<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Observing Broadcast CCP messages when CCP mode is Multicast in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89005#M6847</link>
    <description>&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;We're running R80.10 on these still and kernel version will still be 2.6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cphaprob -a if shows:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Required interfaces: 8&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;Sync UP sync(secured), multicast&lt;BR /&gt;Mgmt Disconnected non sync(non secured), multicast&lt;BR /&gt;eth2-01 UP non sync(non secured), multicast&lt;BR /&gt;eth1-01 UP non sync(non secured), multicast&lt;BR /&gt;eth1-03 UP non sync(non secured), multicast&lt;BR /&gt;eth3-07 UP non sync(non secured), multicast&lt;BR /&gt;eth3-03 UP non sync(non secured), multicast&lt;BR /&gt;bond0 UP non sync(non secured), multicast, bond Load Sharing&lt;BR /&gt;bond1 UP non sync(non secured), multicast, bond Load Sharing&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 7&lt;/P&gt;&lt;P&gt;eth2-01 xxxx&amp;nbsp;&lt;BR /&gt;eth1-01 xxxx&amp;nbsp;&lt;BR /&gt;eth1-03 xxxx&amp;nbsp;&lt;BR /&gt;eth3-07 xxxx&amp;nbsp;&lt;BR /&gt;eth3-03 xxxx&lt;BR /&gt;bond0 xxxx&lt;BR /&gt;bond1 xxxx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These interfaces are not under load though so surely multi-queue or more SND cores won't help?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jun 2020 12:00:21 GMT</pubDate>
    <dc:creator>Tom_Cripps</dc:creator>
    <dc:date>2020-06-18T12:00:21Z</dc:date>
    <item>
      <title>Observing Broadcast CCP messages when CCP mode is Multicast</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/88988#M6843</link>
      <description>&lt;P&gt;I am seeing Broadcast packets for CCP from my active gateway on two interfaces even though my CCP method is multicast? Has anyone seen this at all before?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm also seeing RX_DRP and RX_OVR increase the same amount appearing to be in a "lockstep" as described in&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;'s books.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect this may be causing us problems when our current standby member becomes active, as we see irregular behavior when it is handling traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 09:49:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/88988#M6843</guid>
      <dc:creator>Tom_Cripps</dc:creator>
      <dc:date>2020-06-18T09:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Observing Broadcast CCP messages when CCP mode is Multicast</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89004#M6846</link>
      <description>&lt;P&gt;Gateway code &amp;amp; kernel version?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What CCP mode does &lt;STRONG&gt;cphaprob -a if&lt;/STRONG&gt; show?&lt;/P&gt;
&lt;P&gt;If you are getting RX-DRP/RX-OVR lockstep it usually means to need to add more SND cores and then possibly enable Multi-Queue, but this is version dependent.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 11:50:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89004#M6846</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-06-18T11:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Observing Broadcast CCP messages when CCP mode is Multicast</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89005#M6847</link>
      <description>&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;We're running R80.10 on these still and kernel version will still be 2.6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cphaprob -a if shows:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Required interfaces: 8&lt;BR /&gt;Required secured interfaces: 1&lt;/P&gt;&lt;P&gt;Sync UP sync(secured), multicast&lt;BR /&gt;Mgmt Disconnected non sync(non secured), multicast&lt;BR /&gt;eth2-01 UP non sync(non secured), multicast&lt;BR /&gt;eth1-01 UP non sync(non secured), multicast&lt;BR /&gt;eth1-03 UP non sync(non secured), multicast&lt;BR /&gt;eth3-07 UP non sync(non secured), multicast&lt;BR /&gt;eth3-03 UP non sync(non secured), multicast&lt;BR /&gt;bond0 UP non sync(non secured), multicast, bond Load Sharing&lt;BR /&gt;bond1 UP non sync(non secured), multicast, bond Load Sharing&lt;/P&gt;&lt;P&gt;Virtual cluster interfaces: 7&lt;/P&gt;&lt;P&gt;eth2-01 xxxx&amp;nbsp;&lt;BR /&gt;eth1-01 xxxx&amp;nbsp;&lt;BR /&gt;eth1-03 xxxx&amp;nbsp;&lt;BR /&gt;eth3-07 xxxx&amp;nbsp;&lt;BR /&gt;eth3-03 xxxx&lt;BR /&gt;bond0 xxxx&lt;BR /&gt;bond1 xxxx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These interfaces are not under load though so surely multi-queue or more SND cores won't help?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 12:00:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89005#M6847</guid>
      <dc:creator>Tom_Cripps</dc:creator>
      <dc:date>2020-06-18T12:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: Observing Broadcast CCP messages when CCP mode is Multicast</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89052#M6848</link>
      <description>&lt;P&gt;Tough to say, please provide output of "Super Seven" commands and &lt;STRONG&gt;enabled_blades&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Super-Seven-Performance-Assessment-Commands-s7pac/m-p/40528?search-action-id=15769896851&amp;amp;search-result-uid=40528" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Super-Seven-Performance-Assessment-Commands-s7pac/m-p/40528?search-action-id=15769896851&amp;amp;search-result-uid=40528&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 14:51:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89052#M6848</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-06-18T14:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: Observing Broadcast CCP messages when CCP mode is Multicast</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89058#M6849</link>
      <description>&lt;P&gt;Enabled Blades:&lt;/P&gt;&lt;P&gt;[Expert@XXXX:0]# enabled_blades&lt;BR /&gt;fw vpn mon vpn&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Super Seven output is attached Tim. This is from our current standby member also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2020 15:11:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89058#M6849</guid>
      <dc:creator>Tom_Cripps</dc:creator>
      <dc:date>2020-06-18T15:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Observing Broadcast CCP messages when CCP mode is Multicast</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89203#M6852</link>
      <description>&lt;P&gt;Please provide the Super Seven run on the active member, I can tell it was run on the standby due to the 100% F2F.&lt;/P&gt;
&lt;P&gt;In regards to the high RX-DRP, it may be skewed by the fact that it is a standby member, and you are seeing unknown protocols in your network as mentioned here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/core-affinity-R80-40-two-cores/m-p/88834/highlight/true#M17841" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/core-affinity-R80-40-two-cores/m-p/88834/highlight/true#M17841&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 12:50:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89203#M6852</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-06-19T12:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Observing Broadcast CCP messages when CCP mode is Multicast</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89224#M6855</link>
      <description>&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;Thank you getting back in touch, we have identified this being an with the Hardware module we are using. Changing the interface into a new module has resolved this. I suspect there is a problem with the NIC on that module, we are not seeing errors anymore, but are still seeing FWHA_IFCONF_REQ and FWHA_IF_PROBE_REQ requests on the second interface which was erroring, not anymore though.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 14:48:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Observing-Broadcast-CCP-messages-when-CCP-mode-is-Multicast/m-p/89224#M6855</guid>
      <dc:creator>Tom_Cripps</dc:creator>
      <dc:date>2020-06-19T14:48:31Z</dc:date>
    </item>
  </channel>
</rss>

