<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 1550 VPN establishment delay in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85505#M3564</link>
    <description>&lt;P&gt;I have not performed any measurements. Basically user experience being reported. And my own.&lt;/P&gt;&lt;P&gt;Also, as mentioned in other reports, it does not happen very time. Some connections get immediate connectivity.&lt;/P&gt;&lt;P&gt;How do I get a tcpdump on a 1550?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 17 May 2020 06:24:05 GMT</pubDate>
    <dc:creator>BorisL</dc:creator>
    <dc:date>2020-05-17T06:24:05Z</dc:date>
    <item>
      <title>1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85390#M3545</link>
      <description>&lt;P&gt;Some users observe that when connecting to VPN (from Capsule on Windows or IOS in our case), there is a delay until they can reach internal resources. They have to wait between 15 seconds and half a minute until they can reach devices with the allowed protocols.&lt;/P&gt;&lt;P&gt;Has anybody else experienced this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2020 15:00:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85390#M3545</guid>
      <dc:creator>BorisL</dc:creator>
      <dc:date>2020-05-15T15:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85478#M3551</link>
      <description>It does take some time for the VPN to negotiate and connect.&lt;BR /&gt;How precisely are you measuring this?&lt;BR /&gt;Have you done any tcpdumps to see what's going on?</description>
      <pubDate>Sat, 16 May 2020 22:35:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85478#M3551</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-16T22:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85498#M3559</link>
      <description>&lt;P&gt;What about Endpoint Security VPN client ? It has a nice progress window where you can see which phase of VPN establishment takes the most time. Usually that is the one where topology is downloaded from gateway if needed.&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2020 03:38:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85498#M3559</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-05-17T03:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85504#M3563</link>
      <description>&lt;P&gt;Also happpens with Endpoint Security Client. The delay occurs after negotiation is complete.&lt;/P&gt;&lt;P&gt;The other strange thing is that this does not happen for all connections. Some connections (few) get immediate connectivity.&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2020 06:22:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85504#M3563</guid>
      <dc:creator>BorisL</dc:creator>
      <dc:date>2020-05-17T06:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85505#M3564</link>
      <description>&lt;P&gt;I have not performed any measurements. Basically user experience being reported. And my own.&lt;/P&gt;&lt;P&gt;Also, as mentioned in other reports, it does not happen very time. Some connections get immediate connectivity.&lt;/P&gt;&lt;P&gt;How do I get a tcpdump on a 1550?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2020 06:24:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85505#M3564</guid>
      <dc:creator>BorisL</dc:creator>
      <dc:date>2020-05-17T06:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85581#M3568</link>
      <description>tcpdump is accessible in expert mode from the CLI.</description>
      <pubDate>Mon, 18 May 2020 01:28:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85581#M3568</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-18T01:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85629#M3574</link>
      <description>&lt;P&gt;I would instantly involve TAC using chat if there is a good chance to replicate the issue in a quick RAS !&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 08:28:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85629#M3574</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-05-18T08:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85642#M3576</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For iOS setting the "tunType" custom data value to force snx (SSL) may improve the delay in cases where the client might be attempting IPSec first for example and failing.&lt;/P&gt;
&lt;P&gt;Refer: &lt;A href="http://supportcontent.checkpoint.com/documentation_download?id=20361" target="_blank"&gt;http://supportcontent.checkpoint.com/documentation_download?id=20361&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 11:06:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85642#M3576</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-05-18T11:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85644#M3577</link>
      <description>&lt;P&gt;Hi Chris.&lt;/P&gt;&lt;P&gt;I will test this creating an iPhone profile to add the setting.&lt;/P&gt;&lt;P&gt;Nevertheless I must note that:&lt;/P&gt;&lt;P&gt;- the delay in accessing internal devices occurs after negotiation is over and "connected" status is presented by the client.&lt;/P&gt;&lt;P&gt;- users have also reported the delay using Windows 10 Capsule and Enpoint Security from Mac, so it does not seem to be specific to IOS, but rather to the 1550.&lt;/P&gt;&lt;P&gt;- we have no reports on this delay when connecting to R80.10, R80.30 or R80.40 open servers&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 11:46:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85644#M3577</guid>
      <dc:creator>BorisL</dc:creator>
      <dc:date>2020-05-18T11:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85646#M3578</link>
      <description>&lt;P&gt;Thanks for clarifying, please test the latest build of R80.20.05 if not already and engage TAC to assist further.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 11:54:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85646#M3578</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-05-18T11:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85647#M3579</link>
      <description>&lt;P&gt;We had a very bad experience with TAC (Premium Support) in previous issue with 1550, so I prefer to wait and test available recommendations posted here.&lt;/P&gt;&lt;P&gt;Users will have to live with the short delay (sometimes a couple of retries connecting to their device) in the meantime.&lt;/P&gt;&lt;P&gt;Thanks again and best regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 12:11:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85647#M3579</guid>
      <dc:creator>BorisL</dc:creator>
      <dc:date>2020-05-18T12:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85648#M3580</link>
      <description>&lt;P&gt;Btw, are you talking about slow RDP connection ?&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 12:14:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85648#M3580</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-05-18T12:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85649#M3581</link>
      <description>&lt;P&gt;The problem is with the first connection attempts failing to any device independently of protocol (RDP, http, https or vnc). Once connected speed and latency are fine with all protocols.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 12:19:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85649#M3581</guid>
      <dc:creator>BorisL</dc:creator>
      <dc:date>2020-05-18T12:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85651#M3582</link>
      <description>&lt;P&gt;I am asking because recently I had a problem with my 1470 where RDP will connect instantly on WAN interface but very slow on DMZ interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess you have already eliminated possible sources of delays such as TP blades ?&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 12:25:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85651#M3582</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-05-18T12:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85652#M3583</link>
      <description>&lt;P&gt;These are VPN connections from Internet (WAN) to intranet.&lt;/P&gt;&lt;P&gt;No Threat Prevention issues detected or logged.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 12:36:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85652#M3583</guid>
      <dc:creator>BorisL</dc:creator>
      <dc:date>2020-05-18T12:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85653#M3584</link>
      <description>&lt;P&gt;Have you tried to temporarily disable SecureXL ?&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 12:38:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85653#M3584</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-05-18T12:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85654#M3585</link>
      <description>&lt;P&gt;No. I have not.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will have to leave this issue alone for a while.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks to all.&lt;/P&gt;</description>
      <pubDate>Mon, 18 May 2020 12:45:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/85654#M3585</guid>
      <dc:creator>BorisL</dc:creator>
      <dc:date>2020-05-18T12:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/90038#M3790</link>
      <description>&lt;P&gt;Yes. Disabling SecureXL seems to solve the issue.&amp;nbsp; TAC also suggested we do that.&lt;/P&gt;&lt;P&gt;Question is: what is the performance hit for not using SecureXL?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 09:02:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/90038#M3790</guid>
      <dc:creator>BorisL</dc:creator>
      <dc:date>2020-06-29T09:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/90042#M3791</link>
      <description>&lt;P&gt;It depends. Paste 'fwaccel stats -s' with SecureXL enabled to check it.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 09:59:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/90042#M3791</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-06-29T09:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: 1550 VPN establishment delay</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/90043#M3792</link>
      <description>&lt;P&gt;Btw, leaving SecureXL disabled is only a workaround and shall be temporary solution, not permanent one. You should really involve TAC for this and escalate if not satisfied with how is the problem handled. Especially if you have Premium Support.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2020 10:07:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1550-VPN-establishment-delay/m-p/90043#M3792</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-06-29T10:07:30Z</dc:date>
    </item>
  </channel>
</rss>

