Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Travis_Krings
Participant

SmartEvent Smart-1 appliance sizing information?

Does anyone know if there are any recent SmartEvent sizing recommendations posted somewhere?  All I can find is the document below that is for R77.x and the old Smart-1 models.  We currently run a Smart-1 225 and I can't turn on the consolidated sessions setting to report on the firewall blade because it pretty much brings the appliance to its knees when I have that running.  I'm looking to replace with a 525, 5050, or open server on my own hardware and given how much these appliances cost I want to be sure I am buying a new SmartEvent appliance that will easily be able to handle my logs with the consolidated sessions setting turned on.

Also, was certain I remembered a support engineer telling me a while back that once you had mgmt and gateways running R80.10+ you could report on the firewall blade in SmartEvent without having the full consolidated sessions turned on.  That does not seem to be the case, and I put in a ticket and they said you can only get this with consolidated sessions.  If anyone knows of a way to report on the firewall blade without the huge performance hit of consolidated sessions please let me know.

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

The way we size Smart-1 Appliances these days is "logs per second."
There's a couple different metrics here: sustained logs per second and burst.
You can see this on the datasheet:
https://www.checkpoint.com/downloads/products/smart-1-security-management-platform-datasheet.pdf

Also, older Smart-1 appliances with R80.x have this information in the following SK: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

The SK you linked has the CPLogInvestigator tool in it, which can tell you how much logs you're actually processing right now.

As for running reports on consolidated firewall sessions, there is a certain amount of correlation that happens without full consolidated sessions.
What is it you're looking to report on specifically in this case?
0 Kudos
Travis_Krings
Participant

Thanks for the information.  What I'm looking to do is be able to run reports and get data from the firewall blade.  Since we don't have a tool like Firemon these reports were very helpful to look at a specific rule and narrow down what is allowed, building up new rules, etc.  I don't necessarily need full correlation, just the ability to get reports on the firewall blade logs.

0 Kudos
Travis_Krings
Participant

Currently in my SmartEvent console the statistics/status window tells me the recommended events per day is 1.3M, and we are already at 1.7M with no consolidated sessions turned on.  If I turn on consolidated sessions it seems that they tell me to expect a 5x increase in events per day.  We are replacing this with a new Smart-1 appliance, so I want to make sure I size it properly so that I can also report on firewall logs even if that means I have to turn on consolidated sessions.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events