Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
stuart2020
Contributor

CheckPoint 15400 Gateway - R81.20

Hello, 

I've recently upgraded our CheckPoint 15400 ClusterXL Gateways to R81.20 Take 53. Since the upgrade we have 10-15 minutes of extreme slowness where everything grinds to a halt before performing normally again. This happens once maybe twice per day.

I've checked the cpview history and there doesn't seem to be a correlation with increased traffic, high CPU but from SolarWinds I can see that latency to Google increases to over 10,000ms. 

Has anyone else experienced performance issues in R81.20. Any tips for troubleshooting the issue please?

Many Thanks

 

10 Replies
Bob_Zimmerman
Authority
Authority

I have a lot of firewalls on R81.20 with various jumbos including 53. I haven't seen a problem like you describe.

If the issue isn't correlated to high processor usage on the firewall, maybe it's some traffic the firewall drops such as traffic from an internal DNS server out to DNS servers on the public Internet? When DNS misbehaves, so does basically everything else.

(1)
stuart2020
Contributor

Thanks for the suggestion. I've checked DNS and no drops have been detected. I know it could probably be a number of different issues but any more suggestions on possible causes? 

0 Kudos
the_rock
Legend
Legend

Can you check output of fw tab -t connections -s?

Also, does cpview show u top services/connections?

Andy

0 Kudos
stuart2020
Contributor

fw tab -t connections -s

HOST NAME ID #VALS #PEAK #SLINKS
localhost connections 8158 7239 19761 14263

I'm unable to view historical connections in cpview and top connections under the network tab need to be activated. I've uploaded screenshots of real time network and CPU top connections.

0 Kudos
the_rock
Legend
Legend

Make sure gateway object has connections set to auto setting as well. Please open TAC case, sounds like a pretty serious issue.

0 Kudos
stuart2020
Contributor

Where in the gateway object is the connection auto setting? 

Yes, I have raised it with TAC. Just waiting for someone to pick up the ticket. 

0 Kudos
stuart2020
Contributor

Is it the setting in the screenshot that you're referring to? 

the_rock
Legend
Legend

Thats it, you got the right option selected.

stuart2020
Contributor

I've been reading through sk167903 to enable data collection for Network --> Protocols / Connections. The article mentions enabling this feature may cause a performance impact. 

Do you know how much of an impact this has? Is it likely to cause performance issues? 

0 Kudos
the_rock
Legend
Legend

I can totally see the point @Bob_Zimmerman is making. I had never seen this issue myself, so highly unlikely its code problem.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events