Firewall-1

Re: [FW-1] Excluding services from sync

Subject: Re: [FW-1] Excluding services from sync
From: sin <sin AT IMACANDI DOT NET>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Wed, 21 Mar 2007 12:25:11 +0200
Torkel Mathisen wrote:
Hi,

I was thinking about what Christopher McGill said in the etherchannel
post about not syncing http and DNS (udp).

Does anyone have any recommendation about what to not sync in general?

I guess http and DNS is a given. I guess all UDP doesn't really need to
be sync'ed but it's probably only DNS that got any amount of traffic in
most cases.

I'm looking for ways to reduce the sync traffic.

I have a cluster at a customer that does about 150.000 simultaneous connections and at peak time goes to 200.000 and eveyhting is very OK (cpu usage is about 14-20% peak time). What requirements to you have that you need to avoid sync for some types of connections ?

sin

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>