<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Low throughput from 4200 appliance in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63176#M4835</link>
    <description>&lt;P&gt;Q: Which version are you running?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A: R77.30.&lt;/P&gt;
&lt;P&gt;--&amp;gt; having support for eleven more days, so what about the future ?&lt;/P&gt;</description>
    <pubDate>Thu, 19 Sep 2019 14:36:03 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-09-19T14:36:03Z</dc:date>
    <item>
      <title>Low throughput from 4200 appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63052#M4814</link>
      <description>&lt;P&gt;We have a CheckPoint 4200 appliance running as our gateway/firewall. Our WAN speed is 1Gbps, but we can only seem to get 100Mbps throughput from the appliance.&lt;/P&gt;&lt;P&gt;I have connected a computer directly to our WAN-connection to confirm WAN speed, and without going through the firewall i get the correct speed (1Gbps).&amp;nbsp;&lt;/P&gt;&lt;P&gt;The WAN interface (eth1) says "Link Speed: 1000Mbps / Full Duplex".&lt;/P&gt;&lt;P&gt;I have been monitoring with CPview on the firewall, and I have not seen "Total Mbits/sec" go above 102 Mbps. To me it seems like speed is capped at 100Mbps. I am wondering what the cause of this can be, and what steps should I do to troubleshoot this issue? Appreciate any help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 13:40:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63052#M4814</guid>
      <dc:creator>exciteman</dc:creator>
      <dc:date>2019-09-18T13:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Low throughput from 4200 appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63063#M4816</link>
      <description>&lt;P&gt;Try from different clients at the same time - and add up the&amp;nbsp;throughputs...&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 14:20:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63063#M4816</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-18T14:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Low throughput from 4200 appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63066#M4817</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Which version are you running?&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Which blades are you running?&lt;/LI&gt;&lt;LI&gt;Please post output of fwaccel stats -s (or stat, don't remember right now)&lt;/LI&gt;&lt;LI&gt;From expert (#) run ifconfig -a . Do you see errors on the interfaces?&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Output from top&lt;/LI&gt;&lt;LI&gt;Did you tried to connect your host directly to the firewall to perform the speed test?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 14:40:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63066#M4817</guid>
      <dc:creator>FedericoMeiners</dc:creator>
      <dc:date>2019-09-18T14:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Low throughput from 4200 appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63096#M4819</link>
      <description>&lt;P&gt;The maximum speed through a 2core box like 4200 will depend on which blades are enabled (&lt;STRONG&gt;enabled_blades&lt;/STRONG&gt; command), and how much traffic is being pulled into the PXL or F2F paths based on your APCL/URLF and Threat Prevention policies.&amp;nbsp; Please provide the output from the "Super Seven" commands run on your firewall for further analysis:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Super-Seven-Performance-Assessment-Commands-s7pac/m-p/40528" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Super-Seven-Performance-Assessment-Commands-s7pac/m-p/40528&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 22:08:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63096#M4819</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-09-18T22:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Low throughput from 4200 appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63116#M4823</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q: Which version are you running?&amp;nbsp;&lt;/P&gt;&lt;P&gt;A: R77.30.&lt;/P&gt;&lt;P&gt;Q: Which blades are you running?&lt;/P&gt;&lt;P&gt;A:&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Enabled blades.PNG" style="width: 568px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2563iBFB2F6641B76488F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Enabled blades.PNG" alt="Enabled blades.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Q: Please post output of fwaccel stats -s (or stat, don't remember right now)&lt;/P&gt;&lt;P&gt;A:&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;Accelerator Status : on&lt;BR /&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;disabled from rule #12&lt;BR /&gt;Drop Templates : disabled&lt;BR /&gt;NAT Templates : disabled by user&lt;/P&gt;&lt;P&gt;Accelerator Features : Accounting, NAT, Cryptography, Routing,&lt;BR /&gt;HasClock, Templates, Synchronous, IdleDetection,&lt;BR /&gt;Sequencing, TcpStateDetect, AutoExpire,&lt;BR /&gt;DelayedNotif, TcpStateDetectV2, CPLS, McastRouting,&lt;BR /&gt;WireMode, DropTemplates, NatTemplates,&lt;BR /&gt;Streaming, MultiFW, AntiSpoofing, Nac,&lt;BR /&gt;ViolationStats, AsychronicNotif, ERDOS,&lt;BR /&gt;NAT64, GTPAcceleration, SCTPAcceleration,&lt;BR /&gt;McastRoutingV2&lt;BR /&gt;Cryptography Features : Tunnel, UDPEncapsulation, MD5, SHA1, NULL,&lt;BR /&gt;3DES, DES, CAST, CAST-40, AES-128, AES-256,&lt;BR /&gt;ESP, LinkSelection, DynamicVPN, NatTraversal,&lt;BR /&gt;EncRouting, AES-XCBC, SHA256&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Q: From expert (#) run ifconfig -a . Do you see errors on the interfaces?&amp;nbsp;&lt;/P&gt;&lt;P&gt;A: I only see 22 errors on the trunked interface...&lt;/P&gt;&lt;P&gt;Q: Did you tried to connect your host directly to the firewall to perform the speed test?&lt;/P&gt;&lt;P&gt;A: No.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 06:28:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63116#M4823</guid>
      <dc:creator>exciteman</dc:creator>
      <dc:date>2019-09-19T06:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Low throughput from 4200 appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63117#M4824</link>
      <description>&lt;P&gt;I have, and the speed still doesn't exceed 100Mbps.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 06:29:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63117#M4824</guid>
      <dc:creator>exciteman</dc:creator>
      <dc:date>2019-09-19T06:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Low throughput from 4200 appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63122#M4825</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;Super Seven output:&lt;/P&gt;&lt;P&gt;fwaccel stat&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;Accelerator Status : on&lt;BR /&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;disabled from rule #12&lt;BR /&gt;Drop Templates : disabled&lt;BR /&gt;NAT Templates : disabled by user&lt;BR /&gt;&lt;BR /&gt;Accelerator Features : Accounting, NAT, Cryptography, Routing,&lt;BR /&gt;HasClock, Templates, Synchronous, IdleDetection,&lt;BR /&gt;Sequencing, TcpStateDetect, AutoExpire,&lt;BR /&gt;DelayedNotif, TcpStateDetectV2, CPLS, McastRouting,&lt;BR /&gt;WireMode, DropTemplates, NatTemplates,&lt;BR /&gt;Streaming, MultiFW, AntiSpoofing, Nac,&lt;BR /&gt;ViolationStats, AsychronicNotif, ERDOS,&lt;BR /&gt;NAT64, GTPAcceleration, SCTPAcceleration,&lt;BR /&gt;McastRoutingV2&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Cryptography Features : Tunnel, UDPEncapsulation, MD5, SHA1, NULL,&lt;BR /&gt;3DES, DES, CAST, CAST-40, AES-128, AES-256,&lt;BR /&gt;ESP, LinkSelection, DynamicVPN, NatTraversal,&lt;BR /&gt;EncRouting, AES-XCBC, SHA256&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;fwaccel stats -s&lt;/P&gt;&lt;LI-SPOILER&gt;Accelerated conns/Total conns : 0/607 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 40/4009649 (0%)&lt;BR /&gt;F2Fed pkts/Total pkts : 216182/4009649 (5%)&lt;BR /&gt;PXL pkts/Total pkts : 3793427/4009649 (94%)&lt;BR /&gt;QXL pkts/Total pkts : 0/4009649 (0%)&lt;/LI-SPOILER&gt;&lt;P&gt;grep -c ^processor /proc/cpuinfo&lt;/P&gt;&lt;LI-SPOILER&gt;2&lt;/LI-SPOILER&gt;&lt;P&gt;fw ctl affinity -l -r&lt;/P&gt;&lt;LI-SPOILER&gt;CPU 0: eth2 eth3&lt;BR /&gt;fw_1&lt;BR /&gt;CPU 1: eth1 Mgmt&lt;BR /&gt;fw_0&lt;BR /&gt;All: usrchkd mpdaemon in.acapd vpnd lpd rad fwd in.msd fwpushd cprid cpd&lt;/LI-SPOILER&gt;&lt;P&gt;netstat -ni&lt;/P&gt;&lt;LI-SPOILER&gt;Kernel Interface table&lt;BR /&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Iface&lt;/TD&gt;&lt;TD&gt;MTU&lt;/TD&gt;&lt;TD&gt;Met&lt;/TD&gt;&lt;TD&gt;RX-OK&lt;/TD&gt;&lt;TD&gt;RX-ERR&lt;/TD&gt;&lt;TD&gt;RX-DRP&lt;/TD&gt;&lt;TD&gt;RX-OVR&lt;/TD&gt;&lt;TD&gt;TX-OK&lt;/TD&gt;&lt;TD&gt;TX-ERR&lt;/TD&gt;&lt;TD&gt;TX-DRP&lt;/TD&gt;&lt;TD&gt;TX-OVR&lt;/TD&gt;&lt;TD&gt;Flg&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mgmt&lt;/TD&gt;&lt;TD&gt;1500&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;352341&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;315754&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;BMRU&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eth1&lt;/TD&gt;&lt;TD&gt;1500&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;195704407&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;3154326&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;102409603&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;BMRU&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eth2&lt;/TD&gt;&lt;TD&gt;1500&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;251686&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;1549&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;150148&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;BMRU&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eth3&lt;/TD&gt;&lt;TD&gt;1500&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;104346397&lt;/TD&gt;&lt;TD&gt;23&lt;/TD&gt;&lt;TD&gt;385319&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;189718282&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;BMRU&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eth3.3&lt;/TD&gt;&lt;TD&gt;1500&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;390303&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;46120&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;BMRU&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eth3.5&lt;/TD&gt;&lt;TD&gt;1500&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;97345634&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;181543112&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;BMRU&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eth3.6&lt;/TD&gt;&lt;TD&gt;1500&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;5467821&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;8966394&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;BMRU&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eth3.7&lt;/TD&gt;&lt;TD&gt;1500&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;BMRU&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eth3.9&lt;/TD&gt;&lt;TD&gt;1500&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;79155&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;1099&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;BMRU&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eth3.10&lt;/TD&gt;&lt;TD&gt;1500&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;473634&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;260472&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;BMRU&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eth3.15&lt;/TD&gt;&lt;TD&gt;1500&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;81049&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;8108&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;BMRU&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;eth3.20&lt;/TD&gt;&lt;TD&gt;1500&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;508709&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;229251&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;BMRU&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;lo&lt;/TD&gt;&lt;TD&gt;16436&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;1101289&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;1101289&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;LRU&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;fw ctl multik stat&lt;/P&gt;&lt;LI-SPOILER&gt;ID | Active | CPU | Connections | Peak&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;0 | Yes | 1 | 271 | 3596&lt;BR /&gt;1 | Yes | 0 | 368 | 3657&lt;/LI-SPOILER&gt;&lt;P&gt;cpstat os -f multi_cpu -o 1&lt;/P&gt;&lt;LI-SPOILER&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 1| 79| 20| 80| ?| 2183|&lt;BR /&gt;| 2| 4| 62| 34| 66| ?| 2183|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 1| 79| 20| 80| ?| 2183|&lt;BR /&gt;| 2| 4| 62| 34| 66| ?| 2183|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 2| 85| 13| 87| ?| 2272|&lt;BR /&gt;| 2| 17| 51| 32| 68| ?| 2272|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 2| 85| 13| 87| ?| 2272|&lt;BR /&gt;| 2| 17| 51| 32| 68| ?| 2272|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 83| 16| 84| ?| 2235|&lt;BR /&gt;| 2| 11| 43| 47| 53| ?| 2235|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 83| 16| 84| ?| 2235|&lt;BR /&gt;| 2| 11| 43| 47| 53| ?| 2235|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 85| 14| 86| ?| 2254|&lt;BR /&gt;| 2| 1| 37| 63| 37| ?| 2254|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Processors load&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;|CPU#|User Time(%)|System Time(%)|Idle Time(%)|Usage(%)|Run queue|Interrupts/sec|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;BR /&gt;| 1| 0| 85| 14| 86| ?| 2254|&lt;BR /&gt;| 2| 1| 37| 63| 37| ?| 2254|&lt;BR /&gt;---------------------------------------------------------------------------------&lt;/P&gt;&lt;/LI-SPOILER&gt;&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 08:25:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63122#M4825</guid>
      <dc:creator>exciteman</dc:creator>
      <dc:date>2019-09-19T08:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Low throughput from 4200 appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63175#M4834</link>
      <description>&lt;P&gt;You are getting frame loss (RX-DRP) rates of between 0.3% and 1.6% on your interfaces due to buffering misses which is probably the main thing slowing you down.&amp;nbsp; This is almost certainly due to high CPU load on your 2 cores, given the large number blades you have enabled on an old 2-core box like that 4200, 100Mbps top throughput doesn't seem that unreasonable to me.&amp;nbsp; Currently you have a 2/2 CoreXL split on your box, in some cases disabling CoreXL and going to a 1/1 split helps on a 2-core box but given your high PXL% I don't think doing that will help in this case.&lt;/P&gt;
&lt;P&gt;The 4200 only has 4GB of RAM which may not be enough for all you are trying to do.&amp;nbsp; Please provide output of the &lt;STRONG&gt;free -m&lt;/STRONG&gt; command to see if a memory upgrade will help.&lt;/P&gt;
&lt;P&gt;You can probably pick up some more speed by tuning your policies, the two major areas in your case are Threat Prevention and APCL/URLF. In order to figure out where to focus your efforts, try this and report back what you see:&lt;/P&gt;
&lt;P&gt;1) Run Internet speed test and note throughput&lt;/P&gt;
&lt;P&gt;2) On the gateway from expert mode run commands &lt;STRONG&gt;ips off&lt;/STRONG&gt; and &lt;STRONG&gt;fw amw unload&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;3) Wait 60 seconds&lt;/P&gt;
&lt;P&gt;4) From a completely new browser instance run an Internet speed test and note throughput.&amp;nbsp; If throughput has substantially increased you need to tune your IPS &amp;amp; Threat Prevention configuration.&lt;/P&gt;
&lt;P&gt;5) Run commands &lt;STRONG&gt;ips on&lt;/STRONG&gt; and &lt;STRONG&gt;fw amw fetch local&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;6) Wait 60 seconds&lt;/P&gt;
&lt;P&gt;7)&amp;nbsp;From a completely new browser instance run an Internet speed test and note throughput. (should be about the same as #1)&lt;/P&gt;
&lt;P&gt;8)&lt;/img&gt; On gateway object in SmartConsole, uncheck the APCL and URLF blades and reinstall policy to the gateway.&lt;/P&gt;
&lt;P&gt;9) Wait 60 seconds&lt;/P&gt;
&lt;P&gt;9)&amp;nbsp;From a completely new browser instance run an Internet speed test and note throughput. If throughput has substantially increased you need to tune your APCL/URLF policy, typically this will involve removing the "Any Any Any Accept" rule at the bottom of your APCL/URLF policy (which is not necessary except for logging purposes), and making sure you are using object "Internet" in the Destination column of all APCL/URLF rules and NOT "Any".&lt;/P&gt;
&lt;P&gt;10) Recheck the APCL and URLF checkboxes and reinstall policy to the gateway.&lt;/P&gt;
&lt;P&gt;11)&amp;nbsp;From a completely new browser instance run an Internet speed test and note throughput. (should be about the same as #1)&lt;/P&gt;
&lt;P&gt;Let us know what you find out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 14:19:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63175#M4834</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-09-19T14:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Low throughput from 4200 appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63176#M4835</link>
      <description>&lt;P&gt;Q: Which version are you running?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A: R77.30.&lt;/P&gt;
&lt;P&gt;--&amp;gt; having support for eleven more days, so what about the future ?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 14:36:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63176#M4835</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-19T14:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Low throughput from 4200 appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63237#M4837</link>
      <description>&lt;P&gt;Thanks for the input!&lt;/P&gt;&lt;P&gt;I’ve done the steps you suggested, and I found this:&lt;/P&gt;&lt;P&gt;free -m command:&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;total&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;used&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;free&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;shared&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;buffers&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;cached&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Mem:&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;3973&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;3289&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;684&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;0&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;34&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;834&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;-/+ buffers/cache:&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;2420&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;1553&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;Swap:&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;10268&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;0&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;10268&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Throughput tests (peaks - CPview):&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Without any changes: 74 Mbps&lt;/P&gt;&lt;P&gt;ips off &amp;amp; fw amw unload: 234 Mbps&lt;/P&gt;&lt;P&gt;Reverted (ips on &amp;amp; fw amw fetch local) 93 Mbps&lt;/P&gt;&lt;P&gt;APCL &amp;amp; URLF blades disabled: 115 Mbps&lt;/P&gt;&lt;P&gt;Reverted (APCL &amp;amp; URLF enabled) 95 Mbps&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it seems like the IPS &amp;amp; Threat Prevention needs tuning. Do you have any suggestions for that?&lt;/P&gt;&lt;P&gt;I will do your suggested tuning for APCL/URLF also.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 09:08:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63237#M4837</guid>
      <dc:creator>exciteman</dc:creator>
      <dc:date>2019-09-20T09:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: Low throughput from 4200 appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63259#M4838</link>
      <description>&lt;P&gt;Looks like your box is not hitting swap at all which is good, no memory upgrade needed.&lt;/P&gt;
&lt;P&gt;We'll need to do a few more tests to determine whether it is IPS specifically (more likely) or the rest of Threat Prevention (less likely) that is causing the bulk of the slowdown:&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;1) Run Internet speed test and note throughput&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;2) On the gateway from expert mode run commands &lt;STRONG&gt;ips off&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;3) Wait 60 seconds&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;4) From a completely new browser instance run an Internet speed test and note throughput.&amp;nbsp; If throughput has substantially increased you need to tune your IPS configuration.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;5) Run command &lt;STRONG&gt;ips on&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;6) Run command &lt;STRONG&gt; fw amw unload&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;7) Wait 60 seconds&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;8)&lt;/img&gt; From a completely new browser instance run an Internet speed test and note throughput.&amp;nbsp; If throughput has substantially increased you need to tune your TP (AV/ABOT) configuration.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;9) Run command &lt;STRONG&gt;fw amw fetch local&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;You may well see a performance improvement at both steps #4 &amp;amp; #8, I'd suggest focusing on where you get the biggest increase for tuning.&amp;nbsp; If turning off IPS provides most of the gain, determine which IPS profile is in use by your 4200 gateway and open it for editing.&amp;nbsp; Sort the IPS protections by the "Performance Impact" rating and disable all IPS Protections with a "Critical" or "High" rating.&amp;nbsp; That should help a lot.&lt;/P&gt;
&lt;P&gt;If turning off Threat Prevention (amw) provided most of the gain, my guess is that Anti-virus is causing most of the overhead as Anti-bot tends to be pretty low impact.&amp;nbsp; I'll need to see the AV &amp;amp; ABOT settings in the relevant TP profile applied to your gateway to make specific recommendations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 13:50:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-throughput-from-4200-appliance/m-p/63259#M4838</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-09-20T13:50:45Z</dc:date>
    </item>
  </channel>
</rss>

