Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Cathy_Cheng
Participant

Check Point Endpoint remote access VPN Slow Network Performance

 

We are experiencing slow network performance when connected via Check Point Remote Access VPN.

We have Cloudguard as the VPN gateway, VPN protocol IKEV2, Endpoint remote access vpn client version is  E89.25

client logs are not set to extended

 R82.10 Cloudguard Gateway is using the following settings for Remote Access VPN:

Phase 1: AES-256. SHA256, DH Group 14
Phase 2: AES-256. SHA256

We have tested network speed from an AWS EC2 instance to the Internet using the same CloudGuard gateway and AWS Internet Gateway. The throughput is approximately 1 Gbps.

This indicates that the CloudGuard gateway and AWS Internet Gateway are unlikely to be the primary bottleneck.

The performance issue appears to be specific to traffic traversing the Remote access vpn

We have also confirmed that AES-NI is supported on the gateway:

fw ctl get int AESNI_is_supported

AESNI_is_supported = 1

SecureXL is also enabled and processing traffic. Current statistics show:

fwaccel stats -s
Accelerated conns/Total conns : 0/603 (0%)
LightSpeed conns/Total conns : 0/603 (0%)
Accelerated pkts/Total pkts : 5738741623/7815153810 (73%)
LightSpeed pkts/Total pkts : 0/7815153810 (0%)
F2Fed pkts/Total pkts : 2076412187/7815153810 (26%)
F2V pkts/Total pkts : 51192425/7815153810 (0%)
CPASXL pkts/Total pkts : 141377524/7815153810 (1%)
PSLXL pkts/Total pkts : 5450678682/7815153810 (69%)
UDP IS XL pkts/Total pkts : 146512835/7815153810 (1%)
CPAS pipeline pkts/Total pkts : 0/7815153810 (0%)
PSL pipeline pkts/Total pkts : 0/7815153810 (0%)
UDP IS pipeline pkts/Total pkts : 0/7815153810 (0%)
QOS inbound pkts/Total pkts : 0/7815153810 (0%)
QOS outbound pkts/Total pkts : 0/7815153810 (0%)
Corrected pkts/Total pkts : 0/7815153810 (0%)

Need assistance to identify what is causing the network slowness issue in checkpoint VPN

 
 
 
 
 
 
 
 
 
 
 
 
0 Kudos
3 Replies
Timothy_Hall
MVP Gold
MVP Gold

Did you follow the AWS VPN best practices below, which are mentioned in my new Max Power 2026 book and call for reducing the MTU to less than 1500, depending on the algorithms you are using:

https://docs.aws.amazon.com/vpn/latest/s2svpn/cgw-best-practice.html

From the Gaia OS of a gateway, you can determine if there is a low intervening MTU between you and your VPN peer (like 1450 in this example) by using tracepath:

tracepath.pngtracepath.png

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization
(1)
Cathy_Cheng
Participant

Thanks Timothy, below is the tracepath result  How do I determine what MTU size I should change it to?

 

tracepath vpn client ip 
1?: [LOCALHOST] pmtu 9001
1: 10.100.0.2 2.224ms pmtu 8926
1: no reply
2: no reply
3: no reply
4: no reply
5: no reply
6: no reply
7: no reply
8: no reply
9: no reply
10: no reply
11: no reply
12: no reply
13: no reply
14: no reply
15: 10.100.0.2 236.905ms reached
Resume: pmtu 8926 hops 15 back 1

0 Kudos
Timothy_Hall
MVP Gold
MVP Gold

Run tracepath to the client's globally routable external IP address, not through the tunnel.  If I'm reading that correctly, it appears you ran tracepath through the tunnel to the client's assigned Office Mode address.

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events