- Products
- Learn
- Local User Groups
- Partners
- More
Call For Papers
Your Expertise, Our Stage
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
The Great Exposure Reset
AI Security Masters E4:
Introducing Cyata, Securing the Agentic AI Era
CheckMates Go:
CheckMates Fest
Does anyone know a way to determine where a bottleneck is with data transfer speeds?
In my particular scenario I have a 6400 appliance on one site, and a Spark 1570 (locally managed) on the other site. Both sites have 1Gb ISP circuits. There's a VPN between the gateways which is used for one machine at each side to communicate. (Veeam backup replication from site 1 to site 2). Both firewalls capable of far exceeding the limiting 1Gbps ISP speed.
We started off getting around 200mb transfer rate.
After excluding this traffic from all threat blades on the 6400, and adding the IP's to fw ctl fast_accel, and disabling the treat blades on the Spark, we're now up to around 450mb transfer speeds. Still a far cry from what we'd expect. How can I determine what's slowing it down?
First and foremost, you need to see which side is causing a bottleneck.
Which encryption algorithms are involved and are the transfers multi-threaded?
At the moment we're using AES256/SHA256 for both phases.
I have no idea whether the transfers are multi-threaded. How would I tell? 🙄
i.e. Can you configure Veeam to initiate multiple concurrent connections rather than a single one?
Ah, I'll ask the Veeam team. I don't have access to any of the Veeam kit.
On the 1570 run the command top and hit 1 to display individual CPU usage. Now start the 450Mbps transfer, does one of the CPUs on the 1570 hit 100% while the other one(s) are relatively idle? If so the transfer is not multithreaded. It is likely that the 1570 is your bottleneck.
Thanks, I'll test that when the Veeam guys reply to me. Am I right in assuming that Spark appliance don't offer the same "fast_accel" options as the enterprise appliances? So if it is maxing out a CPU on the Spark, it's pretty much tough luck?
Something similar has recently been introduced with the R81.10.x version so expect to hear more about it once the centrally managed version is GA.
====
Smart Accel – (EA level)
Improves gateway performance by accelerating low-risk traffic sources:
Video streaming (Netflix, YouTube, Spotify)
Well known corporate services (Microsoft, Google, Apple, Check Point Services)
Social Media services (Facebook, TikTok)
Web Conferences (Skype, WebEx, Zoom)
Great thanks. This box is locally managed so I'll suggest to the customer giving R81.10 a try on this box.
In any case, the 1500 support only MD5 or SHA1 hardware acceleration for integrity checks, regardless of the OS version.
You could try to change the hash to see if it makes a difference.
fw ctl fast_accel does appear to be a functional command on the R81.10.xx code on SMBs.
It might give you more headroom, but I suspect the real issue is this is an elephant flow.
Yup. Hence the Veeam multi-thread suggestion above 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 35 | |
| 22 | |
| 17 | |
| 12 | |
| 9 | |
| 9 | |
| 8 | |
| 8 | |
| 8 | |
| 7 |
Tue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 17 Mar 2026 @ 03:00 PM (CET)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - EMEATue 17 Mar 2026 @ 02:00 PM (EDT)
From SASE to Hybrid Mesh: Securing Enterprise AI at Scale - AMERWed 18 Mar 2026 @ 10:00 AM (CET)
The Cloud Architects Series: An introduction to Check Point Hybrid Mesh in 2026 - In Seven LanguagesThu 19 Mar 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #2: AI Security Challenges and SolutionsTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY