Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Bynet_Security_
Explorer

Slow traffic on https/http on site to site

Hello everyone,
I set up a site to site between a Check Point 1500 machine that is managed locally and a Fortigate machine
The site above works fine but all traffic in https + http is very slow.
We checked downloading and uploading files and it was fine.
I would be happy to get some direction on what to check to locate the source of the problem
And if possible also an explanation of how to check if something is unclear.
Thanks to all who answered

0 Kudos
4 Replies
AdiGH
Employee
Employee

Hey, which Check Point product do you have installed? 

0 Kudos
Lesley
Mentor Mentor
Mentor

what blades you have enabled on the 1500?

What encryption methods you use on the site to site?

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
Chris_Atkinson
Employee Employee
Employee

Potentially an MTU issue, look into MSS clamping per sk121114.

CCSM R77/R80/ELITE
0 Kudos
Timothy_Hall
Legend Legend
Legend

Please post outputs of Super Seven plus enabled_blades

MSS clamping would normally only apply to IPSec traffic and not HTTPS traffic.  This is because in IPSec the whole ESP packet (mostly) is digitally signed and therefore cannot be fragmented (DF flag).  With HTTPS the payload stream of data is digitally signed, and the packets carrying it can be fragmented into a zillion pieces, as long as the payload stream of data being carried reassembles correctly.  This is why HTTPS/TLS based Remote Access VPN clients are more resistant to low MTU performance issues.

Attend my online "Be your Own TAC: Part Deux" CheckMates event
March 27th with sessions for both the EMEA and Americas time zones
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 18 Mar 2025 @ 09:30 AM (EET)

    CheckMates Live Greece

    Tue 25 Mar 2025 @ 12:00 PM (MDT)

    Salt Lake City: CPX 2025 Recap

    Tue 08 Apr 2025 @ 12:00 PM (MDT)

    Denver: CPX 2025 Recap
    CheckMates Events