Operating System - OpenVMS
cancel
Showing results for 
Search instead for 
Did you mean: 

HTTP Slow Out Of VMS Through Firewall-1

 
Robert Atkinson
Respected Contributor

HTTP Slow Out Of VMS Through Firewall-1

We have a curious problem with HTTP.

I'm in the middle of setting up a BL860 cluster on VMS 8.3-1H1. Everything works as expected, except HTTP.

Apache (CSWS) is serving up a static page of about 100K, but can take 10 minutes to transfer. When we look at the data coming over, we can see it writing incredibly slowly.

The data goes through Firewall-1, the new cluster is in a private LAN to stop any uneanted traffic from escaping.

Other IP protocols are fine. If I access the same page from within the LAN, it's also fine, so that rules out the network card/link. I've also loaded the page into IIS and accessed that through the firewall, which again is fine, so it seems to rule out problems with HTTP filtering.

We think there could be a problem related directly to Firewall-1 and the size of the packets VMS is presenting. I've got another PIX firewall that I could try, but the pass-thru module attached to the blades seems to refuse to negotiate down to 10/100, so we have to use hardware capable of gigabit.

I know this is a long shot, but I wondered if anyone else has come across anything similar, or could give me a clue where I coud start looking and tweaking parameters?

Cheers, Rob.
19 REPLIES 19
marsh_1
Honored Contributor

Re: HTTP Slow Out Of VMS Through Firewall-1

rob,

not much help but you're probably best off putting this in the network forum.

fwiw

Hoff
Honored Contributor

Re: HTTP Slow Out Of VMS Through Firewall-1

Seems that this traffic has exceeded the capabilities of this model of the Check Point Firewall-1 firewall.

I've seen a few firewalls crater exactly like this (including having protocol-specific speed differences), either due to the volume of data or due to the overhead of firewall-based inspections. Check the rules and settings and processing and NAT here, as a start.

Check with Check Point here first, or shop around for better bandwidth with another widget.

Ignoring the issue around setting the speed (which is generally via LANCP in OpenVMS I64) this looks to be the firewall.
Wim Van den Wyngaert
Honored Contributor

Re: HTTP Slow Out Of VMS Through Firewall-1

I know nothing but try netstat -s (ucx sho prot) on the browser side (pc in command prompt) before and after the request.

May be ICMP or other counters indicates something.

Wim
Wim
David Jones_21
Trusted Contributor

Re: HTTP Slow Out Of VMS Through Firewall-1

We run into problems generally with our firewall and TCP window scaling.
I'm looking for marbles all day long.
Wim Van den Wyngaert
Honored Contributor

Re: HTTP Slow Out Of VMS Through Firewall-1

Rob,

Could you also define slow ?

Wim
Wim