<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does heavy hit rule position still matter on performance? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142186#M25289</link>
    <description>&lt;P&gt;I need to move some heavy hit rules from top to bottom and wonder if this will affect gateway performance on modern firewalls such Checkpoint. Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 22 Feb 2022 15:36:18 GMT</pubDate>
    <dc:creator>Jin_Zhou</dc:creator>
    <dc:date>2022-02-22T15:36:18Z</dc:date>
    <item>
      <title>Does heavy hit rule position still matter on performance?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142186#M25289</link>
      <description>&lt;P&gt;I need to move some heavy hit rules from top to bottom and wonder if this will affect gateway performance on modern firewalls such Checkpoint. Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 15:36:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142186#M25289</guid>
      <dc:creator>Jin_Zhou</dc:creator>
      <dc:date>2022-02-22T15:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: Does heavy hit rule position still matter on performance?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142187#M25290</link>
      <description>&lt;P&gt;I will let others give their feedback, but personally, I only found that to matter in pre R80 versions.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 15:39:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142187#M25290</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-22T15:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Does heavy hit rule position still matter on performance?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142190#M25291</link>
      <description>&lt;P&gt;Adjusting rule position will not change fw performance anymore - but you are able to identify unmatched rules that can be disabled after some time to lower the number of rules.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 15:43:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142190#M25291</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-02-22T15:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Does heavy hit rule position still matter on performance?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142194#M25292</link>
      <description>&lt;P&gt;In gateway versions R80.10 and later, it won't make a difference.&amp;nbsp; The relevant new feature is Column-based Matching which is enabled by default.&amp;nbsp; Not strictly necessary, but if you can limit as much as possible using "Any" in the Destination column of your rules it will help maximize the gains provided by this feature:&amp;nbsp;&lt;A id="link_11" href="https://community.checkpoint.com/t5/Management/Unified-Policy-Column-based-Rule-Matching/m-p/9888?search-action-id=39799898198&amp;amp;search-result-uid=9888" target="_blank"&gt;Unified Policy&amp;nbsp;Column-based&amp;nbsp;Rule&amp;nbsp;Matching.&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 16:05:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142194#M25292</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-02-22T16:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Does heavy hit rule position still matter on performance?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142197#M25293</link>
      <description>&lt;P&gt;Excellent recommendation!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Feb 2022 16:19:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142197#M25293</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2022-02-22T16:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: Does heavy hit rule position still matter on performance?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142271#M25294</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;with all due respect, I would rather say, it won't make &lt;U&gt;&lt;EM&gt;much&lt;/EM&gt;&lt;/U&gt; of a difference.&lt;/P&gt;
&lt;P&gt;Moving a heavily used rule down in the policy will actually require more CPU cycles to match. It is just with R8x family, it requires &lt;EM&gt;&lt;U&gt;much less&lt;/U&gt;&lt;/EM&gt; efforts than with R7x. There still be minor performance drag, depending on how big is the policy.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Saying it will not matter at all is not 100% correct &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 08:27:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142271#M25294</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-02-23T08:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Does heavy hit rule position still matter on performance?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142302#M25295</link>
      <description>&lt;P&gt;In my experience moving rules around even in very large policies does not make a measurable difference in CPU use in R80.10+.&amp;nbsp; But I would agree the difference is not zero, and in the real world probably not worth the administrator's time to analyze and move rules around for this form of optimization.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 13:23:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142302#M25295</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-02-23T13:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: Does heavy hit rule position still matter on performance?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142303#M25296</link>
      <description>&lt;P&gt;I agree with both of you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;. In my experience as well, difference is so minor, that it might not be worth spending too much time on it...&lt;/P&gt;</description>
      <pubDate>Wed, 23 Feb 2022 13:30:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142303#M25296</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-23T13:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Does heavy hit rule position still matter on performance?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142356#M25297</link>
      <description>&lt;P&gt;&lt;SPAN&gt;sk32578 talks to some version specific edge cases (mostly historic) as the others have alluded to but generally speaking you should be fine.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 01:09:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Does-heavy-hit-rule-position-still-matter-on-performance/m-p/142356#M25297</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-02-24T01:09:23Z</dc:date>
    </item>
  </channel>
</rss>

