Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SecurityNed
Collaborator

Checkpoint NGFW Showing "High Utilization" Symptoms When Pushing Policies

Hello Everyone!

We are currently experiencing very unusual behavior as of writing, wherein when push a policy on our NGFW, at 50% we experience "High Utilization" symptoms wherein traffic gets dropped for a period of time then regains it back right after the policy is successfully pushed. 

This is a photo that represents the behavior above 

Image (1).jpg

And because of the said behavior, after the policy installation, the NGFW also shows to be as disconnected in the SmartConsole, but regains it back after a minute or two.

I have ticked already connection persistence to be at "Keep All Connections" to check whether it improves but unfortunately it didn't and I'm currently lost right now, as just yesterday we didn't experience this behavior at all.

Hoping for someone's insight on this manner.

Thanks!

Ned

EDIT: I'm currently running on R81.10 JHF Take 170 on my firewall

0 Kudos
3 Replies
Chris_Atkinson
Employee Employee
Employee

What is the hardware / appliance used and are the Management and Gateway separate machines?

Are you installing both access policy & threat prevention concurrently when the issue occurs?

Would also suggest reviewing sk169096 - Accelerated Install Policy for Access Control Policy to see if the scenario is preventing accelerated policy install.

 

CCSM R77/R80/ELITE
0 Kudos
the_rock
Legend
Legend

I had that exact issue in my lab while back and after I upgraded to R81.20, it all went away. Ironically enough, to echo what @Chris_Atkinson said, when I would disable accelerated policy install, there was no issue (this was in R81.10)

Andy

0 Kudos
Timothy_Hall
Legend Legend
Legend

Please provide output of free -m.  My guess is your gateway is short on free memory which can manifest the symptoms you are seeing, since a policy installation is a very memory-intensive action.  If setting "keep all connections" didn't make a difference your issue is probably not CPU-related.  

I assume you just have a single firewall and no cluster?  If a cluster is present does a failover occur during policy install?  Beyond that is there any traffic policing, broadcast suppression on STP events on the switchports the firewall is attached to during a policy installation?

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events