<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Performance Question in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74379#M15086</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37340"&gt;@tniop_kcehc&lt;/a&gt; &lt;BR /&gt;(nice community name:-)&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Arial','sans-serif';"&gt;Tip!&lt;BR /&gt;I'd turn on AES-NI in BIOS on Open Server. AES-NI is Intel's dedicated instruction set, which significantly improves the speed of Encrypt-Decrypt actions and allows one to increase AES throughput. Check Point supports AES-NI on many appliances, only when running Gaia OS with 64-bit kernel. On these appliances AES-NI is enabled by default. AES-NI is also supported on Open Servers.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;AES-NI is Intel's dedicated instruction set, which significantly improves the speed of Encrypt-Decrypt actions and allows one to increase AES throughput for:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; &lt;SPAN style="font-size: 11.0pt;"&gt;&lt;STRONG&gt;Site-to-Site VPN&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; &lt;SPAN style="font-size: 11.0pt;"&gt;&lt;STRONG&gt;Remote Access VPN&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; &lt;SPAN style="font-size: 11.0pt;"&gt;&lt;STRONG&gt;Mobile Access&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; &lt;SPAN style="font-size: 11.0pt;"&gt;&lt;STRONG&gt;HTTPS Interception&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;With the following command you can test and compare &lt;STRONG&gt;all encryption methods&lt;/STRONG&gt;. After these results I would always recommend to activate AES-NI and AES is preferred to 3DES because it offers many performance advantages through the hardware acceleration.&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000; font-size: 11.0pt;"&gt;&lt;STRONG&gt;Warning notice:&lt;/STRONG&gt;&lt;/SPAN&gt; &lt;SPAN style="font-size: 11.0pt;"&gt;If you execute this command you have 100% CPU usage for a long time!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;STRONG&gt;# cpopenssl speed&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a111.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4341i35336DDAC026A462/image-size/medium?v=v2&amp;amp;px=400" role="button" title="a111.png" alt="a111.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;This makes it possible to compare encryption algorithms. It shows that e.g. AES 256 is more performant than DES. Therefore AES 256 should rather be used for VPN connections than DES or 3DES. This is also well described in the following SK &lt;SPAN style="font-size: 11.0pt; font-family: 'Arial','sans-serif';"&gt;&lt;A title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk73980" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk73980" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;Relative speeds of algorithms for IPsec and SSL&lt;/A&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I had published an article about this that might help you:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3278-r80x-performance-tuning-tip-aes-ni" target="_blank" rel="noopener"&gt;R80.x - Performance Tuning Tip - AES-NI&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Arial','sans-serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2020 20:54:48 GMT</pubDate>
    <dc:creator>HeikoAnkenbrand</dc:creator>
    <dc:date>2020-02-06T20:54:48Z</dc:date>
    <item>
      <title>VPN Performance Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74378#M15085</link>
      <description>&lt;P&gt;We are working on a new firewall concept for our company. Now the question has arisen, which encryption is the most effective&amp;nbsp;and at the same time offers a high level of protection?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any experiences or recommendations here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 20:41:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74378#M15085</guid>
      <dc:creator>tniop_kcehc</dc:creator>
      <dc:date>2020-02-06T20:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74379#M15086</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37340"&gt;@tniop_kcehc&lt;/a&gt; &lt;BR /&gt;(nice community name:-)&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Arial','sans-serif';"&gt;Tip!&lt;BR /&gt;I'd turn on AES-NI in BIOS on Open Server. AES-NI is Intel's dedicated instruction set, which significantly improves the speed of Encrypt-Decrypt actions and allows one to increase AES throughput. Check Point supports AES-NI on many appliances, only when running Gaia OS with 64-bit kernel. On these appliances AES-NI is enabled by default. AES-NI is also supported on Open Servers.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;AES-NI is Intel's dedicated instruction set, which significantly improves the speed of Encrypt-Decrypt actions and allows one to increase AES throughput for:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; &lt;SPAN style="font-size: 11.0pt;"&gt;&lt;STRONG&gt;Site-to-Site VPN&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; &lt;SPAN style="font-size: 11.0pt;"&gt;&lt;STRONG&gt;Remote Access VPN&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; &lt;SPAN style="font-size: 11.0pt;"&gt;&lt;STRONG&gt;Mobile Access&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style="margin-left: 36.0pt; text-indent: -18.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt; &lt;SPAN style="font-size: 11.0pt;"&gt;&lt;STRONG&gt;HTTPS Interception&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;With the following command you can test and compare &lt;STRONG&gt;all encryption methods&lt;/STRONG&gt;. After these results I would always recommend to activate AES-NI and AES is preferred to 3DES because it offers many performance advantages through the hardware acceleration.&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000; font-size: 11.0pt;"&gt;&lt;STRONG&gt;Warning notice:&lt;/STRONG&gt;&lt;/SPAN&gt; &lt;SPAN style="font-size: 11.0pt;"&gt;If you execute this command you have 100% CPU usage for a long time!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;STRONG&gt;# cpopenssl speed&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a111.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4341i35336DDAC026A462/image-size/medium?v=v2&amp;amp;px=400" role="button" title="a111.png" alt="a111.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;This makes it possible to compare encryption algorithms. It shows that e.g. AES 256 is more performant than DES. Therefore AES 256 should rather be used for VPN connections than DES or 3DES. This is also well described in the following SK &lt;SPAN style="font-size: 11.0pt; font-family: 'Arial','sans-serif';"&gt;&lt;A title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk73980" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk73980" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;Relative speeds of algorithms for IPsec and SSL&lt;/A&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I had published an article about this that might help you:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3278-r80x-performance-tuning-tip-aes-ni" target="_blank" rel="noopener"&gt;R80.x - Performance Tuning Tip - AES-NI&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt; font-family: 'Arial','sans-serif';"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 20:54:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74379#M15086</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-02-06T20:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74381#M15087</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm going to test this command "cpopenssl speed"&amp;nbsp; in a maintenance window on our current firewall.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 20:59:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74381#M15087</guid>
      <dc:creator>tniop_kcehc</dc:creator>
      <dc:date>2020-02-06T20:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74382#M15088</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/37340"&gt;@tniop_kcehc&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I like to use the following for phase 1 and phase 2:&lt;BR /&gt;AES256&lt;BR /&gt;SHA256&lt;/P&gt;
&lt;P&gt;This is a middle way between performance and security.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Heiko&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 21:01:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74382#M15088</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-02-06T21:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74383#M15089</link>
      <description>&lt;P&gt;THX&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 21:04:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74383#M15089</guid>
      <dc:creator>tniop_kcehc</dc:creator>
      <dc:date>2020-02-06T21:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74447#M15107</link>
      <description>&lt;P&gt;Isn't it better to use a higher encryption standard.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="test.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4346i6501CC64B3ADB3A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="test.JPG" alt="test.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 13:12:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74447#M15107</guid>
      <dc:creator>Jan_Elbers</dc:creator>
      <dc:date>2020-02-07T13:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74450#M15109</link>
      <description>&lt;P&gt;&lt;FONT&gt;I think higher encryption is better.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Feb 2020 13:43:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74450#M15109</guid>
      <dc:creator>KelvinB</dc:creator>
      <dc:date>2020-02-07T13:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74586#M15123</link>
      <description>&lt;P class="western"&gt;I get this question a lot, so I decided to include my opinion on it in the third edition of my book.&amp;nbsp; My recommended settings from the book are below and are primarily geared to improve performance with a reasonable level of security for most organizations.&amp;nbsp; This is most certainly a matter of opinion and I would be surprised if the following does not generate any debate:&lt;/P&gt;
&lt;P class="western"&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-SPOILER&gt;
&lt;P class="western"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 class="western"&gt;&lt;A target="_blank" name="_Toc502781307"&gt;&lt;/A&gt; Recommended IPSec VPN Settings&lt;/H2&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;The following sections detail which VPN algorithm settings should be used to provide a reasonable level of IPSec VPN performance without sacrificing security. Please note that these recommendations are made primarily to improve performance, and also provide what I feel is a reasonable level of VPN security for most organizations.&lt;/P&gt;
&lt;DIV id="tinyMceEditorTimothy_Hall_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P class="western" style="margin-left: 0.25in; margin-bottom: 0in;"&gt;&lt;EM&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bang.jpg" style="width: 64px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4375i885A816C9157230C/image-size/large?v=v2&amp;amp;px=999" role="button" title="bang.jpg" alt="bang.jpg" /&gt;&lt;/span&gt;Do not just blindly follow these recommendations; please perform a thorough risk analysis that includes any regulatory, legal, life safety, and privacy considerations that are relevant to your organization’s mission, and adjust these recommendations as needed for your specific situation.&lt;/EM&gt;&lt;/P&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;IKE Protocol: V2 (Check Point Firewalls), IKE Protocol V1 for third-party VPNs&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;IKE Phase 1 Encryption: AES-256&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;IKE Phase 1 Data Integrity: SHA-256&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;IKE Phase 1 DH Group: 20 (384-bit ECP)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;IKE Phase 1 SA Lifetime (minutes): 720&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;IKE Phase 2 Encryption: AES-GCM-128 (AES-NI present, otherwise AES-128)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;IKE Phase 2 Data Integrity: SHA-256&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;IKE Phase 2 SA Lifetime (seconds): 3600&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;PFS: Disabled (Use DH Group 19 if PFS is required)&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;Use Aggressive Mode: Disabled&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;Support IP Compression: Disabled&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;VPN Tunnel Sharing (Domain-based VPN): “One VPN tunnel per subnet pair”&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;VPN Tunnel Sharing (Route-based VPN): “One VPN tunnel per Gateway pair”&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;Permanent Tunnels: (Check Point Firewalls Only) “On all tunnels in the community”&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="western" style="margin-bottom: 0in;"&gt;Permanent Tunnels in DPD Mode: Enabled for third-party peers, see &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108600" target="_blank" rel="noopener"&gt;sk108600: VPN Site-to-Site with 3rd party&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI-SPOILER&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Feb 2020 20:06:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/74586#M15123</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-02-09T20:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Performance Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/120844#M22457</link>
      <description>&lt;P&gt;Hi Tim/Heiko,&lt;/P&gt;&lt;P&gt;Thanks for sharing this information.&amp;nbsp; Very useful.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a couple of questions that I hope you can help with.&lt;/P&gt;&lt;P&gt;My community is the default one called "Remote Access".&amp;nbsp; This type of community provides no option to configure Encryption settings.&amp;nbsp; The Encryption options for this community have to be set under Global Properties, Remote Access, VPN - Authentication and the available settings in this area appear to be limited (I only see limited Diffie-Hellman groups).&lt;/P&gt;&lt;P&gt;If I do start to create a new mesh community I notice many more Encryption options available within the community settings for example Group 19 and 20.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I want my VPN community to use these more secure methods do I need to migrate to a new commnutiy or am I missing something?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 13:36:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Performance-Question/m-p/120844#M22457</guid>
      <dc:creator>Marcus_Smith</dc:creator>
      <dc:date>2021-06-10T13:36:52Z</dc:date>
    </item>
  </channel>
</rss>

