<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best Practices to check the performance of the equipment in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151679#M24911</link>
    <description>&lt;P&gt;We encountered a problem that users were having trouble accessing the Internet. We were asked to test the Check Point perimeter cluster. Is there any Best Practice on how we can check the performance of the equipment, including the interfaces and its traffic that leads to the Internet. Maybe there is some script that will give us statistics and useful information on the interfaces? HCP please do not suggest &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Jun 2022 06:57:02 GMT</pubDate>
    <dc:creator>Hllrdm</dc:creator>
    <dc:date>2022-06-24T06:57:02Z</dc:date>
    <item>
      <title>Best Practices to check the performance of the equipment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151679#M24911</link>
      <description>&lt;P&gt;We encountered a problem that users were having trouble accessing the Internet. We were asked to test the Check Point perimeter cluster. Is there any Best Practice on how we can check the performance of the equipment, including the interfaces and its traffic that leads to the Internet. Maybe there is some script that will give us statistics and useful information on the interfaces? HCP please do not suggest &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 06:57:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151679#M24911</guid>
      <dc:creator>Hllrdm</dc:creator>
      <dc:date>2022-06-24T06:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices to check the performance of the equipment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151681#M24912</link>
      <description>&lt;P&gt;&lt;A class="event-info" href="https://community.checkpoint.com/t5/Security-Gateways/CPview-and-DiagnosticsView-TechTalk-Video-Q-amp-A-and-Slides/m-p/127903#M18584" target="_blank"&gt;Monitoring and analyzing Check Point devices with CPview and DiagnosticsView&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 08:49:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151681#M24912</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-06-24T08:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices to check the performance of the equipment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151682#M24913</link>
      <description>&lt;P&gt;Is there some kind of coordinate plan for checking the interfaces and its traffic and the presence of errors (e.g., some scripts)? Administrator Guide we have already looked at. We started this thread to get information from our colleagues from experience, not to link to sk and Administrator Guide&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 07:19:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151682#M24913</guid>
      <dc:creator>Hllrdm</dc:creator>
      <dc:date>2022-06-24T07:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices to check the performance of the equipment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151690#M24917</link>
      <description>&lt;P&gt;Nice answer, thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 07:52:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151690#M24917</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-06-24T07:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices to check the performance of the equipment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151693#M24918</link>
      <description>&lt;P&gt;I do not think you should brush out valid recommendations. Admin guides and SKs are what you should look for in the first place, especially if you do not have experience with the procedures.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;sk167553 is exactly what you are looking for, with step-by-step elaborate procedures, starting from basic sanity checks.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;For interface specifics, also look into&amp;nbsp;&lt;SPAN&gt;sk166424.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 08:06:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151693#M24918</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-06-24T08:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices to check the performance of the equipment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151696#M24920</link>
      <description>&lt;P&gt;hey,&lt;/P&gt;
&lt;P&gt;can you elaborate a bit more on "&lt;SPAN&gt;encountered a problem that users were having trouble accessing the Internet&lt;/SPAN&gt;" .&lt;/P&gt;
&lt;P&gt;(also would help stating the HW model and set-up [like cluster and such])&lt;/P&gt;
&lt;P&gt;I want to see what problems you encounter as we also have some HUGE load situations randomly (search for my other post) and in our case (and others from here got the same) it seems to be a sort of DNS attack. Still is manageable from our side and we're working to get a final protection/solution implemented.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, if there is no HW issue (CPU, memory others) then it can be high number of connections.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can see that in below screenshot from SmartView Monitor...&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17026iDABC5179FE35396C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 08:51:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151696#M24920</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-06-24T08:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices to check the performance of the equipment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151716#M24927</link>
      <description>&lt;P&gt;Hi! Answering the questions in more detail:&lt;BR /&gt;1. Our users are having trouble opening some sites (periodically) -- sites load slowly or don't open. After some time everything comes back to normal.&lt;BR /&gt;2. We are using cluster solution. In HCP we don't see errors on interfaces.&lt;BR /&gt;3. In ifconfig we see an increase of drops on RX (1-2 drops once per second) on all interfaces. But on the switch in front of the Check Point equipment we don't see these drops.&lt;BR /&gt;4. We are not sure if the problem is Check Point, but I was asked to check Check Point operation and the most interesting thing I found was drops on the RX and no drops on the switch.&lt;BR /&gt;Maybe there are some options on how we can solve the problem?&lt;BR /&gt;We don't see that the peaks are large.&lt;BR /&gt;At 8:30 we rebooted the device and then changed the cluster activity (it is now active equipment. We have a work day that starts at 9am. &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="peak.jpg" style="width: 956px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17030i43B365521093C1AF/image-size/large?v=v2&amp;amp;px=999" role="button" title="peak.jpg" alt="peak.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 12:51:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151716#M24927</guid>
      <dc:creator>Hllrdm</dc:creator>
      <dc:date>2022-06-24T12:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices to check the performance of the equipment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151725#M24929</link>
      <description>&lt;P&gt;Several notes:&lt;/P&gt;
&lt;P&gt;1. "Slow internet" may be related to NAT reaching capacity. If you are using a single NAT Hide IP address for all your internal networks, I would look into this first.&amp;nbsp;&lt;BR /&gt;2. RX drops mean receiving side drops. This may be caused by too many frames in the buffer and not enough CPU effort to de-queue those. Look at those interfaces to get more details.&amp;nbsp; You will not see anything on the switch, because it is your FW interface and not the switch that is dropping frames. If rasing RX errors/drops coincide with the Internet issue, that may be the cause.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 13:35:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151725#M24929</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-06-24T13:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices to check the performance of the equipment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151726#M24930</link>
      <description>&lt;P&gt;More notes:&lt;BR /&gt;&lt;BR /&gt;3. You did not specify, what HW model you are using. Depending on how many CPUs you have, peak 35% CPU utilization may be a symptom of one or several cores running 100%, which would cause all kinds of traffic issues, including RX drops and errors, slow internet, and more.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;4. I encourage you to look into the SK I mentioned earlier. It actually provides you with step by step analysis of ANY performance issue you might have.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 13:40:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151726#M24930</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-06-24T13:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Best Practices to check the performance of the equipment</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151728#M24931</link>
      <description>&lt;P&gt;The RX-DRPs may be a red herring.&amp;nbsp; As Val said they have nothing to do with the quality of the physical cabling or interface.&lt;/P&gt;
&lt;P&gt;1) What version are you running on the gateway?&amp;nbsp; Upgrading to at least R81 and making sure Dynamic Balancing/Split is enabled will solve most gateway performance problems and help dynamically adjust to spikes in load.&amp;nbsp;&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164155&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank"&gt;sk164155: Dynamic Balancing for CoreXL&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2) First off if the RX-DRP rate is &amp;lt; 0.1% compared to RX-OK on an interface don't worry about it.&amp;nbsp; If it is higher than that the RX-DRPs may just indicate the reception of unknown/unsupported protocols.&amp;nbsp; In the output of &lt;STRONG&gt;ethtool -S (interface)&lt;/STRONG&gt; actual queuing frame drops due to insufficient CPU resources available on your SNDs will increment counters that have something like "missed" or "fifo" or "buffer" in their name.&amp;nbsp; If there are way more total RX-DRPs than individual counters for these types of variables it is unknown/unsupported protocols coming in, which do not increment any of the &lt;STRONG&gt;ethtool&lt;/STRONG&gt; counters at all.&amp;nbsp;&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk166424&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk166424: Number of RX packet drops on interfaces increases on a Security Gateway R80.30 and higher with Gaia kernel 3.10&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;3) If you are running R80.40 or earlier, providing the output of the command &lt;STRONG&gt;enabled_blades&lt;/STRONG&gt; as well as the output of the "Super Seven" will allow me to diagnose your situation and provide recommendations.&amp;nbsp;&amp;nbsp;&lt;A id="link_12" href="https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/m-p/40528?search-action-id=45128800391&amp;amp;search-result-uid=40528" target="_blank"&gt;S7PAC&amp;nbsp;- Super Seven Performance Assessment Commands&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jun 2022 14:17:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Best-Practices-to-check-the-performance-of-the-equipment/m-p/151728#M24931</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-06-24T14:17:01Z</dc:date>
    </item>
  </channel>
</rss>

