<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec Throughput in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223730#M42925</link>
    <description>&lt;P&gt;Enabled blades is : Firewall, S2S VPN, Mobile Access, App Control, URL Filtering, IPS, Antibot, Antivirus, network policy management &amp;amp; Log.&lt;/P&gt;
&lt;P&gt;The encryption i used on VPN community string is AES-256 for phase 1 and 3DES for phase 2&lt;/P&gt;</description>
    <pubDate>Thu, 15 Aug 2024 09:48:16 GMT</pubDate>
    <dc:creator>handiansudianto</dc:creator>
    <dc:date>2024-08-15T09:48:16Z</dc:date>
    <item>
      <title>IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223724#M42920</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;My internet connection speed is 100Mbps, testing by accessing speedtest.net and showing 101.90Mbps for download and 115.14Mbps for upload.&lt;/P&gt;
&lt;P&gt;I also have IPsec site to site tunnel to connecting our onprem to azure, and when i do speed test by copy larger file from onprem to the azure i can see the traffic is not fully utilize the available bandwidth.&lt;/P&gt;
&lt;P&gt;testing speed only get about 3-4 MB/s or about 30Mbps. Anyone know how to fine tuning my checkpoint to get better utilization for ipsec?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-08-15 145439.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27250i7FFE597F04E01B49/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-08-15 145439.png" alt="Screenshot 2024-08-15 145439.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 08:04:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223724#M42920</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-08-15T08:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223725#M42921</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/88545"&gt;@handiansudianto&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And what about the load of the participating gateways in S2S tunnel? One for eg. SCP connection is handled by one CPU core. Can you check the CPU-s on both side?&lt;/P&gt;
&lt;P&gt;Maybe the bottleneck is on the AZURE side? Can you check it somehow without VPN?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 08:28:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223725#M42921</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-15T08:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223726#M42922</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;This depends on a few factors. Most common:&lt;/P&gt;
&lt;P&gt;What blades are enabled on the gateways.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What encryption methods are used? (for example 3DES is not only very unsafe but also very intensive for the load)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 08:40:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223726#M42922</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-15T08:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223728#M42924</link>
      <description>&lt;P&gt;How i can check the load?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 09:45:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223728#M42924</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-08-15T09:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223730#M42925</link>
      <description>&lt;P&gt;Enabled blades is : Firewall, S2S VPN, Mobile Access, App Control, URL Filtering, IPS, Antibot, Antivirus, network policy management &amp;amp; Log.&lt;/P&gt;
&lt;P&gt;The encryption i used on VPN community string is AES-256 for phase 1 and 3DES for phase 2&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 09:48:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223730#M42925</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-08-15T09:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223736#M42927</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/88545"&gt;@handiansudianto&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#cpview&amp;nbsp;&lt;/P&gt;
&lt;P&gt;#top&lt;/P&gt;
&lt;P&gt;#htop&lt;/P&gt;
&lt;P&gt;If you are not familiar with the last 2 commands use #cpview CPU tab. You will see the CPU utilization&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 10:43:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223736#M42927</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-15T10:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223740#M42928</link>
      <description>&lt;DIV id="tinyMceEditor_6c1990b66ecachandiansudianto_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;Here result of 3 command, seems the utilization is normal.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cpvoew.png" style="width: 833px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27251i003A6B8F55DAAB75/image-size/large?v=v2&amp;amp;px=999" role="button" title="cpvoew.png" alt="cpvoew.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="top.png" style="width: 901px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27252i55D1933C1E1D5516/image-size/large?v=v2&amp;amp;px=999" role="button" title="top.png" alt="top.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="htop.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27253i241BD4CDF14FFF2A/image-size/large?v=v2&amp;amp;px=999" role="button" title="htop.png" alt="htop.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 10:48:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223740#M42928</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-08-15T10:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223741#M42929</link>
      <description>&lt;P&gt;3des is the worst for performance see:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk73980" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk73980&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk98950" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk98950&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Change asap since it is very weak encryption method&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 11:03:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223741#M42929</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-15T11:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223749#M42930</link>
      <description>&lt;P&gt;I can tell you that literally 99% of the time when I worked with folks on this exact problem, I always found it to be one of the 2 problems.&lt;/P&gt;
&lt;P&gt;1) Encryption methods used&amp;nbsp;&lt;/P&gt;
&lt;P&gt;OR&lt;/P&gt;
&lt;P&gt;2) MTU size&lt;/P&gt;
&lt;P&gt;Never a combination of both.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 12:35:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223749#M42930</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-15T12:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223750#M42931</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Site-to-Site VPN performance issues generally come down to some combination of these three things:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1) &lt;STRONG&gt;Path Low MTU Issues&lt;/STRONG&gt; - From expert mode on your Check Point firewall run &lt;STRONG&gt;tracepath&lt;/STRONG&gt; to your Azure VPN peer, this will report the max MTU for that network path.&amp;nbsp; If it is less than 1500 you may need to allow ICMP Type 3, Code 4 packets into your firewall from anywhere for pmtud to work, or look at TCP MSS Clamping&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2) &lt;STRONG&gt;Slow algorithms in use like 3DES&lt;/STRONG&gt; (already mentioned in this thread) - remember that the Phase 2/IPSec tunnel transfers the vast majority of data through a VPN so its encryption setting will have a far greater impact than the one for IKE/Phase 1.&amp;nbsp; You may want to look at using the GCM versions of AES which are even more efficient than standard AES and also capable of being fully offloaded into the AES-NI processor extension, if the Azure peer supports GCM&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;3) Encryption/Decryption operations for a particular VPN tunnel can only happen on &lt;STRONG&gt;one core, or are stuck in the slowpath&lt;/STRONG&gt; - If the first two listed are not the issue (check them first), the traffic may be in the F2F/slowpath due to what blades you have enabled or other unusual conditions being present, or it is being bottlenecked by single-core limitations as in the case of an elephant flow&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;All this is covered quite extensively in my &lt;A href="http://www.maxpowerfirewalls.com/gw-optimization-course.html" target="_blank" rel="noopener"&gt;Gateway Performance Optimization Course&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 14:14:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223750#M42931</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-11-28T14:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223814#M42953</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Changed to AES-128 and have better throughput. Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 01:32:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223814#M42953</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-08-16T01:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223816#M42954</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Here result of tracepath, seem 1500 MTU i used. Am i right?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 852px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27262i31403D571738DF5E/image-size/large?v=v2&amp;amp;px=999" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 01:36:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223816#M42954</guid>
      <dc:creator>handiansudianto</dc:creator>
      <dc:date>2024-08-16T01:36:08Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec Throughput</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223818#M42956</link>
      <description>&lt;P&gt;You got it.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 02:22:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-Throughput/m-p/223818#M42956</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-16T02:22:08Z</dc:date>
    </item>
  </channel>
</rss>

