Sorry for delay, but we can only move this traffic over to the Checkpoint POC at weekends. Here is output of commands.
Additionally, even though we removed the heavy traffic from the management network, we still had timeouts on pushing polices to the gateways. The management network was on its own NIC with negligible traffic on it.
+-----------------------------------------------------------------------------+
| Super Seven Performance Assessment Commands v0.5 (Thanks to Timothy Hall) |
+-----------------------------------------------------------------------------+
| Inspecting your environment: OK |
| This is a firewall....(continuing) |
| |
| Referred pagenumbers are to be found in the following book: |
| Max Power: Check Point Firewall Performance Optimization - Second Edition |
| |
| Available at http://www.maxpowerfirewalls.com/ |
| |
+-----------------------------------------------------------------------------+
| Command #1: fwaccel stat |
| |
| Check for : Accelerator Status must be enabled (R77.xx/R80.10 versions) |
| Status must be enabled (R80.20 and higher) |
| Accept Templates must be enabled |
| Message "disabled" from (low rule number) = bad |
| |
| Chapter 9: SecureXL throughput acceleration |
| Page 278 |
+-----------------------------------------------------------------------------+
| Output: |
+---------------------------------------------------------------------------------+
|Id|Name |Status |Interfaces |Features |
+---------------------------------------------------------------------------------+
|0 |SND |enabled |eth0,eth1,eth2,eth3,eth4,|Acceleration,Cryptography |
| | | |eth5,eth6,eth7,eth8,eth9 | |
| | | | |Crypto: Tunnel,UDPEncap,MD5, |
| | | | |SHA1,3DES,DES,AES-128,AES-256,|
| | | | |ESP,LinkSelection,DynamicVPN, |
| | | | |NatTraversal,AES-XCBC,SHA256, |
| | | | |SHA384,SHA512 |
+---------------------------------------------------------------------------------+
Accept Templates : enabled
Drop Templates : disabled
NAT Templates : enabled
+-----------------------------------------------------------------------------+
| Command #2: fwaccel stats -s |
| |
| Check for : Accelerated conns/Totals conns: >25% good, >50% great |
| Accelerated pkts/Total pkts : >50% great |
| PXL pkts/Total pkts : >50% OK |
| F2Fed pkts/Total pkts : <30% good, <10% great |
| |
| Chapter 9: SecureXL throughput acceleration |
| Page 287, Packet/Throughput Acceleration: The Three Kernel Paths |
+-----------------------------------------------------------------------------+
| Output: |
Accelerated conns/Total conns : 24244/24248 (99%)
Accelerated pkts/Total pkts : 406167491/420691241 (96%)
F2Fed pkts/Total pkts : 14523750/420691241 (3%)
F2V pkts/Total pkts : 1896781/420691241 (0%)
CPASXL pkts/Total pkts : 0/420691241 (0%)
PSLXL pkts/Total pkts : 3894/420691241 (0%)
CPAS pipeline pkts/Total pkts : 0/420691241 (0%)
PSL pipeline pkts/Total pkts : 0/420691241 (0%)
CPAS inline pkts/Total pkts : 0/420691241 (0%)
PSL inline pkts/Total pkts : 0/420691241 (0%)
QOS inbound pkts/Total pkts : 0/420691241 (0%)
QOS outbound pkts/Total pkts : 0/420691241 (0%)
Corrected pkts/Total pkts : 0/420691241 (0%)
+-----------------------------------------------------------------------------+
| Command #3: grep -c ^processor /proc/cpuinfo && /sbin/cpuinfo |
| |
| Check for : If number of cores is roughly double what you are excpecting, |
| hyperthreading may be enabled |
| |
| Chapter 7: CoreXL Tuning |
| Page 239 |
+-----------------------------------------------------------------------------+
| Output: |
4
+-----------------------------------------------------------------------------+
| Command #4: fw ctl affinity -l -r |
| |
| Check for : SND/IRQ/Dispatcher Cores, # of CPU's allocated to interface(s) |
| Firewall Workers/INSPECT Cores, # of CPU's allocated to fw_x |
| R77.30: Support processes executed on ALL CPU's |
| R80.xx: Support processes only executed on Firewall Worker Cores|
| |
| Chapter 7: CoreXL Tuning |
| Page 221 |
+-----------------------------------------------------------------------------+
| Output: |
CPU 0:
CPU 1: fw_1
mpdaemon fwd in.asessiond cprid lpd vpnd pdpd core_uploader pepd cprid cpd
CPU 2: fw_2
mpdaemon fwd in.asessiond cprid lpd vpnd pdpd core_uploader pepd cprid cpd
CPU 3: fw_0
mpdaemon fwd in.asessiond cprid lpd vpnd pdpd core_uploader pepd cprid cpd
All: eth0 eth1 eth2 eth3 eth4 eth5 eth6 eth7 eth8 eth9
+-----------------------------------------------------------------------------+
| Command #5: netstat -ni |
| |
| Check for : RX/TX errors |
| RX-DRP % should be <0.1% calculated by (RX-DRP/RX-OK)*100 |
| TX-ERR might indicate Fast Ethernet/100Mbps Duplex Mismatch |
| |
| Chapter 2: Layers 1&2 Performance Optimization |
| Page 28-35 |
| |
| Chapter 7: CoreXL Tuning |
| Page 204 |
| Page 206 (Network Buffering Misses) |
+-----------------------------------------------------------------------------+
| Output: |
Kernel Interface table
Iface MTU Met RX-OK RX-ERR RX-DRP RX-OVR TX-OK TX-ERR TX-DRP TX-OVR Flg
eth0 1500 0 3541645 0 0 0 2379741 0 0 0 BMRU
eth1 1500 0 212796665 0 0 0 199639598 0 0 0 BMRU
eth2 1500 0 15599188 0 0 0 16592379 0 0 0 BMRU
eth3 1500 0 3451769 0 0 0 4768745 0 0 0 BMRU
eth4 1500 0 6550841 0 0 0 10364709 0 0 0 BMRU
eth5 1500 0 9500965 0 0 0 9651053 0 0 0 BMRU
eth6 1500 0 15439074 0 0 0 9479612 0 0 0 BMRU
eth7 1500 0 111170 0 0 0 119436 0 0 0 BMRU
eth8 1500 0 1296925 0 0 0 1784413 0 0 0 BMRU
eth9 1500 0 152823124 0 0 0 154795415 0 0 0 BMRU
lo 65536 0 235433 0 0 0 235433 0 0 0 ALMPNRU
interface eth0: There were no RX drops in the past 0.5 seconds
interface eth0 rx_missed_errors : 0
interface eth0 rx_fifo_errors :
interface eth0 rx_no_buffer_count: 0
interface eth1: There were no RX drops in the past 0.5 seconds
interface eth1 rx_missed_errors : 0
interface eth1 rx_fifo_errors :
interface eth1 rx_no_buffer_count: 0
interface eth2: There were no RX drops in the past 0.5 seconds
interface eth2 rx_missed_errors : 0
interface eth2 rx_fifo_errors :
interface eth2 rx_no_buffer_count: 0
interface eth3: There were no RX drops in the past 0.5 seconds
interface eth3 rx_missed_errors : 0
interface eth3 rx_fifo_errors :
interface eth3 rx_no_buffer_count: 0
interface eth4: There were no RX drops in the past 0.5 seconds
interface eth4 rx_missed_errors : 0
interface eth4 rx_fifo_errors :
interface eth4 rx_no_buffer_count: 0
interface eth5: There were no RX drops in the past 0.5 seconds
interface eth5 rx_missed_errors : 0
interface eth5 rx_fifo_errors :
interface eth5 rx_no_buffer_count: 0
interface eth6: There were no RX drops in the past 0.5 seconds
interface eth6 rx_missed_errors : 0
interface eth6 rx_fifo_errors :
interface eth6 rx_no_buffer_count: 0
interface eth7: There were no RX drops in the past 0.5 seconds
interface eth7 rx_missed_errors : 0
interface eth7 rx_fifo_errors :
interface eth7 rx_no_buffer_count: 0
interface eth8: There were no RX drops in the past 0.5 seconds
interface eth8 rx_missed_errors : 0
interface eth8 rx_fifo_errors :
interface eth8 rx_no_buffer_count: 0
interface eth9: There were no RX drops in the past 0.5 seconds
interface eth9 rx_missed_errors : 0
interface eth9 rx_fifo_errors :
interface eth9 rx_no_buffer_count: 0
+-----------------------------------------------------------------------------+
| Command #6: fw ctl multik stat |
| |
| Check for : Large # of conns on Worker 0 - IPSec VPN/VoIP? |
| Large imbalance of connections on a single or multiple Workers |
| |
| Chapter 7: CoreXL Tuning |
| Page 241 |
| |
| Chapter 8: CoreXL VPN Optimization |
| Page 256 |
+-----------------------------------------------------------------------------+
| Output: |
ID | Active | CPU | Connections | Peak
----------------------------------------------
0 | Yes | 3 | 8140 | 8391
1 | Yes | 1 | 8380 | 8382
2 | Yes | 2 | 7878 | 8196
+-----------------------------------------------------------------------------+
| Command #7: cpstat os -f multi_cpu -o 1 -c 5 |
| |
| Check for : High SND/IRQ Core Utilization |
| High Firewall Worker Core Utilization |
| |
| Chapter 6: CoreXL & Multi-Queue |
| Page 173 |
+-----------------------------------------------------------------------------+
| Output: |
Processors load
---------------------------------------------------------------------------------
|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|
---------------------------------------------------------------------------------
| 1| 0| 59| 41| 59| ?| 33444|
| 2| 6| 2| 92| 8| ?| 33444|
| 3| 5| 2| 92| 8| ?| 33444|
| 4| 6| 3| 91| 9| ?| 33444|
---------------------------------------------------------------------------------
Processors load
---------------------------------------------------------------------------------
|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|
---------------------------------------------------------------------------------
| 1| 0| 59| 41| 59| ?| 33444|
| 2| 6| 2| 92| 8| ?| 33444|
| 3| 5| 2| 92| 8| ?| 33444|
| 4| 6| 3| 91| 9| ?| 33444|
---------------------------------------------------------------------------------
Processors load
---------------------------------------------------------------------------------
|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|
---------------------------------------------------------------------------------
| 1| 0| 56| 44| 56| ?| 62684|
| 2| 6| 2| 93| 7| ?| 62682|
| 3| 6| 2| 93| 7| ?| 31341|
| 4| 6| 2| 93| 7| ?| 31341|
---------------------------------------------------------------------------------
Processors load
---------------------------------------------------------------------------------
|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|
---------------------------------------------------------------------------------
| 1| 0| 56| 44| 56| ?| 62684|
| 2| 6| 2| 93| 7| ?| 62682|
| 3| 6| 2| 93| 7| ?| 31341|
| 4| 6| 2| 93| 7| ?| 31341|
---------------------------------------------------------------------------------
Processors load
---------------------------------------------------------------------------------
|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|
---------------------------------------------------------------------------------
| 1| 0| 58| 42| 58| ?| 63937|
| 2| 5| 2| 94| 6| ?| 31970|
| 3| 4| 1| 95| 5| ?| 63941|
| 4| 6| 2| 93| 7| ?| 63941|
---------------------------------------------------------------------------------
+-----------------------------------------------------------------------------+
| Thanks for using s7pac |
+-----------------------------------------------------------------------------+