<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Lightspeed Under the Hood TechTalk: Video, Slides, and Q&amp;amp;A in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/169265#M30641</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;could you please confirm this from admin guide:&amp;nbsp;&lt;/P&gt;&lt;P&gt;The NVIDIA ConnectX 100G QSFP28 Ports accelerate the connections in &lt;STRONG&gt;hardware when packets are received on one NVIDIA ConnectX 100G QSFP28 Port and destined to go out another&lt;/STRONG&gt; NVIDIA ConnectX 100G QSFP28 Port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so traffic is accelerated only between two ports of NVIDIA card? Bond of those ports is supported?&lt;/P&gt;&lt;P&gt;And is supported to use QSFP+ 40Gb/s in NVIDIA card? The customer requires 40Gb not 100Gb.&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jan 2023 11:24:34 GMT</pubDate>
    <dc:creator>Martin_Raska</dc:creator>
    <dc:date>2023-01-26T11:24:34Z</dc:date>
    <item>
      <title>Lightspeed Under the Hood TechTalk: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146616#M23294</link>
      <description>&lt;P&gt;Here is the video recording:&lt;/P&gt;
&lt;P&gt;&lt;div class="lia-vid-container video-embed-center"&gt;&lt;div id="lia-vid-6304648819001w960h540r858" class="lia-video-brightcove-player-container"&gt;&lt;video-js data-video-id="6304648819001" data-account="6058022097001" data-player="default" data-embed="default" class="vjs-fluid" controls="" data-application-id="" style="width: 100%; height: 100%;"&gt;&lt;/video-js&gt;&lt;/div&gt;&lt;script src="https://players.brightcove.net/6058022097001/default_default/index.min.js"&gt;&lt;/script&gt;&lt;script&gt;(function() {  var wrapper = document.getElementById('lia-vid-6304648819001w960h540r858');  var videoEl = wrapper ? wrapper.querySelector('video-js') : null;  if (videoEl) {     if (window.videojs) {       window.videojs(videoEl).ready(function() {         this.on('loadedmetadata', function() {           this.el().querySelectorAll('.vjs-load-progress div[data-start]').forEach(function(bar) {             bar.setAttribute('role', 'presentation');             bar.setAttribute('aria-hidden', 'true');           });         });       });     }  }})();&lt;/script&gt;&lt;a class="video-embed-link" href="https://community.checkpoint.com/t5/video/gallerypage/video-id/6304648819001"&gt;(view in My Videos)&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Selected Q&amp;amp;A below.&lt;BR /&gt;Slides are attached.&lt;/P&gt;
&lt;H3&gt;What features does Lightspeed support on QLS/MLS appliances?&lt;/H3&gt;
&lt;P&gt;Currently, firewall only without VPN will be accelerated on the SmartNIC. Traffic that utilizes other blades will work the same as it does on other Quantum appliances without SmartNIC acceleration. We will share a list of working features in the initial phase with limitations. In later phases, we will support VPN acceleration and TLS encryption/decryption for SSL Inspection. We plan to support all features in Lightspeed.&lt;/P&gt;
&lt;H3&gt;Are the MLS appliances specific to Maestro?&lt;/H3&gt;
&lt;P&gt;QLS appliances can also be used with Maestro as well.&lt;/P&gt;
&lt;H3&gt;What code release do the QLS/MLS appliances run?&lt;/H3&gt;
&lt;P&gt;It will be the standard R81.10 release with a standard JHF in the first release, followed by R81.20.&lt;/P&gt;
&lt;H3&gt;Which QLS can be recommended as a replacement for a 5600?&lt;/H3&gt;
&lt;P&gt;QLS250 is the smallest appliance offered with the Lightspeed capability.&lt;/P&gt;
&lt;H3&gt;Are elephant flows an issue?&lt;/H3&gt;
&lt;P&gt;Firewall only elephant flows will not be an issue as it is accelerated in the SmartNIC.&lt;/P&gt;
&lt;H3&gt;When is VSX planned to be supported?&lt;/H3&gt;
&lt;P&gt;Target is Q3 2022.&lt;/P&gt;
&lt;H3&gt;How does acceleration on the NIC affect troubleshooting tools like tcpdump and fw monitor?&lt;/H3&gt;
&lt;P&gt;Currently, only tcpdump is supported for capturing packets. All other standard SecureXL troubleshooting should still apply.&lt;/P&gt;
&lt;H3&gt;Are the SmartNICs available for regular Quantum Security Gateways?&lt;/H3&gt;
&lt;P&gt;No, only on the QLS and MLS appliances.&lt;/P&gt;
&lt;H3&gt;Are all Inspection Settings supported in Lightspeed?&lt;/H3&gt;
&lt;P&gt;Only traffic that is fully accelerated by SecureXL, which would exclude many of the Inspection Settings.&lt;/P&gt;
&lt;H3&gt;Is there a roadmap to utilize VMware host connectX NICs to be mapped into the Checkpoint VM, so that the CloudGuard gateway could leverage VM Hosts ASICs?&lt;/H3&gt;
&lt;P&gt;This is under discussion, but no plans just yet.&lt;/P&gt;
&lt;H3&gt;What is the performance between different Lightspeed SmartNIC cards on the same appliance?&lt;/H3&gt;
&lt;P&gt;We can only accelerate traffic between ports on the same SmartNIC.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Is there a specification about Firewall Only Flows? For example, CIFS?&lt;/H3&gt;
&lt;P&gt;Firewall only means all connections that don't require deep packet inspection or additional parson. For example, if DCERPC is defined in the rulebase, we need to run additional protocol parsers and that traffic will not be accelerated. If it is an access rule for TCP port 445, that will will accelerated&lt;/P&gt;
&lt;H3&gt;If I understand right, the bond interfaces with ports on different cards don't work with full acceleration?&lt;/H3&gt;
&lt;P&gt;It will eventually be supported with SW hairpining.&lt;/P&gt;
&lt;H3&gt;How is NAT performed?&lt;/H3&gt;
&lt;P&gt;It works the same as it does with the regular SecureXL NAT acceleration, based on relevant rules and tables.&lt;/P&gt;
&lt;H3&gt;How do we view the Lightspeed accelerated flows?&lt;/H3&gt;
&lt;P&gt;It's the same as it is for regular SecureXL flows.&lt;/P&gt;
&lt;H3&gt;What is the target release for the SSL acceleration on QLS/MLS?&lt;/H3&gt;
&lt;P&gt;We are working on the integration with Nvidia and do not have a final date yet.&lt;/P&gt;
&lt;H3&gt;Are hit counters still available for security policy &amp;amp; nat policy for accelerated traffic?&lt;/H3&gt;
&lt;P&gt;Yes, as this information comes from SecureXL.&lt;/P&gt;
&lt;H3&gt;Is there any plan to integrate rulebase offloading or high-session rate protection into the SmartNIC cards?&lt;/H3&gt;
&lt;P&gt;Yes.&lt;/P&gt;
&lt;H3&gt;First packet will always go F2F for rulebase lookup, so no accept templating at Lightspeed level?&lt;/H3&gt;
&lt;P&gt;Correct, it should happen at the SIM driver (SecureXL) level.&lt;/P&gt;
&lt;H3&gt;Are there plans for Identity Awareness LDAP based rules to be supported by this?&lt;/H3&gt;
&lt;P&gt;This is already supported.&lt;/P&gt;
&lt;H3&gt;Are 1GB ports supported?&lt;/H3&gt;
&lt;P&gt;10GB ports support 1GB speeds, however this is not supported in the initial release.&lt;/P&gt;
&lt;H3&gt;Is it possible to manually drop an accelerated connection? (similar to: fw tab -t connections -x &amp;lt;VALUES&amp;gt;)&lt;/H3&gt;
&lt;P&gt;Yes.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 18:21:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146616#M23294</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-21T18:21:49Z</dc:date>
    </item>
    <item>
      <title>Re: Lightspeed Under the Hood TechTalk: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146665#M23311</link>
      <description>&lt;P&gt;Unfortunately I couldn't make the session yesterday, so I will post my question here:-)&lt;/P&gt;
&lt;P&gt;Is the DLP blade supported?&amp;nbsp; On the product catalogue I cannot add the blade and I see it's also not listed on the datasheet.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 06:35:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146665#M23311</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-04-21T06:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Lightspeed Under the Hood TechTalk: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146703#M23337</link>
      <description>&lt;P&gt;Is the video working for anyone? For me it just shows 'This video is currently being processed. Please try again in a few minutes.', but it's been like that for the last 6 hours.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 12:12:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146703#M23337</guid>
      <dc:creator>Nik_Bloemers</dc:creator>
      <dc:date>2022-04-21T12:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: Lightspeed Under the Hood TechTalk: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146705#M23338</link>
      <description>&lt;P&gt;Not currently, least not in an accelerated manner.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 12:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146705#M23338</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-04-21T12:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Lightspeed Under the Hood TechTalk: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146709#M23339</link>
      <description>&lt;P&gt;Thanks Chris, I understand that it would not be accelerated, but is it supported at all?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 12:36:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146709#M23339</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-04-21T12:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Lightspeed Under the Hood TechTalk: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146715#M23341</link>
      <description>&lt;P&gt;Traffic the SmartNIC cannot accelerate will be handled the same as it is on a regular Quantum appliance.&lt;BR /&gt;It will work but won’t be accelerated by the SmartNIC.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 13:20:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146715#M23341</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-21T13:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: Lightspeed Under the Hood TechTalk: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146720#M23343</link>
      <description>&lt;P&gt;Appreciate the feedback!&amp;nbsp; My questioned stemmed from the fact that I could not add the DLP blade as an option when building out a quote using the product catalog - looks like that is a glitch in there as opposed to a technical limitation, will reach out to the sales team.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 13:43:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146720#M23343</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-04-21T13:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Lightspeed Under the Hood TechTalk: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146722#M23344</link>
      <description>&lt;H3 id="toc-hId--1004722751"&gt;&lt;EM&gt;How does acceleration on the NIC affect troubleshooting tools like tcpdump and fw monitor?&lt;/EM&gt;&lt;/H3&gt;
&lt;P&gt;&lt;EM&gt;Currently, only fw monitor is supported for capturing packets. All other standard SecureXL troubleshooting should still apply.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Isn't the correct answer to this question tcpdump and not fw monitor (either -e or -F) and not cppcap?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 13:52:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146722#M23344</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-04-21T13:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Lightspeed Under the Hood TechTalk: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146734#M23348</link>
      <description>&lt;P&gt;You're correct, I'll fix.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 14:39:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/146734#M23348</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-21T14:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Lightspeed Under the Hood TechTalk: Video, Slides, and Q&amp;A</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/169265#M30641</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;could you please confirm this from admin guide:&amp;nbsp;&lt;/P&gt;&lt;P&gt;The NVIDIA ConnectX 100G QSFP28 Ports accelerate the connections in &lt;STRONG&gt;hardware when packets are received on one NVIDIA ConnectX 100G QSFP28 Port and destined to go out another&lt;/STRONG&gt; NVIDIA ConnectX 100G QSFP28 Port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so traffic is accelerated only between two ports of NVIDIA card? Bond of those ports is supported?&lt;/P&gt;&lt;P&gt;And is supported to use QSFP+ 40Gb/s in NVIDIA card? The customer requires 40Gb not 100Gb.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2023 11:24:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Lightspeed-Under-the-Hood-TechTalk-Video-Slides-and-Q-amp-A/m-p/169265#M30641</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2023-01-26T11:24:34Z</dc:date>
    </item>
  </channel>
</rss>

