Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
handiansudianto
Advisor
Jump to solution

Alert when utilization is high

Hello,

can we get notification if there any user who consume bandwidth more than 75% for example?

0 Kudos
1 Solution

Accepted Solutions
Amir_Senn
Employee
Employee

AFAIK, there's no way to alert this.

We can check amount of data but this could be misleading because it also depends on session time.

You can limit traffic bandwidth in the rulebase itself if it helps, or analyze the data you already have with SmartView.

Kind regards, Amir Senn

View solution in original post

6 Replies
the_rock
Legend
Legend

I believe its possible with Smart Event, I can check Monday in my lab.

Andy

0 Kudos
the_rock
Legend
Legend

I checked in my R81.20 lab where I have dedicated SE server and could not find something similar. I also verified in SV monitor (you need that blade enabled for full functionality), but cant seem to find much better there either. Maybe Im just looking at the wrong places...

Anyway, tagged @Amir_Senn , Im positive he will know, as he helped me with similar queries in the past.

Have a nice weekend!

Andy

0 Kudos
Amir_Senn
Employee
Employee

AFAIK, there's no way to alert this.

We can check amount of data but this could be misleading because it also depends on session time.

You can limit traffic bandwidth in the rulebase itself if it helps, or analyze the data you already have with SmartView.

Kind regards, Amir Senn
the_rock
Legend
Legend

Thanks for confirming @Amir_Senn 👍

0 Kudos
handiansudianto
Advisor

Hello @the_rock @Amir_Senn 

Thanks you, if this not possible from checkpoint side i will try search if there any 3rd party application which can do this.

0 Kudos
Timothy_Hall
Legend Legend
Legend

One roundabout way you could get this information is via the fw ctl multik print_heavy_conn command which reads the kernel table heavy_conn_table containing all current elephant flows, and also those detected for the last 24 hours.  There does not seem to be any way to immediately alert when a heavy connection is detected nor is there any logfile of such that you could follow with tail -f.  If you have at least R81.10 or the latest Jumbo HFA for R81/R80.40, another mechanism you can use to show current top connections (not necessarily declared elephants) is the top_conns command described here: sk172229: Top Connections Tool

So perhaps you could write a script that occasionally runs one of the above commands on your gateway searching for any displayed entries emanating from the subnets/VLANs where your user population is located.  This could be done once an hour for top_conns (which is realtime only) or once a day for fw ctl multik print_heavy_conn.  This solution wouldn't notify you in real time if some user was starting to hog bandwidth and is certainly not perfect, but if they are doing it constantly you will eventually catch them.  Both of these great commands are covered and utilized for lab exercises in my Gateway Performance Optimization class.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events