<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the best approach to troubleshoot &amp;quot;slow connections&amp;quot;? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-best-approach-to-troubleshoot-quot-slow-connections/m-p/13747#M91265</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This document here:&amp;nbsp;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98348&amp;amp;partition=General&amp;amp;product=Security" rel="nofollow" style="color: #e45785; background-color: #ffffff; border: 0px; text-decoration: underline; padding: 0px calc(12px + 0.35ex) 0px 0px;"&gt;sk98348: Best Practices - Security Gateway Performance&lt;/A&gt;&amp;nbsp;!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Nov 2018 12:02:55 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2018-11-06T12:02:55Z</dc:date>
    <item>
      <title>What is the best approach to troubleshoot "slow connections"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-best-approach-to-troubleshoot-quot-slow-connections/m-p/13746#M91264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello fellow Check Point admins,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to keep it short - how do you troubleshoot slow connections?&lt;/P&gt;&lt;P&gt;Every now and then I receive requests from users/sys admins who complain that their backup jobs or all different kinds of traffic appears to be really slow once they have to pass a firewall in our environment. In most cases I am pretty sure that this is not the case, at least not related to the firewall. But as we all know - it always has to be the firewalls fault. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So that leads to the before mentioned questions. Currently I do several things to verify if I have some issues on the fw side, like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- checking the related interfaces and error counters&lt;/P&gt;&lt;P&gt;- enable accounting in the logging of a related rule to see the transmitted data size&lt;/P&gt;&lt;P&gt;- check for possible TCP out of state logs, which could be related to timeouts and therefore throttle the connection due to reconnect attempts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But to be honest, I am pretty sure that there are other, better, approaches to determine if the firewall is the cause of slow downs or not. So please, tell me about your recommendations. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Maik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 09:37:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-best-approach-to-troubleshoot-quot-slow-connections/m-p/13746#M91264</guid>
      <dc:creator>Maik</dc:creator>
      <dc:date>2018-11-06T09:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best approach to troubleshoot "slow connections"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-best-approach-to-troubleshoot-quot-slow-connections/m-p/13747#M91265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This document here:&amp;nbsp;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98348&amp;amp;partition=General&amp;amp;product=Security" rel="nofollow" style="color: #e45785; background-color: #ffffff; border: 0px; text-decoration: underline; padding: 0px calc(12px + 0.35ex) 0px 0px;"&gt;sk98348: Best Practices - Security Gateway Performance&lt;/A&gt;&amp;nbsp;!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Nov 2018 12:02:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-best-approach-to-troubleshoot-quot-slow-connections/m-p/13747#M91265</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-11-06T12:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best approach to troubleshoot "slow connections"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-best-approach-to-troubleshoot-quot-slow-connections/m-p/13748#M91266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Günther,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. I am familiar with this document but I do not think that it is helping me in this case.&lt;/P&gt;&lt;P&gt;Maybe my description of the initial question was kinda bad worded.&lt;/P&gt;&lt;P&gt;I have users who have to run their backup service [TSM backup] via a firewall after a specific network migration. Now they complain that the backup takes 16 minutes instead of 4 minutes as before. A report of the backup from before shows a throughput of about 160MB/s while the current status only shows only about 50 MB/s. The related security gateway is a 64k appliance which has no trouble regarding the actual CPU and interface load. I'm basically struggeling to find a way to prove that the firewall is not the cause - or if it should be, to change that.&lt;/P&gt;&lt;P&gt;There are ways to caluclate the throughput based on the window size and round trip time - but is here any way to show the actual throughput of a specific session / between two hosts?&lt;/P&gt;&lt;P&gt;Maybe &lt;A href="https://community.checkpoint.com/migrated-users/41625"&gt;https://community.checkpoint.com/people/d401179d-0d5b-369d-a0f2-387c3ef54533&lt;/A&gt; has an idea? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Maik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 07:42:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-best-approach-to-troubleshoot-quot-slow-connections/m-p/13748#M91266</guid>
      <dc:creator>Maik</dc:creator>
      <dc:date>2018-11-07T07:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best approach to troubleshoot "slow connections"?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-best-approach-to-troubleshoot-quot-slow-connections/m-p/13749#M91267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A good start is always running the "Super Seven" on the firewall to check its overall health and state as described here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/9630"&gt;TechTalk: Security Gateway Performance Optimization with Tim Hall&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These commands should more or less work on a 64k but that box is not one of my major areas of expertise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Beyond that, one of the first things you should try to determine is whether the bad performance is caused by excessive latency (and possibly its evil sidekick jitter), flat-out packet loss, or maybe even both.&amp;nbsp; Packet loss can generally be found and fixed, but latency issues are a bit tougher to figure out.&amp;nbsp; Usually taking a packet capture of the problematic traffic then pulling it&amp;nbsp; into Wireshark is helpful; look for TCP zero window events and long inter-packet delays.&amp;nbsp; At a basic level you need to figure out is the client primarily waiting around for the server to do something or is it the other way around; the firewall could potentially be the cause of latency as well.&amp;nbsp; That will at least give you a place to start looking for resource issues such as congestion or overloaded networks/systems.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;90% of troubleshooting is knowing the right place to look, the remaining 10% of figuring out how to fix it isn't nearly as difficult.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2018 14:43:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/What-is-the-best-approach-to-troubleshoot-quot-slow-connections/m-p/13749#M91267</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-11-08T14:43:37Z</dc:date>
    </item>
  </channel>
</rss>

