- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We have a small problem Houston.
One of our gateways is located in the kingdom far far away with over 200ms latency to the log server. Lately we noticed that part of the logs started to be saved locally on the gateway.
Investigation proved that we have reached the "limit" of a single TCP pipe (latency plus window size) that's around 1.5Mbps. Other evidence includes the fact that 2GB log file on log server never fills faster than 1.5hrs (note though that includes 2 VS logs so technically rate there is 2x1.5=3Mbps) and TCP send queue is noticeable on the gateway.
Solutions could be:
Does anyone know if it's really possible - to have multiple TCP connections for log transfer. I did some digging in UC but did not find anything. I'm interested in VSX "version"
Or does anyone know if we can "split" MLM or have two MLMs?
Unless Check Point has a multi-threaded log transfer agents already, I suspect that you are limited to the choices you have described.
One exception, possibly, is the use of the bandwidth (or WAN) optimization appliances on both sides. You really would not know if this approach works until you try. Riverbed is probably one of the better known names in that market.
WAN Optimization – WAN technologies from Riverbed
You can give them a call and try to get their engineers' opinion on the subject and anticipated (or not) improvements.
hehe - we just ripped out all the WAN accelerators as all they did was cause headaches ![]()
Yeah - I'm bit curious about multi-threaded log transfer ![]()
Might migrate the secondary MDS to the kingdom far far away and use that as log server for local firewalls - seems like the most logical step with the least cost. Additionally it will make local FW admin much faster for local admins as SmartDashboard gets really slow with that sort of latency
...begs the obvious question: did you have these issues with log transfers when the WAN accelerators were in play? ![]()
no, but we didn't as many logs either
we have multiplied firewalls and logs ten-fold since then
There is also a possibility of the UDP log shipping with TCP error checks.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY