## Optimizing an IPS profile for SMB

Policy install on SMB appliances can fail if the IPS configuration enables too many protections. According to CP, SMB devices were never designed to run a full IPS policy and it is suggested to check [_sk105217 "Commit function failed"/"Installation failed" error on policy installation failure on sma..._](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105217&partition=Advanced&product=Security) for configuration suggestions:

- When managed by R80.x Security Management server, create an IPS profile based on the top of the built-in Optimized Profile; up to R77.30 Security Management server, clone the Recommended Profile.

- Deactivate the " _Server protections_" option in IPS policy of the SMB Profile. In R80.x, it is found in the Pre R80 Settings:

.bmp)

- Deactivate IPS protections whose CVE is from 2010 and/or older - these are vulnerabilities you would rarely find in Small Office environment and the performance impact of them is not cost effective.

In R80.x you can add categories to _Profile > IPS > Additional Activation > Protections to deactivate_ list:

.bmp)

- You can also deactivate IPS protections for traffic that does not pass through those gateways, e.g. Protocol FTP if FTP is never used.

If this adaptions do not resolve the policy install issue, you can consult [_sk117793 Policy installation / fetch fails on Centrally Managed 1400 appliance_](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117793&partition=Advanced&product=Small)  and [_sk126372 Policy installation on SMB appliances fails with "Load on Module failed - not enough disc s..._](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk126372&partition=Advanced&product=Small).

Please note that this is my own configuration that has not been checked by CheckPoint - and is open for discussions, corrections and additions. Also see this list [SMB documents](https://community.checkpoint.com/t5/SMB-Appliances-and-SMP/SMB-documents/m-p/57239#M2222/jump-to/first-unread-message) for more.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

- Tags:
- [smb](https://community.checkpoint.com/t5/tag/smb/tg-p/board-id/smb-smp)

- [smb configuration](https://community.checkpoint.com/t5/tag/smb%20configuration/tg-p/board-id/smb-smp)

[5\\
\\
\\
Kudos](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1648/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40091?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

- [All forum topics](https://community.checkpoint.com/t5/Spark-Firewall-SMB/bd-p/smb-smp/page/156 "Spark Firewall (SMB)")
- [Previous Topic](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Want-help-with-traffic-blocking-from-one-side/td-p/27038 "Want help with traffic blocking from one side")
- [Next Topic](https://community.checkpoint.com/t5/Spark-Firewall-SMB/How-can-i-upgrade-checkpoint-1470-appliance-to-R88-10/td-p/26236 "How can i upgrade checkpoint 1470 appliance to R88.10 ?")

1 Solution

Accepted Solutions

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2018-09-0606:48 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1660)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103/highlight/true#M1660)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1660/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40103)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

This has been resolved by following this procedure:

\- Cleared directories $FWDIR/state/\_\_tmp/FW1, $FWDIR/database/cpeps\_flash/ and $FWDIR/database/cpeps/

\- enable only FW blade on SMB device object

\- install policy

\- enable TP blades on SMB object again

\- install policy

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

[View solution in original post](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1660/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40103?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

24 Replies

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2018-05-3007:55 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1649)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40092/highlight/true#M1649)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1649/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40092)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

Is it possible to exclude all but certain protocols from IPS ? For example if I want only HTTP(S), DNS and SMTP inspected.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40092?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2018-06-0205:16 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1650)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40093/highlight/true#M1650)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1650/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40093)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

As stated above, you can deactivate IPS for protocols not needing inspection.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40093?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2018-06-0208:00 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1651)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40094/highlight/true#M1651)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1651/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40094)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

You do want me to go and exclude all protocol one by one. Ugh, that's what I want to avoid?

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40094?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[PhoneBoy](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7)

Admin

‎2018-06-0210:42 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1652)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40095/highlight/true#M1652)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1652/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40095)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

IPS only inspects traffic allowed by your access policy.

If you only allow HTTPS, DNS, and SMTP via your access policy, IPS will only inspect that traffic.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40095?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2018-06-0310:23 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1653)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40096/highlight/true#M1653)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1653/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40096)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

Thanx for the clarification. That is somehow logical but I am being paranoid lately

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40096?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[Rodney\_Hopkins2](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8812)

Contributor

‎2018-09-0106:49 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1654)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40097/highlight/true#M1654)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1654/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40097)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

This is absolutely true.  I would add one additional piece of information.  In my experience with 1100 devices, the recommendation to disable protections earlier than 2010 was not enough.  As the years progressed, I had to disable protections from later years as well.  For example, in 2014, disabling protections older than 2010 worked.  By 2015, I had to disable protections older than 2012.  2016, disable protections older than 2013 and so on.  For the 1100 series at least, it worked out to roughly a window of 3 to 5 years of IPS protections that I could have enabled at any given time.

The newer 1400 series have more RAM and are more powerful, so they may be able to handle more.

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1654/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40097?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2018-09-0407:44 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1655)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40098/highlight/true#M1655)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1655/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40098)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

Just recently, i discovered that after firmware update to R77.20.80, on a 1140 SMB appliance policy install will fail as there are too many enabled blades, that is FW, VPN, IPS, ABOT, AV, APCL, URLF, QoS. Even setting new .80 Advanced Settings "Move temporary policy files to storage" to true does not help. That is a bad sign for a hardware that is supported until summer 2020...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40098?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2018-09-0408:16 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1656)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40099/highlight/true#M1656)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1656/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40099)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

Yeah, hmm... It is now evident that SMB appliances are just not up to task of being full FW + TP solution. It is good that there are so many blades to choose from but running all of them at the same time is overkill even on 1470/1490.  I have enabled only the AC/UF and IPS blades. Works somehow but SFWD process crashes way to often (max rss increased to 300MB). I understood there are other people experiencing same problem.

Would love to enable HTTPS inspection also. But I am kind of afraid to do it

And I wonder what it will be when/if R80.20 is released.

For me, stability is more important than anything else.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40099?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2018-09-0411:53 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1657)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40100/highlight/true#M1657)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1657/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40100)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

You have to think of SMB appliances as successors to the Edge / Safe@Office units - and in comparison, they have a whole lot more functionality - apart from NGTP, just look into the advanced routing possible now. But that enabling NGTP Blades lowers the traffic throughput is clear, and you can not argue that buying the blades and services makes the hardware able to cope with them performance-wise. More expensive hardware makes more ressources available, it would be unnecessarys otherwise 😉

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1657/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40100?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[Rodney\_Hopkins2](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8812)

Contributor

‎2018-09-0501:02 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1658)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40101/highlight/true#M1658)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1658/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40101)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

Have you hit upon the magic combination or magic number of blades that can be enabled at once?

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40101?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2018-09-0511:56 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1659)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40102/highlight/true#M1659)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1659/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40102)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

No, because that also depends very much on the traffic, both its load and mix that can be quite different at every customer.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40102?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2018-09-0606:48 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

This has been resolved by following this procedure:

\- Cleared directories $FWDIR/state/\_\_tmp/FW1, $FWDIR/database/cpeps\_flash/ and $FWDIR/database/cpeps/

\- enable only FW blade on SMB device object

\- install policy

\- enable TP blades on SMB object again

\- install policy

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[Pedro\_Espindola](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/4362)

Employee

‎2018-09-0607:57 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1661)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40104/highlight/true#M1661)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1661/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40104)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

Hello Hristo,

In the beginning I had some issues with HTTPS Inspection, but I worked with TAC and R&D was able to reach a stable build, I believe starting from build 402. GA is 392, but build 437 is available for download in [sk134253](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk134253) and also corrects some CVEs and VPN issues.

I am currently running HTTPS Inspection and full NGTP in a 1450 cluster with 12 users, 3 Site-to-site VPN Tunnels, 200 Mbps link. It is working fine.

There were some serious memory leak issues in SFWD but they seem to be solved as well. It has been weeks without a failover due to SFWD crash.

I believe we will see greater improvements in R77.20.85 also, which should be out in October.

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1661/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40104?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2018-09-0608:20 PM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1662)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40105/highlight/true#M1662)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1662/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40105)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

Hey Pedro,

I am running cluster of two 1470 appliances used by 70 users, 5 SS VPNs, few remote access users on a dual ISP connection with total 100 Mbps capacity. Not too much I think. Build is also 437.

Some days it will work fine, no issues. But on most of the days SFWD will crash every now and then. It is immediately restarted by a watchdog service and there is no failover in the cluster. In fact the only visible effect is that all SS VPNs are restarted (currently open user connections are dropped).  I have no other custom settings on the device other than the RSS memory increased to 300MB. R77.20.75 build 239 was the last one that had stable SFWD process that never crashed.

SecureXL does not work also for me. When I enabled it device restarts in few minutes. TAC was able to fix that and provide me with custom build but I had to replace it with 437 because of the CVE security fixes. I hope they will include this fix in the main branch.

HTTPS Inspection generally works here but I have disabled it because of the SNI problem that seems to be properly fixed only in R80.10 so far. Check this thread:

[https://community.checkpoint.com/thread/6245-is-there-any-workaround-for-sni-https-traffic-when-enab...](https://community.checkpoint.com/thread/6245-is-there-any-workaround-for-sni-https-traffic-when-enabled-the-https-probe-bypass)

I hope stability will be improved even more but as we discussed in another thread current Gaia embedded design is not very good (everything is handled by a single process). I am assuming this and other things will change in R80.20 if it is still planned release for SMB.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40105?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2018-09-1402:07 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1663)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40106/highlight/true#M1663)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1663/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40106)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

You wrote:

I would expect that a much smaller hardware footprint exists on this kind of embedded devices and that everything is handled by a single process is only a symptom of a reduction process. I do not expect these things to change in the future - if the hardware platform gets more power ( see the difference between 600/1100 and 7x0/14x0 models ), more functionality can be added. But in the same time, the "big" GAiA devices also get better hardware that makes new functionality possible. So the SMB devices will always keep behind and no full R80.20 port could ever be released for install on SMB. I do remember the older SMB units being included in turbines to provide them safe internet connectivity. 1200Rs are just looking richt for this field of application.

Next Version is R77.20.81, and a little bird has told me that it might bring more flexible ISP connections (more than four).

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1663/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40106?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2018-09-1402:15 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1664)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40107/highlight/true#M1664)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1664/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40107)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

Hi,

This is all too exciting but sadly SecureXL does not really work on SMB if you have ISP in load-balancing configuration. On primary/backup it works fine. I hope they fix that as well.

Reference [sk104679](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104679)

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40107?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2018-09-1402:54 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1665)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40108/highlight/true#M1665)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1665/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40108)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

The sk104679 does speak about ISP Redundancy enabled in Primary/Backup mode, and it also includes SMB as well as all CP versions up to R77.30. The configuration of ISPs in load-balancing configuration does not work with SecureXL at all despite of hotfixes installed. I would not expect that this can be fixed for SMBs...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40108?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2018-09-1403:00 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1666)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40109/highlight/true#M1666)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1666/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40109)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

Why would LB cause more load than HA? Btw, it is more like load sharing, not really balancing.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40109?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2018-09-1403:04 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1667)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40110/highlight/true#M1667)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1667/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40110)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

HA only has to check if the primary is up, but LS has to distribute the load according to some algorithm or config between the ISPs. This is similar ti the use of multiple cores as distributing work there also needs ressources...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40110?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2018-09-1403:11 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1668)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40111/highlight/true#M1668)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1668/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40111)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

Correct me if I am wrong but LB only works on outbound connections? Also, I do not think link selection algorithm is that complex to cause any significant load. It all depends on how many concurrent connections there are of course but still... Do not underestimate SMB power

Also, If it cannot LB between 2x ISP links why on earth would I need 4x ? One primary and three backups sounds crazy to me.

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40111?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2018-09-1403:28 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1669)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40112/highlight/true#M1669)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1669/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40112)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

You can use SecureXL together with ISP redundancy (let us use the correct term). but not when ISP LB is needed - but what is the gain of using SecureXL on SMBs ? LB surely works on outbound connections as you rarely can control inbound connections.

The question of link selection algorithm is a rather complicated theme especially if the ISPs have different performance characteristics. Dpending on hard- and software, adding a second core might give 30% to 70% improvement (maybe even up tp 90%, but Amdahl's law rules).

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40112?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2018-09-1403:55 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1670)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40113/highlight/true#M1670)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1670/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40113)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

Hmm, isn't SecureXL supposed to offload some traffic from firewall module thus reducing actual load on the system? Something especially needed on these low-end devices.

I believe link selection on SMB is pure round-robin algorithm.  I seriously doubt it is accounting for latency and such.... or keeping in time stats and trying to use some predictive methods... May be utilizing some fast math to prioritize link based on pre-configured preference.

I would vote for adding more memory and disk space rather than increasing number of cores but this is purely personal preference

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40113?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[HristoGrigorov](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680)

MVP Gold

‎2018-09-1403:59 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1671)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40114/highlight/true#M1671)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1671/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40114)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

Now, look at this. Beautiful isn't it?

\[cpWatchDog 2162 1744208784\]@RD6281\[13 Sep 12:41:03\] \[INFO\] CPWD is already performing active monitoring on CheckPoint services/processes

\[cpWatchDog 2162 1744208784\]@RD6281\[13 Sep 12:41:04\] \[SUCCESS\] cposd started successfully (pid=2814)

\[cpWatchDog 2162 1744208784\]@RD6281\[13 Sep 12:41:04\] \[SUCCESS\] RTDB started successfully (pid=2834)

\[cpWatchDog 2162 1744208784\]@RD6281\[13 Sep 12:42:38\] \[SUCCESS\] SFWD started successfully (pid=5397)

\[cpWatchDog 2162 1744208784\]@RD6281\[13 Sep 12:42:43\] \[SUCCESS\] CPHAMCSET started successfully (pid=6707)

\[cpWatchDog 2162 1744208784\]@RD6281\[14 Sep 9:03:11\] \[ERROR\] Process SFWD terminated abnormally : Unhandled signal 6 (). Core dumped.

\[cpWatchDog 2162 1744208784\]@RD6281\[14 Sep 9:04:11\] \[SUCCESS\] SFWD started successfully (pid=21999)

\[cpWatchDog 2162 1744208784\]@RD6281\[14 Sep 11:32:19\] \[ERROR\] Process SFWD terminated abnormally : Unhandled signal 6 (). Core dumped.

\[cpWatchDog 2162 1744208784\]@RD6281\[14 Sep 11:33:19\] \[SUCCESS\] SFWD started successfully (pid=28000)

\[cpWatchDog 2162 1744208784\]@RD6281\[14 Sep 13:40:58\] \[ERROR\] Process SFWD terminated abnormally : Unhandled signal 11 (SIGSEGV). Core dumped.

\[cpWatchDog 2162 1744208784\]@RD6281\[14 Sep 13:41:58\] \[SUCCESS\] SFWD started successfully (pid=30460)

0

Kudos

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40114?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

[G\_W\_Albrecht](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294)

MVP Silver

‎2018-09-1404:13 AM

[Show option menu](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091# "Show option menu")

- Mark as New
- Bookmark
- Subscribe
- Mute
- [Subscribe to RSS Feed](https://community.checkpoint.com/rss/message?board.id=smb-smp&message.id=1672)
- [Permalink](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40115/highlight/true#M1672)
- [Print](https://community.checkpoint.com/t5/forums/forumtopicprintpage/board-id/smb-smp/message-id/1672/print-single-message/true/page/1)
- [Report Inappropriate Content](https://community.checkpoint.com/t5/notifications/notifymoderatorpage/message-uid/40115)

[Jump to solution](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/m-p/40103#M1660)

This is a completely different theme, so please post that seperately from **Optimizing an IPS profile for SMB**

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

[1\\
\\
\\
Kudo](https://community.checkpoint.com/t5/kudos/messagepage/board-id/smb-smp/message-id/1672/tab/all-users "Click here to see who gave kudos to this post.")

[Click here to give kudos to this post.](https://community.checkpoint.com/t5/forums/v5/forumtopicpage.kudosbuttonv2.kudoentity:kudoentity/kudosable-gid/40115?t:ac=board-id/smb-smp/thread-id/1648&t:cp=kudos/contributions/tapletcontributionspage&ticket=0TpTpfPHoolj_-1 "Click here to give kudos to this post.")

1

2

3

4

5

0.5

1.0

1.5

2.0

2.5

3.0

3.5

4.0

4.5

5.0

[Reply](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

Post Reply

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

| User | Count |
| --- | --- |
| <br>[sx8n20394](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/107449) | 7 |
| <br>[israelfds95](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/93117) | 7 |
| <br>[jorgeluiznim](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/85528) | 5 |
| <br>[velo](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/110726) | 1 |
| <br>[BikeMan](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54723) | 1 |
| <br>[emmap](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054) | 1 |
| <br>[CEEJAY](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/112446) | 1 |
| <br>[Max\_Leorne](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/142185) | 1 |
| <br>[Chris\_Atkinson](https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630) | 1 |

[View All ≫](https://community.checkpoint.com/t5/forums/kudosleaderboardpage/board-id/smb-smp/timerange/one_month/page/1/tab/authors)

Trending Discussions

[Reach My Device – A Native Option for Secure Remote Access to Quantum Spark Appliances](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Reach-My-Device-A-Native-Option-for-Secure-Remote-Access-to/td-p/280076)

[Downgrading a Quantum Spark Appliance: From 'Upgrade Not Supported' to a Working Boot Loader Recover](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Downgrading-a-Quantum-Spark-Appliance-From-Upgrade-Not-Supported/td-p/279888)

[L2TP Remote Access VPN - Can't Connect on SMB 2550 R82.00.10](https://community.checkpoint.com/t5/Spark-Firewall-SMB/L2TP-Remote-Access-VPN-Can-t-Connect-on-SMB-2550-R82-00-10/td-p/279943)

Upcoming Events

Sort by:

- [All](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091#)
- [Virtual](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091#)
- [In-Person](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091#)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Tue 28 Jul 2026 @ 11:00 AM (EDT)

[Under the Hood - Check Point and Illumio – Modern Network Defense Against AI-Based Threats](https://community.checkpoint.com/t5/CheckMates-Events/Under-the-Hood-Check-Point-and-Illumio-Modern-Network-Defense/ev-p/279701)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 12:00 PM (SGT)

[The AI Security Report 2026: A Turning Point for Enterprise Defense - SGT](https://community.checkpoint.com/t5/CheckMates-Events/The-AI-Security-Report-2026-A-Turning-Point-for-Enterprise/ev-p/280019)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 02:00 PM (IDT)

[The AI Security Report 2026: A Turning Point for Enterprise Defense - AMER](https://community.checkpoint.com/t5/CheckMates-Events/The-AI-Security-Report-2026-A-Turning-Point-for-Enterprise/ev-p/280021)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 03:00 PM (CEST)

[The AI Security Report 2026: A Turning Point for Enterprise Defense EMEA](https://community.checkpoint.com/t5/CheckMates-Events/The-AI-Security-Report-2026-A-Turning-Point-for-Enterprise/ev-p/280020)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 11:00 AM (EDT)

[TechTalk: On-Premise SD-WAN Management](https://community.checkpoint.com/t5/CheckMates-Events/TechTalk-On-Premise-SD-WAN-Management/ev-p/279370)

Thu 30 Jul 2026 @ 11:30 AM (CDT)

[CheckMates Live DFW: Agentic AI Security Deep Dive & Hands-On](https://community.checkpoint.com/t5/CheckMates-Events/CheckMates-Live-DFW-Agentic-AI-Security-Deep-Dive-amp-Hands-On/ev-p/279920)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Tue 28 Jul 2026 @ 11:00 AM (EDT)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 12:00 PM (SGT)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 02:00 PM (IDT)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 03:00 PM (CEST)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Wed 29 Jul 2026 @ 11:00 AM (EDT)

[TechTalk: On-Premise SD-WAN Management](https://community.checkpoint.com/t5/CheckMates-Events/TechTalk-On-Premise-SD-WAN-Management/ev-p/279370)

[Virtual](https://community.checkpoint.com/labels/Virtual)

Thu 30 Jul 2026 @ 10:00 AM (PDT)

[AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI Gateway](https://community.checkpoint.com/t5/CheckMates-Events/AI-Security-Masters-E12-READY-OR-NOT-Securing-the-AI-Enterprise/ev-p/277411)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Tue 11 Aug 2026 @ 11:30 AM (EDT)

[New York City: Agentic AI Security Deep Dive & Hands-On](https://community.checkpoint.com/t5/CheckMates-Events/New-York-City-Agentic-AI-Security-Deep-Dive-amp-Hands-On/ev-p/279476)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 13 Aug 2026 @ 11:30 AM (EDT)

[Waltham, MA: Agentic AI Security Deep Dive & Hands-On](https://community.checkpoint.com/t5/CheckMates-Events/Waltham-MA-Agentic-AI-Security-Deep-Dive-amp-Hands-On/ev-p/279475)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 20 Aug 2026 @ 08:30 AM (COT)

[Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IA](https://community.checkpoint.com/t5/CheckMates-Events/Medellin-Workspace-Evolution-Hybrid-Mesh-Management-Visibilidad/ev-p/280003)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 20 Aug 2026 @ 06:00 PM (COT)

[Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de Seguridad](https://community.checkpoint.com/t5/CheckMates-Events/Medellin-Workspace-Intelligence-IA-Generativa-en-Acci%C3%B3n-para/ev-p/280004)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Thu 27 Aug 2026 @ 09:00 AM (CEST)

[Check Point Hands-On SASE and Cloud Workshop - Zurich](https://community.checkpoint.com/t5/CheckMates-Events/Check-Point-Hands-On-SASE-and-Cloud-Workshop-Zurich/ev-p/279914)

[In-Person](https://community.checkpoint.com/labels/In-Person)

Wed 21 Oct 2026 @ 09:00 AM (BST)

[AI Security Workshop - Glasgow](https://community.checkpoint.com/t5/CheckMates-Events/AI-Security-Workshop-Glasgow/ev-p/278505)

[CheckMates Events](https://community.checkpoint.com/t5/CheckMates-Events/eb-p/events)

[Top](https://community.checkpoint.com/t5/Spark-Firewall-SMB/Optimizing-an-IPS-profile-for-SMB/td-p/40091)

About CheckMates

- [Getting Started & FAQ](https://community.checkpoint.com/t5/help/faqpage)
- [Community Guidelines](https://community.checkpoint.com/t5/user/TermsOfServicePage)

Learn Check Point

- [Check Point for Beginners](https://community.checkpoint.com/t5/Check-Point-for-Beginners-2-0/bg-p/check-point-for-beginners-2-0)
- [Check Point Trivia](https://community.checkpoint.com/t5/Check-Point-Trivia/bg-p/trivia)
- [CheckFlix Videos](https://community.checkpoint.com/t5/CheckFlix/ct-p/checkflix)

Advanced Learning

- [Check Point Security Masters](https://community.checkpoint.com/t5/Check-Point-Security-Masters/gp-p/ccsm)
- [Tip of the Week](https://community.checkpoint.com/t5/SecureKnowledge-Tip-of-the-Week/bg-p/secureknowledge)
- [TechTalks](https://community.checkpoint.com/t5/TechTalks/ct-p/techtalks%20role=)
- [Training and Certification](https://community.checkpoint.com/t5/Training-and-Certification/bd-p/training-and-certification)

Resources

- [CheckMates Toolbox](https://community.checkpoint.com/t5/CheckMates-Toolbox/ct-p/CheckMatesToolbox)
- [Developers (Code Hub)](https://community.checkpoint.com/t5/Developers-API-CLI/bd-p/codehub)
- [Product Announcements](https://community.checkpoint.com/t5/Product-Announcements/bg-p/products-blog)
- [Upcoming Events](https://community.checkpoint.com/t5/Upcoming-Events/bg-p/checkmates-live)

Non-English Discussions

- [Español](https://community.checkpoint.com/t5/Espa%C3%B1ol/bd-p/spanish)
- [French](https://community.checkpoint.com/t5/Fran%C3%A7ais/bd-p/francais)
- [Japanese](https://community.checkpoint.com/t5/Japanese-%E6%97%A5%E6%9C%AC%E8%AA%9E/bd-p/Japanese)
- [Português](https://community.checkpoint.com/t5/Portugu%C3%AAs/bd-p/portuguese)
- [Russian](https://community.checkpoint.com/t5/Russian/bd-p/russian)
- [Chinese](https://community.checkpoint.com/t5/Chinese/bd-p/taiwan)

YOU DESERVE THE BEST SECURITY

We’re Social. Follow Us [CheckMates on LinkedIn](http://linkedin.com/company/cpcheckmates)  [Check Point on YouTube](https://www.youtube.com/user/CPGlobal) [CheckMates on Facebook](https://www.facebook.com/cpcheckmates/) [CheckMates on Instagram](https://www.instagram.com/cpcheckmates/)

©1994-2026 Check Point Software Technologies Ltd. All rights reserved. [Copyright](https://www.checkpoint.com/copyright/) [Privacy Policy](https://www.checkpoint.com/privacy/) [About Us](https://www.checkpoint.com/about-us/) [UserCenter](https://usercenter.checkpoint.com/)

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.

Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
