We are currently using Checkpoint Appliance 23500 in our Data Centre which is running in Cluster (Active/Standby).
We have approx: 2500 to 3000 active remote VPN users connecting to the firewall at a time during Peak business hours.
The Internet on the Checkpoint Firewall is 2Gbps, and it peaks upto 800Mbps during business hours.
There is 20 CPU's, and we have Multi-Threading enabled so total 40 Virtual CPU's, the CPU peaks to max 55% during the peak business hours.
Hub mode is configured to route all traffic through the gateway (due to security reasons we cannot change it).
Enabled blades:
[Expert@QTS-CP-NW-FW02:0]# enabled_blades
fw vpn cvpn urlf av appi ips identityServer anti_bot content_awareness mon vpn
Most of the Remote VPN users have an Internet speed of about 200Mbps, some even have 500Mbps.
But after connecting to Checkpoint Endpoint VPN the speed goes below 15 Mbps (Download) and Upload (50 Mbps), which is affecting 2000+ users.
Below are some of the verification done from our side:
1. We have auto_detect set for endpoint_vpn_ipsec_transport in Guidbedit Firewall properties.
2. SecureXL is enabled:
[Expert@QTS-CP-NW-FW02:0]# fwaccel stats -s
Accelerated conns/Total conns : 10/39553 (0%)
Accelerated pkts/Total pkts : 163746283249/335101509859 (48%)
F2Fed pkts/Total pkts : 9663120065/335101509859 (2%)
F2V pkts/Total pkts : 2927705054/335101509859 (0%)
CPASXL pkts/Total pkts : 0/335101509859 (0%)
PSLXL pkts/Total pkts : 161692106545/335101509859 (48%)
QOS inbound pkts/Total pkts : 0/335101509859 (0%)
QOS outbound pkts/Total pkts : 0/335101509859 (0%)
Corrected pkts/Total pkts : 0/335101509859 (0%)
3. We tried to change the Remote VPN Phase 1 and Phase 2 encryption algorithm to lower encryption AES-128 SHA-1, but still no improvements.
Also we have Multiple Interface option in VPN Clients --> Office Mode checked.
"Support connectivity enhancement for gateways with multiple external interfaces"
Need assistance to identify what is causing the network slowness issue in checkpoint VPN.