<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is &amp;quot;Drop-reason of FW = Capacity&amp;quot;? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237517#M46103</link>
    <description />
    <pubDate>Fri, 03 Jan 2025 12:43:18 GMT</pubDate>
    <dc:creator>SteveM</dc:creator>
    <dc:date>2025-01-03T12:43:18Z</dc:date>
    <item>
      <title>What is "Drop-reason of FW = Capacity"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237512#M46099</link>
      <description>&lt;P&gt;Hi all, we're replacing EOL 15000 series FWs with 6000 series. The configurations are largely identical (using ClusterXL in active/standby) and the replacement FWs are sized correctly. We've had several failed migration attempts to the new Firewalls - all acceptance tests complete succesfully, yet when production traffic starts to return to normal levels following end of the outage window, poor performance is observed.&lt;/P&gt;&lt;P&gt;According to CPVIEW, there are a high number of drops due to "Capacity" - yet nowhere can I find what this relates to. It can't be CPU or interface, since these are nowhere near maximum.&amp;nbsp; Does anyone know what can cause drops due to "capacity"? This counter can be seen to incremement at a high rate and having ruled everything else out, it would appear this is the cause of the perceived performance issues.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 12:32:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237512#M46099</guid>
      <dc:creator>SteveM</dc:creator>
      <dc:date>2025-01-03T12:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: What is "Drop-reason of FW = Capacity"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237514#M46100</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73513"&gt;@SteveM&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where do you see this in CPVIEW? Can you attach a screenshot? Just blur the sensitive info.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 12:36:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237514#M46100</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-03T12:36:41Z</dc:date>
    </item>
    <item>
      <title>Re: What is "Drop-reason of FW = Capacity"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237515#M46101</link>
      <description>&lt;P&gt;Probably memory, look at the first few output lines of &lt;STRONG&gt;fw ctl pstat&lt;/STRONG&gt; for capacity statistics.&amp;nbsp; Make sure that connection table size is set to "automatically" on your gateway/cluster object, and not still set to a manual limit which was the only option in the SecurePlatform/IPSO days (and still required for VSX).&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 12:39:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237515#M46101</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-01-03T12:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: What is "Drop-reason of FW = Capacity"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237516#M46102</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/23369"&gt;@Steve_Pearson&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And of course we need some info more:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;what is the version (version + take)&lt;/LI&gt;
&lt;LI&gt;Do you see any interesting in /var/log/messages&lt;/LI&gt;
&lt;LI&gt;dynamic balancing is enabled?&lt;/LI&gt;
&lt;LI&gt;in you do a manual failover, the problem arise on site B too?&lt;/LI&gt;
&lt;LI&gt;what kind of traffic affected?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 12:41:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237516#M46102</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-03T12:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: What is "Drop-reason of FW = Capacity"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237517#M46103</link>
      <description />
      <pubDate>Fri, 03 Jan 2025 12:43:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237517#M46103</guid>
      <dc:creator>SteveM</dc:creator>
      <dc:date>2025-01-03T12:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: What is "Drop-reason of FW = Capacity"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237518#M46104</link>
      <description>&lt;P&gt;Memory doesn't exceed 32%, but the concurrent connection table is set to 25000 limit on the new Cluster object - but automatic on the old FWs. It looks like this could be the cause - according to CPVIEW, the concurrent connections never exceeds 24,720. Thank you!!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 12:50:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237518#M46104</guid>
      <dc:creator>SteveM</dc:creator>
      <dc:date>2025-01-03T12:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: What is "Drop-reason of FW = Capacity"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237521#M46106</link>
      <description>&lt;P&gt;That could be your issue, just change it to automatic, as thats best setting, since it lets firewall auto calculate the usage. Install policy, test.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 13:38:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237521#M46106</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-03T13:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: What is "Drop-reason of FW = Capacity"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237525#M46108</link>
      <description>&lt;P&gt;I would also check bottom setting.&lt;/P&gt;
&lt;DIV id="mc-main-content" role="main"&gt;
&lt;UL class="listbullet"&gt;
&lt;LI class="listbullet"&gt;
&lt;P class="listcontinue"&gt;Enable or disable firewall drop optimization to improve gateway resource consumption during periods of heavy traffic load. Let SecureXL handle traffic that the firewall policy determines should be dropped.&lt;/P&gt;
&lt;P class="listcontinue"&gt;Not enabling this option means that only &lt;STRONG class="bold"&gt;Allowed&lt;/STRONG&gt; connections are off loaded to SecureXL, leaving the gateway to handle connections that should be dropped or rejected.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29083i69E3601CF3174BA6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 13:48:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-quot-Drop-reason-of-FW-Capacity-quot/m-p/237525#M46108</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-03T13:48:26Z</dc:date>
    </item>
  </channel>
</rss>

