<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: limited througput in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165428#M7964</link>
    <description>&lt;P&gt;Thank you all for your help.&lt;/P&gt;&lt;P&gt;Testing with iperf and parallel streams indeed gives me much better results (nearly 900 Mbit/s over the WAN IF and natting).&lt;/P&gt;&lt;P&gt;Also copying files by winSCP was much better.&lt;/P&gt;&lt;P&gt;Thanks again for your help.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Dec 2022 15:07:38 GMT</pubDate>
    <dc:creator>mcguppy</dc:creator>
    <dc:date>2022-12-16T15:07:38Z</dc:date>
    <item>
      <title>limited througput</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165251#M7956</link>
      <description>&lt;P&gt;Hi community&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some througput problems with several Checkpoint Quantum Spark 1800 running R80.20.40.&lt;/P&gt;&lt;P&gt;For the Internal networks I am using the 10Gbit/s DMZ interface in trunk mode and put all the VLANs onto this trunk. The DMZ interface is connected to a datacenterswitch 10Gbit/s port.&lt;/P&gt;&lt;P&gt;The WAN Port is connected to the same switch but with 1Gbit/s as of the speed on the FW is 1 Gbit/s only.&lt;/P&gt;&lt;P&gt;The HCI server platform is connected to the same switch with 25Gbit/s ports (each host).&lt;/P&gt;&lt;P&gt;I am doing performance tests with iperf.&lt;/P&gt;&lt;P&gt;Having 2 VMs in the same subnet, I get a throughput of 21Gbit/s in a 10sec measurement in both directions.&lt;/P&gt;&lt;P&gt;Moving 1 VM into another subnet, so the traffic has to pass the FW, I only get about 350Mbit/s in a 10 sec measurement, even then links to the FW is 10Gbit/s and there is nearly no other traffic on this DMZ interface.&lt;/P&gt;&lt;P&gt;The same picture is, when testing with a client connected directly in the same subnet than the FW WAN Interface and testing over a natting to the VM on the HCI platform acting as iperf server. I only get about 350Mbit/s ore even less throughput.&lt;/P&gt;&lt;P&gt;I am using always the same VM as iperf server, which is able to handle even 21Gbit/s like seen in the test within the iperf server and client in the same subnet.&lt;/P&gt;&lt;P&gt;I checked the datasheet of Checkpoint Quantum Spark 1800 and the values of security features throughput are much higher than the 350Mbit/s I am seeing.&lt;/P&gt;&lt;P&gt;What I am doing wrong or what is limiting this throughput. The security settings in the FW are most set to the default values, except the access policy control I had to change from “Standard” to “Strict”.&lt;/P&gt;&lt;P&gt;How can I find the bottleneck here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;&lt;P&gt;Kind regards, Stefan&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 07:33:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165251#M7956</guid>
      <dc:creator>mcguppy</dc:creator>
      <dc:date>2022-12-15T07:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: limited througput</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165253#M7957</link>
      <description>&lt;P&gt;On the surface it seems like other areas have been proportionally better dimensioned than the firewall.&lt;/P&gt;
&lt;P&gt;Have you attempted the test with multiple parallel threads/connections?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 08:16:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165253#M7957</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-12-15T08:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: limited througput</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165257#M7958</link>
      <description>&lt;P&gt;Which blades are active ?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 09:18:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165257#M7958</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-12-15T09:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: limited througput</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165262#M7959</link>
      <description>&lt;P&gt;iperf is often not the greatest thing to use for testing as (by default) a single transport stream is used.&lt;/P&gt;&lt;P&gt;What I find provides a much more interesting figure in most cases is a file transfer via. SMB.&lt;BR /&gt;As SMB is multithreaded, it'll utilize multiple connection streams and you'll very likely get a much nicer (and realistic) number.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 09:49:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165262#M7959</guid>
      <dc:creator>Swiftyyyy</dc:creator>
      <dc:date>2022-12-15T09:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: limited througput</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165310#M7961</link>
      <description>&lt;P&gt;I believe iperf by default will use a single stream.&lt;BR /&gt;When we do performance tests, we do it with multiple streams, simulating multiple users.&lt;BR /&gt;A single heavy stream is commonly referred to as an elephant flow.&lt;BR /&gt;Due to how CoreXL and SecureXL work, they will be limited in throughput compared to the data sheet numbers.&lt;/P&gt;
&lt;P&gt;On our regular gateways, we have a technology called HyperFlow (added in R81.20) that improves throughput in these cases.&lt;BR /&gt;SMB gateways do not yet have this feature.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 15:32:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165310#M7961</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-15T15:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: limited througput</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165428#M7964</link>
      <description>&lt;P&gt;Thank you all for your help.&lt;/P&gt;&lt;P&gt;Testing with iperf and parallel streams indeed gives me much better results (nearly 900 Mbit/s over the WAN IF and natting).&lt;/P&gt;&lt;P&gt;Also copying files by winSCP was much better.&lt;/P&gt;&lt;P&gt;Thanks again for your help.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Dec 2022 15:07:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/limited-througput/m-p/165428#M7964</guid>
      <dc:creator>mcguppy</dc:creator>
      <dc:date>2022-12-16T15:07:38Z</dc:date>
    </item>
  </channel>
</rss>

