In the past, I noticed that VXLAN requires fast packet processing, as higher packet latency can cause problems.

Therefore, I decided to enable SecureXL using the parameter sim_enable_vxlan = 1 (set the value of the SecureXL kernel parameter sim_enable_vxlan to one in the $PPKDIR/conf/simkern.conf) to speed up packet handling within the tunnel.
In addition, I enabled Fast Acceleration for these address ranges to ensure that traffic always uses the Fastpath.
I also created exclusions for IPS, Anti-Bot, and other similar blades for these network segments so that no traffic in these segments is inspected by those engines.
Are there any other optimization options to further improve VXLAN packet throughput through the firewall?
Info:
- R82 Gaia Administration Guide - Configuring VXLAN Interfaces
- sk156672: SecureXL Fast Accelerator (fw fast_accel)
- sk170014: Virtual Extensible LAN (VXLAN) Configuration Guide
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips