<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FW_ACCEL traffic not acceleration in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210398#M39863</link>
    <description>&lt;P&gt;put tcp 9020 in the services and right click on it to exclude it&lt;/P&gt;
&lt;P&gt;Rule will hit ALL services BUT 9020&lt;/P&gt;</description>
    <pubDate>Wed, 03 Apr 2024 20:26:20 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2024-04-03T20:26:20Z</dc:date>
    <item>
      <title>FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210381#M39850</link>
      <description>&lt;P&gt;Hey guys!&lt;/P&gt;&lt;P&gt;I need help.&lt;BR /&gt;I have been trying to add this traffic to fast_accel, it is backup transfer traffic.&lt;BR /&gt;See below:&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fwaccel.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25146i5749D74DF53CEAA9/image-size/large?v=v2&amp;amp;px=999" role="button" title="fwaccel.PNG" alt="fwaccel.PNG" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't understand what this connection would be (........................) without any flag marked.&lt;BR /&gt;I created a rule to run a test with iperf3 and it worked perfectly.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 18:11:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210381#M39850</guid>
      <dc:creator>Elbis</dc:creator>
      <dc:date>2024-04-03T18:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210383#M39852</link>
      <description>&lt;P&gt;Whats src/dst?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 18:42:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210383#M39852</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-03T18:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210384#M39853</link>
      <description>&lt;P&gt;Are you asking what type of solution or application is at the source and target?&lt;/P&gt;&lt;P&gt;If so, on the source&amp;nbsp;Spectrum Protect Plus (IBM) and on the target Storage Dell.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 18:50:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210384#M39853</guid>
      <dc:creator>Elbis</dc:creator>
      <dc:date>2024-04-03T18:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210385#M39854</link>
      <description>&lt;P&gt;You should see the F flag:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;In the output of the SecureXL command "&lt;CODE&gt;fwaccel conns&lt;/CODE&gt;", connections that are accelerated based on a Fast Acceleration rules are labeled with the "&lt;CODE&gt;F&lt;/CODE&gt;" flag (R81 and higher).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Now it shows the L flag:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;L - Shows connections, for which SecureXL created internal links.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That is why it is not passed via fast accel&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 18:54:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210385#M39854</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-04-03T18:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210386#M39855</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;Apologies, should have clarified. I meant what is source IP and what is destination IP?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 18:55:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210386#M39855</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-03T18:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210387#M39856</link>
      <description>&lt;P&gt;Good point.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 18:57:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210387#M39856</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-03T18:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210388#M39857</link>
      <description>&lt;P&gt;Follow this SK btw for fastaccel:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk156672" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk156672&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Fast Accel enforces only rulebase that does not require deep packet inspection.&lt;BR /&gt;For example: Application Control, URL Filtering and Content Awareness are not included.&lt;BR /&gt;For the other cases: Fast Accel rules are prioritized over the access rule base.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Maybe if you did the exclusion from inspection blades correct, it is still stuck in secureXL.&lt;/P&gt;
&lt;P&gt;You could turn off and on fwaccel off -&amp;gt; fwaccel on&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 19:01:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210388#M39857</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-04-03T19:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210389#M39858</link>
      <description>&lt;P&gt;Ok, I got it.&lt;BR /&gt;I had read this SK several times.&lt;BR /&gt;I made an exception rule in the IPS policy, it is the only blade we have enabled. But she's not at the top of the table, I don't know if that could influence her.&lt;BR /&gt;In any case, outside of firewall production hours I will execute the command fwaccel off -&amp;gt; fwaccel on.&lt;/P&gt;&lt;P&gt;I'll bring you new news later.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 19:06:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210389#M39858</guid>
      <dc:creator>Elbis</dc:creator>
      <dc:date>2024-04-03T19:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210391#M39859</link>
      <description>&lt;P&gt;I dont believe order matters.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 19:22:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210391#M39859</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-03T19:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210393#M39860</link>
      <description>&lt;P&gt;For test change your IPS rule. The one where you defined the profile.&lt;/P&gt;
&lt;P&gt;Now you should have something like this:&lt;/P&gt;
&lt;P&gt;source&lt;/P&gt;
&lt;P&gt;dest&lt;/P&gt;
&lt;P&gt;services (any)&lt;/P&gt;
&lt;P&gt;profile&lt;/P&gt;
&lt;P&gt;Change services to ALL (any) BUT 9020. Right click on it to make exclusion (red cross).&lt;/P&gt;
&lt;P&gt;Test with that then for 100% sure it will bypass IPS inspection.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 19:37:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210393#M39860</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-04-03T19:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210397#M39862</link>
      <description>&lt;P&gt;I'm not sure I understand 100%.&lt;/P&gt;&lt;P&gt;see my rule is like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ips.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25148iD3B2AF5BF2D57E24/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ips.PNG" alt="ips.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for the help!!&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 20:18:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210397#M39862</guid>
      <dc:creator>Elbis</dc:creator>
      <dc:date>2024-04-03T20:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210398#M39863</link>
      <description>&lt;P&gt;put tcp 9020 in the services and right click on it to exclude it&lt;/P&gt;
&lt;P&gt;Rule will hit ALL services BUT 9020&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 20:26:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210398#M39863</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-04-03T20:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210400#M39864</link>
      <description>&lt;P&gt;You may need to make similar rule for inspection settings as well, but most people never change it from default, so its possible may not even apply in your case.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 22:25:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210400#M39864</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-03T22:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210438#M39866</link>
      <description>&lt;P&gt;The fact that the connection appears in the output of &lt;STRONG&gt;fwaccel conns&lt;/STRONG&gt; and there is not an "S" flag shown indicates that the connection is fastpath already.&amp;nbsp; Because the original offload decision for the connection was to the fastpath anyway, the hit count on your fast_accel rule will not be incremented, nor will an "F" appear in the flags.&amp;nbsp; See&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk180496" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk180496: No match on SecureXL Fast Accelerator (fw fast_accel)&lt;/SPAN&gt;&lt;/A&gt;.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Keep in mind that only traffic in the Medium Path (either passive or active streaming) can be successfully forced to the fastpath with fast_accel.&amp;nbsp; Traffic originally destined for the F2F/slowpath will still be processed there and the fast_accel will not work for that traffic.&amp;nbsp; Connections that are F2F/slowpath do not show up at all in the output of &lt;STRONG&gt;fwaccel conns&lt;/STRONG&gt; so that is not the case here.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 12:01:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210438#M39866</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-04-04T12:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210480#M39879</link>
      <description>&lt;P&gt;Firstly thanks for the help.&lt;/P&gt;&lt;P&gt;My case is a little complicated.&lt;/P&gt;&lt;P&gt;I have a much lower than expected rate in this communication. The entire infrastructure has 10Gb interfaces.&lt;/P&gt;&lt;P&gt;When I ran the test with iperf3 before the "fast_accel" rules with servers on the same networks where the backup transfers are made, I obtained a rate of 700Mb. After following the fast_accel rules and carrying out another test with iperf, my rate went to 3.5Gb.&lt;BR /&gt;Backup traffic continues at 700Mb and appears as such in the fw conns table. Only the test with iperf made the hit count on the rule, and the servers are on the same network as the rule created.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fwconns.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25163iF593623708667D0E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="fwconns.PNG" alt="fwconns.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="fwips.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25164i05D4BC3FC4ED98EE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="fwips.PNG" alt="fwips.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 17:24:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210480#M39879</guid>
      <dc:creator>Elbis</dc:creator>
      <dc:date>2024-04-04T17:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210489#M39880</link>
      <description>&lt;P&gt;Are the connections shown in your last screenshot of the actual port 9020 backup connections (and not iperf3)?&amp;nbsp; If so they are in the fastpath already and will not cause the fast_accel hit counter to go up.&amp;nbsp; The blade-based exception you created for IPS and port 9020 has probably made this traffic eligible for the fastpath already.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When the backup is running, do any of your gateway's&amp;nbsp; SND cores hit 100%?&amp;nbsp; If they don't something else other than the firewall is slowing down that backup traffic (possibly fragmentation), for the gateway please provide the output of &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt; for the relevant interfaces the backup traffic is traversing to look for network problems.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just because the server being backed up has a 10Gbit NIC doesn't mean the backup software can actually push traffic at 10Gbit, you may want to look at resource utilization on the server being backed up and see if the backup software is running out of CPU at 700Mbit.&amp;nbsp; Not impossible if it is encrypting the backup traffic but is limited to a single thread/CPU.&amp;nbsp; Also look at your backup server while this backup is running and make sure it has plenty of resources and is not throttling the inbound backup traffic.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 19:54:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210489#M39880</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-04-04T19:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: FW_ACCEL traffic not acceleration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210494#M39881</link>
      <description>&lt;P&gt;Sounds to me that the traffic hits one CPU core and that it is the limit of speed it can reach.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;700Mbit is very decent for one CPU core.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 20:21:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/FW-ACCEL-traffic-not-acceleration/m-p/210494#M39881</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-04-04T20:21:00Z</dc:date>
    </item>
  </channel>
</rss>

