- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi
i have some dubts about maestro platform an limit concurrent connections behaviour and configuration.
i have an environment maestro dual site, with 3 SGM per site, one SG and VSX /vsls with 2 vs configured, one vs active per site.
if i configure limit concurrent connection for vs1 to 100k, is it 100k for global or 100k per SGM that was included on SG?
Another question, how can i check the total number of concurrent connections ?
if i run vsx stat -l , it gave me a number
if i run g_fw tab -t connections -s , it gave me 6 diferent numbers
..........
Thanks in advanced
Hi,
The SGM's act as independet gateways that share a single configuration. So setting the limit to 100k connections is per SGM as far as I know. The same as setting CoreXL firewall instances on a VS. If you set the number of firewall instances, this number is per SGM.
Which version are you running? In R82 you can get more details with 'insights'. You can also check the number of connections per SGM with the 'asg perf' command.
Martijn
i understand.
so if i configure 100k and the connections balance is properly it means that SG will be able to manage about 300k conncetions.
about cores, it means that if i put 2 cores on this vs, i have 2 fireweall workers in each SGM of this SG....isnt it?
verion:
R81.20 jha 118.
about asg perf -v.....yes but if gave much more number...maybe sums all SGM connections.
thank u for your answer
Hi,
Correct.
100k connection per VS is 300k on a Security Group with 3 members. The same for cores. If you configure 2 cores (firewall instances) on a VS, that VS will get 2 firewalls instances per SGM.
The 'asg perf' command has more options. You can get more details with the '-vv' option and you can check per VS.
If distribution is configured correctly the concurrent connections per SGM should be about the same.
Regards,
Martijn
You get 100K connections per VS but remember that every connection has an Active and a Backup SGM, so each connection is effectively counted twice in the connection tables across all SGMs. So when calculating the total amount of possible connections you should halve the value you configure in SmartConsole and use that as your per-SGM connection limit calculation.
Good point @emmap
if i understand properly, each connection is effectively counted 3 times, (it is a dual site environment, one active, one bck in the same site and another bck on the other site).
Thanks u very much i appreciate your answerers to get more knowledge about this topic.
Each connection is counted 3 times in a Maestro Active/Backup Dual Site configuration. However, if NAT is involved with a connection in this scenario, it is counted a total of 6 times:
This is why it is very important to max out the RAM in Maestro gateways if possible, since the "maximum connections" data sheet number for each gateway at a given RAM level needs to be cut in half for use with Maestro, and then cut in half again if NAT is involved. And those quoted numbers are for IPv4. Even if you avoid NAT by exclusively using IPv6, it takes twice as much RAM to track each IPv6 connection as it does for IPv4, so you are still down to 25% of the published number for maximum concurrent connections per individual Maestro SGM appliance, even with exclusive use of IPv6.
Thank u. I`ll take it into account
I was finding few resources about this kind of topics.
will this kind of low level tuning be available on your new book?
Hi emmap:
If I have three SGMs, and each SGM is handling approximately 300,000 concurrent connections, does that mean the value configured in SmartConsole needs to be set to more than 900,000?
Hi,
I think that the smart console value is by SGM, it means a value of 100k on max limit connections on SC, is a 100K per SGM.....if SG is properly balance it means 100k + 100k + 100k
Yes, exactly this - but then taking into consideration what @Timothy_Hall put in the earlier post there.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Wed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY