<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint Security VPN network performance in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179943#M5108</link>
    <description>&lt;P&gt;E86.50&lt;/P&gt;</description>
    <pubDate>Thu, 04 May 2023 09:44:27 GMT</pubDate>
    <dc:creator>jakmic</dc:creator>
    <dc:date>2023-05-04T09:44:27Z</dc:date>
    <item>
      <title>Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179400#M5104</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have problem with data transfer performance via VPN in our lab environment.&lt;/P&gt;&lt;P&gt;Topology:&lt;/P&gt;&lt;P&gt;Cluster of 2 VM Gateways&lt;/P&gt;&lt;P&gt;Windows VPN client&amp;nbsp;&lt;/P&gt;&lt;P&gt;MacOS ssh server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we are transferring data over LAN (between two networks) speed of 3GB file transfer is some about 200Mbps&lt;/P&gt;&lt;P&gt;When we are transferring data over VPN&amp;nbsp;speed of 3GB file transfer is some about 20Mbps (WinSCP)&lt;/P&gt;&lt;P&gt;Lab environment hasn't any performance problems (CPU of active gateway is about 5%)&lt;/P&gt;&lt;P&gt;WAN network is 1Gbps/1Gbps on every site.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;ESP: AES-256 + SHA256 (we tried lower security algorithms, but nothing changes)&lt;/P&gt;&lt;P&gt;Scheme: IKE&lt;/P&gt;&lt;P&gt;How can we increase VPN network performance&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 09:03:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179400#M5104</guid>
      <dc:creator>jakmic</dc:creator>
      <dc:date>2023-04-28T09:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179401#M5105</link>
      <description>&lt;P&gt;There's a couple of unknowns here - but&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk105119" target="_self"&gt;sk105119&lt;/A&gt;&amp;nbsp; would be your best starting point.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also make sure&amp;nbsp;AES-NI is enabled on the processor level (since you're running OpenServer / VM) otherwise AES-256 will not be accelerated.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Ruan&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 09:19:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179401#M5105</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-04-28T09:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179409#M5106</link>
      <description>&lt;P&gt;Which client version are you using E86.60 or higher?&lt;/P&gt;
&lt;P&gt;(Client side&amp;nbsp;&lt;SPAN&gt;AES-NI support was introduced here)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 00:57:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179409#M5106</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-29T00:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179486#M5107</link>
      <description>&lt;P&gt;What version of gateway?&lt;BR /&gt;Cores/memory allocation for the VM?&lt;BR /&gt;R81.20 might have better performance in this regard due to some internal changes.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Apr 2023 00:39:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179486#M5107</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-29T00:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179943#M5108</link>
      <description>&lt;P&gt;E86.50&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 09:44:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179943#M5108</guid>
      <dc:creator>jakmic</dc:creator>
      <dc:date>2023-05-04T09:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179944#M5109</link>
      <description>&lt;P&gt;2 Cores, Memory 4GB&lt;/P&gt;&lt;P&gt;R81.10 JB Take 87&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 09:50:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179944#M5109</guid>
      <dc:creator>jakmic</dc:creator>
      <dc:date>2023-05-04T09:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179945#M5110</link>
      <description>&lt;P&gt;I neet to check, because VM is running on our Data Center solution - For now, I don't know hardware specification on backend&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 09:54:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179945#M5110</guid>
      <dc:creator>jakmic</dc:creator>
      <dc:date>2023-05-04T09:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179946#M5111</link>
      <description>&lt;P&gt;Yes, there is AES flag recognized by Checkpoint VM&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 10:05:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179946#M5111</guid>
      <dc:creator>jakmic</dc:creator>
      <dc:date>2023-05-04T10:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179969#M5112</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/68667"&gt;@jakmic&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Take the latest version E87.20. It has multiple improvements comparing to E86.50:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;It has AES-NI support on client side&lt;/LI&gt;
&lt;LI&gt;It has new and improved VPN driver&lt;/LI&gt;
&lt;LI&gt;It has experimental flag which may also help:&lt;BR /&gt;In the registry set the following value:&lt;BR /&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\CheckPoint\TRAC]&lt;BR /&gt;"disable_threaded_ipsec"=dword:00000000&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Besides that make sure logging level in the client is set to Basic. Extended mode significantly consumes performance.&lt;/P&gt;
&lt;P&gt;I'm not sure 2 Cores + 4Gb RAM is sufficient for R81.10 gateway. Which hardware do you use for VPN client? There more powerful device you use for testing the higher performance you should get.&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 13:05:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/179969#M5112</guid>
      <dc:creator>AndreiR</dc:creator>
      <dc:date>2023-05-04T13:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/180007#M5113</link>
      <description>&lt;P&gt;Those are bare minimum system requirements for a gateway.&lt;BR /&gt;You'll definitely&amp;nbsp;want to allocate additional cores and RAM if performance is a concern.&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2023 19:26:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/180007#M5113</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-04T19:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/180310#M5114</link>
      <description>&lt;P&gt;For &lt;STRONG&gt;Test&lt;/STRONG&gt; environment and &lt;STRONG&gt;one&lt;/STRONG&gt; VPN user I think is enough &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I went by your proposition and check load on gateway and client computer&lt;/P&gt;&lt;P&gt;During transfer GW had some about 64% in peaks and average 20% , but our client site had&amp;nbsp;&lt;STRONG&gt;100%&amp;nbsp;&lt;/STRONG&gt;(i5-5300U)&lt;/P&gt;&lt;P&gt;On newer Endpoint VPN Client (E87.20) we received 50% faster transfer (30-35Mbps) so&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5692"&gt;@AndreiR&lt;/a&gt;&amp;nbsp;thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We took newer client hardware (i7-12700H) and tried again - now transfers are optimistic - some about 320Mbps (&lt;STRONG&gt;10x more&lt;/STRONG&gt;) - CPU load about 20-23% during transfer&lt;/P&gt;&lt;P&gt;Now I have a question, there is any solution to optimize client Endpoint Security VPN on older hardware?&lt;/P&gt;&lt;P&gt;From another side, when you go to&amp;nbsp;&lt;A href="https://www.checkpoint.com/quantum/remote-access-vpn/#downloads" target="_blank"&gt;https://www.checkpoint.com/quantum/remote-access-vpn/#downloads&lt;/A&gt;&amp;nbsp;(look like main point to download client) you will receive older version (&lt;SPAN&gt;E86.50_CheckPointVPN.msi)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 08:08:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/180310#M5114</guid>
      <dc:creator>jakmic</dc:creator>
      <dc:date>2023-05-09T08:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/180364#M5115</link>
      <description>&lt;P&gt;Trying different encryption algorithms might be at the expense of security.&lt;/P&gt;
&lt;P&gt;I've asked internally for the website links sighted above to be updated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 11:52:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/180364#M5115</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-05-09T11:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/180445#M5116</link>
      <description>&lt;P&gt;In terms of optimizing performance on older computers, there's not much that can be done at this time.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 22:50:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/180445#M5116</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-09T22:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN network performance</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/180536#M5117</link>
      <description>&lt;P&gt;The E87.xx releases do not have a "recommended" release yet, which is probably why it's not linked directly from checkpoint.com&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 16:14:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-network-performance/m-p/180536#M5117</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-10T16:14:31Z</dc:date>
    </item>
  </channel>
</rss>

