- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi everyone!
I'm asking for help in understanding how QoS works, and how to debug correctly when QoS problems occur.
About the problem:
I have 2 security gateways with hosts behind them:
Gateway A has hosts 192.168.1.1 and 192.168.2.2.
Behind gateway B - hosts 192.168.3.1 and 192.168.4.2.
I enable the QoS module and configure the Simple rule and apply it. I configure the rule to target traffic between hosts 192.168.1.1 and 192.168.3.1. I create a load between the other hosts.
I made a rule with a guaranteed bandwidth of 200 Mb/sec. I have attached a photo of the rules from both gateways.
Rules were created on external interfaces of both gateways. The total channel speed is 307 Mb/sec.
As a result, when running Iperf3 between hosts (target and load) the speed does not reach 200 mb/sec according to the rule. In waves the speed varies from 30 to 170 Mb/sec. And on the channel with load the speed is 5-7 mb/sec. As a result, the total utilisation reaches 80%! The QoS module itself works, because under the condition of LIMIT, the speed is really limited. Also the guaranteed bandwidth works if you don't run Iperf on other hosts to create load.
I am asking for help or ideas on how to solve the problem and how to debug correctly.
Thank you in advance for your help!
We need a lot more information, such as:
Attached, screenshots of Iperf measurements, and debugs.
To answer your questions:
What is the device under test? - VM
What JHF are you running? - No hotfix, clean install.
Super Seven debug output attached
The rule essentially works, but with very very high traffic uctilisation
Screenshot of Iperf targeted traffic, while loading on traffic platforms that don't fall under the rules attached. Second screenshot, measuring the speed of all other traffic.(for load).
According to the debug, there are no errors, but there is this entry fg_dns_initarray: Could not open
Very please advise in which direction to look for the problem. I don't understand it yet
A single core and 4GB of RAM is below the minimum hardware requirements in the release notes for R81.20: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Content/Topics-RN/Open-Se...
Personally, I would allocate no less than 4 cores and no less than 8GB of RAM to the VM.
To debug (maybe TAC has better commands)
Andy
?s:
-did it ever work?
-brand new setup?
-what versions?
-all users have same problem?
Hello everyone!
Please help in understanding how QoS works, and how to debug correctly when QoS problems occur.
About the problem:
I have 2 security gateways with hosts behind them:
Gateway A has hosts 192.168.1.1 and 192.168.2.2.
Behind gateway B - hosts 192.168.3.1 and 192.168.4.2
I enable the QoS module and configure the Simple rule and apply it. I configure the rule to target traffic between hosts 192.168.1.1 and 192.168.3.1. Create a load between the other hosts.
I made a rule with a guaranteed bandwidth of 200 Mb/sec. I have attached a photo of the rule.
Rules are created on the external interfaces of both gateways. The total channel speed is 307 Mb/sec.
As a result, when running Iperf3 between hosts (target and load) the speed does not reach 200 mb/sec according to the rule. In waves the speed varies from 30 to 170 Mb/sec. And on the channel with load the speed is 5-7 mb/sec. As a result, the total utilisation reaches 80%! The QoS module itself works, because under the LIMIT condition, the speed is really limited. Also the guaranteed bandwidth works if you don't run Iperf on other hosts to create load.
I am asking for help or ideas on how to solve the problem and how to debug correctly.
Thank you in advance for your help!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 21 | |
| 15 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY