- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
Bandwidth on a device in front of external interface is 950 Mbps (I connected a laptop to the ISP's provider's router directly), bandwidth behind of internal interface is 95 Mbps (I disconnected entire LAN from the gateway and connected a laptop only). Apparently there an issue with CP.
Is there a way to measure bandwidth on the Gateway? I'm running Gaia on Open Server R81.
Thank you,
Vlad.
cpview will report throughput... we don't support installing speedtest tools on the gateway itself but you have utilities such as curl available.
What blades are enabled and did the test involve multiple concurrent threads/connections?
How is the interface speed/duplex configured and is the server hardware listed on our HCL?
There are likely many other relevant questions...
Can not exactly say there is a issue with CP. When you disconnect lan and attach only laptop obviously only laptop is sending a traffic. While with LAN other hosts are pumping the traffic. TO confirm use cpview and under CPU -> Top Connections see who is transferring the data.
Plus if you feel hosts are sending a data and no getting proper bw; capture the packet using tcpdump on your internal interface or external inteface for a min or so and then analyze it with cpmonitor.
Blason, there are 5 instances under cpview -> CPU -> Top Connections. What is a difference between them?
Thank you.
Those shows that firewall has 6 core - one is used for SND while 5 instances displays the connections are being handled by 5 worker cores. Due to CoreXL Fw spawns and utilizes multiple cores on firewall.
What is your precise method for testing speed?
What precise observations did you make on the gateways while attempting this speed test?
Super Seven output while the device is under test will help: https://community.checkpoint.com/t5/Scripts/S7PAC-Super-Seven-Performance-Assessment-Commands/m-p/40...
In any case, a single flow from a single system may not achieve full bandwidth you have available or the capacity of the appliance.
It is not necessarily indicative of a problem.
Hi PhoneBoy,
I ran speed test on couple random websites.
https://www.att.com/support/speedtest/
The gateway in production. I do not have a test gateway.
I noticed the bandwidth issue started when our ISP replaced the router and increased the bandwidth. So, the bandwidth in front of CP increased accordingly provider's service, but behind of CP was not changed.
Thank you,
Vlad.
Ok - Are you noticing RX_DROPs on that interface? and are those getting increased rapidly? Please provide output netstat -ni 2
and ethtool -S <interface_name>
then ethttool -g <interface_name>
Oh you ran the wrong netstat command. It should be netstat -ni 2 and not netstat ni 2. It looks like Buffer size is not set to max provided you are noticing too much rx-DRP
I believe most of these speed test websites use a single TCP connection.
Which, as I noted before, is potentially problematic and won’t give you an accurate result of available bandwidth.
The output of the Super Seven commands are needed to confirm what is actually happening.
You can install iperf3 on the firewall's Gaia OS directly, see here: Test bandwidth/speed from Gaia
However all this will measure is performance between the firewall itself and an iperf3 server, but not the actual throughput for traffic being fully inspected while crossing/transiting the firewall. However this tool can be useful for finding network errors/bottlenecks outside the firewall itself.
Hi Timothy,
My next step to set iperf3 server on the WAN side, client on the LAN and run bandwidth test.
Thank you,
Vlad.
Hi Chris,
I attached three screenshots with: throughput, enabled blades and external interface configuration. Full duplex is enabled on both interfaces.
Yes, I tested involving multiple threads/connections and single host as well. The bandwith is the same in both tests.
There is one more detail. When ISP replaced their router and increased bandwidth it did not affect the LAN. LAN bandwidth is remaining 95 Mbps, WAN bandwidth increased up to 950 Mbps.
Vlad.
To even begin to determine definitely what is happening here, please answer the following questions:
My speculation, based on the very limited information you have provided this far, is you’re using a method that invokes a single heavy TCP stream.
This is called an elephant flow and is not in any way indicative of the overall bandwidth available for other traffic flowing through the gateway.
Note that we’ve made some improvements to handing elephant flows in R81.20 with HyperFlow.
However, it’s only supported on Check Point appliances, currently.
See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
What license is applied to this machine, is corexl enabled for multiple cores?
Refer also:
sk98871: HTTP-based speed test shows strong degradation in download speed when Anti-Virus is set to inspect all HTTP and HTTPS traffic
Chris, how to check if CoreXL is activated? I think we have only two core license. I read sk98871 and can try to stop Anti-Virus blade.
Also, I asked our account manager for a trial SecureXL license.
Suggest providing the info requested prior from @PhoneBoy regarding the S7 commands otherwise the following outputs from the gateway would be helpful short of the above.
fw ctl multik stat
cplic print
To manage/enable corexl (license permitting):
cpconfig > option 7
You can generate your own eval license per the instructions here: https://community.checkpoint.com/t5/General-Topics/How-to-Request-an-Evaluation-License-for-Security...
The "All-in-One" eval should give you a license for 8 cores.
If you only have a two core license, that will limit your performance substantially since only two cores will be used.
I applied trial "All-in-One" license. The license appeared in the Smart Console. Next, per instructions I restarted the Gateway and checked license status in the Smart Console right after. It was not there.
Thats really surprising!! What does your cplic print -x output says?
Oh🙂, please ignore my last post. I re-opened Smart Console, trial license still there.
Im so glad you posted this, because in all my years dealing with CP, I could NEVER find a logical way to do this. I cant even count how many TAC cases I opened asking this question...I stopped counting after 15 probably (lol). Yes, its gotten better in R80+, but I still have customers asking me for something simple/easy.
Just to make sure we're aligned, pls see summary of bandwidth measurements at our GWs:
Single flow
Total throughput
Can be measured using CPView -> Network -> Interfaces -> Traffic (RX Traffic & TX Traffic TOTAL)
Additional option: use the CPVIEW -> Traffic -> Traffic Rate
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
9 | |
6 | |
5 | |
4 | |
4 | |
3 | |
3 | |
2 | |
2 |
Wed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksWed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY