- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello overyone,
I'm looking for a tool or way to diagnose slow network performance via VPN.
I have 2 gateways connected by VPN S2S. The problem is the long file download times between locations. Files from the Internet are downloaded quickly, so it's probably a VPN problem.
Any ideas? Thanks in advance for your advice.
BR
What encryption are you using in phase 2?
Check Point appliances work better with AES due to AES NI CPU Instruction set with the Intel CPUs.
So if you are using 3DES (for whaever reason), change to AES128 at the very least.
Maybe there are other blades being applied to this traffic as well.
If I ever suspect that DPI may be the issue, try fast accelerating it to see if this alleviates the issues (on both FWs).
https://support.checkpoint.com/results/sk/sk156672
This is only to check if it's a VPN or DPI performance issue, it's up to you to keep this permanent or not.
Fast_acceleration disables all form of security blades (except firewall), so not recommended generally unless the traffic is 100 % trusted.
What are the "download protocols" ?
I assume it's HTTPS from the internet, but maybe it's CIFS / SMB over the tunnel?
Different blades with varying performance impact may be applied depending on the protocol.
Generally this is due to the use of slow VPN algorithms, or a low MTU between the two VPN peers. Here are the relevant pages from my Gateway Performance Optimization Course that you should find helpful:
Thank you very much for your tips.
The encryption in my VPN community looks like this:
- phase 1
Encryption Algorithm: aes-128
Data Integrity: sha256
-phase 2
Encryption Algorithm: aes-gcm-128
Data Integrity: sha1
What do you think should be changed? In phase 2 Encryption Algorithm on aes-128? And Data Integrity on sha256?
Will changing encryption break VPN connections?
BR
Your algorithm selection is fine, probably a low MTU issue.
I agree with the guys, seen that be an issue before.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY