Hi community
I have some througput problems with several Checkpoint Quantum Spark 1800 running R80.20.40.
For the Internal networks I am using the 10Gbit/s DMZ interface in trunk mode and put all the VLANs onto this trunk. The DMZ interface is connected to a datacenterswitch 10Gbit/s port.
The WAN Port is connected to the same switch but with 1Gbit/s as of the speed on the FW is 1 Gbit/s only.
The HCI server platform is connected to the same switch with 25Gbit/s ports (each host).
I am doing performance tests with iperf.
Having 2 VMs in the same subnet, I get a throughput of 21Gbit/s in a 10sec measurement in both directions.
Moving 1 VM into another subnet, so the traffic has to pass the FW, I only get about 350Mbit/s in a 10 sec measurement, even then links to the FW is 10Gbit/s and there is nearly no other traffic on this DMZ interface.
The same picture is, when testing with a client connected directly in the same subnet than the FW WAN Interface and testing over a natting to the VM on the HCI platform acting as iperf server. I only get about 350Mbit/s ore even less throughput.
I am using always the same VM as iperf server, which is able to handle even 21Gbit/s like seen in the test within the iperf server and client in the same subnet.
I checked the datasheet of Checkpoint Quantum Spark 1800 and the values of security features throughput are much higher than the 350Mbit/s I am seeing.
What I am doing wrong or what is limiting this throughput. The security settings in the FW are most set to the default values, except the access policy control I had to change from “Standard” to “Strict”.
How can I find the bottleneck here?
Thank you for your help.
Kind regards, Stefan