count, only that get annoying messages in the log file.
Reply With Quote
  #3 (permalink)  
Old 2008-03-28
Brittin_C Brittin_C is offline
Junior Member
 
Join Date: 2008-03-07
Posts: 28
Rep Power: 0
Brittin_C has an average reputation (10+)
Default Re: Issue with pushing policy in R65

Does anyone know if SmartDefense uses other CPUs that the FW Enforcement engine isnt using. By default in SPLAT 2.6?

Or does that require CoreXL?
Reply With Quote
  #4 (permalink)  
Old 2008-03-31
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Issue with pushing policy in R65

Most of SMDF is run as part of the FW Kernel so it does not use other CPUs. CoreXL/Muli-core will.
Reply With Quote
  #5 (permalink)  
Old 2008-03-31
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 891
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Issue with pushing policy in R65

Your hardware is underpowered.

When we were running R61 on an IP530 (IPSO 4.1) with 512 MB of RAM, a policy push would take a minute or more with 130 rules and most SmartDefense checks enabled. It ran 50% to 100% CPU during the day.

I just put in a Dell 2650 with a single 3 GHz dual core processor and 4 GB of RAM. Now the R65 verify and push takes maybe 20 seconds and it idles about 6%.

Are you running the SmartCenter on the IP380? If so, that will clobber your performance on that hardware as well.

Ray
Reply With Quote
  #6 (permalink)  
Old 2008-04-01
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,027
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Issue with pushing policy in R65

Never run your management on the Nokia as really cripples the box! If you are going to invest the price of a Nokia and a Check Point license then the cost of a SPLAT box is hardly going to be noticed.
Reply With Quote
  #7 (permalink)  
Old 2008-04-03
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 142
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: Issue with pushing policy in R65

get a splat box with 2 gb of ram and your problems will go away.
Reply With Quote
  #8 (permalink)  
Old 2008-04-05
Wainer19 Wainer19 is offline
Junior Member
 
Join Date: 2006-10-28
Location: Canada
Posts: 15
Rep Power: 0
Wainer19 has an average reputation (10+)
Default Re: Issue with pushing policy in R65

Hi,

Thought I would add my two cents here, I previously had some issues with R65 and according to support;

# R65 is not be supported on: IP130, IP265, and IP530
# R65 UTM (Anti Virus and Web Filtering) is only supported on disk based with 1GB RAM (Hybrid or flash-based systems is NOT supported)
# R65 on Flash-based or Hybrid system requires 1GB RAM and 1GB CF as a minimum
# NGX R65 (no AV and Web Filtering) requires 512MB RAM on Disk-based systems .

I tend to agree with the memory requirements, listed above. Would you run XP with 128M of RAM (minimum needed)... Huge leaps and bounds in R65 since R55 and the min requirements were 256M of RAM... So, I personally wouldn't recommened anything less then 1Gb for R65
__________________
CCNA, CCSE, NSA, A+
Reply With Quote
  #9 (permalink)  
Old 2008-05-05
murawai murawai is offline
Junior Member
 
Join Date: 2006-02-01
Posts: 6
Rep Power: 0
murawai has an average reputation (10+)
Default Re: Issue with pushing policy in R65

I am seeing this issue also with R65. Our policy push now takes serveral minutes and CPU on the mgmt server goes very high during the verification (which is the longest part of the process). We are running Smart Center server on windows Server 2003 with SPLAT enforcement modules. Our Windows server has 2GB RAM and 1.4Ghz processor. I would have thought this would have been OK...
Reply With Quote
  #10 (permalink)  
Old 2008-05-05
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 891
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Issue with pushing policy in R65

Hi Murawai,

How many rules and objects (approximately)? What's the network connectivity between the SmartCenter and the firewalls? Have the NICs been checked for errors and duplex mismatches?

What is the hardware for the management server and the enforcement modules?

My SmartCenter is a SPLAT Dell 1950 with 2 GB of RAM. The enforcement modules are Dell 2950's. A policy verification and push of a 130 rule policy takes about 40 seconds.

Ray
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 18:49.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0