Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
HeikoAnkenbrand
MVP Gold
MVP Gold
Jump to solution

VXLAN - Perfomance optimation question

In the past, I noticed that VXLAN requires fast packet processing, as higher packet latency can cause problems.

VXLAN_dhglkdfgh.png

Therefore, I decided to enable SecureXL using the parameter sim_enable_vxlan = 1 (set the value of the SecureXL kernel parameter sim_enable_vxlan to one in the $PPKDIR/conf/simkern.conf) to speed up packet handling within the tunnel.
In addition, I enabled Fast Acceleration for these address ranges to ensure that traffic always uses the Fastpath.
I also created exclusions for IPS, Anti-Bot, and other similar blades for these network segments so that no traffic in these segments is inspected by those engines.

Are there any other optimization options to further improve VXLAN packet throughput through the firewall?

Info:
- R82 Gaia Administration Guide - Configuring VXLAN Interfaces 
- sk156672: SecureXL Fast Accelerator (fw fast_accel)
- sk170014: Virtual Extensible LAN (VXLAN) Configuration Guide

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips
0 Kudos
1 Solution

Accepted Solutions
HeikoAnkenbrand
MVP Gold
MVP Gold

I found the reason why enabling SecureXL didn’t provide any performance benefit. The following SK explains that the UPPAK mode doesn’t support VXLAN. I’ve now switched SecureXL to KPPAK mode, and everything is working perfectly.

Software Releases for Quantum LightSpeed Appliances QLS / MLS and Quantum Force Appliances 9000, 190... 

UPPAK_645645.jpg

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips

View solution in original post

1 Reply
HeikoAnkenbrand
MVP Gold
MVP Gold

I found the reason why enabling SecureXL didn’t provide any performance benefit. The following SK explains that the UPPAK mode doesn’t support VXLAN. I’ve now switched SecureXL to KPPAK mode, and everything is working perfectly.

Software Releases for Quantum LightSpeed Appliances QLS / MLS and Quantum Force Appliances 9000, 190... 

UPPAK_645645.jpg

➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events