Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Richard_Wieser
Contributor

Remote Access VPN Packet loss

We have a cluster of 2 19000 appliances running R81.20 JHF 118. We have 10 Gbps connection to the ISP. After upgrading the switch that the cluster is connected to, we are seeing packet loss on Remote Access VPNs. S2S VPNs seem unaffected. Depending on the time of the day, we up to 50% loss on ping tests. I realize it's probably caused by the equipment that was changed (Cisco C9500) but I want to rule out any thing on the Check Point side as seems to only affect RA VPN traffic.

WAN interface:
Interface eth3-01
state on
mac-addr 00:xx:xx:xx:xx:xx
type ethernet
link-state link up
mtu 1500
auto-negotiation on
speed 25G
ipv6-autoconfig Not configured
monitor-mode off
duplex full
link-speed Not configured
comments WAN
ipv4-address xxx.xxx.xxx.xxx/24
ipv6-address ***************
ipv6-local-link-address ***************

Thanks

0 Kudos
30 Replies
Duane_Toler
MVP Silver
MVP Silver

You're doing 1000 byte size pings.  The ethernet MTU is only 1500 by default and your interfaces are using exactly that.  You may be inducing an issue.  You're also not going to get jumbo frames across all L3 hops through the Internet, but you can on your local LAN segments.  Jumbo frames are a layer2 construct primarily, but some L3 routing engines can route jumbo packets on higher end gear.  Looks like your 19000 series can handle up to 9000 bytes only (not 9216 like some switch vendors will allow and enable).  Check your local PC MTU and be careful not to "slashdot" yourself. 

Your output above also shows no jumbo frames enabled on your NICs, so check your new switches and see if they have jumbo enabled by default now.  If so, that might be your issue.  The new switches having to fragment packets at a higher rate than earlier, which will no doubt fill the output queues, pushing packets to the tail of the queue and getting dropped (even if QoS and WTD aren't configured).

 

--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events