<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point Firewalls Connection Table in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269772#M53410</link>
    <description>&lt;P&gt;It should not but there is not enough information to give a firm answer/s.&lt;/P&gt;
&lt;P&gt;Performance question answers are not always straight forward and as much information as possible should be collected and used to investigate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Automatic&lt;/STRONG&gt; has been the default for new installations for many versions now.&lt;/P&gt;
&lt;P&gt;The more connections that are handled by the gateway the more memory used - to record the connection details in the connections table (and NAT and other tables).&lt;/P&gt;
&lt;P&gt;CPU is consumed by the firewall software enforcing the policy. Rule matching.&lt;/P&gt;
&lt;P&gt;SecureXL can offload the CPUs significantly if a lot of traffic is handled on the fast path, but traffic handled by blades like IPS, App. Control and Content Awareness will take more CPU.&lt;/P&gt;
&lt;P&gt;HTTPS Inspection will also require more CPU resources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fwaccel stats -s&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_PerformanceTuning_AdminGuide/Content/Topics-PTG/SecureXL.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_PerformanceTuning_AdminGuide/Content/Topics-PTG/SecureXL.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;What version/s are you running?&lt;/P&gt;
&lt;P&gt;What was the CPU utilization before?&lt;/P&gt;
&lt;P&gt;Do you plan to have more traffic load in the future?&lt;/P&gt;
&lt;P&gt;Any more blades to be added in the future? E.G. IPS or other Threat Prevention blades.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can use various commands to monitor the usage or RAM and CPU, including &lt;STRONG&gt;cpview&lt;/STRONG&gt;, &lt;STRONG&gt;fw&lt;/STRONG&gt; &lt;STRONG&gt;ctl&lt;/STRONG&gt; &lt;STRONG&gt;pstat&lt;/STRONG&gt;,&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I still like the old command:&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;fw tab -t connections -s&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_CLI_ReferenceGuide/Content/Topics-CLIG/SECMG/cpstat.htm?Highlight=cpstat" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_CLI_ReferenceGuide/Content/Topics-CLIG/SECMG/cpstat.htm?Highlight=cpstat&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just for guidance and initial learning:&lt;/P&gt;
&lt;P&gt;Snippet from&amp;nbsp;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk39555" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk39555&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="Connections Table and Memory Pool"&gt;Connections Table and Memory Pool&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- These settings exist only in SmartDashboard R77.30 and lower.&lt;/P&gt;
&lt;P&gt;To control connections table size and kernel memory from SmartDashboard, select one of these options in the section "&lt;STRONG&gt;Calculate connections hash table size and memory pool&lt;/STRONG&gt;":&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Automatically&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(default and recommended) - Automatically calculates all values for this Security Gateway / Cluster / VSX Virtual System. The administrator does not need to change them. The derived settings are typically high maximum memory pool and low initial memory pool size values.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Manually&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Table size, Hash size, and HMEM size are set manually. It is not recommended to change this setting to a high value, because the more memory you allocate, the larger the impact on Security Gateway performance.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="Connections Hash Table Size"&gt;Connections Hash Table Size&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- This setting exists only in SmartDashboard R77.30 and lower.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Connections hash table size&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Size of the hash table in bytes (default =&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;131072&lt;/CODE&gt;). This value must be an integer that is an exponential power of two and approximately four times the value of the "&lt;STRONG&gt;Maximum concurrent connection&lt;/STRONG&gt;".&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Example:&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If the connection limit is set to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;50000&lt;/CODE&gt;, the hash table size should be 2&lt;SUP&gt;16&lt;/SUP&gt;=&lt;CODE&gt;65536&lt;/CODE&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A larger hash size has a good effect on performance.&lt;/LI&gt;
&lt;LI&gt;An effective hash table size should be approximately four times the number of average concurrent connections.&lt;BR /&gt;In most cases, the maximum operational limit of a 4 MB hash table size can support a maximum of one million connections.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When you use the "&lt;STRONG&gt;Automatic&lt;/STRONG&gt;" setting, the connections hash table size, memory pool size, and maximum memory pool size values change in these ranges:&lt;/P&gt;
&lt;DIV class="table-wrapper"&gt;
&lt;TABLE class="footnote" border="1" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR class="SubTitle" align="middle" bgcolor="#d6dff0"&gt;
&lt;TD&gt;&lt;STRONG&gt;Concurrent connections limit&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Hash size (bytes)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Mem. Pool (MB)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Max. Mem. Pool (MB)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;0-21000&lt;/TD&gt;
&lt;TD&gt;65536&lt;/TD&gt;
&lt;TD&gt;6-8&lt;/TD&gt;
&lt;TD&gt;24-33&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;22000-43000&lt;/TD&gt;
&lt;TD&gt;131072&lt;/TD&gt;
&lt;TD&gt;8-17&lt;/TD&gt;
&lt;TD&gt;35-68&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;44000-87000&lt;/TD&gt;
&lt;TD&gt;262144&lt;/TD&gt;
&lt;TD&gt;17-34&lt;/TD&gt;
&lt;TD&gt;70-139&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;88000-174000&lt;/TD&gt;
&lt;TD&gt;524288&lt;/TD&gt;
&lt;TD&gt;35-69&lt;/TD&gt;
&lt;TD&gt;140-278&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;175000-349000&lt;/TD&gt;
&lt;TD&gt;1048576&lt;/TD&gt;
&lt;TD&gt;70-139&lt;/TD&gt;
&lt;TD&gt;280-559&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;350000-699000&lt;/TD&gt;
&lt;TD&gt;2097152&lt;/TD&gt;
&lt;TD&gt;140-279&lt;/TD&gt;
&lt;TD&gt;560-1119&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;700000-1398000&lt;/TD&gt;
&lt;TD&gt;4194304&lt;/TD&gt;
&lt;TD&gt;280-559&lt;/TD&gt;
&lt;TD&gt;1121-2047&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;Example:&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;For a maximum concurrent connections limit of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;725000&lt;/CODE&gt;, automatic calculations result in these values:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Connections hash table size:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;4194304&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Memory pool size:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;290&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;MB&lt;/LI&gt;
&lt;LI&gt;Maximum memory pool size:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;1161&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;MB&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Automatic settings do not account for the physical memory available on the Security Gateway / Cluster Members. The examples in the above section show a high maximum limit and low memory pool size.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Feb 2026 11:59:44 GMT</pubDate>
    <dc:creator>Don_Paterson</dc:creator>
    <dc:date>2026-02-05T11:59:44Z</dc:date>
    <item>
      <title>Check Point Firewalls Connection Table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269770#M53409</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;Our Infrastructure consists of External &amp;amp; Internal firewalls in Cluster HA Availability mode. Check Point Firewalls are Virtual Machines deployed on Vmware Esxi Hosts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewalls have assigned resources of:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;4 vCPUs&lt;/LI&gt;&lt;LI&gt;16 GB RAM&lt;/LI&gt;&lt;LI&gt;NICs are VMXNET 3&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Recently, while performing zdebug on internal firewalls we've noticed 98-100% connection table utilization. TAC advised us to change the capacity optimization setting from 2500 to automatic. After the change we've noticed that the cpu utilization on the active gateway now is around 35%.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is if this is going to create any issue on the internal firewalls in the future ? i.e resource exhaustion ? kernel corruption ? it would be advisable to increase the vCPU on the affected gateways ?&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 11:34:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269770#M53409</guid>
      <dc:creator>katsarasd</dc:creator>
      <dc:date>2026-02-05T11:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Firewalls Connection Table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269772#M53410</link>
      <description>&lt;P&gt;It should not but there is not enough information to give a firm answer/s.&lt;/P&gt;
&lt;P&gt;Performance question answers are not always straight forward and as much information as possible should be collected and used to investigate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Automatic&lt;/STRONG&gt; has been the default for new installations for many versions now.&lt;/P&gt;
&lt;P&gt;The more connections that are handled by the gateway the more memory used - to record the connection details in the connections table (and NAT and other tables).&lt;/P&gt;
&lt;P&gt;CPU is consumed by the firewall software enforcing the policy. Rule matching.&lt;/P&gt;
&lt;P&gt;SecureXL can offload the CPUs significantly if a lot of traffic is handled on the fast path, but traffic handled by blades like IPS, App. Control and Content Awareness will take more CPU.&lt;/P&gt;
&lt;P&gt;HTTPS Inspection will also require more CPU resources.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fwaccel stats -s&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_PerformanceTuning_AdminGuide/Content/Topics-PTG/SecureXL.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_PerformanceTuning_AdminGuide/Content/Topics-PTG/SecureXL.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;What version/s are you running?&lt;/P&gt;
&lt;P&gt;What was the CPU utilization before?&lt;/P&gt;
&lt;P&gt;Do you plan to have more traffic load in the future?&lt;/P&gt;
&lt;P&gt;Any more blades to be added in the future? E.G. IPS or other Threat Prevention blades.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can use various commands to monitor the usage or RAM and CPU, including &lt;STRONG&gt;cpview&lt;/STRONG&gt;, &lt;STRONG&gt;fw&lt;/STRONG&gt; &lt;STRONG&gt;ctl&lt;/STRONG&gt; &lt;STRONG&gt;pstat&lt;/STRONG&gt;,&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I still like the old command:&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;fw tab -t connections -s&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_CLI_ReferenceGuide/Content/Topics-CLIG/SECMG/cpstat.htm?Highlight=cpstat" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_CLI_ReferenceGuide/Content/Topics-CLIG/SECMG/cpstat.htm?Highlight=cpstat&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just for guidance and initial learning:&lt;/P&gt;
&lt;P&gt;Snippet from&amp;nbsp;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk39555" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk39555&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="Connections Table and Memory Pool"&gt;Connections Table and Memory Pool&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- These settings exist only in SmartDashboard R77.30 and lower.&lt;/P&gt;
&lt;P&gt;To control connections table size and kernel memory from SmartDashboard, select one of these options in the section "&lt;STRONG&gt;Calculate connections hash table size and memory pool&lt;/STRONG&gt;":&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Automatically&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(default and recommended) - Automatically calculates all values for this Security Gateway / Cluster / VSX Virtual System. The administrator does not need to change them. The derived settings are typically high maximum memory pool and low initial memory pool size values.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Manually&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Table size, Hash size, and HMEM size are set manually. It is not recommended to change this setting to a high value, because the more memory you allocate, the larger the impact on Security Gateway performance.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="Connections Hash Table Size"&gt;Connections Hash Table Size&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- This setting exists only in SmartDashboard R77.30 and lower.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Connections hash table size&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Size of the hash table in bytes (default =&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;131072&lt;/CODE&gt;). This value must be an integer that is an exponential power of two and approximately four times the value of the "&lt;STRONG&gt;Maximum concurrent connection&lt;/STRONG&gt;".&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Example:&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If the connection limit is set to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;50000&lt;/CODE&gt;, the hash table size should be 2&lt;SUP&gt;16&lt;/SUP&gt;=&lt;CODE&gt;65536&lt;/CODE&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A larger hash size has a good effect on performance.&lt;/LI&gt;
&lt;LI&gt;An effective hash table size should be approximately four times the number of average concurrent connections.&lt;BR /&gt;In most cases, the maximum operational limit of a 4 MB hash table size can support a maximum of one million connections.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When you use the "&lt;STRONG&gt;Automatic&lt;/STRONG&gt;" setting, the connections hash table size, memory pool size, and maximum memory pool size values change in these ranges:&lt;/P&gt;
&lt;DIV class="table-wrapper"&gt;
&lt;TABLE class="footnote" border="1" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR class="SubTitle" align="middle" bgcolor="#d6dff0"&gt;
&lt;TD&gt;&lt;STRONG&gt;Concurrent connections limit&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Hash size (bytes)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Mem. Pool (MB)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;&lt;STRONG&gt;Max. Mem. Pool (MB)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;0-21000&lt;/TD&gt;
&lt;TD&gt;65536&lt;/TD&gt;
&lt;TD&gt;6-8&lt;/TD&gt;
&lt;TD&gt;24-33&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;22000-43000&lt;/TD&gt;
&lt;TD&gt;131072&lt;/TD&gt;
&lt;TD&gt;8-17&lt;/TD&gt;
&lt;TD&gt;35-68&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;44000-87000&lt;/TD&gt;
&lt;TD&gt;262144&lt;/TD&gt;
&lt;TD&gt;17-34&lt;/TD&gt;
&lt;TD&gt;70-139&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;88000-174000&lt;/TD&gt;
&lt;TD&gt;524288&lt;/TD&gt;
&lt;TD&gt;35-69&lt;/TD&gt;
&lt;TD&gt;140-278&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;175000-349000&lt;/TD&gt;
&lt;TD&gt;1048576&lt;/TD&gt;
&lt;TD&gt;70-139&lt;/TD&gt;
&lt;TD&gt;280-559&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;350000-699000&lt;/TD&gt;
&lt;TD&gt;2097152&lt;/TD&gt;
&lt;TD&gt;140-279&lt;/TD&gt;
&lt;TD&gt;560-1119&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;700000-1398000&lt;/TD&gt;
&lt;TD&gt;4194304&lt;/TD&gt;
&lt;TD&gt;280-559&lt;/TD&gt;
&lt;TD&gt;1121-2047&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;EM&gt;Example:&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;For a maximum concurrent connections limit of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;725000&lt;/CODE&gt;, automatic calculations result in these values:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Connections hash table size:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;4194304&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;Memory pool size:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;290&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;MB&lt;/LI&gt;
&lt;LI&gt;Maximum memory pool size:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;1161&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;MB&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Automatic settings do not account for the physical memory available on the Security Gateway / Cluster Members. The examples in the above section show a high maximum limit and low memory pool size.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 11:59:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269772#M53410</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2026-02-05T11:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Firewalls Connection Table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269774#M53411</link>
      <description>&lt;P&gt;I should also mention the &lt;STRONG&gt;hcp -r all&lt;/STRONG&gt; command, just to get the Health Check Point tests run and see current health status.&lt;/P&gt;
&lt;P&gt;That may help to get a view of what's happening in there and then also have a benchmark.&lt;/P&gt;
&lt;P&gt;After running &lt;STRONG&gt;hcp&lt;/STRONG&gt; you should be able to connect to the gateway and view the report in a html page:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://&amp;lt;gateway-ip:port&amp;gt;/hcp" target="_blank"&gt;https://&amp;lt;gateway-ip&amp;gt;:&amp;lt;port-if-needed&amp;gt;/hcp&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 12:07:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269774#M53411</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2026-02-05T12:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Firewalls Connection Table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269781#M53412</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18248"&gt;@Don_Paterson&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for the valuable info.&lt;/P&gt;&lt;P&gt;According to what you asked:&lt;/P&gt;&lt;P&gt;What version/s are you running?--&amp;gt; 81.20 take 120&lt;/P&gt;&lt;P&gt;What was the CPU utilization before?--&amp;gt; it as around 4-5 %&lt;/P&gt;&lt;P&gt;Do you plan to have more traffic load in the future? We expect more groth&lt;/P&gt;&lt;P&gt;Any more blades to be added in the future? E.G. IPS or other Threat Prevention blades.--&amp;gt; IPS, Anti-Bot, Anti-Virus are enabled&lt;BR /&gt;&lt;BR /&gt;Also i've run the hcp -r all command on the firewall and the results seem fine.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 13:02:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269781#M53412</guid>
      <dc:creator>katsarasd</dc:creator>
      <dc:date>2026-02-05T13:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Firewalls Connection Table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269783#M53413</link>
      <description>&lt;P&gt;TAC is 100% correct and here is why I would suggest the same. Main reason is because when its set to automatic, gateway would technically calculate needed memory/cpu usage based on consumption, rather than when its set to manual.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 13:34:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269783#M53413</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-05T13:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Firewalls Connection Table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269786#M53414</link>
      <description>&lt;P&gt;You are welcome.&lt;/P&gt;
&lt;P&gt;The CPU utilization numbers would need some supporting information like number of connections and connections/second at the same point in time.&lt;/P&gt;
&lt;P&gt;5% normally indicates a gateway that is idling and handling very little or no traffic at the point in time when the CPU resource utilisation is measured.&lt;/P&gt;
&lt;P&gt;It is also important to monitor the active gateway in the cluster and not the standby, and to understand the differences in the numbers taken from each of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This document can give you an idea of the possible maximum throughput capabilities of an R81.20 gateway with 4 CPU cores and different combinations of blades.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.checkpoint.com/downloads/products/cloudguard-gateway-performance-for-vmware-esxi-datasheet.pdf" target="_blank"&gt;https://www.checkpoint.com/downloads/products/cloudguard-gateway-performance-for-vmware-esxi-datasheet.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should talk to presales.&lt;/P&gt;
&lt;P&gt;If you need more CPUs to handle more traffic in the future then more CPU licenses would be needed unless they are already purchased and in the vSEC license pool.&lt;/P&gt;
&lt;P&gt;They can also advise on performance and future planning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can learn about performance monitoring from various sources (example below) but it may be quicker to talk to presales or professional services.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/m-p/40528#M703" target="_blank"&gt;https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/m-p/40528#M703&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 13:55:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Firewalls-Connection-Table/m-p/269786#M53414</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2026-02-05T13:55:16Z</dc:date>
    </item>
  </channel>
</rss>

