Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Cathy_Cheng
Participant

Check Point Endpoint remote access VPN Slow Network Performance

 

We are experiencing slow network performance when connected via Check Point Remote Access VPN.

We have Cloudguard as the VPN gateway, VPN protocol IKEV2, Endpoint remote access vpn client version is  E89.25

client logs are not set to extended

 R82.10 Cloudguard Gateway is using the following settings for Remote Access VPN:

Phase 1: AES-256. SHA256, DH Group 14
Phase 2: AES-256. SHA256

We have tested network speed from an AWS EC2 instance to the Internet using the same CloudGuard gateway and AWS Internet Gateway. The throughput is approximately 1 Gbps.

This indicates that the CloudGuard gateway and AWS Internet Gateway are unlikely to be the primary bottleneck.

The performance issue appears to be specific to traffic traversing the Remote access vpn

We have also confirmed that AES-NI is supported on the gateway:

fw ctl get int AESNI_is_supported

AESNI_is_supported = 1

SecureXL is also enabled and processing traffic. Current statistics show:

fwaccel stats -s
Accelerated conns/Total conns : 0/603 (0%)
LightSpeed conns/Total conns : 0/603 (0%)
Accelerated pkts/Total pkts : 5738741623/7815153810 (73%)
LightSpeed pkts/Total pkts : 0/7815153810 (0%)
F2Fed pkts/Total pkts : 2076412187/7815153810 (26%)
F2V pkts/Total pkts : 51192425/7815153810 (0%)
CPASXL pkts/Total pkts : 141377524/7815153810 (1%)
PSLXL pkts/Total pkts : 5450678682/7815153810 (69%)
UDP IS XL pkts/Total pkts : 146512835/7815153810 (1%)
CPAS pipeline pkts/Total pkts : 0/7815153810 (0%)
PSL pipeline pkts/Total pkts : 0/7815153810 (0%)
UDP IS pipeline pkts/Total pkts : 0/7815153810 (0%)
QOS inbound pkts/Total pkts : 0/7815153810 (0%)
QOS outbound pkts/Total pkts : 0/7815153810 (0%)
Corrected pkts/Total pkts : 0/7815153810 (0%)

Need assistance to identify what is causing the network slowness issue in checkpoint VPN

 
 
 
 
 
 
 
 
 
 
 
 
0 Kudos
1 Reply
Timothy_Hall
MVP Gold
MVP Gold

Did you follow the AWS VPN best practices below, which are mentioned in my new Max Power 2026 book and call for reducing the MTU to less than 1500, depending on the algorithms you are using:

https://docs.aws.amazon.com/vpn/latest/s2svpn/cgw-best-practice.html

From the Gaia OS of a gateway, you can determine if there is a low intervening MTU between you and your VPN peer (like 1450 in this example) by using tracepath:

tracepath.pngtracepath.png

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events