<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN tunnel latency with AWS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193721#M35993</link>
    <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;100%. Version aside, even if you were on R81.20 and had same problem, I would also say to check the same things Chris mentioned.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 28 Sep 2023 01:14:50 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-09-28T01:14:50Z</dc:date>
    <item>
      <title>VPN tunnel latency with AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193719#M35991</link>
      <description>&lt;P&gt;Hello everybody!&lt;BR /&gt;How are you doing?&lt;BR /&gt;I am writing to you because we are having a latency problem against one of the VPNs that are created against an AWS platform.&lt;BR /&gt;On our side we have two VTI interfaces configured and the connections are made through an Internet link.&lt;BR /&gt;The current version of Gaia is R80.30.&lt;BR /&gt;The problem is that we see that the transfers made over this VPN have a limit of between 1.5 Mbps and 3.5 Mbps. In view of this, some files are reported to be lost due to timeouts or excessive slowness when transferring certain files.&lt;BR /&gt;We checked the connections with the CPView tool but found nothing unusual.&lt;BR /&gt;Do you have any idea what it could be? Or what could we check?&lt;BR /&gt;Thank you very much, we wanted to know this, before opening a case with TAC.&lt;BR /&gt;Regardss to al!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 00:32:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193719#M35991</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2023-09-28T00:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel latency with AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193720#M35992</link>
      <description>&lt;P&gt;R80.30 is no longer supported and you should consider upgrading to R81.10 / R81.20.&lt;/P&gt;
&lt;P&gt;With that said could you please confirm some elements for context?&lt;/P&gt;
&lt;P&gt;- Configured MTU value&lt;/P&gt;
&lt;P&gt;- MSS clamping enabled y/n&lt;/P&gt;
&lt;P&gt;- Jumbo version&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 01:04:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193720#M35992</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-09-28T01:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel latency with AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193721#M35993</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;100%. Version aside, even if you were on R81.20 and had same problem, I would also say to check the same things Chris mentioned.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 01:14:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193721#M35993</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-28T01:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel latency with AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193761#M36010</link>
      <description>&lt;P&gt;Almost certainly a sub-1500 MTU somewhere in the network path as Chris mentioned.&amp;nbsp; This is covered in my &lt;A href="http://www.maxpowerfirewalls.com/gw-optimization-course.html" target="_self"&gt;Gateway Performance Optimization Course&lt;/A&gt;, here is the relevant content:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mtu11.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22601iB3D5FE200AF33F0E/image-size/large?v=v2&amp;amp;px=999" role="button" title="mtu11.png" alt="mtu11.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mtu12.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22602i6336756C9A1D0E82/image-size/large?v=v2&amp;amp;px=999" role="button" title="mtu12.png" alt="mtu12.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mtu13.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22603i17D512907B224D12/image-size/large?v=v2&amp;amp;px=999" role="button" title="mtu13.png" alt="mtu13.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 12:38:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193761#M36010</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-09-28T12:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel latency with AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193764#M36013</link>
      <description>&lt;P&gt;Hi Chris.&lt;BR /&gt;How are you doing?&lt;BR /&gt;Thank you for your reply.&lt;BR /&gt;Yes, we know, we still have the update pending, we had to do a rollback due to a problem when upgrading.&lt;BR /&gt;The jumbo currently installed is 251.&lt;BR /&gt;The configured MTU is 1500 on both VTIs.&lt;BR /&gt;We check that the MSS is enabled, through the following command #fw_clamp_vpn_mss&lt;BR /&gt;Thank you very much for your response.&lt;BR /&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 13:31:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193764#M36013</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2023-09-28T13:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel latency with AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193767#M36014</link>
      <description>&lt;P&gt;Hello Timothy.&lt;BR /&gt;How are you doing?&lt;BR /&gt;Nice to meet you.&lt;BR /&gt;Thank you very much for your answer and detailed explanation, it is very useful for us to better understand this latency problem.&lt;BR /&gt;We will try the solution proposed in the materials you shared with us to validate that it fits our issue and to solve it.&lt;BR /&gt;Again thank you very much for your response.&lt;BR /&gt;We will let you know the results soon.&lt;BR /&gt;Thank you very much for your reply.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 13:45:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193767#M36014</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2023-09-28T13:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel latency with AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193769#M36016</link>
      <description>&lt;P&gt;Let me clarify.&lt;BR /&gt;The previous command I mentioned returned a value of 1 as enabled, however when I ran the following command the result was 0&lt;BR /&gt;command: #fw ctl get int fw_clamp_tcp_mss&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 13:59:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193769#M36016</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2023-09-28T13:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel latency with AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193770#M36017</link>
      <description>&lt;P&gt;There can be other causes but AWS typically mandated changes to the tunnel MTU &amp;amp; MSS please refer&amp;nbsp;&lt;SPAN&gt;s&lt;/SPAN&gt;&lt;SPAN&gt;k108958.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 14:08:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193770#M36017</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-09-28T14:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel latency with AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193811#M36026</link>
      <description>&lt;P&gt;AWS generated config file states MTU should be set at 1399 and recommends enabling MSS Clamping. I have many S2S against AWS and things have been running smooth.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 269px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22605iD13D2BE9A3C58675/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 19:58:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193811#M36026</guid>
      <dc:creator>Zolocofxp</dc:creator>
      <dc:date>2023-09-28T19:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel latency with AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193814#M36027</link>
      <description>&lt;P&gt;Thats an excellent point...I mostly dealt with Azure VPN tunnels and IM sure same sort of file is generated on AWS as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 20:03:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193814#M36027</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-28T20:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel latency with AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193891#M36043</link>
      <description>&lt;P&gt;Hi guys.&lt;BR /&gt;While trying to do a tracepath we could detect the following error related to the mtu when running in another shell window a debug in parallel.&lt;BR /&gt;I share with you the output of the command.&lt;BR /&gt;fw_log_drop_ex: Packet proto=17 x.x.x.x.x -&amp;gt; x.x.x.x.x dropped by fwlinux_nfipout Reason: packet with IP_DF larger than MTU;&lt;BR /&gt;Considering this error, do you recommend changing the MTU on both ends? The 2 VTI and also on the VPC side? On both ends it is 1500.&lt;BR /&gt;Thank you very much.&lt;BR /&gt;Regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 13:31:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193891#M36043</guid>
      <dc:creator>Agust</dc:creator>
      <dc:date>2023-09-29T13:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel latency with AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193892#M36044</link>
      <description>&lt;P&gt;If AWS config file shows you certain value, as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28648"&gt;@Zolocofxp&lt;/a&gt;&amp;nbsp;mentioned yesterday, then thats most logical value you should use, so it matches on both ends.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 13:34:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-latency-with-AWS/m-p/193892#M36044</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-29T13:34:26Z</dc:date>
    </item>
  </channel>
</rss>

