<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to calculate IPS and Antibot throghput in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-calculate-IPS-and-Antibot-throghput/m-p/15151#M1057</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;How can we calculate IPS and Antibot throughput on production firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Nov 2017 12:54:39 GMT</pubDate>
    <dc:creator>Nikhil_Patil</dc:creator>
    <dc:date>2017-11-29T12:54:39Z</dc:date>
    <item>
      <title>How to calculate IPS and Antibot throghput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-calculate-IPS-and-Antibot-throghput/m-p/15151#M1057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;How can we calculate IPS and Antibot throughput on production firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Nov 2017 12:54:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-calculate-IPS-and-Antibot-throghput/m-p/15151#M1057</guid>
      <dc:creator>Nikhil_Patil</dc:creator>
      <dc:date>2017-11-29T12:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to calculate IPS and Antibot throghput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-calculate-IPS-and-Antibot-throghput/m-p/15152#M1058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm assuming you have a firewall already in production, and you want to know how much IPS and Anti-bot is potentially slowing down traffic or increasing CPU load.&amp;nbsp; There is not an easy way to directly measure this, however what you can do is execute the following steps to determine what kind of impact these blades are having as currently configured:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) During the firewall's busiest period measure current CPU load with cpview/sar/mpstat/top/cpstat/etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Disable IPS on the fly with the &lt;STRONG&gt;ips off&lt;/STRONG&gt; command on the gateway, wait 30 seconds&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Measure current CPU load with cpview/sar/mpstat/top/cpstat/etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Disable all Threat Prevention (which includes Anti-bot) on the fly with the&lt;STRONG&gt; fw amw unload&lt;/STRONG&gt; command on the gateway, wait 30 seconds&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5) Measure current CPU load with cpview/sar/mpstat/top/cpstat/etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6) Reinstall Access and TP policy to the gateway immediately&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compare your CPU measurements throughout the process and you should be able to deduce what kind of overhead is being incurred by these blades.&amp;nbsp; They can frequently be tuned to substantially reduce performance impact...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My Book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; Second Edition Coming Soon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Nov 2017 14:30:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-calculate-IPS-and-Antibot-throghput/m-p/15152#M1058</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-11-29T14:30:09Z</dc:date>
    </item>
  </channel>
</rss>

