<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ARP table size increase  is not surviving the reboot in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/63595#M9915</link>
    <description>&lt;P&gt;Perfect!&amp;nbsp; I just read the pages (2nd edition) and it was helpful.&amp;nbsp; Thanks again.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Sep 2019 19:02:40 GMT</pubDate>
    <dc:creator>Brian_Deutmeyer</dc:creator>
    <dc:date>2019-09-24T19:02:40Z</dc:date>
    <item>
      <title>ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49210#M9900</link>
      <description>&lt;P&gt;Has anyone run in to it after the upgrade to R80.20?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 16:40:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49210#M9900</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-03-29T16:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49215#M9901</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11879"&gt;@Vladimir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This doesn't work after a reboot:&lt;/P&gt;
&lt;P&gt;&amp;gt; set arp table cache-size 4096&lt;BR /&gt;&amp;gt; save config&lt;/P&gt;
&lt;P&gt;A quick and dirty solution:-)&lt;/P&gt;
&lt;P&gt;Add the following to the start script until the problem is solved by Check Point TAC!&lt;/P&gt;
&lt;P&gt;echo 4096 &amp;gt; /proc/sys/net/ipv4/neigh/default/gc_thresh3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 16:57:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49215#M9901</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-29T16:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49218#M9902</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 16:58:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49218#M9902</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-03-29T16:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49219#M9903</link>
      <description>&lt;P&gt;Still from the good old SPLAT times under R65:-)&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 16:58:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49219#M9903</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-29T16:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49220#M9904</link>
      <description>&lt;P&gt;$#!!, now I remember running into it years ago &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 17:01:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49220#M9904</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-03-29T17:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49221#M9905</link>
      <description>&lt;P&gt;Still works today. Shouldn't read the R&amp;amp;D team:-)&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 17:08:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49221#M9905</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-29T17:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49222#M9906</link>
      <description>&lt;P&gt;Heiko, in the context of VSX, would this be a global setting for the entire VSX box, or is there a way to do it for individual VS?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 17:09:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49222#M9906</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-03-29T17:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49226#M9907</link>
      <description>Looks like a global setting.</description>
      <pubDate>Fri, 29 Mar 2019 17:56:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49226#M9907</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-29T17:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49227#M9908</link>
      <description>&lt;P&gt;Well, if this is issue still persists to date, perhaps &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43772" target="_self"&gt;sk43772&lt;/A&gt;&amp;nbsp;should be rewritten, as it is still explicitly states:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gaia Portal / Gaia Clish will override any settings placed in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;/etc/sysctl.conf&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;file. Any changes made to this file do&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;not&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;take effect after a reboot.&lt;/P&gt;
&lt;P&gt;To configure threshold level for ARP cache on Gaia OS:&lt;/P&gt;
&lt;P&gt;Note: Gaia OS accepts maximal threshold level of 16384.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;In Gaia Portal:&lt;/P&gt;
&lt;P&gt;Go to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;Network Management&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section - click on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;ARP&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page - go to section&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;ARP Table Settings&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section - enter the desired value in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;Maximum Entries&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;field.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In Gaia Clish:&lt;/P&gt;
&lt;EM&gt;&lt;STRONG&gt;HostName&amp;gt; set arp table cache-size &amp;lt;Number_of_Entries&amp;gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&lt;STRONG&gt;HostName&amp;gt; save config&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To check the current threshold level for ARP cache on Gaia OS::&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;In Gaia Clish:&lt;/P&gt;
&lt;EM&gt;&lt;STRONG&gt;HostName&amp;gt; show arp table cache-size&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In Expert mode:&lt;/P&gt;
&lt;EM&gt;&lt;STRONG&gt;[Expert@HostName:0]# dbget ip:arp:cache_size&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Notes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Once set in the Gaia Portal / Gaia Clish, the settings will survive a reboot.&lt;/LI&gt;
&lt;LI&gt;Settings are applies immediately (reboot, restart of any services, policy installation are&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;not&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;required)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Maximum Entries&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;value in the Gaia Portal corresponds to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;gc_thresh3&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;parameter in Linux kernel.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;In Gaia OS, the value of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;gc_thresh1&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and the value of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;gc_thresh2&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;are automatically determined by the value of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;gc_thresh3&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;value:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;value of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;gc_thresh1&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is 1/8 the value of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;gc_thresh3&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;value of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;gc_thresh2&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is 1/2 the value of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;gc_thresh3&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 18:15:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49227#M9908</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-03-29T18:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49239#M9910</link>
      <description>&lt;P&gt;We are using&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;/etc/rc.loca&lt;/STRONG&gt;l&lt;/SPAN&gt;&amp;nbsp;file for similar cases. In this case, here is one-time command which will make sure that parameter will survive a reboot:&lt;/P&gt;
&lt;PRE&gt;# echo "echo 4096 &amp;gt; /proc/sys/net/ipv4/neigh/default/gc_thresh3" &amp;gt;&amp;gt; /etc/rc.local&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;But be aware that the current threshold level for ARP cache on Gaia OS:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;In Gaia Clish:&lt;/P&gt;
&lt;EM&gt;&lt;STRONG&gt;HostName&amp;gt; show arp table cache-size&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In Expert mode:&lt;/P&gt;
&lt;EM&gt;&lt;STRONG&gt;[Expert@HostName:0]# dbget ip:arp:cache_size&lt;/STRONG&gt;&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Will still give you original value configured via clish command (not that one set via echo).&lt;/P&gt;
&lt;P&gt;So maybe the better way would be to use bash/clish command:&lt;/P&gt;
&lt;PRE&gt;# echo "clish -c 'set arp table cache-size 4096'" &amp;gt;&amp;gt; /etc/rc.local&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 20:27:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49239#M9910</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2019-03-29T20:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49298#M9911</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1702"&gt;@JozkoMrkvicka&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a very nice solution:&lt;/P&gt;
&lt;PRE&gt;# echo "clish -c 'set arp table cache-size 4096'" &amp;gt;&amp;gt; /etc/rc.local&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;Gives me the idea to more dirty hacks&lt;img id="smileylol" class="emoticon emoticon-smileylol" src="https://community.checkpoint.com/i/smilies/16x16_smiley-lol.png" alt="Smiley LOL" title="Smiley LOL" /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Mar 2019 17:48:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49298#M9911</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-30T17:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49349#M9912</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11879"&gt;@Vladimir&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using the&amp;nbsp; following clish commands to change the arp table size and save the configuration should survive after reboot (and did survive in my tests)&lt;/P&gt;
&lt;P&gt;&amp;gt; set arp table cache-size 4096&lt;BR /&gt;&amp;gt; save config&lt;/P&gt;
&lt;P&gt;Please open a technical service request to CeckPoint support to investigate the problem on your machine.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Mar 2019 13:36:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/49349#M9912</guid>
      <dc:creator>Itaiw</dc:creator>
      <dc:date>2019-03-31T13:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/63487#M9913</link>
      <description>&lt;P&gt;How many arp entries can my table hold if my size is 4096?&amp;nbsp; I'm unsure if this maps 1 to 1, like one arp entry means 1 spot from 4096 (4096 - 1 = 4095 arp entries left)?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 21:12:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/63487#M9913</guid>
      <dc:creator>Brian_Deutmeyer</dc:creator>
      <dc:date>2019-09-23T21:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/63557#M9914</link>
      <description>&lt;P&gt;Yes it is a one-to-one mapping, the 4096 corresponds to a variable called &lt;CODE&gt;gc_thresh3&lt;/CODE&gt; which specifies the hard maximum of IP to MAC address mappings in the table.&amp;nbsp; &lt;CODE&gt;gc_thresh2&lt;/CODE&gt;is typically 1/2 of&amp;nbsp;&lt;CODE&gt;gc_thresh3&lt;/CODE&gt; and specifies when more aggressive garbage collection starts in an attempt to free up table entries and avoid a "Neighbour table overflow" condition.&amp;nbsp; This situation can impact performance and was covered on pages 66-70 of my "Max Power" book.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 12:40:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/63557#M9914</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-09-24T12:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table size increase  is not surviving the reboot</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/63595#M9915</link>
      <description>&lt;P&gt;Perfect!&amp;nbsp; I just read the pages (2nd edition) and it was helpful.&amp;nbsp; Thanks again.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2019 19:02:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ARP-table-size-increase-is-not-surviving-the-reboot/m-p/63595#M9915</guid>
      <dc:creator>Brian_Deutmeyer</dc:creator>
      <dc:date>2019-09-24T19:02:40Z</dc:date>
    </item>
  </channel>
</rss>

