<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Check Point Endpoint remote access VPN Slow Network Performance in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-Endpoint-remote-access-VPN-Slow-Network-Performance/m-p/281511#M46767</link>
    <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;&lt;SPAN&gt;We are experiencing&amp;nbsp;&lt;/SPAN&gt;slow network performance when connected via Check Point Remote Access VPN.&lt;/P&gt;&lt;P class=""&gt;We have Cloudguard as the VPN gateway, VPN protocol IKEV2, Endpoint remote access vpn client version is&amp;nbsp; E89.25&lt;/P&gt;&lt;P class=""&gt;client logs are not set to extended&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;R82.10 Cloudguard Gateway is using the following settings for Remote Access VPN:&lt;/P&gt;&lt;P&gt;Phase 1: AES-256. SHA256, DH Group 14&lt;BR /&gt;Phase 2: AES-256. SHA256&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have tested network speed from an AWS EC2 instance to the Internet using the&amp;nbsp;&lt;/SPAN&gt;same CloudGuard gateway and AWS Internet Gateway. The throughput is approximately 1 Gbps.&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;This indicates that the CloudGuard gateway and AWS Internet Gateway are unlikely to be the primary bottleneck.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;The performance issue appears to be specific to traffic traversing the Remote access vpn&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;We have also confirmed that AES-NI is supported on the gateway:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;fw ctl get int AESNI_is_supported

AESNI_is_supported = 1&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P class=""&gt;&lt;SPAN&gt;SecureXL is also enabled and processing traffic. Current statistics show:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;fwaccel stats -s&lt;BR /&gt; Accelerated conns/Total conns : 0/603 (0%) &lt;BR /&gt;LightSpeed conns/Total conns : 0/603 (0%) &lt;BR /&gt;Accelerated pkts/Total pkts : 5738741623/7815153810 (73%) &lt;BR /&gt;LightSpeed pkts/Total pkts : 0/7815153810 (0%) &lt;BR /&gt;F2Fed pkts/Total pkts : 2076412187/7815153810 (26%)&lt;BR /&gt; F2V pkts/Total pkts : 51192425/7815153810 (0%) &lt;BR /&gt;CPASXL pkts/Total pkts : 141377524/7815153810 (1%) &lt;BR /&gt;PSLXL pkts/Total pkts : 5450678682/7815153810 (69%) &lt;BR /&gt;UDP IS XL pkts/Total pkts : 146512835/7815153810 (1%) &lt;BR /&gt;CPAS pipeline pkts/Total pkts : 0/7815153810 (0%)&lt;BR /&gt; PSL pipeline pkts/Total pkts : 0/7815153810 (0%) &lt;BR /&gt;UDP IS pipeline pkts/Total pkts : 0/7815153810 (0%) &lt;BR /&gt;QOS inbound pkts/Total pkts : 0/7815153810 (0%) &lt;BR /&gt;QOS outbound pkts/Total pkts : 0/7815153810 (0%)&lt;BR /&gt; Corrected pkts/Total pkts : 0/7815153810 (0%)&lt;/PRE&gt;&lt;P class=""&gt;Need assistance to identify what is causing the network slowness issue in checkpoint VPN&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;A class="" href="https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-remote-access-VPN-Slow-Network-Performance/m-p/281465#" target="_blank" rel="noopener" aria-label="Add Tag..."&gt;Add tags&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 25 Aug 2026 22:05:02 GMT</pubDate>
    <dc:creator>Cathy_Cheng</dc:creator>
    <dc:date>2026-08-25T22:05:02Z</dc:date>
    <item>
      <title>Check Point Endpoint remote access VPN Slow Network Performance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-Endpoint-remote-access-VPN-Slow-Network-Performance/m-p/281511#M46767</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P class=""&gt;&lt;SPAN&gt;We are experiencing&amp;nbsp;&lt;/SPAN&gt;slow network performance when connected via Check Point Remote Access VPN.&lt;/P&gt;&lt;P class=""&gt;We have Cloudguard as the VPN gateway, VPN protocol IKEV2, Endpoint remote access vpn client version is&amp;nbsp; E89.25&lt;/P&gt;&lt;P class=""&gt;client logs are not set to extended&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;R82.10 Cloudguard Gateway is using the following settings for Remote Access VPN:&lt;/P&gt;&lt;P&gt;Phase 1: AES-256. SHA256, DH Group 14&lt;BR /&gt;Phase 2: AES-256. SHA256&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have tested network speed from an AWS EC2 instance to the Internet using the&amp;nbsp;&lt;/SPAN&gt;same CloudGuard gateway and AWS Internet Gateway. The throughput is approximately 1 Gbps.&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;This indicates that the CloudGuard gateway and AWS Internet Gateway are unlikely to be the primary bottleneck.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;The performance issue appears to be specific to traffic traversing the Remote access vpn&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;We have also confirmed that AES-NI is supported on the gateway:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN&gt;fw ctl get int AESNI_is_supported

AESNI_is_supported = 1&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P class=""&gt;&lt;SPAN&gt;SecureXL is also enabled and processing traffic. Current statistics show:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;fwaccel stats -s&lt;BR /&gt; Accelerated conns/Total conns : 0/603 (0%) &lt;BR /&gt;LightSpeed conns/Total conns : 0/603 (0%) &lt;BR /&gt;Accelerated pkts/Total pkts : 5738741623/7815153810 (73%) &lt;BR /&gt;LightSpeed pkts/Total pkts : 0/7815153810 (0%) &lt;BR /&gt;F2Fed pkts/Total pkts : 2076412187/7815153810 (26%)&lt;BR /&gt; F2V pkts/Total pkts : 51192425/7815153810 (0%) &lt;BR /&gt;CPASXL pkts/Total pkts : 141377524/7815153810 (1%) &lt;BR /&gt;PSLXL pkts/Total pkts : 5450678682/7815153810 (69%) &lt;BR /&gt;UDP IS XL pkts/Total pkts : 146512835/7815153810 (1%) &lt;BR /&gt;CPAS pipeline pkts/Total pkts : 0/7815153810 (0%)&lt;BR /&gt; PSL pipeline pkts/Total pkts : 0/7815153810 (0%) &lt;BR /&gt;UDP IS pipeline pkts/Total pkts : 0/7815153810 (0%) &lt;BR /&gt;QOS inbound pkts/Total pkts : 0/7815153810 (0%) &lt;BR /&gt;QOS outbound pkts/Total pkts : 0/7815153810 (0%)&lt;BR /&gt; Corrected pkts/Total pkts : 0/7815153810 (0%)&lt;/PRE&gt;&lt;P class=""&gt;Need assistance to identify what is causing the network slowness issue in checkpoint VPN&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;A class="" href="https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-remote-access-VPN-Slow-Network-Performance/m-p/281465#" target="_blank" rel="noopener" aria-label="Add Tag..."&gt;Add tags&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 25 Aug 2026 22:05:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-Endpoint-remote-access-VPN-Slow-Network-Performance/m-p/281511#M46767</guid>
      <dc:creator>Cathy_Cheng</dc:creator>
      <dc:date>2026-08-25T22:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Endpoint remote access VPN Slow Network Performance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-Endpoint-remote-access-VPN-Slow-Network-Performance/m-p/281513#M46768</link>
      <description>&lt;P&gt;Did you follow the AWS VPN best practices below, which are mentioned in my new Max Power 2026 book and call for reducing the MTU to less than 1500, depending on the algorithms you are using:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.aws.amazon.com/vpn/latest/s2svpn/cgw-best-practice.html" target="_blank" rel="noopener"&gt;https://docs.aws.amazon.com/vpn/latest/s2svpn/cgw-best-practice.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;From the Gaia OS of a gateway, you can determine if there is a low intervening MTU between you and your VPN peer (like 1450 in this example) by using &lt;STRONG&gt;tracepath&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tracepath.png" style="width: 772px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35126i8F99A4ED2C76C421/image-size/large?v=v2&amp;amp;px=999" role="button" title="tracepath.png" alt="tracepath.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;tracepath.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 23:46:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-Endpoint-remote-access-VPN-Slow-Network-Performance/m-p/281513#M46768</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-08-25T23:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Endpoint remote access VPN Slow Network Performance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-Endpoint-remote-access-VPN-Slow-Network-Performance/m-p/281516#M46769</link>
      <description>&lt;P&gt;Thanks Timothy, below is the tracepath result&amp;nbsp; How do I determine what MTU size I should change it to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tracepath vpn client ip&amp;nbsp;&lt;BR /&gt;1?: [LOCALHOST] pmtu 9001&lt;BR /&gt;1: 10.100.0.2 2.224ms pmtu 8926&lt;BR /&gt;1: no reply&lt;BR /&gt;2: no reply&lt;BR /&gt;3: no reply&lt;BR /&gt;4: no reply&lt;BR /&gt;5: no reply&lt;BR /&gt;6: no reply&lt;BR /&gt;7: no reply&lt;BR /&gt;8: no reply&lt;BR /&gt;9: no reply&lt;BR /&gt;10: no reply&lt;BR /&gt;11: no reply&lt;BR /&gt;12: no reply&lt;BR /&gt;13: no reply&lt;BR /&gt;14: no reply&lt;BR /&gt;15: 10.100.0.2 236.905ms reached&lt;BR /&gt;Resume: pmtu 8926 hops 15 back 1&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2026 03:02:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-Endpoint-remote-access-VPN-Slow-Network-Performance/m-p/281516#M46769</guid>
      <dc:creator>Cathy_Cheng</dc:creator>
      <dc:date>2026-08-26T03:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Endpoint remote access VPN Slow Network Performance</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Check-Point-Endpoint-remote-access-VPN-Slow-Network-Performance/m-p/281522#M46771</link>
      <description>&lt;P&gt;Run tracepath to the client's globally routable external IP address, not through the tunnel.&amp;nbsp; If I'm reading that correctly, it appears you ran tracepath through the tunnel to the client's assigned Office Mode address.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2026 10:49:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Check-Point-Endpoint-remote-access-VPN-Slow-Network-Performance/m-p/281522#M46771</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-08-26T10:49:05Z</dc:date>
    </item>
  </channel>
</rss>

