<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.x Performance Tuning and Debug Tips – fw monitor in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41571#M3448</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check Point&amp;nbsp;should include this in the SK.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Nov 2018 15:03:42 GMT</pubDate>
    <dc:creator>Tim_Maurer</dc:creator>
    <dc:date>2018-11-22T15:03:42Z</dc:date>
    <item>
      <title>R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41563#M3440</link>
      <description>&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;R80.20 - fw monitor&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/74619_pastedImage_1.png" border="0" width="329" height="190" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc; font-size: 22px;"&gt;&lt;STRONG&gt;Tip 1&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;SecureXL has been significantly revised in R80.20. It now works in user space.&amp;nbsp;This has also led to some changes in "fw monitor".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Since R80.20&amp;nbsp; "fw monitor" is able to show the traffic accelerated with SecureXL. Thus it is possible to see SecureXL (provide more performance&lt;STRONG&gt;)&lt;/STRONG&gt;&amp;nbsp;modules in fw monitor chain. For more informations revert to "SecureXL offloading chain modules" in this article. Now you can see that SecureXL is used, which increases the performance of the firewall.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 15px;"&gt;SecureXL "&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;fwaccel off&lt;/STRONG&gt;&lt;/SPAN&gt;" does &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;not&lt;/STRONG&gt;&lt;/SPAN&gt; have to be &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;disabled on R80.20&lt;/STRONG&gt;&lt;/SPAN&gt; to run "fw monitor". This is good for performance, so "fw monitor" does not affect performance any more.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;# &lt;SPAN style="text-decoration: line-through; color: #ff0000;"&gt;&lt;STRONG&gt;fwaccel off&lt;/STRONG&gt;&lt;/SPAN&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;gt;&amp;nbsp;no longer necessary in R80.20 and above&lt;/P&gt;
&lt;P&gt;# &lt;STRONG&gt;fw monitor -e "accept(...);"&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;R77.30 and R80.10 - fw monitor&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;On R77.30 and R80.10 only disabling SecureXL allows to see the complete connection in fw monitor, which may be required for troubleshooting purposes or revert to "&lt;A class="link-titled" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL%22" target="_blank" rel="noopener"&gt;How to disable SecureXL for specific IP addresses"&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;# &lt;STRONG&gt;fwaccel off&lt;/STRONG&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;# &lt;STRONG&gt;fw monitor -e "accept(...);"&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;Chapter&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;STRONG&gt;More interesting articles:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Architecture-and-Performance-Tuning-Link-Collection/m-p/47883#M9336" target="_blank" rel="noopener" data-objecttype="102"&gt;- R80.x Architecture and Performance Tuning - Link Collection&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://cp.ankenbrand24.de" target="_blank" rel="noopener nofollow noopener noreferrer noopener noreferrer noopener noreferrer"&gt;- Article list (Heiko Ankenbrand)&lt;/A&gt;&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;New fw monitor inspection points in R80.20&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc; font-size: 15px;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 22px;"&gt;Tip 2&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;Furthermore there are new fw monitor inspection points available:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE class="j-table jiveBorder" style="border: 1px solid #c6c6c6;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #efefef; height: 25px;"&gt;
&lt;TH style="width: 10%; height: 25px;"&gt;Inspection point&lt;/TH&gt;
&lt;TH style="width: 22%; height: 25px;"&gt;Name of fw monitor inspection point&lt;/TH&gt;
&lt;TH style="width: 53.6022%; height: 25px;"&gt;Relation to firewall VM&lt;/TH&gt;
&lt;TH style="width: 59.3978%; height: 25px;"&gt;Available since version&lt;/TH&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;i&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Pre-Inbound&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Before the inbound FireWall VM &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:i&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;always&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;I&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Post-Inbound&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;After the inbound FireWall VM&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:I&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;always&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;id&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Pre-Inbound VPN&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Inbound before decrypt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:id&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;iD&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Post-Inbound VPN&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Inbound after decrypt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:ID&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;iq&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Pre-Inbound QoS&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Inbound before QoS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:iq&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;iQ&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Post-Inbound QoS&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Inbound after QoS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:IQ&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;o&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Pre-Outbound&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Before the outbound FireWall VM&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:o&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;always&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;O&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Post-Outbound&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;After the outbound FireWall VM&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:O&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;always&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc;"&gt;&lt;STRONG&gt;e&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;oe&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Pre-Outbound VPN*&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;
&lt;P&gt;Outbound before encrypt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:e&lt;/CODE&gt;)&amp;nbsp;&amp;nbsp;&amp;nbsp; in R80.10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:oe&lt;/CODE&gt;)&amp;nbsp; in R80.20&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;
&lt;P&gt;&lt;SPAN style="color: #00ccff;"&gt;&lt;STRONG&gt;R80.10&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc;"&gt;&lt;STRONG&gt;E&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;OE&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Post-Outbound VPN*&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;
&lt;P&gt;Outbound after encrypt &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:E&lt;/CODE&gt;)&amp;nbsp;&amp;nbsp;&amp;nbsp; in R80.10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:OE&lt;/CODE&gt;)&amp;nbsp; in R80.20&lt;/P&gt;
&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc;"&gt;&lt;STRONG&gt;R80.10&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;oq&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Pre-Outbound QoS&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Outbound before QoS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:oq&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR style="height: 27px;"&gt;
&lt;TD style="width: 10%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;oQ&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 22%; height: 27px;"&gt;Post-Outbound QoS&lt;/TD&gt;
&lt;TD style="width: 53.6022%; height: 27px;"&gt;Outbound after QoS &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; (for example, &lt;CODE class=""&gt;eth1:OQ&lt;/CODE&gt;)&lt;/TD&gt;
&lt;TD style="width: 59.3978%; height: 27px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;R80.20&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;* The fw monitor inspection point is different in R80.10 ("e" or "E") and R80.20 ("oe" and "OE")&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;For more information, see &lt;A title="" href="http://supportcontent.checkpoint.com/solutions?id=sk30583" target="_blank" rel="noopener"&gt;sk30583&lt;/A&gt;, &lt;A href="https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_CLI_ReferenceGuide/208177.htm" target="_blank" rel="noopener"&gt;fw monitor&lt;/A&gt; or &lt;A title="" href="http://downloads.checkpoint.com/dc/download.htm?ID=9068" target="_blank" rel="noopener"&gt;How to use FW Monitor&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;SecureXL offloading chain modules&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 22px;"&gt;Tip 3&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Like I said SecureXL has been significantly revised in R80.20. It now works in user space.&amp;nbsp;This has also led to some changes in "fw monitor"&lt;/P&gt;
&lt;P&gt;There are new fw monitor chain (SecureXL) objects that do not run in the virtual machine.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt;"&gt;# &lt;STRONG&gt;fw ctl chain&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;IMG class="image-5 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/74620_pastedImage_1.png" border="0" /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt;"&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt;"&gt;The new fw monitor chain modules&amp;nbsp;(SecureXL) do not run in the virtual machine (vm).&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: red; font-size: 12.0pt;"&gt;&lt;STRONG&gt;SecureXL inbound (sxl_in)&lt;/STRONG&gt;&lt;/SPAN&gt; &lt;SPAN style="font-size: 12.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; Packet received in SecureXL from network&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: red; font-size: 12.0pt;"&gt;&lt;STRONG&gt;SecureXL inbound CT (sxl_ct)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt; color: red;"&gt;&amp;nbsp;&lt;/SPAN&gt; &lt;SPAN style="font-size: 12.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt; Accelerated packets moved from inbound to outbound processing (post routing)&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: red; font-size: 12.0pt;"&gt;&lt;STRONG&gt;SecureXL outbound (sxl_out)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt; Accelerated packet starts outbound processing&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: red; font-size: 12.0pt;"&gt;&lt;STRONG&gt;SecureXL deliver (sxl_deliver)&lt;/STRONG&gt;&lt;/SPAN&gt; &lt;SPAN style="font-size: 12.0pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; SecureXL transmits accelerated packet&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;New VM chain modules in R80.20&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 22px;"&gt;Tip 4&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;There are more new chain modules in R80.20&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: red;"&gt;&lt;STRONG&gt;vpn before offload (vpn_in)&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;gt; FW inbound preparing the tunnel for offloading the packet (along with the connection)&lt;BR /&gt;&lt;SPAN style="color: red;"&gt;&lt;STRONG&gt;fw offload inbound (offload_in)&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; FW inbound that perform the offload&lt;BR /&gt;&lt;SPAN style="color: red;"&gt;&lt;STRONG&gt;fw post VM inbound&amp;nbsp; (post_vm)&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; Packet was not offloaded (slow path) - continue processing in FW inbound&lt;/P&gt;
&lt;P&gt;# &lt;STRONG&gt;fw ctl chain&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;IMG class="image-6 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/74621_pastedImage_2.png" border="0" /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;New fw monitor chain key (00000000)&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;SPAN style="color: #33cccc;"&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 22px;"&gt;Tip 5&lt;/SPAN&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt;"&gt;In Firewall kernel (now also SecureXL), each kernel is associated with a key (&lt;SPAN style="color: #ff0000;"&gt;red&lt;/SPAN&gt;) witch specifies the type of traffic applicable to the chain modul.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 12.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt;"&gt;# &lt;STRONG&gt;fw ctl chain&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 12.0pt;"&gt;&amp;nbsp;&lt;IMG class="image-7 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/74622_pastedImage_3.png" border="0" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE class="j-table jiveBorder" style="border: 1px solid #c6c6c6; width: 45.8412%;"&gt;
&lt;THEAD&gt;
&lt;TR style="background-color: #efefef;"&gt;
&lt;TH style="width: 12%;"&gt;Key&lt;/TH&gt;
&lt;TH style="width: 30.8412%;"&gt;Function&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style="width: 12%;"&gt;&lt;SPAN style="font-family: terminal, monaco, monospace;"&gt;&lt;STRONG&gt;ffffffff&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 30.8412%;"&gt;IP Option Stip/Restore&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 12%;"&gt;&lt;SPAN style="font-family: terminal, monaco, monospace;"&gt;&lt;STRONG&gt;00000001&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 30.8412%;"&gt;new processed flows&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 12%;"&gt;&lt;SPAN style="font-family: terminal, monaco, monospace;"&gt;&lt;STRONG&gt;00000002&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 30.8412%;"&gt;wire mode&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 12%;"&gt;&lt;SPAN style="font-family: terminal, monaco, monospace;"&gt;&lt;STRONG&gt;00000003&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 30.8412%;"&gt;will applied to all ciphered traffic (VPN)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD style="width: 12%;"&gt;&lt;SPAN style="color: #ff0000; font-family: terminal, monaco, monospace;"&gt;&lt;STRONG&gt;00000000&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TD&gt;
&lt;TD style="width: 30.8412%;"&gt;SecureXL offloading (&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;new in R80.20+&lt;/STRONG&gt;&lt;/SPAN&gt;)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE style="border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;" width="100%"&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TH align="left"&gt;&lt;FONT size="4" color="#ffffff"&gt;References&lt;/FONT&gt;&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;/TABLE&gt;
&lt;P&gt;R&amp;amp;D meeting Israel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 17:15:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41563#M3440</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-05-22T17:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41564#M3441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can see in the lab that many SecureXL connections are visible in fw monitor without disabling SecureXL. Does this mean that under R80.20 we don't have to deactivate&amp;nbsp;SexureXL with "fwaccel off" to run "fw monitor"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you confirm that from Check Point?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Heiko&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Nov 2018 20:05:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41564#M3441</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-11-17T20:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41565#M3442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Reinhard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Nov 2018 20:54:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41565#M3442</guid>
      <dc:creator>Reihard_Westle</dc:creator>
      <dc:date>2018-11-17T20:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41566#M3443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That’s correct and one of the benefits of moving most of SecureXL into user space.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Nov 2018 17:44:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41566#M3443</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-18T17:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41567#M3444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon,&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for this information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Heiko&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Nov 2018 19:03:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41567#M3444</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-11-18T19:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41568#M3445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" height="47" src="https://community.checkpoint.com/legacyfs/online/checkpoint/74677_pastedImage_1.png" width="42" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Nov 2018 09:13:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41568#M3445</guid>
      <dc:creator>Roger_Bachstein</dc:creator>
      <dc:date>2018-11-19T09:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41569#M3446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can someone explain&amp;nbsp;performance benefit of moving SecureXL into user space? My understanding was everything in user space can create a bottleneck&amp;nbsp;and old implementation of SecureXL layer under kernel at low level should be faster.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Nov 2018 10:04:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41569#M3446</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2018-11-19T10:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41570#M3447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The SecureXL driver takes a certain amount of kernel memory&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;per core&lt;/EM&gt;&lt;/STRONG&gt;&amp;nbsp;and that was adding up to more kernel memory than Intel/Linux was allowing.&lt;/P&gt;&lt;P&gt;On the 23900 in particular, we could not leverage all the processor cores due to this limitation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;By moving all (or most) of SecureXL to user space, it's possible to leverage more processor cores as the firewall can entirely run in user space.&lt;/P&gt;&lt;P&gt;(Note it still doesn't by default in R80.20 in non-VSX mode, but it can be enabled.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It also means certain kinds of low-level packet processing that could not easily be done in SecureXL because it was being done in the kernel now can.&lt;/P&gt;&lt;P&gt;For VSX in particular, it means you can now configure the penalty box features on a per-VS basis.&lt;/P&gt;&lt;P&gt;It also improves session establishment rates on the higher-end appliances.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Nov 2018 16:58:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41570#M3447</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-19T16:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41571#M3448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check Point&amp;nbsp;should include this in the SK.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Nov 2018 15:03:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41571#M3448</guid>
      <dc:creator>Tim_Maurer</dc:creator>
      <dc:date>2018-11-22T15:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41572#M3449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Am I right that this will influence tcpdump usage as well?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2018 08:46:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41572#M3449</guid>
      <dc:creator>Sven_Glock</dc:creator>
      <dc:date>2018-11-29T08:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41573#M3450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, namely that you don't need to turn of SecureXL to use it &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2018 13:58:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41573#M3450</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-11-29T13:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41574#M3451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&amp;nbsp; I am dealing with an issue where I have found that when SecureXL is turned on for our R80.20 gateway, traffic is not flowing across our VPN correctly.&amp;nbsp; I just stumbled on this article and I'm very excited to try and use the new features in FW Monitor to isolate the issue.&amp;nbsp; That being said, I noticed your comment here that SecureXL does not run in the user space on non-VSX mode, so I'm presuming the ability to use the SecureXL features of FW Monitor then would not work.&amp;nbsp; I have searched the Checkpoint KB to try and find out how to enable SecureXL to run in the user space on non-VSX, but I'm striking out.&amp;nbsp; Could you point me in the right direction on how to enable that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2019 18:27:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41574#M3451</guid>
      <dc:creator>Rob_Bush</dc:creator>
      <dc:date>2019-01-24T18:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41575#M3452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Might have found it.&amp;nbsp; Is it the "kiss_usermode_enabled" parameter of the SecureXL Kernel Parameters?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jan 2019 18:49:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41575#M3452</guid>
      <dc:creator>Rob_Bush</dc:creator>
      <dc:date>2019-01-24T18:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41576#M3453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please explain why its not enabled by default or how to enable SecureXL in user space or relevant SK which decribe&amp;nbsp;it. Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2019 08:35:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41576#M3453</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2019-02-01T08:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41577#M3454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://community.checkpoint.com/migrated-users/48740"&gt;Martin Raska&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With R80.20 SecureXL works automatically in user space.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can switch SecureXL on and off as usual in R80.20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Permanent:&lt;/P&gt;&lt;P&gt;# &lt;STRONG&gt;cpconfig&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Until the next reboot:&lt;/P&gt;&lt;P&gt;# &lt;STRONG&gt;fwaccel off&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;# &lt;STRONG&gt;fwaccel on&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Heiko&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2019 09:22:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41577#M3454</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-02-01T09:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41578#M3455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, I was confused by Daemon comment "&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;(Note it still doesn't by default in R80.20 in non-VSX mode, but it can be enabled.)&lt;/SPAN&gt;"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2019 09:38:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41578#M3455</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2019-02-01T09:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41579#M3456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To be clear, a LOT of SecureXL is already in userspace (as Heiko said).&lt;/P&gt;&lt;P&gt;Some firewalling is still in the kernel.&lt;/P&gt;&lt;P&gt;There is a separate "user mode" switch specifically for the 23900 on R80.20 (or anything above 40 cores, really) that moves all of the firewall into userspace (same as VSX, where we've already done that).&lt;/P&gt;&lt;P&gt;We haven't published the command yet and I need to check with R&amp;amp;D before I post it here &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2019 15:59:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41579#M3456</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-01T15:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41580#M3457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I want to correct a few inaccuracies that I helped to propagate above thanks to a gentle email from R&amp;amp;D.&lt;/P&gt;&lt;P&gt;SecureXL is actually not in userspace in R80.20, it still mostly happens in the kernel.&lt;/P&gt;&lt;P&gt;That said a lot of other things have moved to userspace that lead to some of the performance/functionality improvements in R80.20 even in Security Gateway mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VSX instances have run in userspace since R75.40VS.&lt;/P&gt;&lt;P&gt;Starting from R80.20, it is possible to run regular Security Gateway (non-VSX) mode with usermode firewall enabled.&lt;/P&gt;&lt;P&gt;It is NOT the default in R80.20 and is&amp;nbsp;ONLY required on platforms that have more than 40 cores (eg 23900).&lt;/P&gt;&lt;P&gt;On platforms with 40 cores or less, you can enable it if you wish, but don't expect a performance improvement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you wish to enable usermode firewall in R80.20:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;cpprod_util FwSetUsermode 1&lt;/LI&gt;&lt;LI&gt;reboot&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In R80.30, we plan to make this the default for the 23900.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Feb 2019 18:54:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/41580#M3457</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-02T18:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/52906#M4022</link>
      <description>&lt;P&gt;On VSX R80.20 with Jumbo 47. I see that the flow is sometimes limited to "id", for trafic related to VPN.&lt;/P&gt;&lt;P&gt;Stating that disabling secureXL, is not longer necessary must be in very specific situations?&lt;/P&gt;&lt;P&gt;And disabling secureXL can make VPN unstable.&lt;/P&gt;&lt;P&gt;Is it backed by Checkpoint and will Checkpoint troubleshoot with fw monitor without disabling secureXL?&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;René Rosenkrantz&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 13:39:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/52906#M4022</guid>
      <dc:creator>Rene_Rosenkrant</dc:creator>
      <dc:date>2019-05-08T13:39:22Z</dc:date>
    </item>
    <item>
      <title>Re: R80.x Performance Tuning and Debug Tips – fw monitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/52907#M4023</link>
      <description>&lt;P&gt;On VSX R80.20 with Jumbo 47. I see that the flow is sometimes limited to "id", for trafic related to VPN.&lt;/P&gt;&lt;P&gt;Stating that disabling secureXL, is not longer necessary must be in very specific situations?&lt;/P&gt;&lt;P&gt;And disabling secureXL can make VPN unstable.&lt;/P&gt;&lt;P&gt;Is it backed by Checkpoint and will Checkpoint troubleshoot with fw monitor without disabling secureXL?&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;René Rosenkrantz&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2019 13:42:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-x-Performance-Tuning-and-Debug-Tips-fw-monitor/m-p/52907#M4023</guid>
      <dc:creator>Rene_Rosenkrant</dc:creator>
      <dc:date>2019-05-08T13:42:46Z</dc:date>
    </item>
  </channel>
</rss>

