<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iperf test speeds are different on internal and external for QoS testing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225169#M43314</link>
    <description>&lt;P&gt;I completely agree. But I'm still puzzled by the fact that that's not the case when I initiate the traffic from PC. Just created a Linux Mint machine to try with, and it also can see 1gbps speeds.&amp;nbsp;&lt;/P&gt;&lt;P&gt;F2F only happens when iperf traffic is initiated from the other GW.&lt;/P&gt;&lt;P&gt;Why do you think could this be?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Aug 2024 18:20:59 GMT</pubDate>
    <dc:creator>kamilazat</dc:creator>
    <dc:date>2024-08-30T18:20:59Z</dc:date>
    <item>
      <title>iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/224981#M43276</link>
      <description>&lt;P&gt;Hello all!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been playing with QoS to understand what goes on and how goes on. Then I noticed a weird behavior.&lt;/P&gt;&lt;P&gt;Here's my simple setup (all R81.20):&lt;/P&gt;&lt;P&gt;PC1 (192.168.1.0/24) -- GW1 ---(10.0.0.0/24)--- GW2 -- PC2 (192.168.4.0/24)&lt;/P&gt;&lt;P&gt;Everything is in an isolated VMware environment, so I don't care about security or systems breaking.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I do iperf3 from PC1 to GW1 I'm getting speeds up to 1gbps. But when I do the same thing between GW1 and GW2 I get a maximum of 315mbps.&lt;/P&gt;&lt;P&gt;At first I thought I wasn't setting QoS properly. But when set a rule with 100mbps limit, everything works with a maximum of 100mbps. I tried parallel connections with iperf3 -c x.x.x.x -P 4, and with different -P values, but the result is always the same.&lt;/P&gt;&lt;P&gt;I looked at fw ctl chain to maybe see something and noticed that inbound and outbound names for QoS are different.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;[Expert@GW1:0]# fw ctl chain&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;in chain (22):&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;0: -7fffffff (0000000000000000) (00000000) SecureXL stateless check (sxl_state_check)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;1: -7ffffffe (0000000000000000) (00000000) SecureXL VPN before decryption (vpn_in_before_decrypt)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;2: -7ffffffd (0000000000000000) (00000000) SecureXL VPN after decryption (vpn_in_after_decrypt)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;3: 6 (0000000000000000) (00000000) SecureXL lookup (sxl_lookup)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;4: 7 (0000000000000000) (00000000) SecureXL QOS inbound (sxl_qos_inbound)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;5: 8 (0000000000000000) (00000000) SecureXL inbound (sxl_inbound)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;6: 9 (0000000000000000) (00000000) SecureXL medium path streaming (sxl_medium_path_streaming)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;7: 10 (0000000000000000) (00000000) SecureXL inline path streaming (sxl_inline_path_streaming)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;8: 11 (0000000000000000) (00000000) SecureXL Routing (sxl_routing)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;9: -7f800000 (00007fd748ef22e2) (ffffffff) IP Options Strip (in) (ipopt_strip)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;10: - 1fffff8 (00007fd748ef2f40) (00000001) Stateless verifications (in) (asm)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;11: - 1fffff7 (00007fd748ef23c0) (00000001) fw multik misc proto forwarding&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;12: 0 (00007fd748f0fb40) (00000001) fw VM inbound (fw)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;13: 2 (00007fd748ef2a80) (00000001) fw SCV inbound (scv)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;14: 4 (00007fd746bbff30) (00000003) QoS inbound offload chain module&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;15: 5 (00007fd748f26dc0) (00000003) fw offload inbound (offload_in)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;16: 20 (00007fd748f26080) (00000001) fw post VM inbound (post_vm)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;17: 100000 (00007fd748f05196) (00000001) fw accounting inbound (acct)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;18: 22000000 (00007fd746bc1ab0) (00000003) QoS slowpath inbound chain mod (fg_sched)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;19: 7f730000 (00007fd748ef324e) (00000001) passive streaming (in) (pass_str)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;20: 7f750000 (00007fd748f43940) (00000001) TCP streaming (in) (cpas)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;21: 7f800000 (00007fd748ef25c8) (ffffffff) IP Options Restore (in) (ipopt_res)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;out chain (16):&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;0: -7f800000 (00007fd748ef22e2) (ffffffff) IP Options Strip (out) (ipopt_strip)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;1: - 1fffff0 (00007fd748ef2dc0) (00000001) TCP streaming (out) (cpas)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;2: - 1ffff50 (00007fd748ef324e) (00000001) passive streaming (out) (pass_str)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;3: - 1f00000 (00007fd748ef2f40) (00000001) Stateless verifications (out) (asm)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;4: 0 (00007fd748f0fb40) (00000001) fw VM outbound (fw)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;5: 10 (00007fd748f26080) (00000001) fw post VM outbound (post_vm)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;6: 15000000 (00007fd746bc0590) (00000003) QoS outbound offload chain modul (fg_pol)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;7: 21000000 (00007fd746bc1ab0) (00000003) QoS slowpath outbound chain mod (fg_sched)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;8: 7f000000 (00007fd748f05196) (00000001) fw accounting outbound (acct)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;9: 7f700000 (00007fd748ef95d8) (00000001) TCP streaming post VM (cpas)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;10: 7f800000 (00007fd748ef25c8) (ffffffff) IP Options Restore (out) (ipopt_res)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;11: 7f900000 (0000000000000000) (00000000) SecureXL outbound (sxl_outbound)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;12: 7fa00000 (0000000000000000) (00000000) SecureXL QOS outbound (sxl_qos_outbound)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;13: 7fb00000 (0000000000000000) (00000000) SecureXL VPN before encryption (vpn_in_before_encrypt)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;14: 7fc00000 (0000000000000000) (00000000) SecureXL VPN after encryption (vpn_in_after_encrypt)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" size="2"&gt;15: 7fd00000 (0000000000000000) (00000000) SecureXL Deliver (sxl_deliver)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Maybe it is because the internal networks are set as "Internal" and the network between the gateways are set as "External" and the gateways are doing something that slows down the connection. I'm pretty sure that I don't know something about this and everything is working as expected.&lt;/P&gt;&lt;P&gt;So I would deeply appreciate if anyone can illuminate me on this.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 15:10:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/224981#M43276</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-08-29T15:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/224983#M43277</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/102202"&gt;@kamilazat&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;What blades are enabled on GW-s? Enabled blades are degradating the throughput. This is a known behaviour.&lt;/LI&gt;
&lt;LI&gt;The CPU-s are highly utilized?&amp;nbsp;
&lt;UL&gt;
&lt;LI&gt;What are the CPU utilization when you reach only the GW1, and what if you reach the GW2 through the GW1?&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;and the througput values.&amp;nbsp;
&lt;UL&gt;
&lt;LI&gt;but you said that, there is no bottleneck in your demo LAB&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I think, this is where the dog is buried.&lt;/P&gt;
&lt;P&gt;cpview command is you friend, monitor the values during the iperf test.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 15:43:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/224983#M43277</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-29T15:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/224987#M43278</link>
      <description>&lt;P&gt;Akos made all super valid points, I would certainly check those as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 16:10:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/224987#M43278</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T16:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225015#M43280</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;1. Only firewall, QoS and Monitoring is enabled on both gateways. I enabled monitoring later to potentially find something out.&lt;/P&gt;&lt;P&gt;2. CPUs are highly utilized in both GW-GW and PC-GW scenarios. Here they are:&lt;/P&gt;&lt;P&gt;GW-GW (GW1 is server, cpview from it)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gw2gw.png" style="width: 611px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27432i6297AAF03E8E0370/image-size/large?v=v2&amp;amp;px=999" role="button" title="gw2gw.png" alt="gw2gw.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iperfgw2gw.png" style="width: 589px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27433i253E20069EF863B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="iperfgw2gw.png" alt="iperfgw2gw.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PC-GW (GW1 is again server)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pc2gw.png" style="width: 596px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27434i2D37A8EEA22727C9/image-size/large?v=v2&amp;amp;px=999" role="button" title="pc2gw.png" alt="pc2gw.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iperfpc2gw.png" style="width: 464px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27435iEB03F0988FE8E5A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="iperfpc2gw.png" alt="iperfpc2gw.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The values are pretty close. All machines are vanilla installations, except GW1 has Take 76 and GW2 is without any JHF. But I'm not sure if that's the issue. I'm now updating that as well anyway.&lt;BR /&gt;&lt;BR /&gt;It's a VMware environment. I still have RAM and CPU left on the host. Both GWs have 4GB RAM with 8 cores, and PCs 2GB RAM and 4 cores.&lt;BR /&gt;&lt;BR /&gt;Please ask for more information &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:31:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225015#M43280</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-08-29T18:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225017#M43281</link>
      <description>&lt;P&gt;I know in the "old days" of CP, lots of people would fix this by simply disabling corexl from cpconfig, rebooting, re-enable corexl, reboot again.&lt;/P&gt;
&lt;P&gt;Not sure that necessarily might be needed in newer versions, but just wondering, can you maybe run top and ps -auxw commands, so we can see what exactly could be causing cpu problem?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:34:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225017#M43281</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T18:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225019#M43282</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/102202"&gt;@kamilazat&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The 4 GB memory is not few a little bit? What does free -m say?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:40:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225019#M43282</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-29T18:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225020#M43283</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;, 4 GB ram is NOT nearly enough, even if you had 8, I would say that is barely enough...&lt;/P&gt;
&lt;P&gt;Yes, run below and send the output.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@CP-GW:0]# free -h&lt;BR /&gt;total used free shared buff/cache available&lt;BR /&gt;Mem: 22G 5.9G 11G 31M 5.6G 15G&lt;BR /&gt;Swap: 8.0G 0B 8.0G&lt;BR /&gt;[Expert@CP-GW:0]#&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:42:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225020#M43283</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T18:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225021#M43284</link>
      <description>&lt;P&gt;Sure.&lt;/P&gt;&lt;P&gt;GW1&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;[Expert@GW1:0]# free -h&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;total used free shared buff/cache available&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Mem: 3.6G 2.0G 283M 30M 1.3G 721M&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Swap: 7.7G 4.2M 7.7G&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;GW2&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@GW3:0]# free -h&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;total used free shared buff/cache available&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Mem: 3.6G 2.0G 230M 20M 1.4G 782M&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Swap: 8.0G 1.2M 8.0G&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;And still I don't understand why I can get 1gbps when I initiate the test from PC, while between GWs it's 300mbps. Just updated the other GW as well btw, still the same.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225021#M43284</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-08-29T18:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225023#M43285</link>
      <description>&lt;P&gt;Less than 1 GB free memory? I hate to say this, but thats not nearly enough my friend : - (&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:53:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225023#M43285</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T18:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225027#M43286</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/102202"&gt;@kamilazat&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Change the core and the memory&lt;/P&gt;
&lt;P&gt;4 Cores, 8 GB.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:09:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225027#M43286</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-29T19:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225029#M43287</link>
      <description>&lt;P&gt;Personally, I would bump it to 6 cores/ at least 12 GB ram (16 if possible)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:11:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225029#M43287</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T19:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225032#M43289</link>
      <description>&lt;P&gt;I completely agree with you. Increased both machines to 10GB and redid the test.&lt;/P&gt;&lt;P&gt;Here's the free -h:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@GW1:0]# free -h&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;total used free shared buff/cache available&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Mem: 9.5G 2.2G 4.4G 20M 2.9G 6.3G&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Swap: 7.7G 0B 7.7G&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Both machines show the same numbers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did watch -n 1 "ps -auxww" during the test and it didn't change.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 1 0.0 0.0 2632 704 ? Ss 21:58 0:01 init [3]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 2 0.0 0.0 0 0 ? S 21:58 0:00 [kthreadd]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 3 0.0 0.0 0 0 ? S 21:58 0:00 [kworker/0:0]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 4 0.0 0.0 0 0 ? S&amp;lt; 21:58 0:00 [kworker/0:0H]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 6 1.9 0.0 0 0 ? S 21:58 0:28 [ksoftirqd/0]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 7 0.0 0.0 0 0 ? S 21:58 0:00 [migration/0]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 8 0.0 0.0 0 0 ? S 21:58 0:00 [rcu_bh]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 9 0.2 0.0 0 0 ? S 21:58 0:03 [rcu_sched]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 10 0.0 0.0 0 0 ? S 21:58 0:00 [rcuob/0]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 11 0.0 0.0 0 0 ? S 21:58 0:00 [rcuos/0]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 12 0.0 0.0 0 0 ? S&amp;lt; 21:58 0:00 [lru-add-drain&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 13 0.0 0.0 0 0 ? S 21:58 0:00 [watchdog/0]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 14 0.0 0.0 0 0 ? S 21:58 0:00 [watchdog/1]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 15 0.0 0.0 0 0 ? S 21:58 0:00 [migration/1]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 16 0.0 0.0 0 0 ? S 21:58 0:00 [ksoftirqd/1]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 18 0.0 0.0 0 0 ? S&amp;lt; 21:58 0:00 [kworker/1:0H]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 19 0.0 0.0 0 0 ? S 21:58 0:00 [rcuob/1]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 20 0.0 0.0 0 0 ? S 21:58 0:00 [rcuos/1]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 21 0.0 0.0 0 0 ? S 21:58 0:00 [watchdog/2]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;admin 22 0.0 0.0 0 0 ? S 21:58 0:00 [migration/2]&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;And top showed:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27437i5A66F3959E6ECE6E/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It looks like all the traffic goes to f2f, which is understandable. iperf uses TCP traffic unless UDP is specified with -u. But with -u the bandwidth goes even lower (played with it to increase the rate but to no avail).&lt;/P&gt;&lt;P&gt;On the other hand, when PC is the iperf client the bandwidth is still close to 1gbps. I don't understand what changes.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:26:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225032#M43289</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-08-29T19:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225034#M43291</link>
      <description>&lt;P&gt;What are the outputs of this commads?&lt;/P&gt;
&lt;P&gt;fwaccel stats -s&lt;/P&gt;
&lt;P&gt;fwaccel stat&lt;/P&gt;
&lt;P&gt;fw ctl affinity -l -r&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:34:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225034#M43291</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-29T19:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225036#M43292</link>
      <description>&lt;P&gt;You are saying even with more ram, though now it shows much more free memory, result is the same?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:35:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225036#M43292</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T19:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225039#M43293</link>
      <description>&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@GW1:0]# fwaccel stats -s&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Accelerated conns/Total conns : 9/9 (100%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;LightSpeed conns/Total conns : 0/9 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Accelerated pkts/Total pkts : 3670/10364 (35%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;LightSpeed pkts/Total pkts : 0/10364 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;F2Fed pkts/Total pkts : 6694/10364 (64%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;F2V pkts/Total pkts : 142/10364 (1%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPASXL pkts/Total pkts : 0/10364 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;PSLXL pkts/Total pkts : 0/10364 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPAS pipeline pkts/Total pkts : 0/10364 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;PSL pipeline pkts/Total pkts : 0/10364 (0%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;QOS inbound pkts/Total pkts : 5779/10364 (55%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;QOS outbound pkts/Total pkts : 5046/10364 (48%)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Corrected pkts/Total pkts : 0/10364 (0%)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@GW1:0]# fwaccel stat&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+---------------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;|Id|Name |Status |Interfaces |Features |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+---------------------------------------------------------------------------------+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;|0 |KPPAK |enabled |eth0,eth1 |Acceleration,Cryptography |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| | | | | |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| | | | |SHA1,3DES,DES,AES-128,AES-256,|&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| | | | |ESP,LinkSelection,DynamicVPN, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| | | | |NatTraversal,AES-XCBC,SHA256, |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;| | | | |SHA384,SHA512 |&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;+---------------------------------------------------------------------------------+&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Accept Templates : enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Drop Templates : disabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;NAT Templates : enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;LightSpeed Accel : disabled&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;[Expert@GW1:0]# fw ctl affinity -l -r&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPU 0:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPU 1:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPU 2:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPU 3: fw_4 (active)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cprid lpd mpdaemon fwd core_uploader fgd50 in.asessiond rtmd cprid cpd msgd&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPU 4: fw_3 (active)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cprid lpd mpdaemon fwd core_uploader fgd50 in.asessiond rtmd cprid cpd msgd&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPU 5: fw_2 (active)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cprid lpd mpdaemon fwd core_uploader fgd50 in.asessiond rtmd cprid cpd msgd&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPU 6: fw_1 (active)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cprid lpd mpdaemon fwd core_uploader fgd50 in.asessiond rtmd cprid cpd msgd&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CPU 7: fw_0 (active)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cprid lpd mpdaemon fwd core_uploader fgd50 in.asessiond rtmd cprid cpd msgd&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;All:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface eth0: has multi queue enabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface eth1: has multi queue enabled&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Just increased the SND cores to test, but still the same.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:40:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225039#M43293</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-08-29T19:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225040#M43294</link>
      <description>&lt;P&gt;True..&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:41:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225040#M43294</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-08-29T19:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225041#M43295</link>
      <description>&lt;P&gt;What does cpview show now? Anything different than before you added the ram?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 19:55:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225041#M43295</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T19:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225042#M43296</link>
      <description>&lt;P&gt;RAM doesn't change while doing the test. And CPU goes crazy as before. At this point I started thinking that it's a VMWare issue. Maybe it calculates the traffic in a different way when it comes to different machines, despite PC having only 2GB RAM and 4 cores. I wouldn't be surprised. I'll try rebooting the host.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 20:00:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225042#M43296</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-08-29T20:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225043#M43297</link>
      <description>&lt;P&gt;I agree, thats probably a good idea.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 20:02:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225043#M43297</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T20:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: iperf test speeds are different on internal and external for QoS testing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225048#M43301</link>
      <description>&lt;P&gt;I couldn't find anything related to VMware either. Rebooted the host, restarted VMWare NAT service. Tomorrow I will use the lab in the company esxi and try cranking up the specs on my machines there. I will update when I get anything new.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your prompt reaction. I appreciate it!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 20:21:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/iperf-test-speeds-are-different-on-internal-and-external-for-QoS/m-p/225048#M43301</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-08-29T20:21:05Z</dc:date>
    </item>
  </channel>
</rss>

