<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Low bandwidth when checkpoint is connected in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24227#M89577</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Install take 142 and review your SND and multiqueue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Jan 2019 11:19:06 GMT</pubDate>
    <dc:creator>Alessandro_Marr</dc:creator>
    <dc:date>2019-01-14T11:19:06Z</dc:date>
    <item>
      <title>Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24222#M89572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello checkmates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have issue with checkpoint firewall R80.10 gaia Os ,we receive 12 mb from the ISP but when you connect checkpoint&amp;nbsp;&lt;/P&gt;&lt;P&gt;firewall its reducing to 3.75 mb we tried to disable some blades but still didnt resolve the issue and we also engaged and had 3 hours session with checkpoint support engineers&amp;nbsp; but that didnt solve any thing as they mentioned that we need to enable secure xl but again when we enable that we loose internet therefore what could be an issue and below is the report from the checkpoint support team.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;As I promised, here are my detailed notes on what we did today, including environment, troubleshooting steps and next possible steps.&lt;BR /&gt; &lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;╔═════════════╗&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;║&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt; ENVIRONMENT&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;╚═════════════╝&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;BR /&gt; &amp;nbsp;One firewall and one management Server, running R80.10&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;╔═════════════════╗&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;║&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt; BUSINESS IMPACT / SEVERITY&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;╚═════════════════╝&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;BR /&gt; &amp;nbsp;Medium&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;╔═══════╗&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;║&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt; ISSUE&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;╚═══════╝&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;BR /&gt; &amp;nbsp;Network speed drags when CheckPoint is introduced to the network.&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;╔═════════════════╗&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;║&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt; TROUBLESHOOTING&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;╚═════════════════╝&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;BR /&gt; Very low bandwith, when the CheckPoint is connected.&lt;BR /&gt; &lt;BR /&gt; Before the CheckPoint, the bandwith was 10.86 and after adding the CheckPoint, the bandwith became 3.57.&lt;BR /&gt; Currently, the speed is 3.72.&lt;BR /&gt; The device is a 5000, running R80.10.&lt;BR /&gt; The enabled blades are General, Application Control, URL Filter, IPS and Anti-Bot.&lt;BR /&gt; &lt;BR /&gt; Entered the firewall via Putty session.&lt;BR /&gt; Ran the command fw ctl zdebug drop | grep 172.16.0.87&lt;BR /&gt; No drops were observed.&lt;BR /&gt; &lt;BR /&gt; Entered SmartDashboard.&lt;BR /&gt; Disabled the IPS blade as a test, since it has been known to cause problems with traffic in the past.&lt;BR /&gt; &lt;BR /&gt; Attempted to push policy.&lt;BR /&gt; The Application Control and URL Filter have expired contratcs, that can not be fetched.&lt;BR /&gt; This is a possible issue.&lt;BR /&gt; &lt;BR /&gt; Speed test after disabling the IPS blade is 4.34&lt;BR /&gt; &lt;BR /&gt; Returned to SmartDashboard.&lt;BR /&gt; Opened the Policy and then the threat Prevention Policy.&lt;BR /&gt; Created an exception, which disabled Anti-Bot and IPS on the test PC (172.16.0.87).&lt;BR /&gt; The speed test was 4.79.&lt;BR /&gt; &lt;BR /&gt; Disabled the Application Control and URL Filter as another test.&lt;BR /&gt; Installation of policy failed because Rule 9 contained Application Control.&lt;BR /&gt; Disbaled Rule 9.&lt;BR /&gt; Pushed policy.&lt;BR /&gt; &lt;BR /&gt; Speed was 4.75.&lt;BR /&gt; &lt;BR /&gt; Returned to SmartDashboard.&lt;BR /&gt; Disabled all blades but the General.&lt;BR /&gt; Pushed policy.&lt;BR /&gt; The speed remained 4.79&lt;BR /&gt; &lt;BR /&gt; Returned to the Putty session.&lt;BR /&gt; Ran the command fw monitor -T -p all -e "accept host (172.16.0.87);"&lt;BR /&gt; No blade holds onto the packets for too long.&lt;BR /&gt; &lt;BR /&gt; Could this be an interface issue?&lt;BR /&gt; &lt;BR /&gt; The interface, leading to the internet is eth3.&lt;BR /&gt; Ethtool eth3 shows the interface is full duplex and with speed of 1000Mb/s.&lt;BR /&gt; Auto negociation is on.&lt;BR /&gt; Turned it off for testing purposes with the command ethtool -s eth3 autoneg off.&lt;BR /&gt; &lt;BR /&gt; Speed test was 2.19.&lt;BR /&gt; &lt;BR /&gt; Returned to the Putty session.&lt;BR /&gt; Ran the command top.&lt;BR /&gt; There is nothing unusual - the memory works well and the 3 CPUs are idle most of the time.&lt;BR /&gt; &lt;BR /&gt; Ran the command cpinfo -y all.&lt;BR /&gt; The firewall is on Take 112.&lt;BR /&gt; There are newer takes but we would only upgrade if absolutely necessery.&lt;BR /&gt; &lt;BR /&gt; Ran the command fwaccel stat.&lt;BR /&gt; SecureXL is DISABLED.&lt;BR /&gt; Enabled it with the command fwaccel on.&lt;BR /&gt; &lt;BR /&gt; Enabling SecureXL stops the Internet.&lt;BR /&gt; Customer stopped SecureXL with the command fwaccel off.&lt;BR /&gt; Ran the command cpconfig.&lt;BR /&gt; SecureXL is enabled.&lt;BR /&gt; Ran the command fw accel stat.&lt;BR /&gt; Here, SecureXL is disabled.&lt;BR /&gt; &lt;BR /&gt; Entered SmartDashboard.&lt;BR /&gt; Opened Logs and Monitoring.&lt;BR /&gt; There is no dropped traffic from the time of the issue.&lt;BR /&gt; &lt;BR /&gt; Ran the command fw ctl affinity -l -r -v -a.&lt;BR /&gt; We see the following output:&lt;BR /&gt; CPU 0 at eth1,&lt;BR /&gt; CPU 1 at fw_2&lt;BR /&gt; CPU 2 at fw_1&lt;BR /&gt; CPU 3 at fw_0&lt;BR /&gt; &lt;BR /&gt; A good next step to do is to install the newest Jumbo Hotfix Accumulator.&lt;BR /&gt; &lt;BR /&gt; Provided the customer with Take 161, which we downloaded from the Support Center.&lt;BR /&gt; &lt;BR /&gt; Entered the Gaia WebUI.&lt;BR /&gt; Opened CPUSE and then Status and Action.&lt;BR /&gt; Clicked on Upload package and uploaded the provided jumbo - Take 161.&lt;BR /&gt; Take 161 was successfully uploaded.&lt;BR /&gt; &lt;BR /&gt; Right-clicked the Take 161 and tried to install the Take.&lt;BR /&gt; The Take can not install since we can not UNinstall Take 121 because of the SMACK Take.&lt;BR /&gt; Uninstalled the Smack Take.&lt;BR /&gt; Successfully managed to install Take 161.&lt;BR /&gt; &lt;BR /&gt; However, on top of the Gaia WebUI's CPUSE, there is a message: "Your currently installed license is not entitled to receive udpates from Check Point Download Center."&lt;BR /&gt; &lt;BR /&gt; Entered the firewall via Putty session.&lt;BR /&gt; Ran the command cplic print -x.&lt;BR /&gt; All the contracts on the box have expired.&lt;BR /&gt; &lt;BR /&gt; Entered SmartDashboard.&lt;BR /&gt; Opened Manage licenses and packages.&lt;BR /&gt; Chose File - Licenses and Contracts - Contracts - Update contracts from the User Center.&lt;BR /&gt; Customer put in his username and password.&lt;BR /&gt; &lt;BR /&gt; Internet is still down.&lt;BR /&gt; Entered the firewall via Putty session.&lt;BR /&gt; Entered cpconfig.&lt;BR /&gt; Disabled SecureXL.&lt;BR /&gt; &lt;BR /&gt; Internet is back up but the speed is around 4.10.&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;╔════════════╗&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;║&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt; NEXT STEPS&lt;BR /&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;╚════════════╝&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;BR /&gt; There is some trouble, since SecureXL brings the Internet down.&lt;BR /&gt; Secure XL should NOT be interfering with the Internet, it should be increasing speed.&lt;BR /&gt; &lt;BR /&gt; Possible next steps include:&lt;BR /&gt; - Start a remote session.&lt;BR /&gt; - Note the time of the session.&lt;BR /&gt; - Enabled SecureXL. Be preapred for Internet to go down.&lt;BR /&gt; - Ask customer to run the command fw ctl zdebug drop | grep [IP], as well as top and tcpdump on eth3.&lt;BR /&gt; - All of this would tell us why exactly Secure XL is bringing the Internet down.&lt;BR /&gt; &lt;BR /&gt; - This is a SecureXL issue.&lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 09:43:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24222#M89572</guid>
      <dc:creator>Sangisha_Daka_K</dc:creator>
      <dc:date>2019-01-14T09:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24223#M89573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Working with TAC is definitely the best way to progress troubleshooting the issue described here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please ensure they're aware of the type of internet connection (PPPoE etc) and verify speed/duplex of connections to any downstream switches or network devices.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 10:59:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24223#M89573</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2019-01-14T10:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24224#M89574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;disable QoS rules &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;and do not overload your box with blades like IPS and URLF or APPC. Then check the speed.&lt;/P&gt;&lt;P&gt;what are the resources you've allocated to that VM or ... is it an Appliance? What model?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 10:59:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24224#M89574</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-01-14T10:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24225#M89575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;5000 appliance without QoS enabled according to the above details provided.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 11:03:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24225#M89575</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2019-01-14T11:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24226#M89576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;oh sorry overlooked details below, indeed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;of PPoE I'd definitely take a good care of the MTU firest &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 11:16:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24226#M89576</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-01-14T11:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24227#M89577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Install take 142 and review your SND and multiqueue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 11:19:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24227#M89577</guid>
      <dc:creator>Alessandro_Marr</dc:creator>
      <dc:date>2019-01-14T11:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24228#M89578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please post the results of the "show interface eth#" statistics here for both, internal and external interfaces.&lt;/P&gt;&lt;P&gt;Rerun the speedtest and note if the error counters incremented and let us know the outcome.&lt;/P&gt;&lt;P&gt;What kind of equipment is connected to the internal and external interfaces of the gateway?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 12:05:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24228#M89578</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-01-14T12:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24229#M89579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please, run a "top" too and post. Your MTU settings is default? 1500&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 12:15:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24229#M89579</guid>
      <dc:creator>Alessandro_Marr</dc:creator>
      <dc:date>2019-01-14T12:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24230#M89580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Low performance here is almost certainly an interface issue, please post output of &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;.&amp;nbsp; Also as advised earlier, make sure MTU is consistent on all interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Latency vs. Loss: Running a continuous ping during a speed test, is there packet loss or high latency?&amp;nbsp; If the former, probably an interface issue that will be revealed by &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SecureXL breaking Internet connectivity is generally indicative of something seriously broken in your network setup/config, and can also be caused by use of PPPoE or MTU issues, see:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk61221&amp;amp;partition=Advanced&amp;amp;product=IPSec" style="max-width: 840px;"&gt;sk61221: Issues requiring adjustment of the Maximum Segment Size (MSS) of TCP SYN and TCP SYN-ACK packets on Security Gateway&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also wondering if the firewall hardware itself has a problem, please provide output of &lt;STRONG&gt;cpstat -f sensors os&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;--&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;CheckMates Break Out Sessions Speaker&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;CPX 2019 Las Vegas &amp;amp; Vienna - Tuesday@13:30&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 13:27:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24230#M89580</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-01-14T13:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24231#M89581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;told him, &lt;STRONG&gt;MTU&lt;/STRONG&gt; on ext. interface&amp;nbsp;is&amp;nbsp;most of the time the thing we do not pay enough attention to when connecting PPPoE to the WAN uplinks.&lt;/P&gt;&lt;P&gt;1500 is overkill for PPPoE therefore decreasing it to 1460 may or may not help, unless some other sensors as you've mentioned Tim interfere with the device circumstances.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 14:20:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24231#M89581</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-01-14T14:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24232#M89582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;here is an example from my 5600 CXL (2018 Appliance):&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Temperature Sensors&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;|Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |Value|Unit&amp;nbsp;&amp;nbsp; |Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |Status|&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;|Intake Temp|40.00|Celsius|Temperature|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0|&lt;BR /&gt;|Outlet Temp|42.00|Celsius|Temperature|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0|&lt;BR /&gt;|CPU Temp&amp;nbsp;&amp;nbsp; |43.00|Celsius|Temperature|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0|&lt;BR /&gt;----------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fan Speed Sensors&lt;BR /&gt;--------------------------------------&lt;BR /&gt;|Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |Value&amp;nbsp; |Unit|Type|Status|&lt;BR /&gt;--------------------------------------&lt;BR /&gt;|System Fan1|6250.00|RPM |Fan |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0|&lt;BR /&gt;|System Fan2|5818.50|RPM |Fan |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0|&lt;BR /&gt;|System Fan3|5443.50|RPM |Fan |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0|&lt;BR /&gt;--------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Voltage Sensors&lt;BR /&gt;---------------------------------&lt;BR /&gt;|Name |Value|Unit|Type&amp;nbsp;&amp;nbsp; |Status|&lt;BR /&gt;---------------------------------&lt;BR /&gt;|VCore|1.74 |Volt|Voltage|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0|&lt;BR /&gt;|+12V |11.98|Volt|Voltage|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0|&lt;BR /&gt;|3.3V |3.31 |Volt|Voltage|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0|&lt;BR /&gt;|VDIMM|1.50 |Volt|Voltage|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0|&lt;BR /&gt;|+5V&amp;nbsp; |5.07 |Volt|Voltage|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0|&lt;BR /&gt;|VBAT |3.12 |Volt|Voltage|&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0|&lt;BR /&gt;---------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;***&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;compare with yours &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ifconfig of the WAN interface please and show us your MTU on it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UP BROADCAST RUNNING MULTICAST&amp;nbsp; &lt;STRONG&gt;MTU:1500&lt;/STRONG&gt;&amp;nbsp; Metric:1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX packets:113156077 errors:0 dropped:0 overruns:0 frame:0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TX packets:93581556 errors:0 dropped:0 overruns:0 carrier:0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; collisions:0 txqueuelen:1000 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RX bytes:84691993709 (78.8 GiB)&amp;nbsp; TX bytes:32822951109 (30.5 GiB)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 14:23:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24232#M89582</guid>
      <dc:creator>Jerry</dc:creator>
      <dc:date>2019-01-14T14:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24233#M89583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yep in regards to the &lt;STRONG&gt;cpstat -f sensors os&lt;/STRONG&gt; command, 0=good, anything else=bad.&amp;nbsp; The classic one from a performance perspective I've seen is a failed CPU fan at 0 rpm, and subsequent massive CPU downclocking to keep the processor from literally bursting into flames.&amp;nbsp; Very difficult to figure out why things are so darn slow in that case.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;--&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;CheckMates Break Out Sessions Speaker&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;CPX 2019 Las Vegas &amp;amp; Vienna - Tuesday@13:30&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2019 16:10:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24233#M89583</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-01-14T16:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24234#M89584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What was inline before CP appliance? who's the ISP provider? Is there requirements from ISP for modem/router models? what is termination point?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2019 04:01:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24234#M89584</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2019-01-18T04:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24235#M89585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="output results" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/77087_Screenshot (134).png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2019 09:18:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24235#M89585</guid>
      <dc:creator>Sangisha_Daka_K</dc:creator>
      <dc:date>2019-01-18T09:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24236#M89586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Besides MTU mentioned earlier did you consider hard-coding speed/duplex config&amp;nbsp;on interfaces and verify same on adjacent routers/switches&amp;nbsp;?&amp;nbsp;Can you run speed test through GW via interface not connected to ISP?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2019 18:40:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/24236#M89586</guid>
      <dc:creator>Alex_Rozhko</dc:creator>
      <dc:date>2019-01-18T18:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/52905#M89587</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I know that this thread has not had any activity in some time, but I was wondering if this issue was ever resolved. If so, what was the root cause?&lt;/P&gt;&lt;P&gt;I have an environment that seems to be experiencing the same issue. There are no interface errors and MTU is 1500 everywhere and there are no interface errors. We have applied Jumbo Hotfix and still experience the issue. Any assistance is appreciated. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 13:36:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/52905#M89587</guid>
      <dc:creator>Van-N</dc:creator>
      <dc:date>2019-05-08T13:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/52917#M89588</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28983"&gt;@Van-N&lt;/a&gt;&amp;nbsp;, please describe the equipment seating between your gateway's external interface and the ISP.&lt;/P&gt;
&lt;P&gt;Make, model, OS.&lt;/P&gt;
&lt;P&gt;I have seen, in smaller environments, specifically with cable modems, occasional need to power-cycle those to regain nominal performance.&lt;/P&gt;
&lt;P&gt;As I did not have access to those devices and they are managed by ISPs, no reasonable explanation to this behavior was ever found.&lt;/P&gt;
&lt;P&gt;Bandwidth was definitely affected and has immediately recovered to full rated capacity after reboot of the ISP equipment.&lt;/P&gt;
&lt;P&gt;Just for kicks, when you are experiencing problems, try to connect a host directly to ISP equipment with the same IP as your gateway and run the tests from it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Vladimir&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 14:42:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/52917#M89588</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-05-08T14:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/52937#M89589</link>
      <description>&lt;P&gt;Two Checkpoint 5100 appliances running Gaia R80.20 in cluster.&amp;nbsp; Connected to Cisco ISR 4300 running 16.6.5, which is connected to ISP device.&lt;/P&gt;&lt;P&gt;Have not had a chance to run checks on the ISP device (power cycle or direct connect) as things are in production now and I am remote so cannot do the physical changes to check those.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 18:26:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/52937#M89589</guid>
      <dc:creator>Van-N</dc:creator>
      <dc:date>2019-05-08T18:26:05Z</dc:date>
    </item>
    <item>
      <title>Re: Low bandwidth when checkpoint is connected</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/99765#M89590</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This is still a major issue with Checkpoint to this day, and is rearing it's ugly head during Covid. Checkpoint is doing something to drastically decrease the bandwidth when remote access clients connect with VPN client. I am on version e83.20 and have experience this for many years. TAC still can't solve it.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2020 01:05:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Low-bandwidth-when-checkpoint-is-connected/m-p/99765#M89590</guid>
      <dc:creator>Tim_McColgan</dc:creator>
      <dc:date>2020-10-22T01:05:31Z</dc:date>
    </item>
  </channel>
</rss>

