- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Can you please update on below queries.
1) How much load can we put on single Tunnel. Is there any traffic limitation over a single IPsec VPN Tunnel?
2) How many IPsec Tunnel can be created? Is there any limitation for creation the IPsec Tunnel ?
Ok, I have moved your post to a more appropriate space.
Answer to both questions: it depends on your Security Gateway performance. There is no hard limit on both throughput and amount of VPN tunnels, but more you have, more CPU time it will consume.
Why is this in Maestro space? Are you asking specifically about Maestro environment? Or is this a general question?
This is the general question
Ok, I have moved your post to a more appropriate space.
Answer to both questions: it depends on your Security Gateway performance. There is no hard limit on both throughput and amount of VPN tunnels, but more you have, more CPU time it will consume.
Thanks for the update
Hey Hardik,
@_Val_ is indeed 100% correct. There is definitely not a hard limit to this, it all depends on how powerful device is. Its sort of similar to discussion as to what is max number of regular/NAT rules one can create in smart console. There was never set limit to it. Honestly, in my 15 years dealing with CP, the MOST VPN tunnels I see someone have was 133 (I still remember that number well lol). And, consider this was back in R77.xx days, so now the code is way better/more stable. Also, same applies for the bandwidth as well.
Andy
It also depends on software version.
In the just released R81.20, we done a number of things to improve performance and stability for VPN:
If VPN performance is a concern, upgrading (or using) R81.20 is highly recommended.
Indeed, very true! I personally found with R81.10 and R81.20 that VPN performs much faster.
Unfortunately I did not get a chance to upgrade it to R80.20 however the most desired thing is to create a separate VPN tunnel if we have multiple ISPs. Checkpoint still not able to resolve the issue.
I once had case where a customer logged a ticket due to a 5800 gateway being unresponsive, CPU's pegged etc. did some troubleshooting and narrowed it down to VPND. Customer of course insisted nothing changed in the environment.
The gateway was the hub in a community with about 100 smaller sites hanging off it. Eventually I managed to run vpn tu and saw there was something like 30 000 tunnels!!! Long story short - one of the customer admins was troubleshooting an IPSEC issue the previous evening and changed the VPN Tunnel sharing setting from "per pair of gateways" to "per pair of hosts" and due to traffic patterns the poor gateways started building tunnels until it almost melted:-)
Think I might still have a screenhot of the VPN TU output kicking around somewhere:-)
O man, that made me laugh, though its not funny, but still... : - ).Yea, I think 30k tunnels would "MELT" any appliance LOL
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
14 | |
12 | |
11 | |
9 | |
8 | |
7 | |
5 | |
5 | |
5 | |
5 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY