<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint VPN users facing extreme slowness in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100653#M9695</link>
    <description>&lt;P&gt;I would consult with TAC about this !&lt;/P&gt;</description>
    <pubDate>Fri, 30 Oct 2020 12:56:50 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2020-10-30T12:56:50Z</dc:date>
    <item>
      <title>Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100636#M9690</link>
      <description>&lt;P&gt;We are currently using Checkpoint Appliance 23500 in our Data Centre which is running in Cluster (Active/Standby).&lt;/P&gt;&lt;P&gt;We have approx: 2500 to 3000 active remote VPN users connecting to the firewall at a time during Peak business hours.&lt;/P&gt;&lt;P&gt;The Internet on the Checkpoint Firewall is 2Gbps, and it peaks upto 800Mbps during business hours.&lt;/P&gt;&lt;P&gt;There is 20 CPU's, and we have Multi-Threading enabled so total 40 Virtual CPU's, the CPU peaks to max 55% during the peak business hours.&lt;/P&gt;&lt;P&gt;Hub mode is configured to route all traffic through the gateway (due to security reasons we cannot change it).&lt;/P&gt;&lt;P&gt;Enabled blades:&lt;/P&gt;&lt;P&gt;[Expert@QTS-CP-NW-FW02:0]# enabled_blades&lt;BR /&gt;fw vpn cvpn urlf av appi ips identityServer anti_bot content_awareness mon vpn&lt;/P&gt;&lt;P&gt;Most of the Remote VPN users have an Internet speed of about 200Mbps, some even have 500Mbps.&lt;/P&gt;&lt;P&gt;But after connecting to Checkpoint Endpoint VPN the speed goes below 15 Mbps (Download) and Upload (50 Mbps), which is affecting 2000+ users.&lt;/P&gt;&lt;P&gt;Below are some of the verification done from our side:&lt;/P&gt;&lt;P&gt;1. We have auto_detect set for&amp;nbsp;endpoint_vpn_ipsec_transport in Guidbedit Firewall properties.&lt;/P&gt;&lt;P&gt;2. SecureXL is enabled:&lt;/P&gt;&lt;P&gt;[Expert@QTS-CP-NW-FW02:0]# fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 10/39553 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 163746283249/335101509859 (48%)&lt;BR /&gt;F2Fed pkts/Total pkts : 9663120065/335101509859 (2%)&lt;BR /&gt;F2V pkts/Total pkts : 2927705054/335101509859 (0%)&lt;BR /&gt;CPASXL pkts/Total pkts : 0/335101509859 (0%)&lt;BR /&gt;PSLXL pkts/Total pkts : 161692106545/335101509859 (48%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/335101509859 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/335101509859 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/335101509859 (0%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. We tried to change the Remote VPN Phase 1 and Phase 2 encryption algorithm to lower encryption AES-128 SHA-1, but still no improvements.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also we have Multiple Interface option in VPN Clients --&amp;gt; Office Mode checked.&lt;/P&gt;&lt;P&gt;"Support connectivity enhancement for gateways with multiple external interfaces"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need assistance to identify what is causing the network slowness issue in checkpoint VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 10:07:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100636#M9690</guid>
      <dc:creator>Lithin_Mathew</dc:creator>
      <dc:date>2020-10-30T10:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100637#M9691</link>
      <description>&lt;P&gt;I read that you have 3000 RA clients in Hub mode - so when you divide GWs 2Gbps by 3000x2 (as most traffic goes thru the GW 2 times), what is left for each client ? Routing all connections makes a heavy load...&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 10:12:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100637#M9691</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-30T10:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100643#M9692</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for your quick response.&lt;/P&gt;&lt;P&gt;We have netflow enabled on the Gateway and as per the bandwidth utilisation report it never exceeds 800Mbps, if bandwidth was an issue we should have seen it peaking up to 2Gbps right.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 10:35:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100643#M9692</guid>
      <dc:creator>Lithin_Mathew</dc:creator>
      <dc:date>2020-10-30T10:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100644#M9693</link>
      <description>&lt;P&gt;What is the traffic on each of the 2 x 2000+ connections? 15 Mbps (Download) and Upload (50 Mbps) times 2000+ times two ?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 10:58:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100644#M9693</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-30T10:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100647#M9694</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually I forgot to mention the below points as well:&lt;/P&gt;&lt;P&gt;1. We ran the speedtest, during non-business hours, that is at 2am EST when the active remote VPN users where around 50, the results were the same.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. During the peak hours we also ran speedtest from the Servers within the DC (which are behind the CP firewall) we get speed upto 700 Mbps for download on these servers, the point to note is all the traffic is going only via the single 2Gbps circuit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So not sure if bandwidth could be the reason which is causing the VPN slowness.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 11:55:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100647#M9694</guid>
      <dc:creator>Lithin_Mathew</dc:creator>
      <dc:date>2020-10-30T11:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100653#M9695</link>
      <description>&lt;P&gt;I would consult with TAC about this !&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 12:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100653#M9695</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-10-30T12:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100661#M9696</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp; for checking on this, actually we already have a ticket opened with Checkpoint Support for the same, currently its escalated to Tier-3 but still we are unable to find the root cause of the issue, so I thought to get help from the Checkpoint Community.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2020 13:20:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100661#M9696</guid>
      <dc:creator>Lithin_Mathew</dc:creator>
      <dc:date>2020-10-30T13:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100759#M9697</link>
      <description>&lt;P&gt;It may be partially a client side issue and should be addressed via the TAC.&lt;/P&gt;
&lt;P&gt;That said with appropriate controls on the endpoint you don’t need to “route all traffic” back to your gateways.&lt;BR /&gt;To me, that seems like a much more scalable approach.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 06:33:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100759#M9697</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-01T06:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100796#M9698</link>
      <description>&lt;P&gt;You don't mention your code version, make sure you are running at least&amp;nbsp;R80.40 Jumbo HFA Take 53+ where major scalability improvements were added for Visitor Mode traffic.&amp;nbsp; Do you know if your users are utilizing Visitor Mode?&lt;/P&gt;
&lt;P&gt;Need to know your CoreXL split, and what does individual core utilization look like during busy periods on SND/IRQ vs Firewall Worker cores?&amp;nbsp; Also need to see &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt; to ensure network interfaces are running cleanly without frame loss.&amp;nbsp; Please provide output of Super Seven commands, ideally taken when Remote Access VPN traffic is high.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 14:37:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100796#M9698</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-11-01T14:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100846#M9699</link>
      <description>&lt;P&gt;I second&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;, hub mode might be the main reason for slow connectivity.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 08:48:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100846#M9699</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-11-02T08:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100852#M9700</link>
      <description>&lt;P&gt;I can second that - Visitor mode can be an issue, see &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk159372&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank"&gt;sk159372: &lt;STRONG&gt;Visitor&lt;/STRONG&gt; &lt;STRONG&gt;Mode&lt;/STRONG&gt; in Remote Access clients&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Even with R80.40 Jumbo HFA Take 53, when the limitation on the maximum number of simultaneous Visitor Mode connections of 1024 was lifted, Visitor mode can only work by adding additional encapsulations to the traffic...&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 09:08:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100852#M9700</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-11-02T09:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100914#M9701</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;We are running R80.30 Take 196.&lt;/P&gt;&lt;P&gt;NAT-T is enabled in VPN Clients &amp;gt; Remote Access, also as of checking now we have 1900+ users connected to RA VPN and only 3 users part of Visitor mode.&lt;/P&gt;&lt;P&gt;We had high CPU on the SND Cores before we enabled Multi-Queue (before June 2020), after we enabling Multi-Queue and adding more cores to the SND (currently 6 cores for Multi-Queue and 34 Cores for FW Workers) we have not seen SND's crossing above 60% CPU during peak hours.&lt;/P&gt;&lt;P&gt;I have attached all the outputs here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 15:08:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100914#M9701</guid>
      <dc:creator>Lithin_Mathew</dc:creator>
      <dc:date>2020-11-02T15:08:58Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100931#M9702</link>
      <description>&lt;P&gt;Your firewall appears to be well-tuned and not struggling.&amp;nbsp; Your issue kind of sounds like this SK, but your SNDs don't seem to be overloaded:&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk165853&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank" rel="noopener"&gt;sk165853: High CPU usage on one CPU core when the number of Remote Access users is high&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;NAT-T should be getting handled in the kernel, but what does the CPU utilization of vpnd look like when things are slow?&amp;nbsp; I'm wondering if some condition is forcing large amounts of RA VPN traffic to get handled by vpnd.&lt;/P&gt;
&lt;P&gt;Beyond that, it could be some kind of low MTU issue in the network path causing issues with IPSec and the inability to fragment.&amp;nbsp; Try forcing a slow client to use either Visitor Mode or NAT-T as specified here and see what happens:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk107433&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank" rel="noopener"&gt;sk107433: How to change transport method with Endpoint Clients&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 16:56:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/100931#M9702</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-11-02T16:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/101089#M9703</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks all for your help on this, we were able to get this fixed at last.&lt;/P&gt;&lt;P&gt;After working with about 6 Checkpoint Engineers from TAC and 8 hours of troubleshooting, we were able to identify, the culprit for this issue was the Multiple Interfaces option in VPN Clients which was checked.&lt;/P&gt;&lt;P&gt;Even though we only had a Single WAN Interface, the option was kept checked for a very long time (more than 2 years), but the impact was felt when covid started and large number of users migrated to Remote VPN.&lt;/P&gt;&lt;P&gt;The internet speed test was less than 2 Mbps when it was checked and it went upto 40 Mbps after this option was unchecked.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 09:26:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/101089#M9703</guid>
      <dc:creator>Lithin_Mathew</dc:creator>
      <dc:date>2020-11-04T09:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/101107#M9704</link>
      <description>&lt;P&gt;Great to know it is resolved! Thanks for sharing&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 11:54:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/101107#M9704</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-11-04T11:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/101159#M9705</link>
      <description>&lt;P&gt;Hi, you seem to be pointing current stats however what is your past baseline? Have you tried to remove any traffic from the route 0 hub mode with&amp;nbsp;&lt;SPAN&gt;sk167000 ( works really well ). Perhapss alleviating some O365 / Teams or whatever you want can help out with that SK. Are you using any sort of QoS ( either on chkp or elsewhere )?.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 22:54:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/101159#M9705</guid>
      <dc:creator>514numbers</dc:creator>
      <dc:date>2020-11-04T22:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/101165#M9706</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/14812"&gt;@514numbers&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;We have certain limitations in our environment for deploying the&amp;nbsp;&lt;SPAN&gt;sk167000 as we have a set of users for whom outlook won't work if they are not connected to VPN (this was done for security reasons), also wanted to know if Checkpoint has a feature for creating multiple VPN profiles for Remote VPN (a feature which we used for Cisco ASA firewall) in this case we can have different settings for different group of users connecting to the same Gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regarding QoS we do have it enabled, I have shared the enabled_blades output in the initial Post.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2020 04:03:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/101165#M9706</guid>
      <dc:creator>Lithin_Mathew</dc:creator>
      <dc:date>2020-11-05T04:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/101542#M9707</link>
      <description>&lt;P&gt;Excellent news!&lt;/P&gt;&lt;P&gt;Curious, if you can say: &amp;nbsp;Was this similar to the kernel parameter "&lt;EM&gt;fw ctl set int tunnel_test_do_in_kernel 1&lt;/EM&gt;" ? (as in&amp;nbsp;&lt;SPAN&gt;sk164933 and sk128652). &amp;nbsp;Your stated solution to disable the probing for multiple interfaces seems to be similar to the effects of that kernel value. &amp;nbsp;Perhaps Val could elucidate further.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Either way, congrats and I can imagine your collective relief!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2020 16:33:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/101542#M9707</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2020-11-09T16:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/181858#M9708</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;
&lt;P&gt;oh great thing ...&lt;BR /&gt;I&amp;nbsp; know about this option, but on a new version like 81.10 and newest SmartConsole i dont find this setting anymore ...&lt;BR /&gt;&lt;SPAN&gt;where is it?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Does it only exists if the gateway has configured more then one external interfaces ?&lt;BR /&gt;&lt;SPAN&gt;Or has it been removed from the SmartConsole?&amp;nbsp;&lt;BR /&gt;Maybe its now in the depths of GuiDBedit ...&amp;nbsp;&lt;BR /&gt;perhaps somebody knows the answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;so i dont have this on my R81.10 enviroment ...&lt;BR /&gt;OLD&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Thomas_Eichelbu_0-1684911226121.png" style="width: 384px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21058i6B37FE7F3F64AC21/image-dimensions/384x216?v=v2" width="384" height="216" role="button" title="Thomas_Eichelbu_0-1684911226121.png" alt="Thomas_Eichelbu_0-1684911226121.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;NEW&lt;/P&gt;
&lt;DIV id="tinyMceEditor_63ce0151053e5Thomas_Eichelbu_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.PNG" style="width: 551px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21059i2455DA4111B5A17D/image-dimensions/551x211?v=v2" width="551" height="211" role="button" title="1.PNG" alt="1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;best regards&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 06:57:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/181858#M9708</guid>
      <dc:creator>Thomas_Eichelbu</dc:creator>
      <dc:date>2023-05-24T06:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint VPN users facing extreme slowness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/182027#M9709</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;can you check into this?&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 21:20:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-VPN-users-facing-extreme-slowness/m-p/182027#M9709</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-24T21:20:47Z</dc:date>
    </item>
  </channel>
</rss>

