Hi everyone,
we are currently investigating a performance issue with Check Point Remote Access VPN and I would appreciate any ideas or experiences with similar behavior.
Our setup:
- Check Point Security Gateway: R81.20
- ClusterXL
- Remote Access VPN Client: E89.11 for Windows
- IPsec Remote Access VPN
- Client Internet connection: ~50 Mbps
- Download speed through the VPN: only ~20 Mbps
Without the VPN connection, the client can utilize approximately the full 50 Mbps. As soon as the Check Point VPN tunnel is established, the download throughput drops to around 20 Mbps.
We initially suspected an MTU/fragmentation issue. The Check Point virtual adapter already uses an MTU of 1350. As a test, I also changed the MTU of the physical Windows network adapter to 1360 and 1350, but this did not result in any noticeable improvement.
The Security Gateway itself does not appear to be under significant CPU load during the tests.
We are planning to perform additional tests with iperf3 against an internal server, including:
- single TCP stream
- multiple parallel TCP streams
- reverse direction
- UDP test
Before going deeper into debugging, I wanted to ask:
Has anyone experienced similar throughput limitations with E89.x Remote Access VPN clients on R81.20?
In particular, are there any known issues or recommended settings regarding:
- Remote Access IPsec performance
- SecureXL / VPN acceleration
- CoreXL
- NAT-T
- TCP MSS / PMTU
- Endpoint VPN client processing
- differences between single and multiple TCP streams
Are there any specific commands, counters, SKs, or debug procedures you would recommend to determine whether the bottleneck is on the Endpoint client or the Security Gateway?
best regards,
Roman