<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Number of concurrent connections shown in CPView Utility depends on the status of SecureXL in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Number-of-concurrent-connections-shown-in-CPView-Utility-depends/m-p/29069#M2296</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are perfectly right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; font-family: 'courier new', courier, monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;fw tab -t connections -s&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;cphacu stat&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;are right choices for&amp;nbsp;sure. I simply supposed that the Cpview is reading always "fw tab -t connections -s" and then it should be similar on both cluster nodes. But it is not true or at least in normal case when SecureXL is active. It is good to know that the&amp;nbsp;Cpview is not right shortcut to check sync of connection table and CLI&amp;nbsp; is right way.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Jun 2018 05:45:26 GMT</pubDate>
    <dc:creator>Petr_Hantak</dc:creator>
    <dc:date>2018-06-08T05:45:26Z</dc:date>
    <item>
      <title>Number of concurrent connections shown in CPView Utility depends on the status of SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Number-of-concurrent-connections-shown-in-CPView-Utility-depends/m-p/29067#M2294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;I have question about n&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;umber of concurrent connections shown in CPView Utility.&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333; font-size: 15px;"&gt;CPView utility is nice and for most of my colleagues very easy understable utility for quick performance check. Usually we are running cluster solution and I must admit that it is quite confusing what we can see on Active and Standby nodes about connections. When SecureXL is active it shows only active connections on STANDBY node but not all synchronized connection summary from connection table.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333; font-size: 15px;"&gt;&lt;STRONG&gt;Active node:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333; font-size: 15px;"&gt;&lt;IMG alt="ACTIVE-member concurent connections" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66262_cpview-active.PNG" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="background-color: #ffffff; : ; color: #333333; font-size: 15px;"&gt;Standby node:&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333; font-size: 15px;"&gt;&lt;IMG alt="STANDBY-member concurent connections" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66266_cpview-standby.PNG" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333; font-size: 15px;"&gt;This situation is correct according to&amp;nbsp;&lt;STRONG style="background-color: #ffffff; color: #000000; font-size: 14px;"&gt;sk103496:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;DIV class="" style="color: #333333; font-weight: bold; font-size: 22px;"&gt;Symptoms&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The number of concurrent connections shown in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk101878" style="color: #905690; text-decoration: none;" target="_blank"&gt;CPView Utility&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is less than shown in the output of '&lt;CODE&gt;fw ctl pstat&lt;/CODE&gt;' or in the output of '&lt;CODE&gt;fw tab -t connections -s&lt;/CODE&gt;' command.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The number of concurrent connections shown in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://supportcontent.checkpoint.com/solutions?id=sk101878" style="color: #905690; text-decoration: none;" target="_blank"&gt;CPView Utility&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;differs depending on whether SecureXL is enabled or disabled.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;DIV class="" style="color: #333333; font-weight: bold; font-size: 22px;"&gt;Cause&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P&gt;The command '&lt;CODE&gt;fwaccel stats&lt;/CODE&gt;' (counter "&lt;CODE&gt;C total conns&lt;/CODE&gt;") shows the connections in SecureXL FWAccel module.&lt;BR /&gt;The command '&lt;CODE&gt;fw ctl pstat&lt;/CODE&gt;' (counter "&lt;CODE&gt;Concurrent Connections&lt;/CODE&gt;") shows the connections in FW module.&lt;/P&gt;&lt;P&gt;CPView Utility is designed to show the actual amount of connections that currently pass through the Security Gateway. This counter is adjusted according to which Check Point kernel module is handling the traffic:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When SecureXL is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;enabled&lt;/EM&gt;, CPView Utility shows the connections from the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;SecureXL FWAccel&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;module (run the command&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;fwaccel stats | grep "C total conns"&lt;/EM&gt;)&lt;/LI&gt;&lt;LI&gt;When SecureXL is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;disabled&lt;/EM&gt;, CPView Utility shows the connections from the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;FW&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;module (run the command&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;fw tab -t connections -s&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and refer to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;#VALS&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;column)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The difference in the number of connections when SecureXL is enabled or disabled is due to the fact that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;SecureXL SIM module does&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;not&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;show certain connections - e.g., ClusterXL synchronization connections.&lt;/LI&gt;&lt;LI&gt;FW module does&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;not&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;show certain connections - e.g., Delayed connections.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In addition, the big difference between the output of '&lt;CODE&gt;fwaccel conns -s&lt;/CODE&gt;' command and output of '&lt;CODE&gt;fwaccel stats | grep "C total conns"&lt;/CODE&gt;' is due to the fact that the command '&lt;CODE&gt;fwaccel conns -s&lt;/CODE&gt;' shows both Client-to-Server&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;and&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Server-to-Client connections, while the command '&lt;CODE&gt;fwaccel stats grep "C total conns"&lt;/CODE&gt;'| compresses these connections into&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;one&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;connection.&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class="" style="color: #333333; font-weight: bold; font-size: 22px;"&gt;Solution&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;P&gt;No fix is required; the system is functioning as designed.&lt;/P&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;DIV class=""&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At least for me it makes sense to see concurent connections equal in CPView for both cluster members. In that case we can see easily that it is synchronized.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know anyone what is behind current design?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you prefer to keep it as is or change it to equal view?&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 13:44:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Number-of-concurrent-connections-shown-in-CPView-Utility-depends/m-p/29067#M2294</guid>
      <dc:creator>Petr_Hantak</dc:creator>
      <dc:date>2018-06-07T13:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: Number of concurrent connections shown in CPView Utility depends on the status of SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Number-of-concurrent-connections-shown-in-CPView-Utility-depends/m-p/29068#M2295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually that SK does not apply to your question. Cpview is just showing ACTIVE concurrent connections running through your firewall. And since standby firewall will only have a handful of active connections (to/from itself) then output is correct. If you want to see that connections table is more or less the same in the cluster just use&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;fw tab -t connections -s&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that will be fairly close on both.&lt;/P&gt;&lt;P&gt;Cpview will show combined values from fwaccel stat&lt;/P&gt;&lt;P&gt;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 18:15:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Number-of-concurrent-connections-shown-in-CPView-Utility-depends/m-p/29068#M2295</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-06-07T18:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: Number of concurrent connections shown in CPView Utility depends on the status of SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Number-of-concurrent-connections-shown-in-CPView-Utility-depends/m-p/29069#M2296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are perfectly right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff; font-family: 'courier new', courier, monospace;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;fw tab -t connections -s&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;cphacu stat&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;are right choices for&amp;nbsp;sure. I simply supposed that the Cpview is reading always "fw tab -t connections -s" and then it should be similar on both cluster nodes. But it is not true or at least in normal case when SecureXL is active. It is good to know that the&amp;nbsp;Cpview is not right shortcut to check sync of connection table and CLI&amp;nbsp; is right way.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 05:45:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Number-of-concurrent-connections-shown-in-CPView-Utility-depends/m-p/29069#M2296</guid>
      <dc:creator>Petr_Hantak</dc:creator>
      <dc:date>2018-06-08T05:45:26Z</dc:date>
    </item>
  </channel>
</rss>

