<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTPS Inspection Performance in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/189343#M34835</link>
    <description>&lt;P&gt;Enhancements were made throughout the chain from handshake through to blade handover in order to realize the improvement.&lt;/P&gt;
&lt;P&gt;I don't have visibility of specifics or portability aspects at this time, those are areas for R&amp;amp;D.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 14 Aug 2023 09:14:58 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-08-14T09:14:58Z</dc:date>
    <item>
      <title>HTTPS Inspection Performance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188680#M34740</link>
      <description>&lt;P&gt;I'm thinking of enabling HTTPS Inspection, but I want to know:&lt;/P&gt;&lt;P&gt;* How it affects the performance of my devices&lt;BR /&gt;* Is an extra blade necessary?&lt;BR /&gt;* Can the certificate generated by the device be generated without any problem?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Aug 2023 23:12:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188680#M34740</guid>
      <dc:creator>Itzel_Gtz26</dc:creator>
      <dc:date>2023-08-04T23:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Performance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188682#M34741</link>
      <description>&lt;P&gt;HTTPS inspection will have a performance impact relative to the traffic mix seen in the environment.&amp;nbsp;&lt;SPAN&gt;To assist offset this R81.20 provides the best HTTPS inspection performance relative to other versions.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Typically you would import a certificate from your organisation's CA and this should be trusted by clients in favour of using one generated from the Management itself.&lt;/P&gt;
&lt;P&gt;Most other blades depend on HTTPS inspection for better visibility / enforcement of encrypted traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2023 05:02:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188682#M34741</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-08-05T05:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Performance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188698#M34742</link>
      <description>&lt;P&gt;Chris,&lt;BR /&gt;&lt;BR /&gt;What are the performance ratings for each device, this is not published in the device spec sheets and really should be.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2023 14:29:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188698#M34742</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2023-08-05T14:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Performance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188716#M34743</link>
      <description>&lt;P&gt;I believe we are planning to update datasheets with the metrics based on R81.20 in future.&lt;/P&gt;
&lt;P&gt;If you need specific data prior you can engage Solution Centre via your local CP office / SE.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Aug 2023 10:21:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188716#M34743</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-08-06T10:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Performance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188723#M34744</link>
      <description>&lt;P&gt;Thanks Chris.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Aug 2023 15:50:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188723#M34744</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2023-08-06T15:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Performance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188832#M34755</link>
      <description>&lt;P&gt;So in R81.10 there is no way to know how it affects performance?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Aug 2023 23:38:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188832#M34755</guid>
      <dc:creator>Itzel_Gtz26</dc:creator>
      <dc:date>2023-08-07T23:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Performance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188885#M34761</link>
      <description>&lt;P&gt;Oh there is, but Checkpoint does not publish this.&amp;nbsp; In my option if you look at the current appliances, there is no hardware offload for SSL encryption/decryption, so you know that if an appliance is rated at 4GB throughput with NGTP there are a few assumptions you would potentially need to make:&lt;BR /&gt;&lt;BR /&gt;- The figures quoted are not with TLS inspection on; Therefore what is inspected&amp;nbsp;in NGTP is greatly reduced.&lt;BR /&gt;- If TLS inspection was turned on, and depending how your policy is configured (big variable) , take that 4GB and you may as well assume throughput figure is more like 500MB (again an assumption).&lt;/P&gt;
&lt;P&gt;In most cases I suspect that Checkpoint would not recommended anything less then a 6600 when TLS inspection is required, and at the cost point this becomes a totally impractical solution for branch offices, which is why allot of companies that are not cash rich are moving away from Checkpoint to vendors that tick all the boxes at a better price point.&lt;BR /&gt;&lt;BR /&gt;What I'm hoping, and again have said this to Checkpoint, that their hardware needs a radical update and all figured, by default should be published with TLS inspection turned on and we need to clear understanding of the testing carried out ie. what is the TLS policy actually inspecting.&lt;BR /&gt;&lt;BR /&gt;Palo and Fortinet both have hardware offload for TLS inspection (Dependent on model and use case).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 09:02:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188885#M34761</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2023-08-08T09:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Performance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188936#M34765</link>
      <description>&lt;P&gt;Are you looking for an arbitrary % overhead figure and to what end?&lt;/P&gt;
&lt;P&gt;Yes there is a performance penalty with multiple inputs/variables that your local SE can help to quantify specific to your environment &amp;amp; requirements.&lt;SPAN&gt;&amp;nbsp;Please work with them to better&amp;nbsp; understand your scenario &amp;amp; sizing accordingly.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 12:21:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188936#M34765</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-08-08T12:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Performance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188951#M34768</link>
      <description>&lt;P&gt;Can I get a clarification on what specific portion of the HTTPS Inspection feature had its performance improved in R81.20, specifically was it:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;1) Bulk encryption/decryption speed &amp;amp; efficiency - kind of unlikely there is much to be gained here that hasn't already been&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;2) HTTPS negotiation, key creation &amp;amp; signing (wstlsd/pkxld), example: &lt;EM&gt;PRJ-35986, PMTR-69155; SSL Inspection; UPDATE: Major&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;performance improvement in HTTPS Inspection of TLS 1.3&amp;nbsp;&lt;/EM&gt;- more likely&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;3) Active streaming allowing TCP window to increase to far higher values &lt;EM&gt;UPDATE: Check Point Active&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Streaming (CPAS) TCP Window scale factor is now increased up to 6&lt;/EM&gt; or a fix for fragmentation occurring when client MSS and server MSS differ under active streaming - most likely but not directly a performance improvement in the HTTPS Inspection feature itself&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 13:09:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188951#M34768</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-08-08T13:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Performance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188961#M34769</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;I'll attempt to source some feedback for you and revert&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 13:52:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188961#M34769</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-08-08T13:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Performance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188996#M34772</link>
      <description>&lt;P&gt;Thanks Chris.&amp;nbsp; Obviously the follow-up question would be are these performance enhancement features unique to R81.20, or can/will they be back-ported into earlier releases via Jumbo HFA.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 19:44:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/188996#M34772</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-08-08T19:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: HTTPS Inspection Performance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/189343#M34835</link>
      <description>&lt;P&gt;Enhancements were made throughout the chain from handshake through to blade handover in order to realize the improvement.&lt;/P&gt;
&lt;P&gt;I don't have visibility of specifics or portability aspects at this time, those are areas for R&amp;amp;D.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 09:14:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HTTPS-Inspection-Performance/m-p/189343#M34835</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-08-14T09:14:58Z</dc:date>
    </item>
  </channel>
</rss>

