<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cluster Full sync taking very long time R80.40 T161 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/160423#M28268</link>
    <description>&lt;P&gt;Just wondering if anyone else has any thoughts on the subject..&lt;/P&gt;
&lt;P&gt;We have a cluster of 28000 series running R80.40 T161 with IPS, APCL, URLF, AB, AV and HTTPS interception turned ON.&lt;/P&gt;
&lt;P&gt;Yesterday we were forced to reboot standby member during day and observed that full sync took nearly half an hour which seemed quite excessive&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;Oct 25 09:55:42 2022 fw1 fwk: CLUS-120120-1: Fullsync started&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;Oct 25 10:20:21 2022 fw1 fwk: CLUS-120122-1: Fullsync completed successfully&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Performance figures at that point:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;total throughput ~15Gbps&lt;/LI&gt;
&lt;LI&gt;internet ~4Gbps&lt;/LI&gt;
&lt;LI&gt;HTTPS inspected ~2Gbps&lt;/LI&gt;
&lt;LI&gt;Threat prevention applied to external traffic only&lt;/LI&gt;
&lt;LI&gt;600,000 concurrent connections&lt;/LI&gt;
&lt;LI&gt;10,000 new connections per second&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;It seemed that sync protocol was not able to keep up with new connection rate - we just saw from connections table size on the standby that it was growing very very slowly. An no obvious errors reported from cphaprob syncstat&lt;/P&gt;
&lt;P&gt;It's a fairly new cluster and we are still in the "tuning" phase (new boxes and new functionality). So we disabled sync for DNS connections and delayed HTTP/S connection sync to 30secs. Which should help of course.&lt;/P&gt;
&lt;P&gt;I just wanted to hear if anyone else is pushing high end appliances close to these numbers and have seen anything like that?&lt;/P&gt;
&lt;P&gt;Has anyone noticed "performance" improvements after upgrading to R81.10 on gateways? I know management gets "faster" but gateways?&lt;/P&gt;
&lt;P&gt;I realize that we are getting close to box MAX:&lt;/P&gt;
&lt;DIV id="tinyMceEditorKaspars_Zibarts_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="image.png" style="width: 576px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18219i4DBA657C6102140F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Oct 2022 06:27:47 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2022-10-26T06:27:47Z</dc:date>
    <item>
      <title>Cluster Full sync taking very long time R80.40 T161</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/160423#M28268</link>
      <description>&lt;P&gt;Just wondering if anyone else has any thoughts on the subject..&lt;/P&gt;
&lt;P&gt;We have a cluster of 28000 series running R80.40 T161 with IPS, APCL, URLF, AB, AV and HTTPS interception turned ON.&lt;/P&gt;
&lt;P&gt;Yesterday we were forced to reboot standby member during day and observed that full sync took nearly half an hour which seemed quite excessive&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;Oct 25 09:55:42 2022 fw1 fwk: CLUS-120120-1: Fullsync started&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;Oct 25 10:20:21 2022 fw1 fwk: CLUS-120122-1: Fullsync completed successfully&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Performance figures at that point:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;total throughput ~15Gbps&lt;/LI&gt;
&lt;LI&gt;internet ~4Gbps&lt;/LI&gt;
&lt;LI&gt;HTTPS inspected ~2Gbps&lt;/LI&gt;
&lt;LI&gt;Threat prevention applied to external traffic only&lt;/LI&gt;
&lt;LI&gt;600,000 concurrent connections&lt;/LI&gt;
&lt;LI&gt;10,000 new connections per second&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;It seemed that sync protocol was not able to keep up with new connection rate - we just saw from connections table size on the standby that it was growing very very slowly. An no obvious errors reported from cphaprob syncstat&lt;/P&gt;
&lt;P&gt;It's a fairly new cluster and we are still in the "tuning" phase (new boxes and new functionality). So we disabled sync for DNS connections and delayed HTTP/S connection sync to 30secs. Which should help of course.&lt;/P&gt;
&lt;P&gt;I just wanted to hear if anyone else is pushing high end appliances close to these numbers and have seen anything like that?&lt;/P&gt;
&lt;P&gt;Has anyone noticed "performance" improvements after upgrading to R81.10 on gateways? I know management gets "faster" but gateways?&lt;/P&gt;
&lt;P&gt;I realize that we are getting close to box MAX:&lt;/P&gt;
&lt;DIV id="tinyMceEditorKaspars_Zibarts_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="image.png" style="width: 576px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18219i4DBA657C6102140F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 06:27:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/160423#M28268</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-10-26T06:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Full sync taking very long time R80.40 T161</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/160435#M28270</link>
      <description>&lt;P&gt;600K connections is A LOT. I would look into an option to set up delayed sync for at least some of the trafffic.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 09:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/160435#M28270</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-26T09:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Full sync taking very long time R80.40 T161</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/160444#M28277</link>
      <description>&lt;P&gt;If it was a FW blade only, it would not be that much. Especially when you look at the datasheet of 28000 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 367px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18222iD1B48DA39598218B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 11:10:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/160444#M28277</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-10-26T11:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Full sync taking very long time R80.40 T161</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/160495#M28309</link>
      <description>&lt;P&gt;Full sync sends over all kernel tables for 600K connections. It is quite a chunk of data.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 18:58:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/160495#M28309</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-26T18:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Full sync taking very long time R80.40 T161</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/160497#M28310</link>
      <description>&lt;P&gt;I agree, thats way too much time. Personally, I would open TAC case to investigate more.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 19:47:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/160497#M28310</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-26T19:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Full sync taking very long time R80.40 T161</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/165422#M29657</link>
      <description>&lt;P&gt;~400.000 concuirrent connections,&amp;nbsp;&lt;/P&gt;&lt;P&gt;~6.000 new conns per sec&lt;/P&gt;&lt;P&gt;162000 appliance&lt;/P&gt;&lt;P&gt;r80.40 take 156&lt;/P&gt;&lt;P&gt;only Firewall Blade&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nov 2 09:51:34 2022 xxxxx fwk: CLUS-120120-1: Fullsync started&lt;BR /&gt;Nov 2 09:52:04 2022 xxxxx fwk: CLUS-120122-1: Fullsync completed successfully&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have many blades and perhaps much more to sync than a firewall only GW.&lt;BR /&gt;however it should not take so long.&lt;/P&gt;&lt;P&gt;check MTU size on both sync interfaces to match.&lt;/P&gt;&lt;P&gt;open a ticket.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 14:44:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/165422#M29657</guid>
      <dc:creator>Alexander_Wilke</dc:creator>
      <dc:date>2022-12-16T14:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Full sync taking very long time R80.40 T161</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/165431#M29660</link>
      <description>&lt;P&gt;Sounds like an unhealthy or overloaded sync network, for both members can you post the output of &lt;STRONG&gt;cphaprob syncstat&lt;/STRONG&gt;, along with &lt;STRONG&gt;fw ctl pstat&lt;/STRONG&gt; in case the firewalls are experiencing other memory issues.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 20:57:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/165431#M29660</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-12-16T20:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Full sync taking very long time R80.40 T161</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/165438#M29663</link>
      <description>&lt;P&gt;Sorry, Elvis has left the building.. I'm not longer with the company and can't get any logs. But I'm 101% sure that sync network was intact. It's a black fiber between DCs approx 1km apart running mearly 100Mbps from 1Gbps available from memory&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 15:44:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/165438#M29663</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-12-16T15:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Full sync taking very long time R80.40 T161</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/165441#M29664</link>
      <description>&lt;P&gt;But come on, now that you work for CP, thats more pressure to fix the issue ; - )&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 16:32:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/165441#M29664</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-16T16:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Full sync taking very long time R80.40 T161</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/165561#M29706</link>
      <description>&lt;P&gt;it's fixed in T1543 &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 11:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/165561#M29706</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2022-12-19T11:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster Full sync taking very long time R80.40 T161</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/165562#M29707</link>
      <description>&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":rolling_on_the_floor_laughing:"&gt;🤣&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2022 11:08:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-Full-sync-taking-very-long-time-R80-40-T161/m-p/165562#M29707</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-19T11:08:40Z</dc:date>
    </item>
  </channel>
</rss>

