<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fw ctl chain in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/130005#M19080</link>
    <description>&lt;P&gt;Perfect. I was just trying to understant better how chain modules and inspection happens.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Valter Junior&lt;/P&gt;</description>
    <pubDate>Wed, 22 Sep 2021 23:31:59 GMT</pubDate>
    <dc:creator>valterj</dc:creator>
    <dc:date>2021-09-22T23:31:59Z</dc:date>
    <item>
      <title>fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125264#M18121</link>
      <description>&lt;P&gt;Hi All.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it available some document or content about fw ctl chain outputs? I'd like to understant deeply all columns and fields (module, chain position, function pointer, mode, etc). The concept about chain modules is a bit complicated.&lt;/P&gt;&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 15:52:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125264#M18121</guid>
      <dc:creator>valterj</dc:creator>
      <dc:date>2021-07-29T15:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125294#M18126</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/66642"&gt;@valterj&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Unfortunately, there is no overview of the chain modules.&lt;BR /&gt;However, you can find some information in the CCTE training materials.&lt;BR /&gt;&lt;BR /&gt;I have written a few articles on the new parameters. Maybe that will help you:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3041-r80x-security-gateway-architecture-logical-packet-flow" target="_blank" rel="noopener"&gt;- R8x - Security Gateway Architecture (Logical Packet Flow)&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/thread/10363-r8020-new-fw-monitor-inspection-points" target="_blank" rel="noopener"&gt;- R80.20 - New FW Monitor inspection points&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/thread/9680-r8020-new-chain-modules" target="_blank" rel="noopener"&gt;- R80.20 - New Chain Modules?&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3180-r8020-securexl-fw-monitor" target="_blank" rel="noopener"&gt;- R80.20 - SecureXL + new chain modules + fw monitor&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can also found more information here:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_PerformanceTuning_AdminGuide/Topics-PTG/CLI/fw-monitor.htm?Highlight=SecureXL%20inbound%20(sxl_in)%20" target="_self"&gt;Performance Tuning R81 Administration Guide -&amp;gt; fw monitor&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 21:04:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125294#M18126</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-07-29T21:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125295#M18127</link>
      <description>&lt;P&gt;SecureXL has been significantly revised in R80.20. It now works in user space.&amp;nbsp;This has also led to some changes in "fw monitor"&lt;/P&gt;
&lt;P&gt;There are new fw monitor chain (SecureXL) objects that do not run in the virtual machine.&lt;/P&gt;
&lt;P&gt;The new fw monitor chain modules&amp;nbsp;(SecureXL) do not run in the virtual machine (vm).&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #000000;"&gt;&lt;STRONG&gt;SecureXL inbound (sxl_in)&lt;/STRONG&gt;&lt;/SPAN&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; Packet received in SecureXL from network&lt;BR /&gt;&lt;SPAN style="color: #000000;"&gt;&lt;STRONG&gt;SecureXL inbound CT (sxl_ct)&lt;/STRONG&gt;&amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt; Accelerated packets moved from inbound to outbound processing (post routing)&lt;BR /&gt;&lt;SPAN style="color: #000000;"&gt;&lt;STRONG&gt;SecureXL outbound (sxl_out)&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt; Accelerated packet starts outbound processing&lt;BR /&gt;&lt;SPAN style="color: #000000;"&gt;&lt;STRONG&gt;SecureXL deliver (sxl_deliver)&lt;/STRONG&gt;&lt;/SPAN&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; SecureXL transmits accelerated packet&lt;/P&gt;
&lt;P&gt;There are more new chain modules in R80.20&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;&lt;SPAN style="color: #000000;"&gt;vpn before offload (vpn_in)&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; FW inbound preparing the tunnel for offloading the packet (along with the connection)&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;&lt;SPAN style="color: #000000;"&gt;fw offload inbound (offload_in)&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; FW inbound that perform the offload&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;&lt;SPAN style="color: #000000;"&gt;fw post VM inbound&amp;nbsp; (post_vm)&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; Packet was not offloaded (slow path) - continue processing in FW inbound&lt;/P&gt;
&lt;P&gt;---&lt;BR /&gt;&lt;BR /&gt;There are&amp;nbsp;new fw monitor inspection points&amp;nbsp; when a packet passes through a R80.20+ Security Gateway:&lt;/P&gt;
&lt;TABLE class="j-table jiveBorder" style="border: 1px solid #c6c6c6;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #efefef; height: 25px;"&gt;
&lt;TH style="width: 10%; height: 25px;"&gt;Inspection point&lt;/TH&gt;
&lt;TH style="width: 22%; height: 25px;"&gt;Name of fw monitor inspection point&lt;/TH&gt;
&lt;TH style="width: 53.6022%; height: 25px;"&gt;Relation to firewall VM&lt;/TH&gt;
&lt;TH style="width: 59.3978%; height: 25px;"&gt;Available since version&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;i&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Pre-Inbound&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Before the inbound FireWall VM &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:i&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;always&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;I&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Post-Inbound&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;After the inbound FireWall VM&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:I&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;always&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;id&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Pre-Inbound VPN&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Inbound before decrypt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:id&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;ID&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Post-Inbound VPN&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Inbound after decrypt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:ID&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;iq&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Pre-Inbound QoS&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Inbound before QoS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:iq&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;IQ&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Post-Inbound QoS&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Inbound after QoS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:IQ&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;o&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Pre-Outbound&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Before the outbound FireWall VM&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:o&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;always&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;O&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Post-Outbound&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;After the outbound FireWall VM&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:O&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;always&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc;"&gt;&lt;STRONG&gt;e&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;oe&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Pre-Outbound VPN&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;
&lt;P&gt;Outbound before encrypt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:e&lt;/CODE&gt;)&amp;nbsp;&amp;nbsp;&amp;nbsp; in R80.10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:oe&lt;/CODE&gt;)&amp;nbsp; in R80.20&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;
&lt;P&gt;&lt;SPAN style="color: #00ccff;"&gt;&lt;STRONG&gt;R80.10&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc;"&gt;&lt;STRONG&gt;E&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;OE&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Post-Outbound VPN&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;
&lt;P&gt;Outbound after encrypt &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:E&lt;/CODE&gt;)&amp;nbsp;&amp;nbsp;&amp;nbsp; in R80.10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:OE&lt;/CODE&gt;)&amp;nbsp; in R80.20&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc;"&gt;&lt;STRONG&gt;R80.10&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;oq&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Pre-Outbound QoS&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Outbound before QoS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:oq&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;OQ&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Post-Outbound QoS&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Outbound after QoS &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:OQ&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;---&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;New in R80.20+:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In Firewall kernel (now also SecureXL), each kernel is associated with a key witch specifies the type of traffic applicable to the chain modul.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV&gt;
&lt;TABLE class="j-table jiveBorder" style="border: 1px solid #c6c6c6; width: 45.8412%;"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #efefef;"&gt;
&lt;TH style="width: 12%;"&gt;Key&lt;/TH&gt;
&lt;TH style="width: 30.8412%;"&gt;Function&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="width: 12%;"&gt;&lt;SPAN style="font-family: terminal, monaco, monospace;"&gt;&lt;STRONG&gt;ffffffff&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 30.8412%;"&gt;all packets&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 12%;"&gt;&lt;SPAN style="font-family: terminal, monaco, monospace;"&gt;&lt;STRONG&gt;00000001&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 30.8412%;"&gt;stateful mode&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 12%;"&gt;&lt;SPAN style="font-family: terminal, monaco, monospace;"&gt;&lt;STRONG&gt;00000002&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 30.8412%;"&gt;wire mode&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 12%;"&gt;&lt;SPAN style="font-family: terminal, monaco, monospace;"&gt;&lt;STRONG&gt;00000003&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 30.8412%;"&gt;all packets&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 12%;"&gt;&lt;SPAN style="color: #0000ff; font-family: terminal, monaco, monospace;"&gt;&lt;STRONG&gt;00000000&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 30.8412%;"&gt;SecureXL offloading&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;P style="background: white;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 09:51:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125295#M18127</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-07-30T09:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125303#M18132</link>
      <description>&lt;P&gt;Heiko explained it better than anyone would...but sadly, there is no official CP document explaining the output of fw ctl chain as he stated.&lt;/P&gt;
&lt;P&gt;Though, I did find below and it seems very informative:&lt;/P&gt;
&lt;P&gt;&lt;A href="http://dkcheckpoint.blogspot.com/2016/07/chapter-2-chain-module.html" target="_self"&gt;FW CTL Chain explanation&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jul 2021 21:42:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125303#M18132</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-07-29T21:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125311#M18133</link>
      <description>&lt;P&gt;&lt;SPAN&gt;A detailed description of the inspection points would be very helpful. Maybe is there a good PDF document or SK that Check Point can publish?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 05:25:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125311#M18133</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-07-30T05:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125320#M18136</link>
      <description>&lt;P&gt;I appreciate your curiosity. The exact output is only relevant to kernel developers and TAC, and might only complicate things, but here is your answer:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;First number - location of the module in the chain&lt;/LI&gt;
&lt;LI&gt;Second number - pointer to the function in the chain&lt;/LI&gt;
&lt;LI&gt;Third number - position, absolute numbers&lt;/LI&gt;
&lt;LI&gt;Fourth number - in which mode this chain check:&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-120px"&gt;1 – stateful mode&lt;/P&gt;
&lt;P class="lia-indent-padding-left-120px"&gt;2 – wired mode&lt;/P&gt;
&lt;P class="lia-indent-padding-left-120px"&gt;3 – all packets&lt;/P&gt;
&lt;P class="lia-indent-padding-left-120px"&gt;fff...ff – al packets (same as 3)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 08:40:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125320#M18136</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-07-30T08:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125322#M18137</link>
      <description>&lt;P&gt;I wonder where did you get this Heiko &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 08:55:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125322#M18137</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-07-30T08:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125323#M18138</link>
      <description>&lt;P&gt;Some additional info about the models themselves is here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98799" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98799&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Once again, unless you are debugging a support case, this is 90% irrelevant&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 08:56:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125323#M18138</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-07-30T08:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125324#M18139</link>
      <description>&lt;P&gt;For example, if you add "fw monitor" chain hooks in a certain position, they will also appear as "fff...ff", which means, your understanding of that key is a guess. "00..01" is also just stateful mode, nothing else. "00..00" is indeed used to for re-injecting accelerated traffic back to SXL.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 09:00:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125324#M18139</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-07-30T09:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125325#M18140</link>
      <description>&lt;P&gt;I have changed it!&lt;BR /&gt;Sorry, copy and paste issue &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jul 2021 09:53:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/125325#M18140</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-07-30T09:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/130005#M19080</link>
      <description>&lt;P&gt;Perfect. I was just trying to understant better how chain modules and inspection happens.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Valter Junior&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 23:31:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-chain/m-p/130005#M19080</guid>
      <dc:creator>valterj</dc:creator>
      <dc:date>2021-09-22T23:31:59Z</dc:date>
    </item>
  </channel>
</rss>

