Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Greatsamps
Contributor
Jump to solution

Gateway becoming swamped under high NAT load

We are an old Checkpoint customer who has recently had a stint with PFSense. We are in the process of migrating back to Checkpoint but have had quite a few problems.

We have sourced 2 Dell R330 4-Core servers with Intel X520 cards in them which are fully supported in the HCL. After several days of fighting, we gave up trying to install as an Open Server; every time as soon as the install tried to partition the disks, the install crashed with an anaconda error that i can find no reference to anywhere.

We then decided to load them with ESXI7 and run in a VM, not ideal but got us going.

ESXI has been configured with 1 virtual switch per nic, and 1 port group per vlan split between the switches.

  1. External traffic has a dedicated port.
  2. Sync has a dedicated port.
  3. Very busy VLAN has a dedicated port.
  4. Everything else shares the remaining port. The management vlan is on here as well which also has some heavy traffic present.

After a bit of fighting we got the ClusterXL cluster setup and have moved some light services over. The problem occurs when we move the heavy traffic onto it.

Our gateways have a lot of NAT to do, on the PF Sense boxes (8 core) there are currently 120,000 states or translations active. The CPU on the boxes is around 15%.

When trying to put this onto the checkpoint the thing basically grinds to a halt. Connectivity on the heavy VLAN's is very intermittent, and even when trying to install a policy, 50% of the time it fails due to lack of IP connectivity to the gateways. What is strange however is that the CPU is not getting pegged, 25% was the highest i saw it.

As soon as we take this heavy traffic off of it, everything is happy again.

For all the heavy traffic, NAT has been configured to hide behind an address range of 64 addresses.

It feels like the network interfaces are getting saturated and as a result packets are being dropped, which can't be the case. We have 4 x 10GB interfaces, and current traffic through the PFSense boxes is around 50Mb.

Before trying with this current configuration, we tried this on a Hyper-V VM with a single NIC. We had exact the same problem. At the time i put that down to being a bit too optimistic with what a single NIC VM could handle which is why we did it again on a properly resourced setup.

I can't believe that a PFSense box can cope with this high level of NAT better than Checkpoint, but at this stage this is what it seems.

Any ideas where i can go with this?

 

 

0 Kudos
12 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events