CPX 2023 HTTPS Best Practices v3
CPX 2023 HTTPS Best Practices v3
Throughput?
Connections
per second
Throughput
Throughput
860 MbpsConnections
2200 conx/sec
per second
82 % CPU
CPU load
©2022 Check Point Software Technologies Ltd. 9
Testing HTTPS Inspection Performance
No failures
asg perf –v --delay 4
Throughput
Connections/second
4x SecureXL
Distributors
12x CoreXL
FW_workers
DNS
120
SSH
100
HTTPS
80
Video CIFS
76% HTTPS
HTTPS
HTTPS
60
HTTPS
40
HTTPS 1k
20 100k HTTPS
10k
0
Preventing Being blind to most of attacks
Percentage of traffic secured CPU Load
DNS
120
SSH
100
HTTPS
80
Video CIFS
76% HTTPS
HTTPS
60 $?
$ HTTPS
40
HTTPS 1k
20 100k HTTPS
10k
0
Preventing Being blind to most of attacks
Percentage of traffic secured CPU Load
Gateway Topology
Access Control Policy
Updatable Objects and Domain Objects in FQDN mode are now supported
sk161612
DNS
domains_tool -d www.example.com
sk161632
CPX 360
sk106623
• “Download and install updates automatically” is enabled by default on fresh installs R81 and later
sk173629
DROP LOG