<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Slow download site-to-site VPN in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233901#M45291</link>
    <description>&lt;P&gt;&lt;FONT color="#000000"&gt;I did tracepath but i got no reply from all hops&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;tracepath 10.2.0.240&lt;BR /&gt;1?: [LOCALHOST] pmtu 1500&lt;BR /&gt;1: no reply&lt;BR /&gt;2: no reply&lt;BR /&gt;3: no reply&lt;BR /&gt;4: no reply&lt;BR /&gt;5: no reply&lt;BR /&gt;6: no reply&lt;BR /&gt;7: no reply&lt;BR /&gt;8: no reply&lt;BR /&gt;9: no reply&lt;BR /&gt;10: no reply&lt;BR /&gt;11: no reply&lt;BR /&gt;12: no reply&lt;BR /&gt;13: no reply&lt;BR /&gt;14: no reply&lt;BR /&gt;15: no reply&lt;BR /&gt;16: no reply&lt;BR /&gt;17: no reply&lt;BR /&gt;18: no reply&lt;BR /&gt;19: no reply&lt;BR /&gt;20: no reply&lt;BR /&gt;21: no reply&lt;BR /&gt;22: no reply&lt;BR /&gt;23: no reply&lt;BR /&gt;24: no reply&lt;BR /&gt;25: no reply&lt;BR /&gt;26: no reply&lt;BR /&gt;27: no reply&lt;BR /&gt;28: no reply&lt;BR /&gt;29: no reply&lt;BR /&gt;30: no reply&lt;BR /&gt;31: no reply&lt;BR /&gt;Too many hops: pmtu 1500&lt;BR /&gt;Resume: pmtu 1500&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Nov 2024 09:41:40 GMT</pubDate>
    <dc:creator>Tomas3miasto</dc:creator>
    <dc:date>2024-11-27T09:41:40Z</dc:date>
    <item>
      <title>Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233771#M45256</link>
      <description>&lt;P&gt;We have had a problem downloading files via a VPN tunnel for some time now.&lt;BR /&gt;When I download a file from the headquarters to our office, our speed is about 15MB/s (sometimes more at startup, but after a while, it drops).&lt;BR /&gt;If I were uploading the same file (I am testing on a 1GB file) to the headquarters, the speed would be about 50MB/s.&lt;/P&gt;&lt;P&gt;Has anyone had a similar case?&lt;BR /&gt;I'm trying to diagnose it but so far without success.&lt;/P&gt;&lt;P&gt;Tomasz&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 07:49:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233771#M45256</guid>
      <dc:creator>Tomas3miasto</dc:creator>
      <dc:date>2024-11-26T07:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233776#M45259</link>
      <description>&lt;P&gt;Site to site? Or client vpn? What encryption methods are used? Make sure not to use for example slow performance methods like 3des. What blades are enabled on the gateway&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 08:16:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233776#M45259</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-11-26T08:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233779#M45260</link>
      <description>&lt;P&gt;site to site. Meshed Community&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Meshed Community.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28556i37F4B466032F1964/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Meshed Community.png" alt="Meshed Community.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; I have disabled almost all blades on my site. Now I have fw, vpn, anti_bot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 08:34:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233779#M45260</guid>
      <dc:creator>Tomas3miasto</dc:creator>
      <dc:date>2024-11-26T08:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233796#M45262</link>
      <description>&lt;P&gt;Try to move away from md5 and 3des not secure and cpu intens. Then test again. Could also be software bug what is cpinfo -y all output?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 11:35:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233796#M45262</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-11-26T11:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233820#M45271</link>
      <description>&lt;P&gt;I would refer to below sk.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk73980" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk73980&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 13:42:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233820#M45271</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-26T13:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233837#M45279</link>
      <description>&lt;P&gt;Almost certainly a sub-1500 MTU somewhere in your network path between the peers, see:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk98074" target="_blank" rel="noopener"&gt;sk98074:&amp;nbsp;MTU&amp;nbsp;and Fragmentation Issues in IPsec&amp;nbsp;VPN&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Command &lt;STRONG&gt;tracepath&lt;/STRONG&gt; run from one peer to the other can be used to confirm a low MTU is present.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2024 15:05:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233837#M45279</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-11-26T15:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233898#M45289</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Here is my cpinfo -y all&lt;/P&gt;&lt;P&gt;[Expert@pl-fw-1:0]# cpinfo -y all&lt;/P&gt;&lt;P&gt;This is Check Point CPinfo Build 914000248 for GAIA&lt;BR /&gt;[MGMT]&lt;BR /&gt;HOTFIX_R81_20_JUMBO_HF_MAIN Take: 89&lt;BR /&gt;[IDA]&lt;BR /&gt;No hotfixes..&lt;BR /&gt;[CPFC]&lt;BR /&gt;No hotfixes..&lt;BR /&gt;[FW1]&lt;BR /&gt;HOTFIX_R81_20_JHF_T89_721_MAIN&lt;BR /&gt;HOTFIX_INEXT_NANO_EGG_AUTOUPDATE&lt;BR /&gt;HOTFIX_R81_20_JHF_T54_BLOCK_PORTAL_MAIN Take: 2&lt;BR /&gt;HOTFIX_R80_40_MAAS_TUNNEL_AUTOUPDATE&lt;BR /&gt;HOTFIX_GOT_TPCONF_AUTOUPDATE&lt;BR /&gt;HOTFIX_R81_20_JUMBO_HF_MAIN Take: 89&lt;BR /&gt;HOTFIX_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE&lt;/P&gt;&lt;P&gt;FW1 build number:&lt;BR /&gt;This is Check Point's software version R81.20 - Build 039&lt;BR /&gt;kernel: R81.20 - Build 001&lt;BR /&gt;[SecurePlatform]&lt;BR /&gt;HOTFIX_R81_20_JUMBO_HF_MAIN Take: 89&lt;BR /&gt;HOTFIX_ENDER_V17_AUTOUPDATE&lt;BR /&gt;[CPinfo]&lt;BR /&gt;No hotfixes..&lt;BR /&gt;[PPACK]&lt;BR /&gt;HOTFIX_R81_20_JUMBO_HF_MAIN Take: 89&lt;BR /&gt;[AutoUpdater]&lt;BR /&gt;HOTFIX_INFRA_CONFIG_AUTOUPDATE&lt;BR /&gt;[DIAG]&lt;BR /&gt;No hotfixes..&lt;BR /&gt;[CVPN]&lt;BR /&gt;HOTFIX_ESOD_SWS_AUTOUPDATE&lt;BR /&gt;HOTFIX_ESOD_SCANNER_AUTOUPDATE&lt;BR /&gt;HOTFIX_ESOD_CSHELL_AUTOUPDATE&lt;BR /&gt;HOTFIX_R81_20_JUMBO_HF_MAIN Take: 89&lt;BR /&gt;[CPUpdates]&lt;BR /&gt;BUNDLE_INEXT_NANO_EGG_AUTOUPDATE Take: 13&lt;BR /&gt;BUNDLE_R81_20_JHF_T54_BLOCK_PORTAL_MAIN Take: 2&lt;BR /&gt;BUNDLE_INFRA_CONFIG_AUTOUPDATE Take: 5&lt;BR /&gt;BUNDLE_CPOTLPAGENT_AUTOUPDATE Take: 50&lt;BR /&gt;BUNDLE_QUID_AUTOUPDATE Take: 14&lt;BR /&gt;BUNDLE_R80_40_MAAS_TUNNEL_AUTOUPDATE Take: 60&lt;BR /&gt;BUNDLE_CORE_FILE_UPLOADER_AUTOUPDATE Take: 23&lt;BR /&gt;BUNDLE_GOT_TPCONF_AUTOUPDATE Take: 128&lt;BR /&gt;BUNDLE_ESOD_SWS_AUTOUPDATE Take: 14&lt;BR /&gt;BUNDLE_ESOD_SCANNER_AUTOUPDATE Take: 10&lt;BR /&gt;BUNDLE_GENERAL_AUTOUPDATE Take: 21&lt;BR /&gt;BUNDLE_INFRA_AUTOUPDATE Take: 67&lt;BR /&gt;BUNDLE_DEP_INSTALLER_AUTOUPDATE Take: 27&lt;BR /&gt;BUNDLE_ESOD_CSHELL_AUTOUPDATE Take: 20&lt;BR /&gt;BUNDLE_ENDER_V17_AUTOUPDATE Take: 26&lt;BR /&gt;BUNDLE_CPVIEWEXPORTER_AUTOUPDATE Take: 40&lt;BR /&gt;BUNDLE_CPOTELCOL_AUTOUPDATE Take: 129&lt;BR /&gt;BUNDLE_R81_20_JUMBO_HF_MAIN Take: 89&lt;BR /&gt;BUNDLE_PUBLIC_CLOUD_CA_BUNDLE_AUTOUPDATE Take: 21&lt;BR /&gt;BUNDLE_HCP_AUTOUPDATE Take: 76&lt;BR /&gt;BUNDLE_CPSDC_AUTOUPDATE Take: 34&lt;BR /&gt;[cpsdc_wrapper]&lt;BR /&gt;HOTFIX_CPSDC_AUTOUPDATE&lt;BR /&gt;[hcp_wrapper]&lt;BR /&gt;HOTFIX_HCP_AUTOUPDATE&lt;BR /&gt;[CPDepInst]&lt;BR /&gt;No hotfixes..&lt;BR /&gt;[CPotelcol]&lt;BR /&gt;HOTFIX_OTLP_GA&lt;BR /&gt;[CPviewExporter]&lt;BR /&gt;HOTFIX_OTLP_GA&lt;BR /&gt;[core_uploader]&lt;BR /&gt;HOTFIX_CHARON_HF&lt;BR /&gt;[CPquid]&lt;BR /&gt;HOTFIX_QUID_AUTOUPDATE&lt;BR /&gt;[CPotlpAgent]&lt;BR /&gt;HOTFIX_OTLP_GA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I changed my configuration to the one recommended by &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Now uploading is better - up to 100MB/s but downloading from 3MB/s to 30Mb/s -&amp;nbsp;&lt;SPAN&gt;sine wave&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but from another place it is much better - about 50MB&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 09:05:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233898#M45289</guid>
      <dc:creator>Tomas3miasto</dc:creator>
      <dc:date>2024-11-27T09:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233901#M45291</link>
      <description>&lt;P&gt;&lt;FONT color="#000000"&gt;I did tracepath but i got no reply from all hops&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;tracepath 10.2.0.240&lt;BR /&gt;1?: [LOCALHOST] pmtu 1500&lt;BR /&gt;1: no reply&lt;BR /&gt;2: no reply&lt;BR /&gt;3: no reply&lt;BR /&gt;4: no reply&lt;BR /&gt;5: no reply&lt;BR /&gt;6: no reply&lt;BR /&gt;7: no reply&lt;BR /&gt;8: no reply&lt;BR /&gt;9: no reply&lt;BR /&gt;10: no reply&lt;BR /&gt;11: no reply&lt;BR /&gt;12: no reply&lt;BR /&gt;13: no reply&lt;BR /&gt;14: no reply&lt;BR /&gt;15: no reply&lt;BR /&gt;16: no reply&lt;BR /&gt;17: no reply&lt;BR /&gt;18: no reply&lt;BR /&gt;19: no reply&lt;BR /&gt;20: no reply&lt;BR /&gt;21: no reply&lt;BR /&gt;22: no reply&lt;BR /&gt;23: no reply&lt;BR /&gt;24: no reply&lt;BR /&gt;25: no reply&lt;BR /&gt;26: no reply&lt;BR /&gt;27: no reply&lt;BR /&gt;28: no reply&lt;BR /&gt;29: no reply&lt;BR /&gt;30: no reply&lt;BR /&gt;31: no reply&lt;BR /&gt;Too many hops: pmtu 1500&lt;BR /&gt;Resume: pmtu 1500&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 09:41:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233901#M45291</guid>
      <dc:creator>Tomas3miasto</dc:creator>
      <dc:date>2024-11-27T09:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233906#M45292</link>
      <description>&lt;P&gt;Hi i run tracepath but I got no reply from all hops&lt;/P&gt;&lt;P&gt;Too many hoops: pmtu 1500&lt;/P&gt;&lt;P&gt;Resume: pmtu 1500&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 10:26:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233906#M45292</guid>
      <dc:creator>Tomas3miasto</dc:creator>
      <dc:date>2024-11-27T10:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233920#M45293</link>
      <description>&lt;P&gt;Is it different if you change mtu size to something else?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 11:51:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233920#M45293</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-27T11:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233921#M45294</link>
      <description>&lt;P&gt;Would recommend to change the md5 to something more secure and performing&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 12:06:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233921#M45294</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-11-27T12:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233922#M45295</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/56063"&gt;@Tomas3miasto&lt;/a&gt;&amp;nbsp;Here is something to consider though when changing MTU. So, as Im sure you might be aware, smaller MTU size means more smaller packats, but bigger mtu size means less amount of bigger packets.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In general, a larger MTU size is better because it reduces overhead and improves throughput.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;However,&amp;nbsp;&lt;MARK class="QVRyCf"&gt;there are some cases where a smaller MTU size is better, such as for high speed interfaces.&lt;/MARK&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Andy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 12:16:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233922#M45295</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-27T12:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233948#M45309</link>
      <description>&lt;P&gt;You can also check&amp;nbsp;&lt;SPAN&gt;sk165853 if this applies.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 14:57:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/233948#M45309</guid>
      <dc:creator>ishuyell</dc:creator>
      <dc:date>2024-11-27T14:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234048#M45336</link>
      <description>&lt;P&gt;Can you please list all the things you tried so far, so we can at least eliminate those as being possibilities for this issue?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 12:43:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234048#M45336</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-28T12:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234268#M45381</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I checked at first netstat -ni and found Rx dropped and RX overruns on eth1 and eth5&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zrzut ekranu 2024-12-02 080250.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28622iD86CAEBF1D287D2C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Zrzut ekranu 2024-12-02 080250.png" alt="Zrzut ekranu 2024-12-02 080250.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I increased&amp;nbsp;rx-ringsize first to 2048 and then to 4096.&lt;/P&gt;&lt;P&gt;Now there are no drops but it did not helped&lt;/P&gt;&lt;P&gt;second - I run&amp;nbsp;fwaccel stats -s&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zrzut ekranu 2024-12-02 081538.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28625i8988502A39D4D36F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Zrzut ekranu 2024-12-02 081538.png" alt="Zrzut ekranu 2024-12-02 081538.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I tried to reduce the F2F traffic - now there is about 12%&lt;/P&gt;&lt;P&gt;third - I disabled almost all blades.&lt;/P&gt;&lt;P&gt;fourth - Changed encryption settings&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Encryption.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28626i8F1080030EEEABFB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Encryption.png" alt="Encryption.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;fifth - increased /decreased MTU ( try 1410,1480, 9000)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I also checked&amp;nbsp;&lt;SPAN&gt;sk165853 but it looks ok&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cpview1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28627iE49F0FDE75C73C38/image-size/medium?v=v2&amp;amp;px=400" role="button" title="cpview1.png" alt="cpview1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also use this manual -&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk61221" target="_blank" rel="noopener"&gt;sk61221 - Issues requiring adjustment of the Maximum Segment Size (MSS) of TCP SYN and TCP SYN-ACK packets on Security Gateway&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;fw_clamp_tcp_mss=1&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;no improvement in sight or only upload&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I decided to order&amp;nbsp;an MTR&amp;nbsp;test between these two sites from ISP&lt;/P&gt;&lt;P&gt;Tomek&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 07:48:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234268#M45381</guid>
      <dc:creator>Tomas3miasto</dc:creator>
      <dc:date>2024-12-02T07:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234278#M45389</link>
      <description>&lt;P&gt;Good to see you take the advise serious.&lt;/P&gt;
&lt;P&gt;one question for this site to site you have 2 gateways right? Are both in control by you? If not maybe the other gateway needs to be checked.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 09:42:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234278#M45389</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-12-02T09:42:35Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234298#M45394</link>
      <description>&lt;P&gt;So is it any better now after all those changes or more less the same?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 12:31:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234298#M45394</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-02T12:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234305#M45397</link>
      <description>&lt;P&gt;Hi Andy&amp;nbsp;&lt;/P&gt;&lt;P&gt;Download more less the same but upload to Sweden is better&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 13:09:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234305#M45397</guid>
      <dc:creator>Tomas3miasto</dc:creator>
      <dc:date>2024-12-02T13:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234306#M45398</link>
      <description>&lt;P&gt;Hi Lesley.&lt;/P&gt;&lt;P&gt;Yes, I will check the gateway on the second site today or tomorrow evening&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 13:10:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234306#M45398</guid>
      <dc:creator>Tomas3miasto</dc:creator>
      <dc:date>2024-12-02T13:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: Slow download site-to-site VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234316#M45404</link>
      <description>&lt;P&gt;Let’s see what is outcome from that gateway maybe that is the (new) bottleneck&lt;/P&gt;</description>
      <pubDate>Mon, 02 Dec 2024 13:40:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Slow-download-site-to-site-VPN/m-p/234316#M45404</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-12-02T13:40:17Z</dc:date>
    </item>
  </channel>
</rss>

