<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BW Saturation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199389#M37372</link>
    <description>&lt;P&gt;Good to know! I always ask TAC people when Im on the phone if they know you, because you are by far the most patient person I ever talked to : - )&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 30 Nov 2023 20:56:14 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-11-30T20:56:14Z</dc:date>
    <item>
      <title>BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199282#M37340</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have a problem with our Internet service.&lt;/P&gt;
&lt;P&gt;We currently have a network design similar to this:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;LAN -&amp;gt; INT_CLUSTER -&amp;gt; EXT_CLUSTER -&amp;gt; INTERNET.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The contracted BW is 500MB, but the LAN network, is having slowness problems.&lt;BR /&gt;The ISP told us that the link is getting saturated, and this is maybe due to a bad practice of some of the LAN users.&lt;/P&gt;
&lt;P&gt;Is there any way to know, which is the IP that is saturating the Internet link, from the Firewall point of view?&lt;/P&gt;
&lt;P&gt;We have ClusterXL HA in version R81.10 with Take 110.&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;
&lt;P&gt;BW Saturation&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 18:21:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199282#M37340</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-11-29T18:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199307#M37343</link>
      <description>&lt;P&gt;Buddy, what has been done so far? Have you ran any captures, checked interface errors, anything at all? Without at least basic info, it would be purely a guess as to what can be causing this.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 01:52:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199307#M37343</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-30T01:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199308#M37344</link>
      <description>&lt;P&gt;Hi, Andy.&lt;/P&gt;
&lt;P&gt;I checked commands like CPview, where I noticed that the Hardware resources were "stable".&lt;/P&gt;
&lt;P&gt;I checked the command "netstat -ni", but the result of this, I did not understand it well.&lt;BR /&gt;This command showed a column of "RX-ERR" and the interface facing the Internet, this column did "show" a numerical value.&lt;/P&gt;
&lt;P&gt;I suspect this may be an "indication" that there is a problem at the ISP level.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 01:59:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199308#M37344</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-11-30T01:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199309#M37345</link>
      <description>&lt;P&gt;The best thing to do is see if the issue happens when you take CP firewall out of the equation. If it does, then its not the firewall, if the problem does not happen, then you know its the firewall issue and need to look further if its on the hw or software level.&lt;/P&gt;
&lt;P&gt;Here are some commands to run.&lt;/P&gt;
&lt;P&gt;ps -auxw&lt;/P&gt;
&lt;P&gt;cpview (you already went through that, but you can also export it and review with command cpview -s export)&lt;/P&gt;
&lt;P&gt;cpstat (bunch of values there for all the given blades, interfaces, etc)&lt;/P&gt;
&lt;P&gt;ethtool command (use -S flag for specific interface...ie ethtool -S eth0)&lt;/P&gt;
&lt;P&gt;top&lt;/P&gt;
&lt;P&gt;free -m&lt;/P&gt;
&lt;P&gt;fwaccel stats&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 02:11:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199309#M37345</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-30T02:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199355#M37356</link>
      <description>&lt;P&gt;Can you post the output of netstat -ni?&lt;BR /&gt;This could be some sort of cabling or flow control issue.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 15:34:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199355#M37356</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-30T15:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199360#M37357</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I share the result of "netstat -ni".&lt;/P&gt;
&lt;P&gt;From this result, what is the "important" value to take into account?&lt;/P&gt;
&lt;P&gt;The interface that has the public IP on my GW is eth1-03.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ni.png" style="width: 0px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23480i97C5AF2C29C638F9/image-size/small?v=v2&amp;amp;px=200" width="0" height="0" role="button" title="ni.png" alt="ni.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ni.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23481iCA8BAD34EDBA561F/image-size/large?v=v2&amp;amp;px=999" role="button" title="ni.png" alt="ni.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;What are the values of the commands I have shared that are "important" to consider?&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 16:19:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199360#M37357</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-11-30T16:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199364#M37359</link>
      <description>&lt;P&gt;The fact you have a non-zero RX (receive) errors on the ISP interface suggest the issue is upstream of the firewall.&lt;BR /&gt;The fact you're got a lot of CRC errors suggest a cabling issue of some sort.&lt;BR /&gt;Receive errors result in retransmissions, which will definitely impact overall performance.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 16:30:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199364#M37359</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-30T16:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199366#M37361</link>
      <description>&lt;P&gt;CRC errors would 100% indicate some sort of cabling problem. Check out below.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/nx-os-software/217554-understand-cyclic-redundancy-check-crc.html#:~:text=to%20Host%2DB.-,CRC%20Error%20Definition,the%20device%20for%20the%20frame" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/ios-nx-os-software/nx-os-software/217554-understand-cyclic-redundancy-check-crc.html#:~:text=to%20Host%2DB.-,CRC%20Error%20Definition,the%20device%20for%20the%20frame&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 16:35:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199366#M37361</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-30T16:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199368#M37362</link>
      <description>&lt;P&gt;eth1-03 does have a few CRC errors (usually a cabling problem but the number is really low) but also has a crapload of RX-OVR indicating an overrun of inbound frames into the NIC card itself resulting in packet loss.&amp;nbsp; You need to use an interface with a faster line speed there, or create an Active-Active bond of multiple interfaces.&amp;nbsp; Just be sure to set the Transmit Hash Policy to L3+4 on both sides of the bond to help ensure roughly equal distribution of traffic between the physical interfaces of the bond.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The easiest way to see the bandwidth hogs is take a look at the elephant/heavy flows the firewall detected in the last 24 hours with the &lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt; command.&amp;nbsp; &lt;STRONG&gt;top_conns&lt;/STRONG&gt; will also give you the live list of top connections consuming resources through the firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 16:44:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199368#M37362</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-11-30T16:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199374#M37364</link>
      <description>&lt;P&gt;Hey bro, any progress today on this? Things any better?&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 18:41:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199374#M37364</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-30T18:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199383#M37367</link>
      <description>&lt;P&gt;Buddy,&lt;/P&gt;
&lt;P&gt;At the moment, the client is reviewing with his ISP the detected problem, since they are observing that his contracted BW is being saturated intermittently.&lt;/P&gt;
&lt;P&gt;For the moment, from Check Point's side, we are only "monitoring" that we do not observe anything unusual.&lt;/P&gt;
&lt;P&gt;I understand that the most relevant value of the "netstat -ni" command that helps me to detect a significant error is the RX-OVR, right?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 19:41:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199383#M37367</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-11-30T19:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199384#M37368</link>
      <description>&lt;P&gt;Thats right. Just follow what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;said, he knows this probably more than anyone out there.&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 19:44:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199384#M37368</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-30T19:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199385#M37369</link>
      <description>&lt;P&gt;In addition to what the others have mentioned, if you can collect a packet capture during the time of the bandwidth saturation, it is possible to analyze that capture using our CPMonitor tool to tell you what the top source/destination/services are.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a look at sk103212 for guidance on how to use the tool. If taking the capture on the external/ISP-facing interface of the firewall, you may want to also take (and analyze) captures on the internal interfaces as well to get a better idea of where the load is coming from.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 20:22:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199385#M37369</guid>
      <dc:creator>D_Schoenberger</dc:creator>
      <dc:date>2023-11-30T20:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199386#M37370</link>
      <description>&lt;P&gt;Damon, nice to see you here mate : - )&lt;/P&gt;
&lt;P&gt;I know its you, since I recognize your car, its same photo you had on every time we would do zoom meetings. Good old https inspection issue, haha.&lt;/P&gt;
&lt;P&gt;Hope you are doing well. Good to know about that tool, dont believe I ever used it before.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 20:27:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199386#M37370</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-30T20:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199387#M37371</link>
      <description>&lt;P&gt;Hey Andy!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I figured using my Zoom profile pic would be the quickest way to be recognized here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CPMonitor comes in handy when trying to track down floods of traffic, always good to keep in your back pocket.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 20:40:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199387#M37371</guid>
      <dc:creator>D_Schoenberger</dc:creator>
      <dc:date>2023-11-30T20:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199389#M37372</link>
      <description>&lt;P&gt;Good to know! I always ask TAC people when Im on the phone if they know you, because you are by far the most patient person I ever talked to : - )&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 20:56:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199389#M37372</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-30T20:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199390#M37373</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have tried the command "&lt;EM&gt;&lt;STRONG&gt;fw ctl multik print_heavy_conn&lt;/STRONG&gt;&lt;/EM&gt;" on my GWs, but I have no result.&lt;/P&gt;
&lt;P&gt;[Expert@GW01:0]# fw ctl multik print_heavy_conn&lt;BR /&gt;[Expert@GW01:0]# &lt;BR /&gt;[Expert@GW01:0]#&lt;/P&gt;
&lt;P&gt;Do I have to install something in particular?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 21:00:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199390#M37373</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-11-30T21:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199393#M37376</link>
      <description>&lt;P&gt;No that just means no elephant flows were detected, try &lt;STRONG&gt;top_conns&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 13:04:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199393#M37376</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-12-01T13:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199394#M37377</link>
      <description>&lt;P&gt;if you have no entries in the heavy_conn_table kernel table (fw tab -t heavy_conn_table -s), no output is expected from this command.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 21:06:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199394#M37377</guid>
      <dc:creator>D_Schoenberger</dc:creator>
      <dc:date>2023-11-30T21:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: BW Saturation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199395#M37378</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I got this result with the command you have shared.&lt;BR /&gt;I understand, that not having any result, I can't have a result either, in the command that Timothy shared, right?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;[Expert@GW01:0]# fw tab -t heavy_conn_table -s&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;HOST NAME ID #VALS #PEAK #SLINKS&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;localhost heavy_conn_table 16 0 0 0 0 0&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 21:30:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BW-Saturation/m-p/199395#M37378</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-11-30T21:30:56Z</dc:date>
    </item>
  </channel>
</rss>

