<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221762#M42467</link>
    <description>&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/VPN-Tunnels-Capacity/td-p/6914" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/VPN-Tunnels-Capacity/td-p/6914&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/td-p/163683" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/td-p/163683&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jul 2024 11:39:50 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-07-24T11:39:50Z</dc:date>
    <item>
      <title>Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221758#M42464</link>
      <description>&lt;P&gt;Hi CheckMates !&amp;nbsp;&lt;BR /&gt;&lt;SPAN class=""&gt;I&lt;/SPAN&gt; &lt;SPAN class=""&gt;would&lt;/SPAN&gt; &lt;SPAN class=""&gt;like&lt;/SPAN&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;SPAN class=""&gt;know&lt;/SPAN&gt; &lt;SPAN class=""&gt;if&lt;/SPAN&gt; &lt;SPAN class=""&gt;GAIA&lt;/SPAN&gt; &lt;SPAN class=""&gt;OS&lt;/SPAN&gt;&lt;SPAN&gt; has a hard limit&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;/SPAN&gt; &lt;SPAN class=""&gt;concurrent&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;S2S&lt;/SPAN&gt; &lt;SPAN class=""&gt;vpn&lt;/SPAN&gt; &lt;SPAN class=""&gt;tunnels&lt;/SPAN&gt;&lt;SPAN class=""&gt;?&lt;/SPAN&gt; &lt;SPAN class=""&gt;Or&lt;/SPAN&gt;&lt;SPAN&gt; am &lt;/SPAN&gt;&lt;SPAN class=""&gt;I&lt;/SPAN&gt; &lt;SPAN class=""&gt;limited&lt;/SPAN&gt; &lt;SPAN class=""&gt;only&lt;/SPAN&gt;&lt;SPAN&gt; by the &lt;/SPAN&gt;&lt;SPAN class=""&gt;performance&lt;/SPAN&gt;&lt;SPAN&gt; of the &lt;/SPAN&gt;&lt;SPAN class=""&gt;hardware&lt;/SPAN&gt;&lt;SPAN class=""&gt;.&lt;BR /&gt;A little about the task - customer has about 10k third party devices that need&lt;SPAN&gt; to be &lt;/SPAN&gt;connected&lt;SPAN&gt; using &lt;/SPAN&gt;the star topology (to center only).&lt;SPAN&gt; The &lt;/SPAN&gt;total bandwidth&lt;SPAN&gt; of the &lt;/SPAN&gt;Internet channel&lt;SPAN&gt; is &lt;/SPAN&gt;about 500 Mbit/s&amp;nbsp;for ALL vpn tunnels. Traffic in these tunnels&lt;SPAN&gt; is &lt;/SPAN&gt;very low.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 09:58:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221758#M42464</guid>
      <dc:creator>let4</dc:creator>
      <dc:date>2024-07-24T09:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221761#M42466</link>
      <description>&lt;P&gt;No such maximum number is listed in the Release Notes:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Maximum-Supported-Items.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Maximum-Supported-Items.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;However, 10K devices is a lot, even if they do not generate too much traffic. the main toll will be on CA &amp;amp; SPI negotiations, on the central GW side.&lt;BR /&gt;&lt;BR /&gt;I would advise to engage PS to validate this will work.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 11:38:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221761#M42466</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-07-24T11:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221762#M42467</link>
      <description>&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/VPN-Tunnels-Capacity/td-p/6914" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/VPN-Tunnels-Capacity/td-p/6914&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/td-p/163683" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/td-p/163683&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 11:39:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221762#M42467</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-24T11:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221829#M42503</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;said, there isn't a real software limit on this.&lt;BR /&gt;However, I will echo is point to involve someone from Check Point (either your Security Engineer or Professional Services) validate the design.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 14:49:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221829#M42503</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-24T14:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221858#M42515</link>
      <description>&lt;P&gt;2 tips I have:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/Large-Scale-VPN.htm?Highlight=limit" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/Large-Scale-VPN.htm?Highlight=limit&lt;/A&gt;&lt;/P&gt;
&lt;H1&gt;Large Scale VPN&lt;/H1&gt;
&lt;P&gt;A VPN that connects branch offices, worldwide partners, remote clients, and other environments, can reach hundreds or thousands of peers. A VPN on this scale brings new challenges.&lt;/P&gt;
&lt;P&gt;Each time a new VPN peer is deployed in production configuration and policy installation is required for all participating VPN&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gwscap variable"&gt;Gateways&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;Large Scale VPN (LSV) addresses these challenges and facilitates deployment without the need for peer configuration and policy installation.&lt;/P&gt;
&lt;P&gt;Second tips. I think there is a default software limit for VPN tunnels. Not 100% sure if this related to VPN clients or site to site vpn's. I suspect the last one. See screenshot.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn-limit.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26981iA779E7E4316BF755/image-size/medium?v=v2&amp;amp;px=400" role="button" title="vpn-limit.jpg" alt="vpn-limit.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 20:37:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221858#M42515</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-07-24T20:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221863#M42517</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;&amp;nbsp;made an excellent point with the screenshot. I had diamond guy tell me once that value does not really have anything to do with number of tunnels, meaning if you put 99k number there it would mean you can create 99,000 tunnels (not at all), but it does help if you have LOTS of tunnels, for sure.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 22:55:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221863#M42517</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-24T22:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221864#M42518</link>
      <description>&lt;P&gt;I never really checked max value for that option before, but shows 1M...I mean, lets be honest...what fw on this planet could withstand 1 million vpn tunnels? LOL&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 23:15:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221864#M42518</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-24T23:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221887#M42523</link>
      <description>&lt;P&gt;Hi! Thank you very much for your answers. It helped me a lot.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 11:45:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221887#M42523</guid>
      <dc:creator>let4</dc:creator>
      <dc:date>2024-07-25T11:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221890#M42524</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/74991"&gt;@let4&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FWIW, below is what Benny said back in 2017, but he never really answered where he got those numbers from. But, lets assume IF they are indeed correct, I would say, logically, 6000 appliance series can probably support about 70K tunnels (just my "mathematical" estimate lol)&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26984iCB91E71D66C9C576/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 12:12:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221890#M42524</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-25T12:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221894#M42526</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi! Thanks for the reply. As I understand it, there are no hard limit. The question remains how size it correctly. As far as I remember, the VPN process in GAIA is able to work in a multithreading. A large number of CPU cores should ensure stability. Is it possible to use Maestro for this task? Or it's not profitable.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 12:28:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221894#M42526</guid>
      <dc:creator>let4</dc:creator>
      <dc:date>2024-07-25T12:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221896#M42527</link>
      <description>&lt;P&gt;Im not maestro expert at all (I know very basics of it), but I know we have customer using it and they have lots of tunnels, no issues, most of them route based actually.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, I would say yes to that question.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 12:33:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221896#M42527</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-25T12:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221909#M42531</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks for help!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 13:46:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221909#M42531</guid>
      <dc:creator>let4</dc:creator>
      <dc:date>2024-07-25T13:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221910#M42532</link>
      <description>&lt;P&gt;Concurrent tunnels depend on RAM, not processor cores. In the past, Check Point included very little RAM in their default configurations, but they've gotten a bit better about that. Even the base 9100 has 16 GB of RAM now. That should be enough for 50k VPNs, no problem. Stick to gateway-to-gateway tunnels (both sides negotiate 0.0.0.0/0) to keep the number of keys per tunnel to a minimum.&lt;/P&gt;
&lt;P&gt;Throughput (no matter how many tunnels) depends on processor power. As long as you have a relatively current processor, a single core can get well over a gigabit of throughput.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 13:50:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221910#M42532</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-07-25T13:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Software limit on the concurrent S2S vpn tunnels for GAIA OS?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221917#M42538</link>
      <description>&lt;P&gt;There are some parts of VPN that have historically been single core, which can create some scalability issues.&lt;BR /&gt;R81.20 has made some additional improvements in this area, as I recall.&lt;/P&gt;
&lt;P&gt;Maestro certainly leverages all this, but again, I would have someone from Check Point validate your proposed design.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jul 2024 14:35:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Software-limit-on-the-concurrent-S2S-vpn-tunnels-for-GAIA-OS/m-p/221917#M42538</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-25T14:35:17Z</dc:date>
    </item>
  </channel>
</rss>

