<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Experiences in Gateway on VMware in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111657#M15440</link>
    <description>&lt;P&gt;Throughput is fine. Latency is maybe 10x higher, but that's going from tens of microseconds to hundreds of microseconds. Not really a noticeable difference in most situations. With VT-D, you can hand a whole PCIe card directly to a VM. In that case, latency is still higher than on dedicated hardware, but less so. Virtualization costs a lot of I/O latency.&lt;/P&gt;
&lt;P&gt;The larger concern is the failure domain. If your VM environment goes down (e.g., your datacenter loses power and all hosts need to come up from scratch), do you need that firewall working to be able to get tech support and/or recover? With virtualization, it's entirely possible to set up your environment in such a way that it's impossible to recover from a full outage.&lt;/P&gt;</description>
    <pubDate>Tue, 23 Feb 2021 19:02:16 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2021-02-23T19:02:16Z</dc:date>
    <item>
      <title>Experiences in Gateway on VMware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111636#M15436</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I wasn't able to find a matching board entry, so I'm creating one here. I'm in need for your experience.&lt;/P&gt;&lt;P&gt;My company has everything virtualized. Only the Checkpoint Security Gateway is not. Now we are discussing the possible virtualization of this machine.&lt;/P&gt;&lt;P&gt;Has anybody experience with this solution? I'm currently torn. Does this method have enouth performance?&lt;/P&gt;&lt;P&gt;Currently we're using an OpenServer with multible VLANs on a Bond and 2 Core licensing.&lt;/P&gt;&lt;P&gt;Hopefully somebody out there has some experience since our reseller has none.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Stephan Kögler&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 15:15:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111636#M15436</guid>
      <dc:creator>Helpdesk_Borken</dc:creator>
      <dc:date>2021-02-23T15:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Experiences in Gateway on VMware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111637#M15437</link>
      <description>&lt;P&gt;Security Gateway on VMWare works, We run dozens that way.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 15:33:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111637#M15437</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2021-02-23T15:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: Experiences in Gateway on VMware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111650#M15438</link>
      <description>&lt;P&gt;For your gateway VMs, I'd suggest creating the interfaces with interface type vxmnet3 (which supports Multi-Queue) instead of the standard e1000.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 17:16:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111650#M15438</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-02-23T17:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Experiences in Gateway on VMware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111654#M15439</link>
      <description>&lt;P&gt;Tim, doesnt Cloudguard Vsec for vmware running R81 preinstalled with vmxnet3? Those that I spinned up in vCenter already had this config. Though I am wondering why it detects a 10G network adapter and not just unlimited link speed.&lt;/P&gt;&lt;P&gt;Do you have any recommend performance ideas? With 4 cores vsec I can with ngfw get almost 3.6gbps when testing with iperf with 1 mb data package over 1 hour.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 17:47:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111654#M15439</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2021-02-23T17:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: Experiences in Gateway on VMware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111657#M15440</link>
      <description>&lt;P&gt;Throughput is fine. Latency is maybe 10x higher, but that's going from tens of microseconds to hundreds of microseconds. Not really a noticeable difference in most situations. With VT-D, you can hand a whole PCIe card directly to a VM. In that case, latency is still higher than on dedicated hardware, but less so. Virtualization costs a lot of I/O latency.&lt;/P&gt;
&lt;P&gt;The larger concern is the failure domain. If your VM environment goes down (e.g., your datacenter loses power and all hosts need to come up from scratch), do you need that firewall working to be able to get tech support and/or recover? With virtualization, it's entirely possible to set up your environment in such a way that it's impossible to recover from a full outage.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2021 19:02:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111657#M15440</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-02-23T19:02:16Z</dc:date>
    </item>
    <item>
      <title>Re: Experiences in Gateway on VMware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111711#M15448</link>
      <description>&lt;P&gt;Yes it should use vmxnet3, but I have seen some VMWare implementations that still default to e1000 for some reason.&amp;nbsp; Just something to check.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 12:40:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/111711#M15448</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-02-24T12:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Experiences in Gateway on VMware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/112019#M15524</link>
      <description>&lt;P&gt;We have sold Check Point gateways in VMware and public clouds for years.&lt;BR /&gt;In the past, the solution went by such names a VE (Virtual Edition), vSEC, and CloudGuard IaaS.&lt;BR /&gt;Currently, it is called CloudGuard Network Security.&lt;BR /&gt;We even have spaces for it on CheckMates &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Your existing Open Server licenses should work with virtualized gateways, though we sell specific licenses for it now.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 18:40:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/112019#M15524</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-02-28T18:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Experiences in Gateway on VMware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/112348#M15591</link>
      <description>&lt;P&gt;Thank you all for your insights.&lt;/P&gt;&lt;P&gt;I'll follow this solution further.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 06:45:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Experiences-in-Gateway-on-VMware/m-p/112348#M15591</guid>
      <dc:creator>Helpdesk_Borken</dc:creator>
      <dc:date>2021-03-03T06:45:53Z</dc:date>
    </item>
  </channel>
</rss>

