Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
Common tasks
401
213455-L, October 2005
6.
Select Automatically to configure the connections hash size and memory pool automati-
cally.
The automatically configured hash size of the connections is 4194304 because it matches the
increased number of connections on the Firewall. The default is 32768.
NAT parameters
If Network Address Translation (NAT) policy is being used by a large number of concurrent
sessions, then the following two parameters can be modified (This is optional since setting the
connections table value also sets the NAT connections table value for FP3, R54, R55 and
above.):
nat_hash_size:
The current limit is 16384. It should be increased to 131072.
nat_limit:
The current limit is 25,000. It should be increased to 180,000.
You can tune the performance of the Check Point NG by entering the following commands at
the firewall CLI and at the Check Point management station command line.
1.
Log in to the local terminal as admin to disable the firewall:
Allow several minutes for Firewall-1 services to stop before entering
/cfg/fw/ena
N
OTE
–
The Switched Firewall automatically restarts Firewall-1 services unless you use the
/cfg/fw/dis
command to disable the unit. For that reason, Nortel recommends that you do
not use the
cpstop
/
cpstart
commands at the management station to disable/enable the firewall.
2.
Log out of the local terminal and re-log in as root.
3.
Edit the file:
$FWDIR/conf/objects_5_0.C
(see
Tuning Check Point NGX performance on page 400
for parameters to tune).
N
OTE
–
Nortel recommends that you use the
guidbedit
utility from within the Check Point
management station to edit objects_5_0.C. You can download the
guidbedit
utility from
http://www.checkpoint.com/tech support/downloadsng/utilities.html#dbtool.
4.
Logout of the local terminal and re-login as admin.
>> /cfg/fw/dis