<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maximum reachable bandwidth 3800 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175531#M32042</link>
    <description>&lt;P&gt;Noted, in that case the issue is different than that stated by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21468"&gt;@Juergen_Blumens&lt;/a&gt;&amp;nbsp;here.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Mar 2023 03:36:59 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-03-21T03:36:59Z</dc:date>
    <item>
      <title>Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175438#M32006</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have an IPsec tunnel between two sites, each with a 3800. The available Internet bandwidth is 1 GBit/sec, and the latency is about 12 msec. There is an IP test node behind the firewall on both sides. We can't achive more than 300 Mbit/sec between the two test nodes over the tunnel. The encryption is AES 256, but even if we set the encryption to none, it stays at this maximum bandwidth. The firewalls have R80.40 JHF 190, all blades (except FW, VPN) are disabled during the tests, exceptions cphwd_medium_path_qid_by_cpu_id = 1&lt;BR /&gt;cphwd_medium_path_qid_by_mspi = 0&lt;BR /&gt;are set. We do not see a CPU overload.&lt;BR /&gt;We ran the download tests with simple http download and also using iperf.&lt;BR /&gt;If we connect the test notes directly to the Internet without the Firewalls, we reach the maximum bandwidth of 1 GBit/sec.&lt;BR /&gt;If we perform an additional parallel download via a second tunnel to another site with a 3800, the bandwidth doubles!&lt;BR /&gt;What is your experience? Is there a maximum bandwidth per connection that is limited by the hardware of the Firewall? Do you have ever seen this magical 300 MBit/sec?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2023 16:07:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175438#M32006</guid>
      <dc:creator>Juergen_Blumens</dc:creator>
      <dc:date>2023-03-20T16:07:48Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175513#M32032</link>
      <description>&lt;P&gt;That's expected behavior for a single heavy "elephant" flow.&lt;BR /&gt;This is constrained by the fact only a single core handles the specific flow.&lt;/P&gt;
&lt;P&gt;We have started to address this in R81.20 with Hyperflow, which &lt;A href="https://community.checkpoint.com/t5/CheckMates-Events/HyperFlow-Under-The-Hood/ev-p/172832" target="_self"&gt;we are doing a Techtalk on next week&lt;/A&gt;.&lt;BR /&gt;Since you're only using Firewall and VPN, Hyperflow wouldn't help as it only helps Medium Path inspection currently.&lt;BR /&gt;However, there are other improvements to VPN that might improve speed somewhat.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 01:45:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175513#M32032</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-21T01:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175514#M32033</link>
      <description>&lt;P&gt;I have a TAC case with customer at the moment and they get, if lucky, maybe 20% bandwidth speeds through the VPN tunnel (other side is Fortigate). Everything was verified on the other end, Fortinet TAC did bunch of checks and TAC asked us on CP side to change the MSS value.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I honestly have no idea where TAC guy got the info that 10-20% is the most you would get through the VPN, because to me, I have a hard time believing that. I was thinking there was a way to actually change mss values per vpn community, but does not seem so.&lt;/P&gt;
&lt;P&gt;Things CP TAC suggested so far that we did:&lt;/P&gt;
&lt;P&gt;-install latest jumbo for R81.10 (though in all fairness, that is a suggestion no matter the problem)&lt;/P&gt;
&lt;P&gt;-cluster failover&lt;/P&gt;
&lt;P&gt;-try disable sxl&lt;/P&gt;
&lt;P&gt;-vpn accel off for that specific tunnel&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 02:04:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175514#M32033</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-21T02:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175520#M32036</link>
      <description>&lt;P&gt;Generally if outright speed is what you're after you may need to adjust some things, refer:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk73980" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk73980&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With that said I see you've tried different encryption methods without success. Do you see individual CPU/cores peaking?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 02:38:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175520#M32036</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-21T02:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175522#M32037</link>
      <description>&lt;P&gt;That was the first thing that initial engineer asked us to do and it did not change anything, it was exact same issue. Not saying its not successful for others, but it was not for us.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 02:24:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175522#M32037</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-21T02:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175527#M32040</link>
      <description>&lt;P&gt;Per &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;above were your tests also running a single flow or multiple threads?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 03:06:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175527#M32040</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-21T03:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175530#M32041</link>
      <description>&lt;P&gt;Multiple.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 03:25:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175530#M32041</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-21T03:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175531#M32042</link>
      <description>&lt;P&gt;Noted, in that case the issue is different than that stated by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21468"&gt;@Juergen_Blumens&lt;/a&gt;&amp;nbsp;here.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 03:36:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175531#M32042</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-21T03:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175532#M32043</link>
      <description>&lt;P&gt;True...every case is different &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 03:38:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175532#M32043</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-21T03:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175619#M32062</link>
      <description>&lt;P&gt;iked being multithreaded in R81.20 should help performance a bit.&amp;nbsp;&lt;BR /&gt;However, VPN traffic not involving other blades will still be constrained to what a single SND core can handle (per flow).&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2023 17:46:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175619#M32062</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-21T17:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175652#M32066</link>
      <description>&lt;P&gt;Please see this lengthy thread which hashes out the performance of the 3800 for VPNs:&lt;/P&gt;
&lt;P&gt;&lt;A id="link_12" href="https://community.checkpoint.com/t5/Security-Gateways/Check-Point-CPAP-SG3800-and-expected-performance-levels/m-p/138484?search-action-id=61027241184&amp;amp;search-result-uid=138484" target="_blank"&gt;Check&amp;nbsp;Point&amp;nbsp;CPAP-SG3800&amp;nbsp;and&amp;nbsp;expected&amp;nbsp;performance&amp;nbsp;l...&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You are almost certainly saturating a single SND core with your fully-accelerated VPN traffic and it simply cannot go any faster.&amp;nbsp; Unfortunately the 3800 uses a ultra-low voltage processor architecture, whose individual cores are at least 2-3 times slower than Xeon cores.&amp;nbsp; Intel tries to make up for this by having more cores available (8 in your case) which doesn't help your situation.&amp;nbsp; I did make some rather unorthodox "last ditch" recommendations in the prior thread that may help you, check them out.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Mar 2023 00:01:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/175652#M32066</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-03-22T00:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176259#M32251</link>
      <description>&lt;P&gt;This is the CPU load and the Bandwidth.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CPU.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20253i4A6992F837E2B828/image-size/large?v=v2&amp;amp;px=999" role="button" title="CPU.png" alt="CPU.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="BW.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20254i0EB60F432A8676EC/image-size/large?v=v2&amp;amp;px=999" role="button" title="BW.png" alt="BW.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 09:36:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176259#M32251</guid>
      <dc:creator>Juergen_Blumens</dc:creator>
      <dc:date>2023-03-27T09:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176260#M32252</link>
      <description>&lt;P&gt;Thanks for your reply and the reference to the other thread. We also tried with a 6200 and did not get more bandwidth. Is the architecture comparable to the 3800?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 09:39:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176260#M32252</guid>
      <dc:creator>Juergen_Blumens</dc:creator>
      <dc:date>2023-03-27T09:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176261#M32253</link>
      <description>&lt;P&gt;Yes comparable in that many / multiple parallel TCP or UDP connections are needed for best results.&lt;/P&gt;
&lt;P&gt;Recent versions have introduced technologies such as &lt;A href="https://youtu.be/JdWbY5IQL9E" target="_self"&gt;Hyperflow&lt;/A&gt; to contend with similar non-VPN scenarios (for systems with +8 CPU cores).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sk178070: HyperFlow in R81.20 and higher&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 11:37:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176261#M32253</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-27T11:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176281#M32264</link>
      <description>&lt;P&gt;I don't know the precise CPU type in the 6200, but the 3800 is rated for 2.75Gbps of VPN throughput while the 6200 is rated for 2.57Gbps, so I'd say they are comparable.&amp;nbsp; I'm assuming these numbers are for all available cores being used simultaneously for VPN, not just one.&lt;/P&gt;
&lt;P&gt;As I mentioned earlier the graphs show that VPN traffic is fully saturating a single SND core, and there is no way to spread the traffic of a single tunnel across multiple SND cores that I know of.&amp;nbsp; Hyperflow does not help with VPN traffic at this time and neither does Lightspeed.&amp;nbsp; Multi-core VPN only applies on Firewall Worker/Instance cores.&lt;/P&gt;
&lt;P&gt;One non-intuitive thing to try: set 3DES for IPSec/Phase 2, measure performance, then set&amp;nbsp;IPSec/Phase 2 for AES-128 and measure again.&amp;nbsp; The AES-128 speed should be at least double that of 3DES, if not you are bumping up against some other kind of limitation other than firewall CPU.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 12:00:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176281#M32264</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-03-27T12:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176309#M32273</link>
      <description>&lt;P&gt;3800 uses an &lt;A href="https://ark.intel.com/content/www/us/en/ark/products/97926/intel-atom-processor-c3758-16m-cache-up-to-2-20-ghz.html" target="_self"&gt;Atom C3758&lt;/A&gt; (8c8t, 3.125W/c), while the 6200 uses a &lt;A href="https://ark.intel.com/content/www/us/en/ark/products/129951/intel-pentium-gold-g5400-processor-4m-cache-3-70-ghz.html" target="_self"&gt;Pentium&amp;nbsp;&lt;/A&gt;&lt;SPAN&gt;&lt;A href="https://ark.intel.com/content/www/us/en/ark/products/129951/intel-pentium-gold-g5400-processor-4m-cache-3-70-ghz.html" target="_self"&gt;G5400&lt;/A&gt; (2c4t, 29W/c). I would expect a 6200 to perform&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;significantly&lt;/STRONG&gt;&lt;/EM&gt; better with a single traffic flow, since it has nearly ten times the power budget to work with.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 14:17:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176309#M32273</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-03-27T14:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176370#M32285</link>
      <description>&lt;P&gt;I would agree, which makes me think that he is bumping against some other kind of performance limitation, not necessarily on the firewall itself.&amp;nbsp; The 3DES/AES-128 test I mentioned in a prior post should help reveal what is going on.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2023 23:35:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176370#M32285</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-03-27T23:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176382#M32287</link>
      <description>&lt;P&gt;A packet capture to see TCP window sizes, MSS (and derived MTU) values would also be helpful perhaps.&lt;/P&gt;
&lt;P&gt;Namely to confirm fragmentation has been dealt with by enabling MSS clamping etc.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 02:43:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/176382#M32287</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-03-28T02:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/179186#M32841</link>
      <description>&lt;P&gt;Even though the 3800 model has 8 cores which is the minimum required to support Hyperflow, I find it interesting that&amp;nbsp;sk178070 was just updated to state that the 3800 model does *not* support Hyperflow.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 01:46:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/179186#M32841</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-04-26T01:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Maximum reachable bandwidth 3800</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/179255#M32849</link>
      <description>&lt;P&gt;Yes, the 3800 does not support Hyperflow due to hardware limitations (not specific to the number of cores available).&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 17:48:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Maximum-reachable-bandwidth-3800/m-p/179255#M32849</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-26T17:48:10Z</dc:date>
    </item>
  </channel>
</rss>

