- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Does anyone know a way to determine where a bottleneck is with data transfer speeds?
In my particular scenario I have a 6400 appliance on one site, and a Spark 1570 (locally managed) on the other site. Both sites have 1Gb ISP circuits. There's a VPN between the gateways which is used for one machine at each side to communicate. (Veeam backup replication from site 1 to site 2). Both firewalls capable of far exceeding the limiting 1Gbps ISP speed.
We started off getting around 200mb transfer rate.
After excluding this traffic from all threat blades on the 6400, and adding the IP's to fw ctl fast_accel, and disabling the treat blades on the Spark, we're now up to around 450mb transfer speeds. Still a far cry from what we'd expect. How can I determine what's slowing it down?
First and foremost, you need to see which side is causing a bottleneck.
Which encryption algorithms are involved and are the transfers multi-threaded?
At the moment we're using AES256/SHA256 for both phases.
I have no idea whether the transfers are multi-threaded. How would I tell? 🙄
i.e. Can you configure Veeam to initiate multiple concurrent connections rather than a single one?
Ah, I'll ask the Veeam team. I don't have access to any of the Veeam kit.
On the 1570 run the command top and hit 1 to display individual CPU usage. Now start the 450Mbps transfer, does one of the CPUs on the 1570 hit 100% while the other one(s) are relatively idle? If so the transfer is not multithreaded. It is likely that the 1570 is your bottleneck.
Thanks, I'll test that when the Veeam guys reply to me. Am I right in assuming that Spark appliance don't offer the same "fast_accel" options as the enterprise appliances? So if it is maxing out a CPU on the Spark, it's pretty much tough luck?
Something similar has recently been introduced with the R81.10.x version so expect to hear more about it once the centrally managed version is GA.
====
Smart Accel – (EA level)
Improves gateway performance by accelerating low-risk traffic sources:
Video streaming (Netflix, YouTube, Spotify)
Well known corporate services (Microsoft, Google, Apple, Check Point Services)
Social Media services (Facebook, TikTok)
Web Conferences (Skype, WebEx, Zoom)
Great thanks. This box is locally managed so I'll suggest to the customer giving R81.10 a try on this box.
In any case, the 1500 support only MD5 or SHA1 hardware acceleration for integrity checks, regardless of the OS version.
You could try to change the hash to see if it makes a difference.
fw ctl fast_accel does appear to be a functional command on the R81.10.xx code on SMBs.
It might give you more headroom, but I suspect the real issue is this is an elephant flow.
Yup. Hence the Veeam multi-thread suggestion above 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 19 | |
| 14 | |
| 12 | |
| 12 | |
| 10 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY