Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Arturxr
Contributor
Jump to solution

VIP ping delay and active addresses of the MGMT interface

Hello, we've discovered that we have high ping latency to the VIP address and the active node address on our Check Point cluster on the MGMT IP. This seems to be causing communication issues between the Identity Collector and Check Point, as timeout errors periodically occur, and some events may not reach Check Point. Furthermore, the pdp monitor user command output returns the message "daemon did not respond or not running!", while the pdp monitor ip command displays a result.
I also can't run the cpinfo -y all command (the output freezes), and the gateway periodically appears red in the Smart Console.

Could you tell me what could be causing the ping latency to the VIP address and the active addresses of the MGMT interface?

0 Kudos
38 Replies
Timothy_Hall
MVP Gold
MVP Gold

Code level?  This option for fwaccel templates was introduced in R81.20.

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization
0 Kudos
Vincent_Bacher
MVP Silver
MVP Silver

Yes, memory issue was my second thought.
In the introductory article he states that he uses IDC.
What do you think of my idea of creating an upstream instance from redundant PDP devices, connecting the IDC to these devices, and then sharing the sessions with the pep / enforcing firewalls (vs), preferably using push instead of SmartPull?
IDC --> PDP --> PEP

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
the_rock
MVP Diamond
MVP Diamond

Im totally with you on that one, Vince. Certainly appears to be memory related.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Vincent_Bacher
MVP Silver
MVP Silver

It was my thought too, but the first person to mention memory here was our performance god Timothy. 😉

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
(1)
the_rock
MVP Diamond
MVP Diamond

Performance god...I like that 🙂

Best,
Andy
"Have a great day and if its not, change it"
Arturxr
Contributor

can you tell me what kind of memory is meant? There is no high utilization in terms of memory and RAM

0 Kudos
Arturxr
Contributor

I also found this picture, can you tell me if we can reconfigure the cores, it seems there are quite a lot of snd cores and few fw cores

 

 

0 Kudos
Arturxr
Contributor

it seems that the problem has been resolved, we will monitor it, we have done core balancing, according to https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_PerformanceTuning_AdminGuide...

in short,: set dynamic-balancing state enable

reboot

the_rock
MVP Diamond
MVP Diamond

Excellent, thanks for letting us know!

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events