Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Saranya_0305
Collaborator

SMB Appliance Disk and Memory

Dear Team,
 
I have SMB appliance model 1530 which was managed centrally where Management Server and SMB appliance at located in different locations.
 
They both have connected by Static routing initially, later we changed to OSPF configuration.
 
Later, when we try to install policy on the device, the below errors triggers at differently at different times.
 
- SIC is not communicating, GeneralSIC error:148
- The IP:xx.xx.xx.xx gateway is not available.-
- Policy timeout.
 
We have reset the SIC multiple times, at that time sometimes able to install the policy but sometime not able to install the policy.
 
We are able to telnet from Gateway to Management Server by ports 18191,18200.
 
But using 18211 Connection refused.
 
We have raised OEMTAC case for this,
 
- Initially they also did reset the SIC and same thing happened on that time its working, after some time it is not working.
- They have collected he Policy debug logs from the Management Server and DrSpark file from the appliance.
 
Line 9740016:  [FW_LOADER 9653 4145583936]@MGMT[23 May 15:05:36] SIC Error for InstallPolicy: timeout elapsed during authentication protocol.
Line 9740115:  [FW_LOADER 9653 4145583936]@MGMT[23 May 15:05:36] opsec_auth_client_connected: SIC Error for InstallPolicy: timeout elapsed during authentication protocol.
Line 9740370:  [FW_LOADER 9653 4145583936]@MGMT[23 May 15:05:36] CPTA_InstallFailReasonTranslate: error number 3048     Ip = 10.0.6.154: Resource temporarily unavailable
Line 9740392:   Installation failed. Reason: SIC General Failure [ SIC error no. 148 ].
 
Based on their analysis, there are several factors.
 
-Insufficient system resources (CPU, memory, disk space)
-High load on the gateway at the time of policy installation
-Temporary network issues between the Management Server and the Gateway
-Too many concurrent operations (e.g., multiple policy installations, upgrades, or other heavy tasks) - # no tasks are running during policy installation.
 
 
Same verified over the logs as well, there is an issue with Peak connections which is causing issue with Memory.
====================================================================================================
 
 
For the temporary network issue, there is slight chance mostly because for the Same Management Server we are able to install the policy for different locations.
 
Before going to investigate network side, I want to know, what is the minimum or maximum memory and disk space utilization is required for running smoothly.
 
If the disk space don't have enough space what are all files can we remove so it doesn't have impact on production. 
 
Peak connections was set to 150000 in SmartConsole.
 
For reference screenshot attached.
 
Regards,
Saranya
0 Kudos
5 Replies
Chris_Atkinson
Employee Employee
Employee

Which version of SMB firmware is used, something older than R81.10.17?

This script from the SK below can be helpful especially for the lower end Spark appliances.

https://support.checkpoint.com/results/sk/sk183290

CCSM R77/R80/ELITE
0 Kudos
Saranya_0305
Collaborator

Hi,

The firmware version is R81.10.15.

 

Regards,

Saranya

0 Kudos
G_W_Albrecht
Legend Legend
Legend

So try sk183290 - also see the discussion here: https://community.checkpoint.com/t5/SMB-Gateways-Spark/Spark-Embedded-physical-memory-high/m-p/24748...

@PhoneBoy  - can we put this in SMB ?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
G_W_Albrecht
Legend Legend
Legend

I would suggest to contact CP TAC to resolve this issue!

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Lesley
Mentor Mentor
Mentor

The admin guide states it can do:

Concurrent Connections 500,000

I would not recommend 500.000 conc connections but the limit is set to 150.000

You peak towards the 8000 connections so to increase this value has no purpose. 

The guide also says:

Connections per Second 10,500 

This you can see via CLI: cpview -> overview -> under network

Second tip: Doctor Spark shows if there are to many hosts connected, does it give this warning / error? 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events