- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- QoS R81.20 - Guarantee not working
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
QoS R81.20 - Guarantee not working
Hi everyone!
I'm asking for help in understanding how QoS works, and how to debug correctly when QoS problems occur.
About the problem:
I have 2 security gateways with hosts behind them:
Gateway A has hosts 192.168.1.1 and 192.168.2.2.
Behind gateway B - hosts 192.168.3.1 and 192.168.4.2.
I enable the QoS module and configure the Simple rule and apply it. I configure the rule to target traffic between hosts 192.168.1.1 and 192.168.3.1. I create a load between the other hosts.
I made a rule with a guaranteed bandwidth of 200 Mb/sec. I have attached a photo of the rules from both gateways.
Rules were created on external interfaces of both gateways. The total channel speed is 307 Mb/sec.
As a result, when running Iperf3 between hosts (target and load) the speed does not reach 200 mb/sec according to the rule. In waves the speed varies from 30 to 170 Mb/sec. And on the channel with load the speed is 5-7 mb/sec. As a result, the total utilisation reaches 80%! The QoS module itself works, because under the condition of LIMIT, the speed is really limited. Also the guaranteed bandwidth works if you don't run Iperf on other hosts to create load.
I am asking for help or ideas on how to solve the problem and how to debug correctly.
Thank you in advance for your help!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We need a lot more information, such as:
- What is the device under test?
- What JHF are you running?
- Output of Super Seven commands while under test: https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/m-p/40...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Attached, screenshots of Iperf measurements, and debugs.
To answer your questions:
What is the device under test? - VM
What JHF are you running? - No hotfix, clean install.
Super Seven debug output attached
The rule essentially works, but with very very high traffic uctilisation
Screenshot of Iperf targeted traffic, while loading on traffic platforms that don't fall under the rules attached. Second screenshot, measuring the speed of all other traffic.(for load).
According to the debug, there are no errors, but there is this entry fg_dns_initarray: Could not open
Very please advise in which direction to look for the problem. I don't understand it yet
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A single core and 4GB of RAM is below the minimum hardware requirements in the release notes for R81.20: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Open-Se...
Personally, I would allocate no less than 4 cores and no less than 8GB of RAM to the VM.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To debug (maybe TAC has better commands)
Andy
?s:
-did it ever work?
-brand new setup?
-what versions?
-all users have same problem?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello everyone!
Please help in understanding how QoS works, and how to debug correctly when QoS problems occur.
About the problem:
I have 2 security gateways with hosts behind them:
Gateway A has hosts 192.168.1.1 and 192.168.2.2.
Behind gateway B - hosts 192.168.3.1 and 192.168.4.2
I enable the QoS module and configure the Simple rule and apply it. I configure the rule to target traffic between hosts 192.168.1.1 and 192.168.3.1. Create a load between the other hosts.
I made a rule with a guaranteed bandwidth of 200 Mb/sec. I have attached a photo of the rule.
Rules are created on the external interfaces of both gateways. The total channel speed is 307 Mb/sec.
As a result, when running Iperf3 between hosts (target and load) the speed does not reach 200 mb/sec according to the rule. In waves the speed varies from 30 to 170 Mb/sec. And on the channel with load the speed is 5-7 mb/sec. As a result, the total utilisation reaches 80%! The QoS module itself works, because under the LIMIT condition, the speed is really limited. Also the guaranteed bandwidth works if you don't run Iperf on other hosts to create load.
I am asking for help or ideas on how to solve the problem and how to debug correctly.
Thank you in advance for your help!
