<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: performance optimization via &amp;quot;SecureXL Fast Accelerator&amp;quot; in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/143974#M25121</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just one query on this. If we put an exception for a particular traffic to bypass all deep inspection blades (&lt;SPAN&gt;AV, AB, IPS, URLF, APPCL,) in TP policy&lt;/SPAN&gt;&amp;nbsp;, would we still need to consider putting that traffic under fast_accel? Or after putting this exception, that traffic should always go accelerated path.&lt;/P&gt;&lt;P&gt;Reason: When doing fwaccel conns, we don't see that exception traffic as PXLSL. However, when we put that in fast_accel table, we see significant improvement of traffic flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Lolith&lt;/P&gt;</description>
    <pubDate>Wed, 16 Mar 2022 19:33:37 GMT</pubDate>
    <dc:creator>lolith</dc:creator>
    <dc:date>2022-03-16T19:33:37Z</dc:date>
    <item>
      <title>performance optimization via "SecureXL Fast Accelerator"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/75073#M25115</link>
      <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;
&lt;P&gt;I want to get safe with my understanding of the&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk156672&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" target="_blank" rel="noopener"&gt;SecureXL Fast Accelerator&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I define a network, host, port or anything possible via the "fw ctl fast_accel" command, these matching packets are going straight the fastest path with no deep inspection ?&lt;/P&gt;
&lt;P&gt;Meaning no AV, no AB, no IPS, no URLF, no APPCL, no service inspection, no TP etc. will be done for these packets regardless if these blades are enabled ?&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 09:36:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/75073#M25115</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-02-13T09:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: performance optimization via "SecureXL Fast Accelerator"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/75080#M25116</link>
      <description>&lt;P&gt;Your understanding is correct. Here is the quote from SK: "&lt;SPAN&gt;&lt;EM&gt;The Fast Acceleration feature lets you define trusted connections to allow bypassing deep packet inspection&lt;/EM&gt;".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If there is part of the traffic which can be trusted by definition, you can then bypass deep inspection&amp;nbsp;for such traffic altogether.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 10:48:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/75080#M25116</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-02-13T10:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: performance optimization via "SecureXL Fast Accelerator"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/75131#M25117</link>
      <description>&lt;P&gt;What Val said.&amp;nbsp; A warning from the third edition of my book about fast_accel:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bang.jpg" style="width: 64px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4430iCCA267DC5D0A4560/image-size/large?v=v2&amp;amp;px=999" role="button" title="bang.jpg" alt="bang.jpg" /&gt;&lt;/span&gt;&lt;EM&gt;While using the fast_accel feature ensures highly efficient handling of the&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;matched traffic in the SXL path, doing so ignores portions of your security policy and&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;can disable almost all firewall inspection of that traffic. As such a variety of bad things&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;can happen inside traffic streams that have been essentially whitelisted by this feature,&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;and a careful risk analysis is necessary before using it. It is NOT RECOMMENDED to&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;use fast_accel if one or both of the systems involved are not trusted and/or under your&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;organization’s direct administrative control.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;As discussed in my CPX 2020 speech &lt;A href="https://community.checkpoint.com/fyrhh23835/attachments/fyrhh23835/member-exclusives/432/3/CPX_Big_Game_Hunting_FINAL2.cleaned.pdf" target="_self"&gt;Big Game Hunting: Elephant Flows&lt;/A&gt;, typically fast_accel is used in the context of elephant flows (heavy connections) to make them go faster and keep from stomping on "mice" connections.&amp;nbsp; Note that there is an alternative solution from R&amp;amp;D that allows the processing/handling of elephant flows to be "spread around" more than one worker core, thus allowing them to go faster without limiting inspection of them with fast_accel.&amp;nbsp; See my preso for more details about this new feature and how to contact R&amp;amp;D to obtain it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 13:20:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/75131#M25117</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-02-13T13:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: performance optimization via "SecureXL Fast Accelerator"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/75150#M25118</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;for your reply.&lt;/P&gt;
&lt;P&gt;I'm aware of the risks. We want to use this for some hosts they did storage and database replications.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 14:01:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/75150#M25118</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-02-13T14:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: performance optimization via "SecureXL Fast Accelerator"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/75159#M25119</link>
      <description>&lt;P&gt;I knew you were aware of the risks, but I feel duty-bound to bring them up whenever fast_accel is mentioned for those who might read this thread later.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 14:38:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/75159#M25119</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-02-13T14:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: performance optimization via "SecureXL Fast Accelerator"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/75160#M25120</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 14:45:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/75160#M25120</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-02-13T14:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: performance optimization via "SecureXL Fast Accelerator"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/143974#M25121</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just one query on this. If we put an exception for a particular traffic to bypass all deep inspection blades (&lt;SPAN&gt;AV, AB, IPS, URLF, APPCL,) in TP policy&lt;/SPAN&gt;&amp;nbsp;, would we still need to consider putting that traffic under fast_accel? Or after putting this exception, that traffic should always go accelerated path.&lt;/P&gt;&lt;P&gt;Reason: When doing fwaccel conns, we don't see that exception traffic as PXLSL. However, when we put that in fast_accel table, we see significant improvement of traffic flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Lolith&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 19:33:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/143974#M25121</guid>
      <dc:creator>lolith</dc:creator>
      <dc:date>2022-03-16T19:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: performance optimization via "SecureXL Fast Accelerator"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/143993#M25122</link>
      <description>&lt;P&gt;It will depend heavily on which blades you have enabled.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;While you can easily exclude all TP enforcement with a "null" TP profile in an explicit TP policy rule, guaranteeing this in an Access Control policy layer with APCL/URLF is much tougher.&amp;nbsp; You cannot define an explicit rule in an APCL/URLF layer that is equivalent to a TP null profile rule.&amp;nbsp; &amp;nbsp;Essentially the traffic must "fall off" the end of the APCL/URLF layer/sub-layer and hit the implicit cleanup rule of Accept to help ensure it will be fully accelerated.&amp;nbsp; fast_accel can make sure that this occurs for traffic that would otherwise go PXL/Medium Path, but always remember that traffic requiring CPAS or F2F handling cannot be forced into the fully-accelerated path with fast_accel.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Mar 2022 23:32:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/143993#M25122</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-03-16T23:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: performance optimization via "SecureXL Fast Accelerator"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/144023#M25123</link>
      <description>&lt;P&gt;We only have IPS blade enabled and that was the whole confusion around this. How come the null profile is not making sure that the traffic is going through fast path. In my experiance the traffic flow improved after we put that explicity under fast_accel table.&lt;/P&gt;&lt;P&gt;Any explanation for this behaviour? Note, we are running R80.40 with latest jumbo take.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Lolith&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 10:02:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/144023#M25123</guid>
      <dc:creator>lolith</dc:creator>
      <dc:date>2022-03-17T10:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: performance optimization via "SecureXL Fast Accelerator"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/144082#M25124</link>
      <description>&lt;P&gt;Probably lots of CIFS/microsoft-ds traffic which will almost always go Medium Path unless forced into full acceleration.&amp;nbsp; See here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/First-impressions-R80-30-on-gateway-one-step-forward-one-or-two/m-p/72593" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/First-impressions-R80-30-on-gateway-one-step-forward-one-or-two/m-p/72593&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 16:10:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/performance-optimization-via-quot-SecureXL-Fast-Accelerator-quot/m-p/144082#M25124</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-03-17T16:10:12Z</dc:date>
    </item>
  </channel>
</rss>

