CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Web Security > Web Intelligence
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-07
technick22 technick22 is offline
Junior Member
 
Join Date: 2007-10-10
Posts: 22
Rep Power: 0
technick22 has an average reputation (10+)
Default load question

Does using the web intellligence engine cause alot of load on the firewall?

I would like to start using it, but do not want to overload my appliances.

Thanks
Nick
Reply With Quote
  #2 (permalink)  
Old 2008-01-07
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: load question

That all depends on your hardware and how much bandwidth you're pushing through it that is subject to inspection. What is your hardware and total bandwidth? If you have almost any hardware built in the last five years, you'll probably be OK.

Ray
Reply With Quote
  #3 (permalink)  
Old 2008-01-20
cciesec2006 cciesec2006 is online now
Senior Member
 
Join Date: 2006-09-26
Posts: 691
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: load question

I load tested the Nokia IP560 (2GB RAM) running IPSO 4.1 build 19
with NGx R61 & HFA_01 back in December 2006. The load testing
equipment I used is Spirent Web Avalanche/Reflector.

With SmartDefense/Web Intelligence turned OFF, I was able to
push about 700Mbps through the box.

With SmartDefense/Web Intelligence turned ON, I was able to push
about 60Mbps. Not only that, the box freezed and had to require
a mannual turned OFF/ON of the power switch.
Reply With Quote
  #4 (permalink)  
Old 2008-01-20
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 873
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: load question

So someone with a DS3 would be OK?

Check your ApacheFormatString protections. There should be two sets, one with an underscore near the end and one set without. If you have the ones WITHOUT the underscore enabled, disable them and enable the ones with the underscore instead. This ia a known issue and will cause freezing.

I haven't figured out why they can't just delete the non-underscore ones, though.

Ray
Reply With Quote
  #5 (permalink)  
Old 2008-01-20
cciesec2006 cciesec2006 is online now
Senior Member
 
Join Date: 2006-09-26
Posts: 691
Rep Power: 2
cciesec2006 has an average reputation (10+)
Default Re: load question

Ray,

Again, it depends. However, with a DS3 connections, that should be
good for most environments.

One disclaimer: I could have destroyed the IP560 with 64k bytes packets
and lot of http/https connections from the Spirent Avlanche/Reflector.
Had I run the test to the fullest, I would think the Nokia IP560 would
freeze at 30Mbps and lot and lot of 64k connections. That would
criple the Nokia IP560; but again, it doesn't reflect the real environment,
unless you're under DoS or DDoS
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:42.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0