<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00.10 in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274693#M13830</link>
    <description>&lt;DIV&gt;&lt;P&gt;Hi everyone,&lt;BR /&gt;I’m working on a Check Point &lt;STRONG&gt;Spark 2570 cluster&lt;/STRONG&gt;, locally managed, running &lt;STRONG&gt;Gaia Embedded R82.00.10 Build 2110&lt;/STRONG&gt;, and I’m experiencing several issues with the &lt;STRONG&gt;Remote Access VPN&lt;/STRONG&gt; configuration.&lt;/P&gt;&lt;H3&gt;&lt;STRONG&gt;Environment setup&lt;/STRONG&gt;&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;Spark &lt;STRONG&gt;2570 cluster&lt;/STRONG&gt;, locally managed&lt;/LI&gt;&lt;LI&gt;Gaia Embedded &lt;STRONG&gt;R82.00.10 Build 2110&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Single Internet connection in cluster mode&lt;/LI&gt;&lt;LI&gt;Internal networks in standard configuration&lt;/LI&gt;&lt;LI&gt;No internal DNS servers available but gateway configured as DNS (tested and working internally)&lt;/LI&gt;&lt;LI&gt;Remote Access VPN configured in &lt;STRONG&gt;Full Tunnel&lt;/STRONG&gt; mode&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;&lt;STRONG&gt;Current VPN status&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;The Remote Access VPN is working, but I’m facing multiple issues that I haven’t been able to resolve yet.&lt;/P&gt;&lt;HR /&gt;&lt;H2&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Problems observed&lt;/STRONG&gt;&lt;/H2&gt;&lt;H3&gt;&lt;STRONG&gt;1. Very slow VPN performance&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;The VPN connects successfully, but throughput is extremely low (only a few Mbps), despite both the remote connection and the cluster’s Internet connection being much faster.&lt;/P&gt;&lt;P&gt;No bandwidth shaping or QoS is configured.&lt;BR /&gt;I’m trying to understand if this is a configuration issue or a limitation/bug of R82.00.10 on Spark appliances.&lt;/P&gt;&lt;HR /&gt;&lt;H3&gt;&lt;STRONG&gt;2. DNS resolution fails unless I manually set a public DNS&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;If I leave the default setting and use &lt;STRONG&gt;the gateway itself as DNS&lt;/STRONG&gt;, name resolution does not work at all.&lt;/P&gt;&lt;P&gt;Since I don’t have internal DNS servers, my goal would be to use the firewall as DNS forwarder, but this seems to fail for Remote Access clients.&lt;/P&gt;&lt;P&gt;The only way to make DNS work is to manually push a &lt;STRONG&gt;public DNS server&lt;/STRONG&gt; to VPN clients, which is not ideal.&lt;/P&gt;&lt;HR /&gt;&lt;H3&gt;&lt;STRONG&gt;3. VPN from inside the LAN does not work (disconnects immediately)&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;If I try to connect to the VPN &lt;STRONG&gt;from the internal network&lt;/STRONG&gt;, the client connects, but after a few seconds it disconnects.&lt;/P&gt;&lt;P&gt;It looks like a routing loop caused by full‑tunnel mode (internal traffic being pushed into the VPN, then routed back inside, etc.).&lt;/P&gt;&lt;P&gt;I’m trying to understand if this behavior is expected in locally managed Spark clusters or if there is a workaround or specific configuration required.&lt;/P&gt;&lt;HR /&gt;&lt;H2&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Questions for the community&lt;/STRONG&gt;&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Has anyone experienced &lt;STRONG&gt;very slow throughput&lt;/STRONG&gt; on Remote Access VPN in R82.00.10 locally managed clusters?&lt;/LI&gt;&lt;LI&gt;Is there a known method to make &lt;STRONG&gt;DNS forwarding&lt;/STRONG&gt; work through the gateway for RA VPN clients?&lt;/LI&gt;&lt;LI&gt;Is it normal that &lt;STRONG&gt;full‑tunnel VPN does not work from inside the LAN&lt;/STRONG&gt;, or is there a specific setting to avoid internal routing loops?&lt;/LI&gt;&lt;LI&gt;Any best practices or recommended settings for RA VPN on locally managed Spark appliances?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any help, suggestions, or shared experiences are highly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 01 Apr 2026 21:28:51 GMT</pubDate>
    <dc:creator>perfect4situa</dc:creator>
    <dc:date>2026-04-01T21:28:51Z</dc:date>
    <item>
      <title>Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00.10</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274693#M13830</link>
      <description>&lt;DIV&gt;&lt;P&gt;Hi everyone,&lt;BR /&gt;I’m working on a Check Point &lt;STRONG&gt;Spark 2570 cluster&lt;/STRONG&gt;, locally managed, running &lt;STRONG&gt;Gaia Embedded R82.00.10 Build 2110&lt;/STRONG&gt;, and I’m experiencing several issues with the &lt;STRONG&gt;Remote Access VPN&lt;/STRONG&gt; configuration.&lt;/P&gt;&lt;H3&gt;&lt;STRONG&gt;Environment setup&lt;/STRONG&gt;&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;Spark &lt;STRONG&gt;2570 cluster&lt;/STRONG&gt;, locally managed&lt;/LI&gt;&lt;LI&gt;Gaia Embedded &lt;STRONG&gt;R82.00.10 Build 2110&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Single Internet connection in cluster mode&lt;/LI&gt;&lt;LI&gt;Internal networks in standard configuration&lt;/LI&gt;&lt;LI&gt;No internal DNS servers available but gateway configured as DNS (tested and working internally)&lt;/LI&gt;&lt;LI&gt;Remote Access VPN configured in &lt;STRONG&gt;Full Tunnel&lt;/STRONG&gt; mode&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;&lt;STRONG&gt;Current VPN status&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;The Remote Access VPN is working, but I’m facing multiple issues that I haven’t been able to resolve yet.&lt;/P&gt;&lt;HR /&gt;&lt;H2&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Problems observed&lt;/STRONG&gt;&lt;/H2&gt;&lt;H3&gt;&lt;STRONG&gt;1. Very slow VPN performance&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;The VPN connects successfully, but throughput is extremely low (only a few Mbps), despite both the remote connection and the cluster’s Internet connection being much faster.&lt;/P&gt;&lt;P&gt;No bandwidth shaping or QoS is configured.&lt;BR /&gt;I’m trying to understand if this is a configuration issue or a limitation/bug of R82.00.10 on Spark appliances.&lt;/P&gt;&lt;HR /&gt;&lt;H3&gt;&lt;STRONG&gt;2. DNS resolution fails unless I manually set a public DNS&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;If I leave the default setting and use &lt;STRONG&gt;the gateway itself as DNS&lt;/STRONG&gt;, name resolution does not work at all.&lt;/P&gt;&lt;P&gt;Since I don’t have internal DNS servers, my goal would be to use the firewall as DNS forwarder, but this seems to fail for Remote Access clients.&lt;/P&gt;&lt;P&gt;The only way to make DNS work is to manually push a &lt;STRONG&gt;public DNS server&lt;/STRONG&gt; to VPN clients, which is not ideal.&lt;/P&gt;&lt;HR /&gt;&lt;H3&gt;&lt;STRONG&gt;3. VPN from inside the LAN does not work (disconnects immediately)&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;If I try to connect to the VPN &lt;STRONG&gt;from the internal network&lt;/STRONG&gt;, the client connects, but after a few seconds it disconnects.&lt;/P&gt;&lt;P&gt;It looks like a routing loop caused by full‑tunnel mode (internal traffic being pushed into the VPN, then routed back inside, etc.).&lt;/P&gt;&lt;P&gt;I’m trying to understand if this behavior is expected in locally managed Spark clusters or if there is a workaround or specific configuration required.&lt;/P&gt;&lt;HR /&gt;&lt;H2&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Questions for the community&lt;/STRONG&gt;&lt;/H2&gt;&lt;UL&gt;&lt;LI&gt;Has anyone experienced &lt;STRONG&gt;very slow throughput&lt;/STRONG&gt; on Remote Access VPN in R82.00.10 locally managed clusters?&lt;/LI&gt;&lt;LI&gt;Is there a known method to make &lt;STRONG&gt;DNS forwarding&lt;/STRONG&gt; work through the gateway for RA VPN clients?&lt;/LI&gt;&lt;LI&gt;Is it normal that &lt;STRONG&gt;full‑tunnel VPN does not work from inside the LAN&lt;/STRONG&gt;, or is there a specific setting to avoid internal routing loops?&lt;/LI&gt;&lt;LI&gt;Any best practices or recommended settings for RA VPN on locally managed Spark appliances?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Any help, suggestions, or shared experiences are highly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 01 Apr 2026 21:28:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274693#M13830</guid>
      <dc:creator>perfect4situa</dc:creator>
      <dc:date>2026-04-01T21:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274696#M13832</link>
      <description>&lt;P&gt;Please provide the precise methods used to test throughput.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Considering this is mentioned in the documentation, DNS should work over Remote Access.&lt;BR /&gt;Try this command via the CLI and see if the situation changes:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;set vpn remote-access advanced-settings enc-dns-traffic true&lt;BR /&gt;&lt;/SPAN&gt;Otherwise, I suggest a TAC case.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2026 22:35:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274696#M13832</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-04-01T22:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274704#M13834</link>
      <description>&lt;P&gt;I would start by upgrading the firmware to R82.00.10 Build 998002133 which was just released just recently.&lt;BR /&gt;There are many fixes that might resolve your issues and I believe TAC will inform you to do so as the first step.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 02:16:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274704#M13834</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2026-04-02T02:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274810#M13841</link>
      <description>&lt;P&gt;Hi PhoneBoy, I've checked the enc-dns-traffic and it's already set as true.&lt;/P&gt;&lt;P&gt;As testing method to verify bandwidth i used from my pc both a simple speed test online tool and iperf test via cli with the same results as up and down you can find it attached.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="upload" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33926i70132B5232A485C5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2026-04-03_13h11_27.png" alt="upload" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;upload&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="download" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33927iB9DC6CE61A4AEC58/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2026-04-03_13h10_48.png" alt="download" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;download&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'm also working with TAC to make this work but seems difficult to solve... So I was hoping for someone in community with the same issues.&lt;/P&gt;&lt;P&gt;Let me know if you have further considerations, BTW on tuesday i should be able to upgrade the gateway.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2026 11:14:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274810#M13841</guid>
      <dc:creator>perfect4situa</dc:creator>
      <dc:date>2026-04-03T11:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274811#M13842</link>
      <description>&lt;P&gt;On tuesday I'll try to upgrade to the latest version that also support suggest today and let you know.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2026 10:32:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274811#M13842</guid>
      <dc:creator>perfect4situa</dc:creator>
      <dc:date>2026-04-03T10:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274817#M13844</link>
      <description>&lt;P&gt;Is this&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because Quantum Spark models do not support AES-NI, AES-128 is the highest encryption level that should be used; AES-256 will be much slower.&amp;nbsp; Be especially sure you are not using 3DES, which is 2-3 times slower than AES:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk98950" target="_blank"&gt;&lt;SPAN&gt;sk98950: Slow traffic speed (high latency) when transferring files over VPN tunnel with 3DES encryption&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For speed testing, using a single testing thread will not show complete results, see here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk167313" target="_blank"&gt;&lt;SPAN&gt;sk167313: Speed tests do not show expected throughput on SMB appliances&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2026 12:27:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274817#M13844</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-04-03T12:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274821#M13845</link>
      <description>&lt;P&gt;Hi Timohy, thank you for the sk.&lt;/P&gt;&lt;P&gt;As suggested I tested RA with AES-128 (default AES-256) but there was no improvement.&lt;/P&gt;&lt;P&gt;Interesting also the possible cause you reported for the low speed result. I don't know if it's enough but some online speedtest report to use multi connection mode to test the internet speed.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2026-04-03_14h50_10.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33928i9F3F2BC61FEFFF97/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2026-04-03_14h50_10.png" alt="2026-04-03_14h50_10.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;2026-04-03_14h50_10.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As additional information i can say the MSS in VPN path to the internet is very low (between 1000-1100) so i think there is also too much overhead.&lt;/P&gt;&lt;P&gt;I tested it with ping and i previously verified source and destination connection has standard 1500 mtu with standard 1472 mss:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mtu" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33929iDC67B8A70545550A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2026-04-03_14h54_21.png" alt="mtu" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;mtu&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2026 12:59:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274821#M13845</guid>
      <dc:creator>perfect4situa</dc:creator>
      <dc:date>2026-04-03T12:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274822#M13846</link>
      <description>&lt;P&gt;Note there is a max ping option that you will need to configure in order to do this test properly.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2026 14:34:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274822#M13846</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-04-03T14:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274823#M13847</link>
      <description>&lt;P&gt;Hi Chris, please let me know what do you mean to test it as well.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2026 14:40:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274823#M13847</guid>
      <dc:creator>perfect4situa</dc:creator>
      <dc:date>2026-04-03T14:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274824#M13848</link>
      <description>&lt;P&gt;In Device &amp;gt; Advanced &amp;gt; Advanced Settings there is an IPS option for 'Max Ping Limit' you would need to increase it to 1500 to check your mss/MTU using ping.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2026 14:45:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274824#M13848</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-04-03T14:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274825#M13849</link>
      <description>&lt;P&gt;Thank you for this, i've changed this parameter to 9000 just to be sure and then the ping test actualy increase his mss but only to 1322.&lt;/P&gt;&lt;P&gt;Is possible VPN RA limit MTU to 1350?&lt;/P&gt;&lt;P&gt;Any suggestion to increase troughput?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2026 15:34:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/274825#M13849</guid>
      <dc:creator>perfect4situa</dc:creator>
      <dc:date>2026-04-03T15:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275060#M13860</link>
      <description>&lt;DIV&gt;&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;after the upgrade I ran additional tests, but the behavior is unchanged.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;DNS:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Tested both automatic DNS and manual DNS pointing to the firewall cluster IP → DNS from VPN clients still not working.&lt;/LI&gt;&lt;LI&gt;Verified via &lt;EM&gt;clish&lt;/EM&gt; that &lt;STRONG&gt;Encrypt DNS requests&lt;/STRONG&gt; is enabled.&lt;/LI&gt;&lt;LI&gt;Added an explicit rule allowing VPN users to access &lt;STRONG&gt;This Gateway&lt;/STRONG&gt; on DNS — no change.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;MSS / performance:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Initial MSS tests may have been affected by an IPS MSS limitation.&lt;/LI&gt;&lt;LI&gt;After adjusting the parameter, MSS reached ~&lt;STRONG&gt;1350 bytes&lt;/STRONG&gt;, which seems acceptable.&lt;/LI&gt;&lt;LI&gt;However, VPN throughput is still low and comparable to previous results.&lt;/LI&gt;&lt;LI&gt;Also tested &lt;STRONG&gt;AES‑128&lt;/STRONG&gt; instead of AES‑256, with no noticeable performance improvement.&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 08 Apr 2026 09:04:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275060#M13860</guid>
      <dc:creator>perfect4situa</dc:creator>
      <dc:date>2026-04-08T09:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275105#M13862</link>
      <description>&lt;P&gt;Did you identify where the MTU restriction occurs, you may require measures such as MSS clamping.&lt;/P&gt;
&lt;P&gt;Which VPN client type / Endpoint version?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Refer:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk121114" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk121114&amp;nbsp;&lt;/A&gt;(MSS clamping settings are described here)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 10:12:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275105#M13862</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-04-09T10:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275119#M13866</link>
      <description>&lt;P&gt;Try deleting/re-adding the site just to make sure the config is propagating to the client.&lt;BR /&gt;If no change, suggest a TAC case.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2026 15:22:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275119#M13866</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-04-08T15:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275152#M13870</link>
      <description>&lt;P&gt;Did you configure DNS domain manually or keep it&amp;nbsp;&lt;SPAN&gt;"Same as DNS domain name" in Advanced Remote Access Options?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If kept same, Spark GWs used to add&amp;nbsp;&lt;EM&gt;.local&amp;nbsp;&lt;/EM&gt;or&amp;nbsp;&lt;EM&gt;.info.local &lt;/EM&gt;suffix into domain names for Remote Access users.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 07:46:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275152#M13870</guid>
      <dc:creator>josi</dc:creator>
      <dc:date>2026-04-09T07:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275158#M13871</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/121476"&gt;@perfect4situa&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I'll check if I can reproduce the issue in my env with a locally managed cluster.&lt;BR /&gt;Btw, I know there is an issue with tunneled connections like PPPoE where accessing Spark WEBUI is slow after RA-VPN connection, but it's my first time to hear about the low throughput.&lt;BR /&gt;&lt;BR /&gt;Is your cluster internet connection Static IP or PPPoE/DHCP?&lt;BR /&gt;The interface is clustered(VIP) right?&lt;BR /&gt;&lt;BR /&gt;Regarding MSS, my understanding is that mss clamping is enabled by default for VPN in Spark, so I think we don't need any manual adjustments...&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 08:05:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275158#M13871</guid>
      <dc:creator>Tom_Hinoue</dc:creator>
      <dc:date>2026-04-09T08:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275160#M13872</link>
      <description>&lt;P&gt;I’m using Check Point Endpoint Security VPN E88.70 (build 986105912).&lt;BR /&gt;I captured traffic on the client PC and observed the following MSS values:&lt;/P&gt;&lt;P&gt;Outgoing MSS from PC: 1310&lt;BR /&gt;Incoming MSS from the destination site: 1379&lt;/P&gt;&lt;P&gt;I’m not sure where or how to verify the MSS on the firewall for Remote Access VPN users.&lt;BR /&gt;I tried capturing traffic on the gateway, but with the following command I don’t see any VPN traffic:&lt;/P&gt;&lt;P&gt;tcpdump -i any -s 0 -nn -vv -w /logs/cattura.pcap&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Any hints on how to capture RA VPN traffic or check/enforce MSS on the firewall would be appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Apr 2026 08:35:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275160#M13872</guid>
      <dc:creator>perfect4situa</dc:creator>
      <dc:date>2026-04-09T08:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275161#M13873</link>
      <description>&lt;DIV&gt;&lt;P&gt;Hi Josi,&lt;/P&gt;&lt;P&gt;Initially — and also in another environment — I kept everything set to &lt;STRONG&gt;Automatic&lt;/STRONG&gt;, using the &lt;STRONG&gt;gateway as DNS&lt;/STRONG&gt; and the &lt;STRONG&gt;gateway domain&lt;/STRONG&gt; as well.&lt;/P&gt;&lt;P&gt;In this case, the issue occurs when &lt;STRONG&gt;“Office Mode first DNS for clients”&lt;/STRONG&gt; is left on &lt;STRONG&gt;Automatic (This gateway)&lt;/STRONG&gt;. With this setting, name resolution does not work as expected. I tested it again and, this time, web navigation worked, but &lt;STRONG&gt;nslookup did not&lt;/STRONG&gt;, which makes me think that the VPN DNS is not being used.&lt;/P&gt;&lt;P&gt;I performed these tests after:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Disabling and re‑enabling the &lt;STRONG&gt;Remote Access VPN blade&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Deleting and recreating the &lt;STRONG&gt;site&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Let me know if you need more details or additional test results.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 09 Apr 2026 09:03:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275161#M13873</guid>
      <dc:creator>perfect4situa</dc:creator>
      <dc:date>2026-04-09T09:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN issues (performance, DNS, internal connections) on Spark 2570 Cluster – R82.00</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275163#M13874</link>
      <description>&lt;DIV&gt;&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;thanks for your feedback and for planning to run the test — much appreciated.&lt;/P&gt;&lt;P&gt;Regarding my setup: the cluster WAN interface is configured with &lt;STRONG&gt;one static IP connection using the clustered VIP&lt;/STRONG&gt;. I did &lt;STRONG&gt;not&lt;/STRONG&gt; configure a single routable IP shared by both members; each gateway has &lt;STRONG&gt;its own public IP address&lt;/STRONG&gt; configured.&lt;/P&gt;&lt;P&gt;On the gateway side, the WAN connection is &lt;STRONG&gt;not PPPoE&lt;/STRONG&gt;.&lt;BR /&gt;On the client side, I’ve tested Remote Access VPN connections from multiple access types, including:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;PPPoE connections&lt;/LI&gt;&lt;LI&gt;LTE connections&lt;/LI&gt;&lt;LI&gt;Static public IP connections&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The behavior is the same in all cases, so it doesn’t appear to be related to the client-side connection type.&lt;/P&gt;&lt;P&gt;Thanks again for looking into this.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 09 Apr 2026 09:18:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Remote-Access-VPN-issues-performance-DNS-internal-connections-on/m-p/275163#M13874</guid>
      <dc:creator>perfect4situa</dc:creator>
      <dc:date>2026-04-09T09:18:16Z</dc:date>
    </item>
  </channel>
</rss>

