<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Concurrent connections drastically increase after switch replacement in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Concurrent-connections-drastically-increase-after-switch/m-p/105897#M8412</link>
    <description>&lt;P&gt;Thanks.&amp;nbsp; Yes, due to the magnitude of the increase I'm thinkng a duplicate packet issue also.&amp;nbsp; I've already done some packet captures but haven't been able to determine anything yet.&amp;nbsp; &amp;nbsp;No errors or drop in netstat -ni.&amp;nbsp; &amp;nbsp;Nothing standing out in ARP table on FW, yet.&amp;nbsp; &amp;nbsp; Thanks for the suggestions.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Dec 2020 20:18:06 GMT</pubDate>
    <dc:creator>Quentin_Antrim</dc:creator>
    <dc:date>2020-12-18T20:18:06Z</dc:date>
    <item>
      <title>Concurrent connections drastically increase after switch replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Concurrent-connections-drastically-increase-after-switch/m-p/105881#M8407</link>
      <description>&lt;P&gt;I have a cluster of two CheckPoint 13000 appliances running R80.30.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;Originally, on the internal side, they were connected to a core cluster of Cisco 6509 switches, each firewall connected to one of the two 6509 switches.&lt;/P&gt;&lt;P&gt;Just recently the core 6509 switches were replaced with a core cluster of Cisco Nexus 9500 switches, each firewall connected to one of the Nexus 9500 switches.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;At the time of the replacement of 6509 switches with the 9500 switches, our average and peak connections almost doubled.&lt;/P&gt;&lt;P&gt;Whereas our previous normal peak would be 60K connections, our new peak became 100K connections, causing us to increase our concurrent connections max limit because of this unexpected increase.&lt;/P&gt;&lt;P&gt;Looking for any help in possible cause of this issue.&amp;nbsp; &amp;nbsp;Has anybody seen anything similar before, and what was the cause/fix?&lt;/P&gt;&lt;P&gt;Also trying to figure out how I can really tell what that increase in connections would be.&amp;nbsp; &amp;nbsp;What could I look for/at to determine what those roughly extra 40K of connections are in the firewall?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Quentin&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 17:54:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Concurrent-connections-drastically-increase-after-switch/m-p/105881#M8407</guid>
      <dc:creator>Quentin_Antrim</dc:creator>
      <dc:date>2020-12-18T17:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent connections drastically increase after switch replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Concurrent-connections-drastically-increase-after-switch/m-p/105882#M8408</link>
      <description>&lt;P&gt;My only suggestion is to check differences in the switch configs. But i fear that had been done already.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 18:07:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Concurrent-connections-drastically-increase-after-switch/m-p/105882#M8408</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-12-18T18:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent connections drastically increase after switch replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Concurrent-connections-drastically-increase-after-switch/m-p/105889#M8410</link>
      <description>&lt;P&gt;Correct.&amp;nbsp; &amp;nbsp;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 18:34:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Concurrent-connections-drastically-increase-after-switch/m-p/105889#M8410</guid>
      <dc:creator>Quentin_Antrim</dc:creator>
      <dc:date>2020-12-18T18:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent connections drastically increase after switch replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Concurrent-connections-drastically-increase-after-switch/m-p/105892#M8411</link>
      <description>&lt;P&gt;I seen a similar behaviour on a couple of nexus 9k and the issue was on switch side where for some reason packets was duplicated.&lt;BR /&gt;I don't know your topology so i can assume nothing, but:&lt;BR /&gt;Did you check if the arp table is compliant with your expectetion either on switches and firewall side?&lt;BR /&gt;Maybe a packet capture can help to identify duplicate packets and "netstat -ni" in expert mode to figureout if you can see error or drop on the firewall interfaces&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 19:26:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Concurrent-connections-drastically-increase-after-switch/m-p/105892#M8411</guid>
      <dc:creator>FraP</dc:creator>
      <dc:date>2020-12-18T19:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Concurrent connections drastically increase after switch replacement</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Concurrent-connections-drastically-increase-after-switch/m-p/105897#M8412</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; Yes, due to the magnitude of the increase I'm thinkng a duplicate packet issue also.&amp;nbsp; I've already done some packet captures but haven't been able to determine anything yet.&amp;nbsp; &amp;nbsp;No errors or drop in netstat -ni.&amp;nbsp; &amp;nbsp;Nothing standing out in ARP table on FW, yet.&amp;nbsp; &amp;nbsp; Thanks for the suggestions.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 20:18:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Concurrent-connections-drastically-increase-after-switch/m-p/105897#M8412</guid>
      <dc:creator>Quentin_Antrim</dc:creator>
      <dc:date>2020-12-18T20:18:06Z</dc:date>
    </item>
  </channel>
</rss>

