<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about consumption process fwd and port 1024/tcp in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-consumption-process-fwd-and-port-1024-tcp/m-p/149863#M24072</link>
    <description>&lt;P&gt;Hello the_rock,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I understood this too, but see, there is a process the fwd on the port 1024/tcp.:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1024-fwd.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16780i1EA600743F25B4D9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1024-fwd.png" alt="1024-fwd.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;So-so..10 rules that have port 1024, total 265 rules in the firewall. But in tcpdump or fw monitor I see very little traffic on port 1024/tcp passing.&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 18:39:40 GMT</pubDate>
    <dc:creator>guiausechi</dc:creator>
    <dc:date>2022-05-31T18:39:40Z</dc:date>
    <item>
      <title>Question about consumption process fwd and port 1024/tcp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-consumption-process-fwd-and-port-1024-tcp/m-p/149858#M24070</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;I would like to ask you about a question. We recently deployed a cluster environment&lt;BR /&gt;on a client. And I have seen a throughput that is quite considerable, but I have followed&lt;BR /&gt;seen a high consumption of port 1024/tcp and the FWD process. Maybe that's because&lt;BR /&gt;80% of the traffic is going through Medium Path(CPASXL)?&lt;/P&gt;&lt;P&gt;Version.: R80.40 - Take 158&lt;BR /&gt;Memory.: 24 GB&lt;BR /&gt;6 vCPU (4 fw / 2 snd)&lt;BR /&gt;HyperThreading.: yes&lt;/P&gt;&lt;P&gt;Something I've been thinking is wrong, practically every second has been running a trace in the fwd process and saved in /var/log/messages.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 17:54:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-consumption-process-fwd-and-port-1024-tcp/m-p/149858#M24070</guid>
      <dc:creator>guiausechi</dc:creator>
      <dc:date>2022-05-31T17:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Question about consumption process fwd and port 1024/tcp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-consumption-process-fwd-and-port-1024-tcp/m-p/149859#M24071</link>
      <description>&lt;P&gt;Interesting...lots of things can use tcp port 1024, fwd is on port 257 though. Do you have port 1024 configured specifically in lots of policy rules?&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 18:02:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-consumption-process-fwd-and-port-1024-tcp/m-p/149859#M24071</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-05-31T18:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Question about consumption process fwd and port 1024/tcp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-consumption-process-fwd-and-port-1024-tcp/m-p/149863#M24072</link>
      <description>&lt;P&gt;Hello the_rock,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I understood this too, but see, there is a process the fwd on the port 1024/tcp.:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1024-fwd.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16780i1EA600743F25B4D9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1024-fwd.png" alt="1024-fwd.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;So-so..10 rules that have port 1024, total 265 rules in the firewall. But in tcpdump or fw monitor I see very little traffic on port 1024/tcp passing.&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 18:39:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-consumption-process-fwd-and-port-1024-tcp/m-p/149863#M24072</guid>
      <dc:creator>guiausechi</dc:creator>
      <dc:date>2022-05-31T18:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Question about consumption process fwd and port 1024/tcp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-consumption-process-fwd-and-port-1024-tcp/m-p/150465#M24424</link>
      <description>&lt;P&gt;read&amp;nbsp;&lt;SPAN&gt;sk116876 for the true meaning of TCP 1024 in cpview&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-SPOILER&gt;(spoiler: it means any high port and not specifically TCP 1024)&lt;/LI-SPOILER&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 06:01:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Question-about-consumption-process-fwd-and-port-1024-tcp/m-p/150465#M24424</guid>
      <dc:creator>JanVC</dc:creator>
      <dc:date>2022-06-09T06:01:28Z</dc:date>
    </item>
  </channel>
</rss>

