- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Explain to me, a fool, how the aggressive aging option should work on standard settings 🙂
By default, we have a drop when 80% of the connection limit AND 80% of the memory are reached.
But how should it work when "fw ctl pstat" shows the limit of concurrent connections as Unlimited?
Based on % memory utilization, did you already review:
Thanks!
Somehow didn't find this SK.
But with fw_salloc_maxmem_usage = 85 and around 90% Utilized memory I don't see any activity of Aggressive Aging.
Default Inspection profile is applied pstat says that AA enabled but not active.
And this is not the first case, so I would like to clarify before TAC.
How are you monitoring / calculating the memory consumption?
cpview + fw ctl pstat
There was one case when the memory jumped over 90% and the firewall literally committed suicide in the following way sk114529 but AA was still enabled and not active.
Do you use many custom TCP/UDP service objects, has aggressive aging been disabled for those?
Which version & JHF is used and is this regular cluster/gateway or Maestro?
Not so many. I have to check, but no more than 5-10 specific services.
Use free -m to assess memory utilization. Ignore the value reported for "free" and look at the "available" number, that is what Aggressive Aging is looking at when deciding whether to activate.
With this you also can see it right?
Free Real Memory' in output of 'cpstat -f memory os' command('MemFree' + 'Buffers' + 'Cached') / 1024 ] from output of 'cat /proc/meminfo' commandYes.
Righ now I have next values:
[Expert@]# free -m
total used free shared buff/cache available
Mem: 31958 27252 910 30 3794 2915
Swap: 32159 9838 22321
[Expert@]# cpstat -f memory os
Total Virtual Memory (Bytes): 67232706560
Active Virtual Memory (Bytes): 40770469888
Total Real Memory (Bytes): 33510506496
Active Real Memory (Bytes): 30454579200
Free Real Memory (Bytes): 3055927296
Memory Swaps/Sec: -
Memory To Disk Transfers/Sec: -
[Expert@]# fw ctl pstat
Virtual System Capacity Summary:
Physical memory used: 26% (7069 MB out of 27164 MB) - below watermark
Kernel memory used: 3% (901 MB out of 27164 MB) - below watermark
Virtual memory used: 21% (5975 MB out of 27164 MB) - below watermark
Used: 5975 MB by FW, 1152 MB by zeco
Concurrent Connections: 19074 (Unlimited)
Aggressive Aging is enabled, not active
Available and Free real Memory are much smaller than 15-20% limit when AA should be in sleep state. But right now, AA still not active
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 19 | |
| 11 | |
| 8 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY