- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: R82 cluster monitoring with Insights
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
R82 cluster monitoring with Insights
Hi Checkmates,
I have created my own lab with 2x 23500 with R82 EA configured as ElasticXL cluster.
Everything looks fine except one minor thing... I don't see any traffic in Insights -> Tools -> ConnView:
It doesn't matter if I use filter on the left to see particular traffic or not ... after I hit Search button - I see nothing.
Of course there is a traffic from host in "net1" (internal) to host in "net2" (external) - it goes via Check Point R82 (NAT+routing_firewall). I can see this traffic via tcpdump/cppcap/fw monitor ... in logs, etc.
On the other hand - the same looks perfect in TechPoint's Quantum R82 ElasticXL (EA Review):
Is there any requirement for this tool to be able to display connections ?
For example some process/daemon/etc. must be configured first ?
BTW
R82 looks amazing, especially ElasticXL in my opinion will be game changer !
--
Best
Marcin
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
After investigating the issue. We found out it is due to the fact connview tool (which insights ConnView tab is using) is not working with Kernel FW mode.
Solution is to change USFW.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Marcin,
You are correct and you should see the connection table with or without filter.
Unless your query exceeded max entries of 1000 on one of your cluster member. but in that case you should have seen pop up alert on insight mentioning this and tell you to narrow down your search by adding more filters.
I will install EA version and see if reproduce.
Will keep you updated.
Regards,
Shai
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @ShaiF
Great, looking forward your test results.
Just to clarify - my lab is absolutely basic one ... I've just addressed two interfaces, added this cluster to SMS, changed CleanUp Rule to become PassAll, started the traffic flow ... and generally that's it.
Insights works great - I see a lt of statistics (first pane), alerts, etc ... only the last pane "doesn't like me" 🙂
Hopefully we will find why.
--
Best
Marcin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey Marcin,
Is this cpview or something else? I have exl lab, so can check as well.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @the_rock,
This is new tool introduced in R82 for cluster monitoring (for ElasticXL and Maestro).
You can run it by executing command "insights" from gateway.
You will love this tool 🙂
--
Best
Marcin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I used eve-ng for this, gives below...will see if that setting is in terminal settings, cant seem to find it lol
Andy
[Expert@CP-EXL-1-s01-01:0]# insights
Insights is supported only on terminals with settings of at least 190 columns and 25 rows.
Current terminal size is (columns = 72, rows = 19)
To watch information regarding your cluster use one of the following commands:
- From gClish:
> show cluster info ...
- From expert:
# cinfo --help
For best view of insights adjust your preferred terminal application with the following settings:
- Terminal type: xterm
- Font: consolas
- Encoding: UTF-8
[Expert@CP-EXL-1-s01-01:0]#
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
just enlarge your terminal window to fulfill this requirement:
Insights is supported only on terminals with settings of at least 190 columns and 25 rows.
As you can see yours is like this:
Current terminal size is (columns = 72, rows = 19)
And then magic will happen 🙂
m.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Never mind, I googled it quick, ran this command and now I see the menu. let me check it later on.
Andy
[Expert@CP-EXL-1-s01-01:0]# stty cols 200 rows 150
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
After investigating the issue. We found out it is due to the fact connview tool (which insights ConnView tab is using) is not working with Kernel FW mode.
Solution is to change USFW.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes,
Thank you @ShaiF for this quick remote session.
And I can confirm what Shai just wrote.
We found out this:
[Expert@R82-01-s01-01:0]# connview
[Error] ConnView is not supported on a Security Gateway that runs the Firewall in the Kernel mode (KSFW). For more information, see sk167052.
And everything is clear now ... It is really "funny" because USFW as we know is enabled by default, but not for 23500 appliance ... which I have in my lab 🙂
/it looks like only this one particular model does not have it enabled by default ... lucky me 😉 /
After I switched to USFW I can see connections in insights.
So in case anybody else will have such "issue" it's just Firewall Mode.
Thank you Shai, it was resolved really fast 🙂
--
Best
m.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
EDITED: My original statement was incorrect, now removed.
@ShaiF knows better 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Val,
In EA take FW mode depends on models and platform (EXL run USFW by default as well on some models and VM). In GA take all appliances and platforms (Single Gateway, ClusterXL, Maestro, EXL..) will have USFW by default.
Regards,
Shai.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Will check this in the lab later 🙂
Andy
