NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW-1] Explosion of Translation table



Title: Explosion of Translation table

I've got 2 Nokias IP 440 on IPSO 3.4.1 configured with VRRP.
Checkpoint 4.1 SP5a - Synchronization on a dedicated link.

I've got a really big bandwith to internet, and a lots of server accessible from internet.

3 days ago, I had 800-900 connections in the 2 translation tables fwx_backw and fwx_forw.

Yesterday, the number of connections in these 2 tables explode just to reach the limits (25000), no need to say that the Nokias don't like this.

I've increased the number of connections accepted in these tables. I've checked the state of memory -> no problem.

As soon as I've increased the number of connections in fwx_forw and fwx_backw, this number increase really fast to more than 40000.

When I look at the content of these table, I see exclusivly non-translated packets from the internet to my web servers.

Question:
1) Is there a way to clear entries in the translation table ?
        - I've tryed "fw tab -t fwx_forw fwx_backw -x" but this is not very good.

2) Is-it normal that the untranslated packets reside in those 2 tables ?


Sylvain DEFIX



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.