<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access VPN throughput significantly lower than connection speed – R81.20 / E89.11 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281467#M46763</link>
    <description>&lt;P&gt;1) Make sure you do not have Extended Logging set on the VPN client: &lt;A href="https://support.checkpoint.com/results/sk/sk177125" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk177125: Traffic bandwidth/download speed is very low when Endpoint Clients are connected to VPN&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2) Bring up the SmartView Monitor while VPN clients are connected, and be absolutely sure they are not using 3DES/MD5 for IPSec Phase 2, as that was the default for a very long time; also check the state of Visitor Mode and NAT-T under the Users...All Users view.&lt;/P&gt;
&lt;P&gt;3) If Visitor Mode is not active for your user, you can try forcing it to rule out MTU issues or possible shaping/limiting of ESP but not port 443: &lt;A href="https://support.checkpoint.com/results/sk/sk107433" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk107433: How to change transport method with Endpoint Clients&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;4) In R81.20 you still have the ability to disable SecureXL for all VPN traffic with &lt;STRONG&gt;vpn accel off&lt;/STRONG&gt;, might be worth a try to see if anything changes performance-wise.&lt;/P&gt;
&lt;P&gt;5) The&amp;nbsp;2x Intel Xeon Silver CPUs in the 16200 have plenty of juice and support AES-NI (may want to confirm it has been properly detected with &lt;STRONG&gt;fw ctl get int AESNI_is_supported&lt;/STRONG&gt;), I doubt it is some kind of single-core performance limitation.&lt;/P&gt;</description>
    <pubDate>Tue, 25 Aug 2026 14:13:38 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2026-08-25T14:13:38Z</dc:date>
    <item>
      <title>Remote Access VPN throughput significantly lower than connection speed – R81.20 / E89.11</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281458#M46759</link>
      <description>&lt;P class=""&gt;&lt;SPAN&gt;Hi everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;we are currently investigating a performance issue with Check Point Remote Access VPN and I would appreciate any ideas or experiences with similar behavior.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Our setup:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Check Point Security Gateway: R81.20&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;ClusterXL&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Remote Access VPN Client: E89.11 for Windows&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;IPsec Remote Access VPN&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Client Internet connection: ~50 Mbps&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Download speed through the VPN: only ~20 Mbps&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;SPAN&gt;Without the VPN connection, the client can utilize approximately the full 50 Mbps. As soon as the Check Point VPN tunnel is established, the download throughput drops to around 20 Mbps.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;We initially suspected an MTU/fragmentation issue. The Check Point virtual adapter already uses an MTU of 1350. As a test, I also changed the MTU of the physical Windows network adapter to 1360 and 1350, but this did not result in any noticeable improvement.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;The Security Gateway itself does not appear to be under significant CPU load during the tests.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;We are planning to perform additional tests with iperf3 against an internal server, including:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;single TCP stream&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;multiple parallel TCP streams&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;reverse direction&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;UDP test&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;SPAN&gt;Before going deeper into debugging, I wanted to ask:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Has anyone experienced similar throughput limitations with E89.x Remote Access VPN clients on R81.20?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;In particular, are there any known issues or recommended settings regarding:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Remote Access IPsec performance&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;SecureXL / VPN acceleration&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;CoreXL&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;NAT-T&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;TCP MSS / PMTU&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Endpoint VPN client processing&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;differences between single and multiple TCP streams&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Are there any specific commands, counters, SKs, or debug procedures you would recommend to determine whether the bottleneck is on the Endpoint client or the Security Gateway?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;best regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Roman&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 10:57:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281458#M46759</guid>
      <dc:creator>Romaryo</dc:creator>
      <dc:date>2026-08-25T10:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN throughput significantly lower than connection speed – R81.20 / E89.11</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281459#M46760</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;first you could take a look at this post: &lt;A href="https://community.checkpoint.com/t5/AI-Network-Firewall/VPN-performance-limits/td-p/141700" target="_blank"&gt;https://community.checkpoint.com/t5/AI-Network-Firewall/VPN-performance-limits/td-p/141700&lt;/A&gt;&amp;nbsp; and refer, for example, to the mentioned SKs.&lt;/P&gt;
&lt;P&gt;You could try to change the encryption algorithm used for VPN (if you not already change these parameters).&lt;/P&gt;
&lt;P&gt;About the performance issue, when it started? the vpn was it always slow? Are you using the latest JHF?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 11:04:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281459#M46760</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-08-25T11:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN throughput significantly lower than connection speed – R81.20 / E89.11</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281460#M46761</link>
      <description>&lt;P&gt;Are you using algorithms that are AES-NI friendly?&lt;/P&gt;
&lt;P&gt;Things like Vistor mode might be a factor but also has 3DES been disabled?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk177966" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk177966&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 11:28:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281460#M46761</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-08-25T11:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN throughput significantly lower than connection speed – R81.20 / E89.11</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281462#M46762</link>
      <description>&lt;P&gt;HW 16200&amp;nbsp;&lt;/P&gt;&lt;P&gt;ESP: AES-256 + SHA256&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 12:33:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281462#M46762</guid>
      <dc:creator>Romaryo</dc:creator>
      <dc:date>2026-08-25T12:33:24Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN throughput significantly lower than connection speed – R81.20 / E89.11</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281467#M46763</link>
      <description>&lt;P&gt;1) Make sure you do not have Extended Logging set on the VPN client: &lt;A href="https://support.checkpoint.com/results/sk/sk177125" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk177125: Traffic bandwidth/download speed is very low when Endpoint Clients are connected to VPN&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2) Bring up the SmartView Monitor while VPN clients are connected, and be absolutely sure they are not using 3DES/MD5 for IPSec Phase 2, as that was the default for a very long time; also check the state of Visitor Mode and NAT-T under the Users...All Users view.&lt;/P&gt;
&lt;P&gt;3) If Visitor Mode is not active for your user, you can try forcing it to rule out MTU issues or possible shaping/limiting of ESP but not port 443: &lt;A href="https://support.checkpoint.com/results/sk/sk107433" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk107433: How to change transport method with Endpoint Clients&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;4) In R81.20 you still have the ability to disable SecureXL for all VPN traffic with &lt;STRONG&gt;vpn accel off&lt;/STRONG&gt;, might be worth a try to see if anything changes performance-wise.&lt;/P&gt;
&lt;P&gt;5) The&amp;nbsp;2x Intel Xeon Silver CPUs in the 16200 have plenty of juice and support AES-NI (may want to confirm it has been properly detected with &lt;STRONG&gt;fw ctl get int AESNI_is_supported&lt;/STRONG&gt;), I doubt it is some kind of single-core performance limitation.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 14:13:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281467#M46763</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-08-25T14:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN throughput significantly lower than connection speed – R81.20 / E89.11</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281508#M46766</link>
      <description>&lt;P class=""&gt;&lt;SPAN&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;Thank you very much!&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;At first glance, I think we have found the solution, and it appears to be described in SK177125.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;I will ask our team to verify this on other users’ laptops as well. On my laptop, I was able to reproduce both the issue and the solution successfully.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;I will keep you updated on our further progress.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there any way to change this parameter centrally? We are using the Standalone version. For example, would it be possible to configure it via a TTM file on the gateway?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 20:56:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Remote-Access-VPN-throughput-significantly-lower-than-connection/m-p/281508#M46766</guid>
      <dc:creator>Romaryo</dc:creator>
      <dc:date>2026-08-25T20:56:22Z</dc:date>
    </item>
  </channel>
</rss>

