<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rate limiting the bandwith from the CP gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33196#M2656</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would advise not to enable QoS on Check Point without a very good reason and further investigate what exactly this traffic is. As Dameon said it is not normal that gateway itself generates big amounts of traffic.Maybe you have some hide NAT setting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What blades are enabled on gateways? What is configured for auto-update of these blades? What's the&amp;nbsp;source and destination of this traffic? What protocol, port, application is that? Can you see it in logs of the gateway? Can you find it in tcpdump or fwmonitor?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Oct 2018 18:55:49 GMT</pubDate>
    <dc:creator>AlekseiShelepov</dc:creator>
    <dc:date>2018-10-08T18:55:49Z</dc:date>
    <item>
      <title>Rate limiting the bandwith from the CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33192#M2652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have some sites that were lean on available bandwidth before we implemented the CP gateway and now our networking guys are getting called out on networking issues. When they look at the top talkers the CP is constantly in the mix if not at the top.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wanting to know if there was a way to limit the bandwidth used for things like updates and such from the gateway. My networking guys are telling me that it looks like the gateway slowly ramps up as if to see how much it can use and I would like to cap that bandwidth usage at these certain sites. If there is not a way to do this then how have others dealt with this issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are a mix of R77.30 and R80.10 gateways with R80.10 management. Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2018 20:25:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33192#M2652</guid>
      <dc:creator>Heath</dc:creator>
      <dc:date>2018-10-04T20:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting the bandwith from the CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33193#M2653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've never heard anyone complain about this.&lt;/P&gt;&lt;P&gt;The updates the gateway downloads should be fairly minimal unless you've configured the system to automatically download all packages with CPUSE (not the default), which would be the only thing that would require any significant bandwidth.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2018 22:57:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33193#M2653</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-04T22:57:14Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting the bandwith from the CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33194#M2654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="http://downloads.checkpoint.com/dc/download.htm?ID=24809"&gt;QoS&lt;/A&gt; ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, I run into similar case and it was caused by backups.If you have enabled logging of Implied Rules, you should be able to find this traffic going from firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2018 21:23:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33194#M2654</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-10-05T21:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting the bandwith from the CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33195#M2655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We haven't setup QoS on the CP but that's an good thought. I know we could do this on the router outside the CP but can this be limited from the CP with a CP QoS policy?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2018 16:23:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33195#M2655</guid>
      <dc:creator>Heath</dc:creator>
      <dc:date>2018-10-08T16:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting the bandwith from the CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33196#M2656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would advise not to enable QoS on Check Point without a very good reason and further investigate what exactly this traffic is. As Dameon said it is not normal that gateway itself generates big amounts of traffic.Maybe you have some hide NAT setting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What blades are enabled on gateways? What is configured for auto-update of these blades? What's the&amp;nbsp;source and destination of this traffic? What protocol, port, application is that? Can you see it in logs of the gateway? Can you find it in tcpdump or fwmonitor?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2018 18:55:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33196#M2656</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-10-08T18:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting the bandwith from the CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33197#M2657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like the option to download hotfixes is set to manual but I did see that 'Automatically update Deployment Agent (recommended)' was enabled. Could this be causing the download spikes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I long term solution is the upgrade the connection bandwidth at the site, but I need to remedy the CP causing the bandwidth to be over utilized in the current state. I've ask our networking team to give me data on when the site has been over utilized so I can hopefully find a correlation in the CP logs. Any suggestions on how to accomplish this easily once I get the data?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2018 22:20:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33197#M2657</guid>
      <dc:creator>Heath</dc:creator>
      <dc:date>2018-10-11T22:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Rate limiting the bandwith from the CP gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33198#M2658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I suppose it's possible but I know the Deployment Agent is very small (few megabytes).&lt;/P&gt;&lt;P&gt;It shouldn't cause a massive bandwidth spike.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other than the periodic downloads of signatures and possibly CPUSE packages, the only other traffic the gateway generates is in response to network traffic (e.g. to categorize URLs or check ThreatCloud), e.g. sk83520:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk83520&amp;amp;t=1539322178269" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk83520&amp;amp;t=1539322178269"&gt;How to verify that Security Gateway and/or Security Management Server can access Check Point servers?&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Those queries in general should be relatively small also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To provide specific advice, more details are clearly needed.&lt;/P&gt;&lt;P&gt;I suggest working with the TAC on this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2018 05:36:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Rate-limiting-the-bandwith-from-the-CP-gateway/m-p/33198#M2658</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-12T05:36:08Z</dc:date>
    </item>
  </channel>
</rss>

