CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > High-End Security > VPN-1 VSX
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-21
munrog munrog is offline
Member
 
Join Date: 2006-06-27
Location: New Zealand
Posts: 70
Rep Power: 3
munrog has an average reputation (10+)
Send a message via MSN to munrog Send a message via Skype™ to munrog
Default VSX connection table limit

Hi folks,

Recently discovered (painfully) that in VSX, the connection table limit default size is set to 15,000 concurrent connections rather than the standard 25,000 in all other Check Point products.

Can anyone tell me where this should have been alerted? I can't see anything in the Check Point logs, only out-of-state packets. Perhaps I am looking in the wrong place...

Should this not have been reported in the OS's messages or dmesg file as well?

Platform was R62 on Xbeam.

Thanks in Advance.
Greg
Reply With Quote
  #2 (permalink)  
Old 2007-06-21
cpcpc cpcpc is offline
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Re: VSX connection table limit

I believe you should be able to see the connection limit change on SmartViewTracker. I remembered after creating a VS and push policy, there is a message in the log saying connection limit change from 25000 to 15000 (or similar).
Reply With Quote
  #3 (permalink)  
Old 2007-06-21
munrog munrog is offline
Member
 
Join Date: 2006-06-27
Location: New Zealand
Posts: 70
Rep Power: 3
munrog has an average reputation (10+)
Send a message via MSN to munrog Send a message via Skype™ to munrog
Default Re: VSX connection table limit

Quote:
Originally Posted by cpcpc View Post
I believe you should be able to see the connection limit change on SmartViewTracker. I remembered after creating a VS and push policy, there is a message in the log saying connection limit change from 25000 to 15000 (or similar).
Thanks but it wasnt the fact that the limit had been increased that I wanted to see. I wanted to see an alert when the connection table limit had been reached.

Cheers
Greg
Reply With Quote
  #4 (permalink)  
Old 2007-06-21
cpcpc cpcpc is offline
Member
 
Join Date: 2006-10-27
Location: MA, USA
Posts: 44
Rep Power: 0
cpcpc has an average reputation (10+)
Default Re: VSX connection table limit

I know that FW-1 R65 now has Aggressive Aging feature that does log the connection table/memory % full info in the syslog. However I don't think VSX has this feature yet...
Reply With Quote
  #5 (permalink)  
Old 2007-08-09
mylove142 mylove142 is offline
Member
 
Join Date: 2006-08-22
Posts: 58
Rep Power: 2
mylove142 has an average reputation (10+)
Default Re: VSX connection table limit

Hi all,
I use Crossbeam X40 + Checkpoint VSX NGAI v25. Now, I see the concurrent connections limit is 15000. Now, I want to change the concurrent connection limit. I know where I can change in the object_5_0.C. But I have one questions: with the memory of Crossbeam X40 is 512, how many concurrent connections limit I can set because If the connection exceeds memory, many following connections will be droped?
If you know the answer, please answer me early.
I have problem with the concurrent connection limit.
Thank you very much.
Duy Khang
Reply With Quote
  #6 (permalink)  
Old 2007-12-13
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 130
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: VSX connection table limit

you need about 256mb for every 25000 connections.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:21.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0