Check Point R81 | CPU Spike Detective - sk166454

แชร์
ฝัง
  • เผยแพร่เมื่อ 18 ก.ย. 2024

ความคิดเห็น • 11

  • @poseidon8510
    @poseidon8510 3 ปีที่แล้ว

    Thanks Mag

  • @rizwanrashid172
    @rizwanrashid172 3 ปีที่แล้ว

    excellent!

  • @subkhanave
    @subkhanave 3 ปีที่แล้ว

    great video
    what monitoring tools do you use for VSX? I use solarwinds NPM but not out of the box for VSX, need to find which one is creating the CPU spike. I'm on R80.30

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 ปีที่แล้ว

      We use HP NMM and OP5,
      VSX monitoring for VS dons´t really work correct as-is, there is issues with SNMP for this.
      More or less it dosn´t give correct value for VS.
      For the physical box SNMP works correct, but its hard to see what VS actually using what.

    • @subkhanave
      @subkhanave 3 ปีที่แล้ว

      @@MagnusHolmberg-NetSec I found this indeni.com and try the trial one and it's more integrated for checkpoint but need to dig more before proposing to my manager.
      Video request : monitoring tool for checkpoint 😁, hope many feedback from users

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 ปีที่แล้ว

      @@subkhanave the main issue with monitoring VSX is that check point dont have support for monitoring VS utlilization.
      same with cpstat vsx -f cpu it only gives the CPU value for the complete box and not per VS.
      We have a case going with R&D for many many months and asfar as iknow there is no solution for it today.

  • @syedshohidahmed9880
    @syedshohidahmed9880 3 ปีที่แล้ว

    Thank you for your video. I'm having cpu spikes on R80.30, every Friday for couple of hours, kernel memory max'd out, all 4 cpu's on 4200 model at 100% can't workout what is it causing it as the file transfer finishes within 20mins 😣 but cpu's stays at 100%

    • @MagnusHolmberg-NetSec
      @MagnusHolmberg-NetSec  3 ปีที่แล้ว +1

      Do you use IPS or similar blades? because 4200 is a small box so you cant run that much traffic thru it.
      Maybe worth to exclude the specific filetransfer that you are suspecting it could be.
      As it happens on a regular basis i would try to schedule a support call for that time.
      Issue with something going in 100% is that there is more or less no room for troubleshooting.

    • @syedshohidahmed9880
      @syedshohidahmed9880 3 ปีที่แล้ว

      @@MagnusHolmberg-NetSec yes we have IPS enabled, going to make an adjustment on threat prevention policy, if not I'll be raising a support call.