<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX &amp; SecureXL in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34661#M7274</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The first problem has been resolved.&lt;/P&gt;&lt;P&gt;SecureXL was not working correctly due to fragmentation.&lt;/P&gt;&lt;P&gt;Changing the routing and MTU changed the behaviour of SecureXL.&lt;/P&gt;&lt;P&gt;Now SecureXL is fast for the connection with problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the customer does a single connection through the firewall. It gets 100 Mbit/s (limited by the other side).&lt;/P&gt;&lt;P&gt;After 6-7 minutes, the speed drops to 20 Mbit/s and cpu of VSX (fwk) goes up.&lt;/P&gt;&lt;P&gt;I think I'm htting a limit at the other side (no Check Point).&lt;/P&gt;&lt;P&gt;No drops at the Check Point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any tips?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Oct 2018 14:46:12 GMT</pubDate>
    <dc:creator>Sander_Zumbrink</dc:creator>
    <dc:date>2018-10-12T14:46:12Z</dc:date>
    <item>
      <title>VSX &amp; SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34659#M7272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm investigating some performance issues where a VSX firewall is in between.&lt;/P&gt;&lt;P&gt;The gateway is running R80.10 with JHF112.&lt;/P&gt;&lt;P&gt;The VS is using IPS, Antibot and application control.&lt;/P&gt;&lt;P&gt;But we've made some exceptions for specific traffic to bypass IPS, Antibot and not log in ApplControl.&lt;/P&gt;&lt;P&gt;Stats: 19% SXL, 59% PXL, 21% F2F.&lt;/P&gt;&lt;P&gt;fwk process uses approx. 50% of available CPU's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Downloads where 1Mbyte/s through this VS.&lt;/P&gt;&lt;P&gt;When I disabled SecureXL (fwaccel off) the speed was 6 Mbyte/s.&lt;/P&gt;&lt;P&gt;This traffic was also using a F5 BIGIP loadbalancer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I make some connections without the loadbalancer, the speed was higher.&lt;/P&gt;&lt;P&gt;With SecureXL enabled it was 10 Mbyte/s and without secureXL it was 20 Mbyte/s.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anybody seen the same? Higher speeds with SecureXL disabled?&lt;/P&gt;&lt;P&gt;And did you find the cause of it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sander Zumbrink&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2018 12:13:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34659#M7272</guid>
      <dc:creator>Sander_Zumbrink</dc:creator>
      <dc:date>2018-10-11T12:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: VSX &amp; SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34660#M7273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What kind of traffic?&lt;/P&gt;&lt;P&gt;Is it multiple flows or only a single flow?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2018 14:36:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34660#M7273</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-12T14:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: VSX &amp; SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34661#M7274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The first problem has been resolved.&lt;/P&gt;&lt;P&gt;SecureXL was not working correctly due to fragmentation.&lt;/P&gt;&lt;P&gt;Changing the routing and MTU changed the behaviour of SecureXL.&lt;/P&gt;&lt;P&gt;Now SecureXL is fast for the connection with problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the customer does a single connection through the firewall. It gets 100 Mbit/s (limited by the other side).&lt;/P&gt;&lt;P&gt;After 6-7 minutes, the speed drops to 20 Mbit/s and cpu of VSX (fwk) goes up.&lt;/P&gt;&lt;P&gt;I think I'm htting a limit at the other side (no Check Point).&lt;/P&gt;&lt;P&gt;No drops at the Check Point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any tips?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2018 14:46:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34661#M7274</guid>
      <dc:creator>Sander_Zumbrink</dc:creator>
      <dc:date>2018-10-12T14:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: VSX &amp; SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34662#M7275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They are doing RSYNC over SSH on port 80.&lt;/P&gt;&lt;P&gt;I've excluded IPS/appl. control/TP.&lt;/P&gt;&lt;P&gt;And made a single port 80 service with application None.&lt;/P&gt;&lt;P&gt;It is a single flow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2018 14:48:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34662#M7275</guid>
      <dc:creator>Sander_Zumbrink</dc:creator>
      <dc:date>2018-10-12T14:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: VSX &amp; SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34663#M7276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well one thing I found out in Israel this week is that fragmented packets are no longer doomed to the slowpath on R80.20 gateways so there is that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as the speed decrease that occurs after 6-7 minutes that sounds pretty odd, when troubleshooting a strange performance issue like that the main determination you need to make early is whether packet &lt;EM&gt;latency&lt;/EM&gt; or &lt;EM&gt;loss&lt;/EM&gt; is causing the slowdown.&amp;nbsp; Easiest way to do that is run a continuous ping between the hosts during the transfer and see if the values being reported by ping change when the slowdown starts.&amp;nbsp; This is not foolproof though as ICMP traffic is handled quite differently depending on the situation, the most common example I can think of is that ICMP is never accelerated by SecureXL whereas TCP and UDP can potentially be accelerated.&amp;nbsp; The only definitive way to determine latency vs. loss as the cause is looking at a packet capture in Wireshark.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Second Edition of my "Max Power" Firewall Book&lt;BR /&gt;&lt;SPAN&gt;Now Available at &lt;/SPAN&gt;&lt;A class="" href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Oct 2018 22:26:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34663#M7276</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-10-12T22:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: VSX &amp; SecureXL</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34664#M7277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like an issue on the customer side. The gateway (not checkpoint) there was limiting the traffic.&lt;/P&gt;&lt;P&gt;I assume that I'm receiving zero-window packets, but the dumps being provided are not complete.&lt;/P&gt;&lt;P&gt;For now the customer is letting the issue go and doing the backups another way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the replies.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2018 07:35:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VSX-SecureXL/m-p/34664#M7277</guid>
      <dc:creator>Sander_Zumbrink</dc:creator>
      <dc:date>2018-10-22T07:35:31Z</dc:date>
    </item>
  </channel>
</rss>

