<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limitation on Ipsec tunnel in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163857#M27378</link>
    <description>&lt;P&gt;O man, that made me laugh, though its not funny, but still... : - ).Yea, I think 30k tunnels would "MELT" any appliance LOL&lt;/P&gt;</description>
    <pubDate>Thu, 01 Dec 2022 13:05:29 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-12-01T13:05:29Z</dc:date>
    <item>
      <title>Limitation on Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163683#M27356</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please update on below queries.&lt;/P&gt;&lt;P&gt;1) How much load can we put on single Tunnel. Is there any traffic limitation over a single IPsec VPN Tunnel?&lt;/P&gt;&lt;P&gt;2) How many IPsec Tunnel can be created? Is there any limitation for creation the IPsec Tunnel ?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 10:31:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163683#M27356</guid>
      <dc:creator>Hardik_Patil_66</dc:creator>
      <dc:date>2022-11-30T10:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation on Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163686#M27357</link>
      <description>&lt;P&gt;Why is this in Maestro space? Are you asking specifically about Maestro environment? Or is this a general question?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 11:04:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163686#M27357</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-30T11:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation on Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163687#M27358</link>
      <description>&lt;P&gt;This is the general question&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 11:11:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163687#M27358</guid>
      <dc:creator>Hardik_Patil_66</dc:creator>
      <dc:date>2022-11-30T11:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation on Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163690#M27359</link>
      <description>&lt;P&gt;Ok, I have moved your post to a more appropriate space.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Answer to both questions: it depends on your Security Gateway performance. There is no hard limit on both throughput and amount of VPN tunnels, but more you have, more CPU time it will consume.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 11:23:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163690#M27359</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-30T11:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation on Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163695#M27361</link>
      <description>&lt;P&gt;Thanks for the update&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 11:35:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163695#M27361</guid>
      <dc:creator>Hardik_Patil_66</dc:creator>
      <dc:date>2022-11-30T11:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation on Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163722#M27365</link>
      <description>&lt;P&gt;Hey Hardik,&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;is indeed 100% correct. There is definitely not a hard limit to this, it all depends on how powerful device is. Its sort of similar to discussion as to what is max number of regular/NAT rules one can create in smart console. There was never set limit to it. Honestly, in my 15 years dealing with CP, the MOST VPN tunnels I see someone have was 133 (I still remember that number well lol). And, consider this was back in R77.xx days, so now the code is way better/more stable. Also, same applies for the bandwidth as well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 13:40:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163722#M27365</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-30T13:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation on Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163778#M27374</link>
      <description>&lt;P&gt;It also depends on software version.&lt;BR /&gt;In the just released R81.20, we done a number of things to improve performance and stability for VPN:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Scalable VPN performance - 3 times faster to process simultaneous Remote Access and Site to Site VPN connections.&lt;/LI&gt;
&lt;LI&gt;Major performance and stability improvement for Remote Access VPN and Site to Site VPN that delivers a significantly greater capacity for VPN tunnels.&lt;/LI&gt;
&lt;LI&gt;Extended Security Gateway certificate validation capabilities for quicker authentication.&lt;/LI&gt;
&lt;LI&gt;Resilient VPN architecture - multi-process architecture to handle IKE negotiations in dedicated scalable daemons, providing unprecedented resiliency.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If VPN performance is a concern, upgrading (or using) R81.20 is highly recommended.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 19:04:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163778#M27374</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-30T19:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation on Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163782#M27375</link>
      <description>&lt;P&gt;Indeed, very true! I personally found with R81.10 and R81.20 that VPN performs much faster.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 19:41:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163782#M27375</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-30T19:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation on Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163824#M27376</link>
      <description>&lt;P&gt;I once had case where a customer logged a ticket due to a 5800 gateway being unresponsive, CPU's pegged etc.&amp;nbsp; did some troubleshooting and narrowed it down to VPND.&amp;nbsp; Customer of course insisted nothing changed in the environment.&lt;/P&gt;
&lt;P&gt;The gateway was the hub in a community with about 100 smaller sites hanging off it. Eventually I managed to run vpn tu and saw there was something like 30 000 tunnels!!!&amp;nbsp; Long story short - one of the customer admins was troubleshooting an IPSEC issue the previous evening and changed the VPN Tunnel sharing setting from "per pair of gateways" to "per pair of hosts" and due to traffic patterns the poor gateways started building tunnels until it almost melted:-)&lt;/P&gt;
&lt;P&gt;Think I might still have a screenhot of the VPN TU output kicking around somewhere:-)&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 10:13:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163824#M27376</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-12-01T10:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation on Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163853#M27377</link>
      <description>&lt;P&gt;Unfortunately I did not get a chance to upgrade it to R80.20 however the most desired thing is to create a separate VPN tunnel if we have multiple ISPs. Checkpoint still not able to resolve the issue.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 12:56:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163853#M27377</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-12-01T12:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: Limitation on Ipsec tunnel</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163857#M27378</link>
      <description>&lt;P&gt;O man, that made me laugh, though its not funny, but still... : - ).Yea, I think 30k tunnels would "MELT" any appliance LOL&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 13:05:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Limitation-on-Ipsec-tunnel/m-p/163857#M27378</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-01T13:05:29Z</dc:date>
    </item>
  </channel>
</rss>

