<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FW Accel Conns 0% in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Accel-Conns-0/m-p/140405#M21551</link>
    <description>&lt;P&gt;As Ben and Heiko said throughput acceleration via the Medium Path is working fine.&amp;nbsp; The zero Accelerated Conns rate just means that SecureXL is not doing Accept templates at all even though &lt;STRONG&gt;fwaccel stat&lt;/STRONG&gt; shows that there is no rule disabling templating.&amp;nbsp; Generally I believe this is caused by Anti-bot being enabled, as SecureXL itself cannot perform the IP reputation checks for Accept templates that is required when Anti-bot is enabled.&amp;nbsp; With the advent of Column-based matching in R80.10 Accept templating rates are much less important than they used to be for most environments, so I wouldn't worry about it.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Feb 2022 14:49:26 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2022-02-03T14:49:26Z</dc:date>
    <item>
      <title>FW Accel Conns 0%</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Accel-Conns-0/m-p/140283#M21518</link>
      <description>&lt;P&gt;Hi Team,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have a firewall running R81 with take 44 that currently has 0% accelerated conns, see output below:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp;Accelerated conns/Total conns : 22/37423 (0%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;Accelerated pkts/Total pkts : 131018190109/134923281770 (97%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;F2Fed pkts/Total pkts : 3905091661/134923281770 (2%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;F2V pkts/Total pkts : 982863959/134923281770 (0%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;CPASXL pkts/Total pkts : 1466487054/134923281770 (1%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;PSLXL pkts/Total pkts : 128928729017/134923281770 (95%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;CPAS pipeline pkts/Total pkts : 0/134923281770 (0%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;PSL pipeline pkts/Total pkts : 0/134923281770 (0%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;CPAS inline pkts/Total pkts : 0/134923281770 (0%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;PSL inline pkts/Total pkts : 0/134923281770 (0%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;QOS inbound pkts/Total pkts : 0/134923281770 (0%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;QOS outbound pkts/Total pkts : 0/134923281770 (0%)&lt;BR /&gt;&amp;nbsp; &amp;nbsp;Corrected pkts/Total pkts : 0/134923281770 (0%)&lt;BR /&gt;&lt;BR /&gt;Reviewing fw accel stat does not show that templating should be disabled,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;+---------------------------------------------------------------------------------+&lt;BR /&gt;&amp;nbsp; &amp;nbsp;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;&amp;nbsp; &amp;nbsp;+---------------------------------------------------------------------------------+&lt;BR /&gt;&amp;nbsp; &amp;nbsp;|0 |SND |enabled |eth1,eth5,eth2,eth3,eth4,|Acceleration,Cryptography |&lt;BR /&gt;&amp;nbsp; &amp;nbsp;| | | |Sync,Mgmt | |&lt;BR /&gt;&amp;nbsp; &amp;nbsp;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;&amp;nbsp; &amp;nbsp;| | | | |SHA1,3DES,DES,AES-128,AES-256,|&lt;BR /&gt;&amp;nbsp; &amp;nbsp;| | | | |ESP,LinkSelection,DynamicVPN, |&lt;BR /&gt;&amp;nbsp; &amp;nbsp;| | | | |NatTraversal,AES-XCBC,SHA256, |&lt;BR /&gt;&amp;nbsp; &amp;nbsp;| | | | |SHA384,SHA512 |&lt;BR /&gt;&amp;nbsp; &amp;nbsp;+---------------------------------------------------------------------------------+&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Accept Templates : enabled&lt;BR /&gt;&amp;nbsp; &amp;nbsp;Drop Templates : disabled&lt;BR /&gt;&amp;nbsp; &amp;nbsp;NAT Templates : enabled&lt;BR /&gt;&lt;BR /&gt;enabled blades output:&amp;nbsp;&lt;BR /&gt;fw urlf av appi ips anti_bot ThreatEmulation Scrub&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I have reviewed&amp;nbsp;&lt;SPAN&gt;sk32578 and the policy does not include anything that would impact connection templating. For my TP blades, we are using the autonomous policy with the edge profile. I am using updateable objects for both azure and o365, and I have them at the top of my rulebase, is there a chance that they impact secureXL?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 18:45:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Accel-Conns-0/m-p/140283#M21518</guid>
      <dc:creator>Sam2</dc:creator>
      <dc:date>2022-02-02T18:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: FW Accel Conns 0%</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Accel-Conns-0/m-p/140345#M21535</link>
      <description>&lt;P&gt;Hi Sam2,&lt;/P&gt;
&lt;P&gt;Please note "&lt;SPAN&gt;&amp;nbsp;Accelerated conns/Total conns"&amp;nbsp; means fully accelerated connections.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As you can see "PSLXL pkts/Total pkts : 128928729017/134923281770 (95%)"&amp;nbsp; so most of your traffic is accelerated but not fully accelerated (Medium path).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Ben&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 08:25:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Accel-Conns-0/m-p/140345#M21535</guid>
      <dc:creator>Ben_Maoz</dc:creator>
      <dc:date>2022-02-03T08:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: FW Accel Conns 0%</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Accel-Conns-0/m-p/140378#M21544</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/61698"&gt;@Sam2&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;It is exactly as &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17281"&gt;@Ben_Maoz&lt;/a&gt;&amp;nbsp; described it. If you need more info on the PSLXL path see my articles:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3041-r80x-security-gateway-architecture-logical-packet-flow" target="_blank" rel="noopener"&gt;- R8x - Security Gateway Architecture (Logical Packet Flow)&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Update-R80-20-Security-Gateway-Architecture-Logical-Packet-Flow/m-p/60401#M12218" target="_self"&gt;- R8x - Security Gateway Architecture (Logical Packet Flow) - Update R80.20+&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3073-r80x-security-gateway-architecture-content-inspection" target="_blank" rel="noopener"&gt;- R8x - Security Gateway Architecture (Content Inspection)&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 10:53:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Accel-Conns-0/m-p/140378#M21544</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2022-02-03T10:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: FW Accel Conns 0%</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Accel-Conns-0/m-p/140405#M21551</link>
      <description>&lt;P&gt;As Ben and Heiko said throughput acceleration via the Medium Path is working fine.&amp;nbsp; The zero Accelerated Conns rate just means that SecureXL is not doing Accept templates at all even though &lt;STRONG&gt;fwaccel stat&lt;/STRONG&gt; shows that there is no rule disabling templating.&amp;nbsp; Generally I believe this is caused by Anti-bot being enabled, as SecureXL itself cannot perform the IP reputation checks for Accept templates that is required when Anti-bot is enabled.&amp;nbsp; With the advent of Column-based matching in R80.10 Accept templating rates are much less important than they used to be for most environments, so I wouldn't worry about it.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 14:49:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-Accel-Conns-0/m-p/140405#M21551</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-02-03T14:49:26Z</dc:date>
    </item>
  </channel>
</rss>

