Re: [FW-1] Nat 0

2008-03-25 Thread Hugo van der Kooij
>> Are you using resource definitions are anything like that that will >> result in your traffic being proxied by your firewall? > > We are using a resource for HTTP "blocked sites" which is being provided > by Websense. > This isn't new though. > > Also, we did determine that https traffic is bein

Re: [FW-1] 3 firewalls configurations

2008-03-25 Thread Raul Lopez Nevot
> > There is no easy solution. At present external loadbalancers would be > the best way to solve this but will require 3 licenses for the gateways > and the costs of the load balancing hardware. > And what happened to stonesoft's StoneBeat FullCluster? I remember my old days on checkpoint over S

Re: [FW-1] 3 firewalls configurations

2008-03-25 Thread Reinhard Stich
hi, is there any special reason for doing that? in nokia clustering you can for example manually assign the load to cluster-nodes. so if you set load to 100 / 100 / 1 the node with load 1 will normally not get a single connection. br reinhard At 15:40 25.03.2008, rar.mail wrote: Hi, I wa

Re: [FW-1] Nat 0

2008-03-25 Thread Ben Wilson
> Are you using resource definitions are anything like that that will > result in your traffic being proxied by your firewall? We are using a resource for HTTP "blocked sites" which is being provided by Websense. This isn't new though. Also, we did determine that https traffic is being translated

Re: [FW-1] Nat 0

2008-03-25 Thread Hugo van der Kooij
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Ben Wilson wrote: | Hi, | | We some changes to the http rules a few weeks ago because Checkpoint was | blocking Content-Disposition header responses and non ASCII header | requests. Since then all out bound web traffic is being translated with | Nat R

Re: [FW-1] 3 firewalls configurations

2008-03-25 Thread Hugo van der Kooij
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 rar.mail wrote: | Hi, | | I want to know if it possible to have a configuration with 3 firewalls, with two actives and one backup, without uses load balancers: | | For two firewalls we use vrrp but for more firewall load balancing, but any other

Re: [FW-1] fwd debug...

2008-03-25 Thread Hugo van der Kooij
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 sin wrote: | Jubei Trippataka wrote: |> The point is that ps wont show the system CPU usage, so the first step |> is to |> determine whether the kernel is hogging the CPU or whether it's user |> space |> processes by using vmstat. Then if it's user sp

[FW-1] 3 firewalls configurations

2008-03-25 Thread rar.mail
Hi, I want to know if it possible to have a configuration with 3 firewalls, with two actives and one backup, without uses load balancers: For two firewalls we use vrrp but for more firewall load balancing, but any other solution ? Any functionnalities on checkpoint or firewall standards,

[FW-1] Nat 0

2008-03-25 Thread Ben Wilson
Hi, We some changes to the http rules a few weeks ago because Checkpoint was blocking Content-Disposition header responses and non ASCII header requests. Since then all out bound web traffic is being translated with Nat Rule 0 and not our manual nat rule. I tried undoing the changes (I don't unde

Re: [FW-1] fwd debug...

2008-03-25 Thread sin
Jubei Trippataka wrote: The point is that ps wont show the system CPU usage, so the first step is to determine whether the kernel is hogging the CPU or whether it's user space processes by using vmstat. Then if it's user space you continue with ps. also top is a good utility to sort processes