R80.20 SecureXL + new chain modules + fw monitor

Document created by Heiko Ankenbrand Champion on Oct 15, 2018Last modified by Heiko Ankenbrand Champion on Oct 15, 2018
Version 9Show Document
  • View in full screen mode

SecureXL has been significantly revised in R80.20. It now works in user space. This has also led to some changes in "fw monitor"

There are new fw monitor chain (SecureXL) objects that do not run in the virtual machine.


SecureXL offloading chain modules


# fw ctl chain


The new fw monitor chain modules (SecureXL) do not run in the virtual machine (vm).


SecureXL inbound (sxl_in)                 > Packet received in SecureXL from network

SecureXL inbound CT (sxl_ct)           > Accelerated packets moved from inbound to outbound processing (post routing)


SecureXL outbound (sxl_out)            > Accelerated packet starts outbound processing

SecureXL deliver (sxl_deliver)          > SecureXL transmits accelerated packet


 New vm chain modules in R80.20


There are more new chain modules in R80.20


vpn before offload (vpn_in)                  > FW inbound preparing the tunnel for offloading the packet (along with the connection)

fw offload inbound (offload_in)            > FW inbound that perform the offload

fw post VM inbound  (post_vm)            > Packet was not offloaded (slow path) - continue processing in FW inbound


# fw ctl chain


fw monitor chain keys


In Firewall kernel (now also SecureXL), each kernel is associated with a key (blue) witch specifies the type of traffic applicable to the chain modul.


# fw ctl chain


ffffffffIP Option Stip/Restore
00000001new processed flows
00000002wire mode
00000003will applied to all ciphered traffic (VPN)
00000000SecureXL offloading (new in R80.20+)
33 people found this helpful