<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: finetune acceleration on internet fw in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123576#M17762</link>
    <description>&lt;P&gt;Ok, no issues here.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jul 2021 07:24:20 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2021-07-12T07:24:20Z</dc:date>
    <item>
      <title>finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123514#M17739</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;i have pretty low acceleration rate on my internet gw (r80.30 ha cluster). tac and professional services didn't solve this issue and said it's appropriate, but i wonder if there is more that i can do to make it better.&lt;/P&gt;
&lt;P&gt;here are some outputs:&lt;/P&gt;
&lt;P&gt;[Expert@]# fwaccel stat&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;|0 |SND |enabled |eth4,eth5,eth0,eth2,eth3 |Acceleration,Cryptography |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,NULL,3DES,DES,CAST, |&lt;BR /&gt;| | | | |CAST-40,AES-128,AES-256,ESP, |&lt;BR /&gt;| | | | |LinkSelection,DynamicVPN, |&lt;BR /&gt;| | | | |NatTraversal,AES-XCBC,SHA256 |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;/P&gt;
&lt;P&gt;Accept Templates : enabled&lt;BR /&gt;Drop Templates : enabled&lt;BR /&gt;NAT Templates : enabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;since the system marked this post as a spam i guess because i posted lots of output, i will try to add other outputs in separate comments.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jul 2021 17:34:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123514#M17739</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-07-11T17:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123515#M17740</link>
      <description>&lt;P&gt;[Expert@]# fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 138/8296 (1%)&lt;BR /&gt;Accelerated pkts/Total pkts : 18393539360/79399018144 (23%)&lt;BR /&gt;F2Fed pkts/Total pkts : 51288084805/79399018144 (64%)&lt;BR /&gt;F2V pkts/Total pkts : 198043963/79399018144 (0%)&lt;BR /&gt;CPASXL pkts/Total pkts : 13960870/79399018144 (0%)&lt;BR /&gt;PSLXL pkts/Total pkts : 9703433109/79399018144 (12%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/79399018144 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/79399018144 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/79399018144 (0%)&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jul 2021 13:04:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123515#M17740</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-07-11T13:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123516#M17741</link>
      <description>&lt;P&gt;[Expert@]# fwaccel stats -d&lt;BR /&gt;Reason Value Reason Value&lt;BR /&gt;-------------------- --------------- -------------------- ---------------&lt;BR /&gt;General 3 CPASXL Decision 10&lt;BR /&gt;PSLXL Decision 1350662 Clear Packet on VPN 0&lt;BR /&gt;Encryption Failed 1 Drop Template 0&lt;BR /&gt;Decryption Failed 4 Interface Down 0&lt;BR /&gt;Cluster Error 0 XMT Error 0&lt;BR /&gt;Anti-Spoofing 10523280 Local Spoofing 418&lt;BR /&gt;Sanity Error 1189 Monitored Spoofed 0&lt;BR /&gt;QXL Decision 0 C2S Violation 0&lt;BR /&gt;S2C Violation 0 Loop Prevention 0&lt;BR /&gt;DOS Fragments 0 DOS IP Options 0&lt;BR /&gt;DOS Blacklists 0 DOS Penalty Box 0&lt;BR /&gt;DOS Rate Limiting 0 Syn Attack 0&lt;BR /&gt;Reorder 0 Virt Defrag Timeout 9&lt;BR /&gt;Invalid Interface 0 Null Routing info 0&lt;BR /&gt;Unable to get out ifn 0 Resource exhausted 0&lt;BR /&gt;Conn not found 0 Failed to del corr 0&lt;BR /&gt;Corr instead of conn 0 Del zombie conn fail 0&lt;BR /&gt;FW UUID no match 3 Offload mismatch 0&lt;BR /&gt;SIM init failed 0 Null stream init info 0&lt;BR /&gt;Unable to get CGNAT 0 Null stream app info 0&lt;BR /&gt;Failed get init info 0 SIM add stream failed 0&lt;BR /&gt;Collid conn not found 0 Del collid conn fail 0&lt;BR /&gt;Add conn after collid 0 SEQ valid 0&lt;BR /&gt;Enqueue QoS failed 0 AUX CI null 0&lt;BR /&gt;Link dead 0 VPN packet too big 0&lt;BR /&gt;NAT64 failed 0 NAT46 failed 0&lt;BR /&gt;Packet &amp;gt; MTU 0 NAC validation 0&lt;BR /&gt;TCP state violation 916 Enforce packet 0&lt;BR /&gt;GTP check packet 0 Bridge route error 0&lt;BR /&gt;Route ifn changed 0 IP forwarding 0&lt;BR /&gt;Copy MACS failed 0 Fragments Drops 0&lt;BR /&gt;Send Notification 0 Conn not found RST 0&lt;BR /&gt;Forward to PPAK fail 0 Cluster forward fail 0&lt;BR /&gt;F2F before encrypt 0 Forward dst encrypt 0&lt;BR /&gt;Correction I/S fail 0 Do inbound F2F 0&lt;BR /&gt;Packet UDP failed 0 F2F not allowed 0&lt;BR /&gt;Do routing 0 Fanout won't F2F 0&lt;BR /&gt;SCTP validation fail 0 SCTP not data 0&lt;BR /&gt;Invalid TCP option 0 Invalid MSS option 0&lt;BR /&gt;Invalid MSS value 0 Invalid window scale 0&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jul 2021 13:04:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123516#M17741</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-07-11T13:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123517#M17742</link>
      <description>&lt;P&gt;[Expert@:0]# fw ctl multik stat&lt;BR /&gt;ID | Active | CPU | Connections | Peak&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;0 | Yes | 11 | 3792 | 6840&lt;BR /&gt;1 | Yes | 10 | 3682 | 6516&lt;BR /&gt;2 | Yes | 9 | 3943 | 6580&lt;BR /&gt;3 | Yes | 8 | 3805 | 6590&lt;BR /&gt;4 | Yes | 7 | 3777 | 6482&lt;BR /&gt;5 | Yes | 6 | 3774 | 6540&lt;BR /&gt;6 | Yes | 5 | 3736 | 6548&lt;BR /&gt;7 | Yes | 4 | 3501 | 6316&lt;BR /&gt;8 | Yes | 3 | 3997 | 6786&lt;BR /&gt;9 | Yes | 2 | 3767 | 6599&lt;BR /&gt;10 | Yes | 1 | 4052 | 6607&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@]# enabled_blades&lt;BR /&gt;fw vpn urlf av appi ips identityServer SSL_INSPECT anti_bot ThreatEmulation mon vpn&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jul 2021 13:05:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123517#M17742</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-07-11T13:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123525#M17743</link>
      <description>&lt;P&gt;A lot of F2F traffic: are you running in explicit proxy mode by chance and/or you have Remote Access users using Visitor Mode?&lt;BR /&gt;It could also just be HTTPS Inspection causing this.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jul 2021 17:32:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123525#M17743</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-11T17:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123533#M17744</link>
      <description>&lt;P&gt;no proxy, no visitor mode.&lt;/P&gt;&lt;P&gt;only ssl inspection&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jul 2021 18:44:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123533#M17744</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-07-11T18:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123536#M17745</link>
      <description>&lt;P&gt;I don’t remember if HTTPS Inspection traffic goes F2F or not (may be CPAS).&lt;BR /&gt;A PPPoE interface is another possible reason.&lt;BR /&gt;See also:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32578" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32578&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jul 2021 19:38:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123536#M17745</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-11T19:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123538#M17746</link>
      <description>&lt;P&gt;no pppoe interface&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jul 2021 21:01:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123538#M17746</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-07-11T21:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123542#M17748</link>
      <description>&lt;P&gt;The SK I pointed you at lists various reasons for traffic going F2F (section 1 primarily but a few others in other sections).&lt;BR /&gt;Any of those apply?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 00:21:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123542#M17748</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-12T00:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123563#M17756</link>
      <description>&lt;P&gt;please share output from "enabled_blades" command&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 05:51:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123563#M17756</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-07-12T05:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123565#M17758</link>
      <description>&lt;P&gt;HTTPSi could be the main reason. See if you can tune the policy to avoid over-inspecting. How does your inspection policy look like?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 05:57:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123565#M17758</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-07-12T05:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123566#M17759</link>
      <description>&lt;P&gt;already shared&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 06:36:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123566#M17759</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-07-12T06:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123568#M17760</link>
      <description>&lt;P&gt;i followed the sk, i didn't found anything special.&lt;/P&gt;&lt;P&gt;besides i do have&amp;nbsp;small pmtu &amp;amp; syn attack protections enabled. and yes i do have critical performance ips protections.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 07:05:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123568#M17760</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-07-12T07:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123573#M17761</link>
      <description>&lt;P&gt;src_group&amp;gt;internet:https = bypass&lt;BR /&gt;src_group&amp;gt;internet:logmein = bypass&lt;BR /&gt;all_lans&amp;gt;dst_group:https = bypass&lt;BR /&gt;src_group&amp;gt;internet:https:url_group = bypass&lt;BR /&gt;all_lans&amp;gt;internet:https:url_group = bypass&lt;BR /&gt;all_lans&amp;gt;internet:https = inspect&lt;BR /&gt;internet&amp;gt;published services:https = inspect&lt;BR /&gt;any&amp;gt;any:https&amp;amp;8080 = bypass&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 07:18:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123573#M17761</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-07-12T07:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123576#M17762</link>
      <description>&lt;P&gt;Ok, no issues here.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 07:24:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123576#M17762</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-07-12T07:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123577#M17763</link>
      <description>&lt;P&gt;Small PMTU and SYN Attack will disable Accept Templates, which means initial connections will go F2F, but the actual connections should be accelerated (assuming nothing else pulls it into F2F).&lt;BR /&gt;Critical IPS Protections should only trigger F2F in circumstances where traffic might trigger a given protection.&lt;BR /&gt;That said, might be worth checking which IPS signatures are having the highest CPU impact:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110737&amp;amp;partition=Basic&amp;amp;product=IPS" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110737&amp;amp;partition=Basic&amp;amp;product=IPS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 07:25:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123577#M17763</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-12T07:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123578#M17764</link>
      <description>&lt;P&gt;Those are most probably the root causes then. Personally, I would be very surprised if PS missed anything here.&lt;/P&gt;
&lt;P&gt;What is the usual situation, FWKs are all running high CPU, or jsut some of them?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 07:26:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123578#M17764</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-07-12T07:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123621#M17768</link>
      <description>&lt;P&gt;HTTPS-Inspected traffic should be in the CPASXL path.&lt;/P&gt;
&lt;P&gt;There are a variety of things that can cause high F2F, usually legacy features or signatures that are enabled.&amp;nbsp; Looking at your enabled blades, I'd say you almost certainly have an IPS signature enabled causing the high F2F.&amp;nbsp; &amp;nbsp;Suggestions:&lt;/P&gt;
&lt;P&gt;1) SYN Attack used to cause large amounts of traffic to go F2F, but that was resolved in R80.20.&amp;nbsp; Please post output of&amp;nbsp;&lt;STRONG&gt;fwaccel synatk config&lt;/STRONG&gt; so we can see if it is properly being handled in SecureXL.&amp;nbsp; Also provide output of&amp;nbsp;&lt;STRONG&gt;fwaccel stats -p&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;2) Do you have any of these IPS signatures enabled (these are quoted from my Max Power book):&lt;/P&gt;
&lt;P&gt;- IP ID Masking/Fingerprint Scrambling&lt;BR /&gt;- Time to Live (TTL) Masking/Fingerprint Scrambling&lt;BR /&gt;- ASCII Only Response Headers&lt;BR /&gt;- Network Quota (check out the “Rate Limiting” feature in Chapter 12 for a much&lt;BR /&gt;more efficient way to enforce quotas)&lt;BR /&gt;- ClusterXL Load Sharing Sticky Decision Function (SDF), which only applies to&lt;BR /&gt;Load Sharing Multicast ClusterXL deployments; note that enabling the Mobile&lt;BR /&gt;Access Blade forces the use of SDF on a Load Sharing Multicast cluster.&lt;/P&gt;
&lt;P&gt;3) Try disabling the IPS checkbox on your gateway and reinstalling policy.&amp;nbsp; Then run &lt;STRONG&gt;fwaccel stats -r&lt;/STRONG&gt;, wait 10 minutes, and run&amp;nbsp;&lt;STRONG&gt;fwaccel stats -s.&lt;/STRONG&gt;&amp;nbsp; Did the F2F % drop a lot?&amp;nbsp; If so we need to focus on your IPS config. Note that doing this will expose your organization to attacks while IPS is disabled.&lt;/P&gt;
&lt;P&gt;4) The next step is labor intensive, and involves running &lt;STRONG&gt;fwaccel conns&lt;/STRONG&gt; and &lt;STRONG&gt;fw ctl multik gconn&lt;/STRONG&gt;.&amp;nbsp; Starting in R80.30 connections handled in F2F are no longer listed in the output of &lt;STRONG&gt;fwaccel conns&lt;/STRONG&gt; but all connections appear in the output of&amp;nbsp;&lt;STRONG&gt;fw ctl multik gconn&lt;/STRONG&gt;.&amp;nbsp; You should be able to do some crunching and figure out what kind of connections are listed by the latter command but not the former; the attributes of these F2F connections (internal/external IP, port numbers, etc.) should give you some hints about why F2F is necessary.&lt;/P&gt;
&lt;P&gt;5) Bit of a long shot, but make sure you do not have wire mode enabled on any of your VPN Communities.&amp;nbsp; Also do you have a large percentage of protocols traversing the firewall that are not TCP or UDP-based?&amp;nbsp; All those protocols cannot be accelerated.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 19:08:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123621#M17768</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-07-12T19:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123623#M17769</link>
      <description>&lt;P&gt;some of them most of the time, but it's dynamic. and something cores get too 100%+ so i don't want to lose any connections that are elephant flow etc&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 16:12:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123623#M17769</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-07-12T16:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: finetune acceleration on internet fw</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123624#M17770</link>
      <description>&lt;P&gt;thanks ! checked.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 16:13:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/finetune-acceleration-on-internet-fw/m-p/123624#M17770</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-07-12T16:13:15Z</dc:date>
    </item>
  </channel>
</rss>

