<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PSL inline vs pipeline? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127749#M24844</link>
    <description>&lt;P&gt;Great explanation, glad to see I was pretty close in my earlier post.&amp;nbsp; Thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 23 Aug 2021 23:41:23 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2021-08-23T23:41:23Z</dc:date>
    <item>
      <title>PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127255#M24834</link>
      <description>&lt;P&gt;Where can I find a R81.10 documentation on what exactly is the difference between PSL inline and PSL pipeline?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PSL_inline_pipeline.JPG" style="width: 354px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13374iE8E0A37EFAC432F2/image-size/large?v=v2&amp;amp;px=999" role="button" title="PSL_inline_pipeline.JPG" alt="PSL_inline_pipeline.JPG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 16:27:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127255#M24834</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-08-17T16:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127283#M24835</link>
      <description>&lt;P&gt;I don't believe these are documented anywhere, but I think the inline path is only used if a Falcon accelerator card is present; that traffic was handled "inline" by the Falcon card between NIC ports.&lt;/P&gt;
&lt;P&gt;The pipeline paths are Check Point's answer to the elephant flow issue of saturating a single core, and is the new feature I was alluding to at the end of my CPX speech on elephant flows.&amp;nbsp; The pipeline paths first appeared in a Jumbo HFA of R80.40 but were not enabled by default.&amp;nbsp; The pipeline paths are enabled by default in R81.10 (not sure about R81) and allow the processing of a single connection's packets to be spread across a limited number of worker cores (3 I think).&amp;nbsp; Not sure if this is only invoked when a worker hits 100% kind of like Priority Queues.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 22:04:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127283#M24835</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-08-17T22:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127362#M24836</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;I had already written an article on Falcon Cards "&lt;A href="https://community.checkpoint.com/docs/DOC-3190-r80x-security-gateway-architecture-acceleration-card-offloading" target="_blank" rel="noopener"&gt;R8x - Security Gateway Architecture (Acceleration Card Offloading)&lt;/A&gt;".&lt;/P&gt;
&lt;P&gt;Then the PSL inline path must be the "Inline path"&lt;STRONG&gt;???&lt;/STRONG&gt;&lt;BR /&gt;Then the PSL pipeline must be the "Buffer path" or "Host path" &lt;BR /&gt;or "the pipeline paths are Check Point's answer to the elephant flow issue" that you describe&lt;STRONG&gt;???&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;I don't really understand it.&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Can someone from Check Point R&amp;amp;D please answer this. &lt;BR /&gt;So that we get a 100% correct statement.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;--------------------------------------------------------------------------------------------------------&lt;BR /&gt;&lt;BR /&gt;Here are the paths to the Falcon Cards:&lt;BR /&gt;&lt;BR /&gt;R80.20+ acceleration cards provide three new acceleration flows:&lt;/P&gt;
&lt;UL&gt;
&lt;LI style="text-indent: -18.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Host path&lt;/LI&gt;
&lt;LI style="text-indent: -18.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Buffer path&lt;/LI&gt;
&lt;LI style="text-indent: -18.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inline path&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Inline path&lt;/EM&gt;&lt;/STRONG&gt; - For HTTP response body (until 1&lt;SUP&gt;st&lt;/SUP&gt; tier match) and TLS bulk encryption/ decryption.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="S_Inline_PSL.JPG" style="width: 777px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13382i2AA126B05EA3D6A5/image-size/large?v=v2&amp;amp;px=999" role="button" title="S_Inline_PSL.JPG" alt="S_Inline_PSL.JPG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;Buffer path&lt;/EM&gt;&lt;/STRONG&gt; - For HTTP requests, HTTP response headers and TLS handshakes.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="S_Host_PSL.JPG" style="width: 768px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13383i96AA8D37F5B20A0C/image-size/large?v=v2&amp;amp;px=999" role="button" title="S_Host_PSL.JPG" alt="S_Host_PSL.JPG" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;Host Path&lt;/EM&gt;&lt;/STRONG&gt; - For non acceleration connections (eg. local connections) and connections on non acceleration card interface.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="S_Host1_PSL.JPG" style="width: 756px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13384i82711D43696A09AE/image-size/large?v=v2&amp;amp;px=999" role="button" title="S_Host1_PSL.JPG" alt="S_Host1_PSL.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 20:35:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127362#M24836</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-08-18T20:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127363#M24837</link>
      <description>&lt;P&gt;Yeah we need a clarification from R&amp;amp;D on this one.&amp;nbsp; In the meantime I forgot to add that the inline paths seem to be part of the MUX feature described in this thread:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/What-does-mux-enabled-kernel-parameter-do-exactly/td-p/112203" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/What-does-mux-enabled-kernel-parameter-do-exactly/td-p/112203&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 20:37:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127363#M24837</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-08-18T20:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127381#M24838</link>
      <description>&lt;P&gt;Information from R&amp;amp;D would be very helpful here.&lt;BR /&gt;No one understands the paths any more!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Aug 2021 06:11:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127381#M24838</guid>
      <dc:creator>udo_kimmich</dc:creator>
      <dc:date>2021-08-19T06:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127468#M24839</link>
      <description>&lt;P&gt;Any news from Check Point to this topic?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 06:19:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127468#M24839</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2021-08-20T06:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127601#M24840</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/32330"&gt;@idants&lt;/a&gt;&amp;nbsp;Do you happen to know what these are?&lt;/P&gt;</description>
      <pubDate>Sat, 21 Aug 2021 06:56:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127601#M24840</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-21T06:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127609#M24841</link>
      <description>&lt;P&gt;I moved to a new position since then.&lt;/P&gt;
&lt;P&gt;Please take it with Chen Muchtar.&lt;/P&gt;</description>
      <pubDate>Sat, 21 Aug 2021 13:27:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127609#M24841</guid>
      <dc:creator>idants</dc:creator>
      <dc:date>2021-08-21T13:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127615#M24842</link>
      <description>&lt;P&gt;Sorry about that.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8659"&gt;@Chen_Muchtar&lt;/a&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Sat, 21 Aug 2021 16:29:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127615#M24842</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-21T16:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127723#M24843</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The statistics you&lt;SPAN&gt;’re&lt;/SPAN&gt; referring to counts the number of packets passing through the different available packet flows in a Check Point GW&lt;/LI&gt;
&lt;LI&gt;SK153832 currently lists the following paths: Firewall path / Slow path (F2F), Medium path (PXL) and Accelerated path&lt;/LI&gt;
&lt;LI&gt;On top of that, we have &lt;STRONG&gt;&lt;SPAN&gt;P&lt;/SPAN&gt;ipeline processing path&lt;/STRONG&gt; – a connection which is handled by more than one CPU (unlike in other paths in which a connection is handled by a dedicated CPU)&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Would be updated in &lt;/SPAN&gt;SK153832&lt;SPAN&gt; by EOW&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Preparations for th&lt;SPAN&gt;is infra &lt;/SPAN&gt;were first &lt;SPAN&gt;introduced&lt;/SPAN&gt; &lt;SPAN&gt;over&lt;/SPAN&gt; R80.40&lt;/LI&gt;
&lt;LI&gt;The project is targeted for R81.20 (would be also ported to several JHFs), its main goal is to allow better utilization of the systems resources to tackle elephant flows scenarios in NGTP &lt;SPAN&gt;env. &lt;/SPAN&gt;at first stage&lt;SPAN&gt; (content would be expanding over future releases) &lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Project is due to start EA phase soon (+ dedicated RnD support), feel free to refer me offline per relevant customers/ EA candidates &lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Addressing additional Qs which were raised over this thread&lt;/SPAN&gt;:&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;“PSL pipeline” refers to packets passing through Pipeline processing path (mentioned above) and handled by PSL&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Until the project release, it will always show as 0&lt;/LI&gt;
&lt;/UL&gt;
&lt;LI&gt;“PSL inline” refers to the legacy Falcon Cards&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;This flow is deprecated and the statistics will be removed in R81.20 and JHFs&lt;/LI&gt;
&lt;LI&gt;This stat will always show as 0 as well&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;All, you're always welcome to approach me on any related matter @ &lt;A href="mailto:Chenmu@checkpoint.com" target="_blank"&gt;Chenmu@checkpoint.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 18:29:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127723#M24843</guid>
      <dc:creator>Chen_Muchtar</dc:creator>
      <dc:date>2021-08-23T18:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127749#M24844</link>
      <description>&lt;P&gt;Great explanation, glad to see I was pretty close in my earlier post.&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 23:41:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127749#M24844</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-08-23T23:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127782#M24845</link>
      <description>&lt;P&gt;I guess we need a TechTalk about it,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8659"&gt;@Chen_Muchtar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 06:22:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/127782#M24845</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-08-24T06:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/151526#M24846</link>
      <description>&lt;P&gt;Did a TechTalk on this happen?&lt;/P&gt;&lt;P&gt;Seems like a good time to do one now, with R81.20 release coming&amp;nbsp; &amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 22:00:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/151526#M24846</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2022-06-22T22:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: PSL inline vs pipeline?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/151549#M24847</link>
      <description>&lt;P&gt;No, we are still trying to convince Chen &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 08:05:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PSL-inline-vs-pipeline/m-p/151549#M24847</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-06-23T08:05:00Z</dc:date>
    </item>
  </channel>
</rss>

