CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Sun Solaris
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-23
Junior Member
 
Join Date: 2007-01-08
Posts: 19
Rep Power: 0
phoenixsecure has an average reputation (10+)
Default Question on performance

Hi,

I have a CP cluster in HA, actif, passif on a SUN 480 with 2 CPU and 1 gig of ram each. The problem is when I reach 100mbits of traffic my CPU go to 100% and I can see a major slow down in performance. My big question is: Can this type of machine (SUN 480, 2 cpu, 1 gig ram) can handle more than 100mbits of traffic? I think it should be able to handle much more than this. And if it should be handling more traffic, any one have any idea why its not.

Thanks.
Reply With Quote
  #2 (permalink)  
Old 2007-10-26
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 146
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: Question on performance

Hi
Well the traffic is not only issue for showing CPU usage high.
Could you please tell me the checkpoint version and HFA also.Also check the Smartdefence settings also a bit information about the licence.

Let me know we will further troubleshoot the issue.


Regards
Ranjit singh
Reply With Quote
  #3 (permalink)  
Old 2007-10-29
Junior Member
 
Join Date: 2007-01-08
Posts: 19
Rep Power: 0
phoenixsecure has an average reputation (10+)
Default Re: Question on performance

Version: NGX (R60) HFA_05, Hotfix 605
OS: Solaris Version: 5.8
License:CPMP-VPG-XL-NGX CPXP-CI-VPX-U-NGX CPVP-VPS-1-NGX
HA, actif, passif
We dont have any smart defense subscription, so its basic there and we dont really use it.
Reply With Quote
  #4 (permalink)  
Old 2007-10-29
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Question on performance

Check which rules you are logging, since it has a big impact on performance.
Reply With Quote
  #5 (permalink)  
Old 2008-01-10
Junior Member
 
Join Date: 2007-04-04
Posts: 6
Rep Power: 0
cp-math has an average reputation (10+)
Default Re: Question on performance

Quote:
Originally Posted by phoenixsecure View Post
Hi,

I have a CP cluster in HA, actif, passif on a SUN 480 with 2 CPU and 1 gig of ram each. The problem is when I reach 100mbits of traffic my CPU go to 100% and I can see a major slow down in performance. My big question is: Can this type of machine (SUN 480, 2 cpu, 1 gig ram) can handle more than 100mbits of traffic? I think it should be able to handle much more than this. And if it should be handling more traffic, any one have any idea why its not.

Thanks.
Hello!

I have the same problem with the same hardware. Can you give me any hints?

Thanks!
Reply With Quote
  #6 (permalink)  
Old 2008-01-11
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Question on performance

My suggestion was to check the logs, spikes in activity can cause the box to struggle. I've seen this before when a spike in one rule caused the box to have to write a lot of logs and it struggled.
Reply With Quote
  #7 (permalink)  
Old 2008-01-11
Member
 
Join Date: 2007-08-04
Posts: 65
Rep Power: 2
eduardw has an average reputation (10+)
Default Re: Question on performance

How many concurrent connections do you have? We had a similar problem with the same hardware and approximate 35000 concurrent connections R55w. Because of the highload the cluster switched a few time a day for node to node.
We replaced the cluster for a HP G5 with 2 dual cores 3 GHz and for gigs of ram, splat R62. Now the average load of the system is 8% instead of 80-100% on the sun. We’ve tried a lot of things before we decide to switch hardware.
Reply With Quote
  #8 (permalink)  
Old 2008-01-17
Junior Member
 
Join Date: 2006-06-02
Posts: 24
Rep Power: 0
rugby1725 has an average reputation (10+)
Default Re: Question on performance

Are you using the onboard interfaces or addon cards. If addons what brand and speed are the cards.

Kris
Reply With Quote
  #9 (permalink)  
Old 2008-01-31
Junior Member
 
Join Date: 2007-05-04
Posts: 4
Rep Power: 0
JeffP has an average reputation (10+)
Default Re: Question on performance

Quote:
Originally Posted by rugby1725 View Post
Are you using the onboard interfaces or addon cards. If addons what brand and speed are the cards.

Kris
That was my guess also. We have seen serious performance degradation through dual/quad cards that do IRQ sharing. When your CPU hit's a 100% check top and see if Soft IRQ is maxed out, that's a prime indicator. Also if you are running QOS ie: FloodGate the multi-cpu support is not available and everything will be pushed through a single core/cpu.
Reply With Quote
  #10 (permalink)  
Old 2008-02-13
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: Question on performance

It does look like the hardware is dying? lmao
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 18:18.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0