- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: IPSec VPN Tunnel & SSL VPN user capacity
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPSec VPN Tunnel & SSL VPN user capacity
Hi,
I am working on an important RFP and need the following clarification on IPsec and SSL VPN -
1. How many Site-to Site VPN does CP 23500 and CP 15600 support ?
2. How many SSL VPN concurrent users does CP 23500 & CP 15600 support ?
A quick response is highly appreciated.
Regards,
Sunandan
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I got reply from Solution Center and they say -
1. We support up to 55k VPN S2S tunnels. (No difference with ClusterXL).
2. We support up to 20K SSL VPN concurrent users with 64GB of RAM.
This is for both 23500 & 15600. This is FYI.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Jerry,
Our appliance comparison chart does not give the number of VPN tunnels and SSL VPN concurrent users.
Thanks/Sunandan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No problem Jerry.
I would wait for some reply from other expert.
Thanks/Sunandan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I fear that an answer to your question will at least start with: It does depend ! In theory, VPN tunnel and SSL User numbers are limited by size of corresponding kernel tables - but in real life, the needed traffic throughput, enabled Blades, IPS/TP profile and rule set as well as a lot more have to be taken into consideration !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have an HA pair of 15600's and I currently have 62 ipsec site-to-site VPN tunnels active and have had more. We have a few sites down at the moment. We use a separate product for SSL VPN.
These are set up mostly with Check Point 1100's and some 1430's, not a lot of users at each site.
Jason
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'd even risk saying that 300 IPSec SA's should be easy-peasy.
If more - as Guenter mentioned - all depends but I'd strongly recommend you to try this first and make sure that in "vpn tu" tool you see all SA's established (with SPI listed).
15600 is one of the newer appliances and I have doubts it won't cope (wether HA or Single) with at least 300-400 VPN Tunnels at least.
Other than that I think that the UPLINK capacity also matters and just assuming it isn't a limitation you really don't need to worry about those numbers. That's just my "5 cents" mate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I got reply from Solution Center and they say -
1. We support up to 55k VPN S2S tunnels. (No difference with ClusterXL).
2. We support up to 20K SSL VPN concurrent users with 64GB of RAM.
This is for both 23500 & 15600. This is FYI.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Experts
I have the same problem, I have an RFP with a similar reference
I need to know in perfect traffic conditions is it possible to support more than 5,000 Site to site and Client to site tunnels for a 6600
and 10,000 site to site and client to site for a 6800.
I hope somebody could help us.
maybe somebody from solution center.
