Hi,
on our firewall (Check Point R81.20 - Build 043), we are observing significant slowdowns when loading images while using map services – especially when panning or zooming maps on portals such as mapy.cz, Google Maps, or Street View.
The issue affects only images (tiles), while other parts of the pages load smoothly.
For selected services (e.g. mapserver.mapy.cz, panorama-mapserver.mapy.cz), we created Custom Applications/Sites and added them to bypass rules for HTTPS Inspection, which helped. However, on other portals where a large number of image requests occur, the slowdowns still persist.
Context:
Firewall: R81.20 - Build 043, KSFW, 16 cores, 14 fw_worker instances
QUIC is blocked
HTTPS Inspection is enabled with categorization, 0% accelerated connections
CPASXL traffic is around 40% of total traffic
Latency increases, especially with a larger number of image requests
Browsers: Chrome/Edge/Firefox (latest versions), OS: Windows 10/11
MS Defender and Windows policies are up-to-date
Perf and Spike Detective show load on fw_worker threads (e.g. kiss_thin_nfa_exec_one_buf_parallel_xlate, cmi_execute_ex)
Questions:
Do you have any recommendations on how to effectively deal with slowdowns during inspection of large numbers of image requests?
Is there a way to bypass only image requests (e.g. by MIME type, file path, or pattern), but inspect all other traffic?
Has anyone seen improvements by switching to USFW mode, if the issue was related only to TLS inspection of map tiles?
Could recent Windows or browser updates have impacted TLS handshake behavior and caused additional inspection load?
Thanks for any insight – we welcome even small real-world experiences.