Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Matlu
Advisor

Possible attacks in a VSX environment

Hello, everyone.

In a VSX environment, which has many VSs, is it possible to detect a behavior pattern that “points” to a DoS or DDoS attack?

I have three VSs that have a CPU consumption overload of more than 90%, but I can't find the reason why.

I have checked the TOP-CONNECTIONS in CPVIEW, but it doesn't show anything.
SXL is enabled on the VSs.

What I noticed with “top -H” is that the fwk<ID VS>_X processes are consuming almost all of the CPU.

So, from a VSX or FW perspective, is it possible to know if this could be related to some type of attack?

Thank you for your comments.

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

Because of the changeover to UPPAK and poll-mode NIC drivers, Linux commands like top won't show CPU utilization accurately.
Using Check Point specific commands like cpview should give you accurate results.

Not sure this applies here since you did not mention specific hardware or software versions, but that's the first thing that comes to mind.

0 Kudos
Matlu
Advisor

We have version R81.20 with JHF Take 84
On 16000 series hardware

I have a question based on your comment. Is it recommended to use Check Point's own commands in general for any scenario?
Because based on this event we had, when we started monitoring traffic in real time with tcpdump, for example, this command did not show complete data, but when we tried cppcap, we noticed a difference (this one worked a little better).

We assume that this is related to the fact that the CPU in our VSs was “flying,” and that is why tcpdump was showing incomplete data.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Is Dynamic Balancing on? (check: dynamic_balancing -p)

sk141412 - This tool (cppcap) was created to resolve various issues in the Linux tool TCPdump that significantly increased CPU load on Security Gateways.

Since you also mentioned cpview, please note:

Take 89 - Improvements and Resolved Issues

PRJ-54415,
PRHF-33710

Security Gateway

In a VSX Cluster environment, the CPVIEWD daemon may cause a high CPU.

 

 

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events