<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SecureXL disabling during policy push causing application issues in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-disabling-during-policy-push-causing-application-issues/m-p/54106#M4102</link>
    <description>&lt;P&gt;We have an R77.30 Gateway that is under heavy load.&amp;nbsp; We have performed tuning, and have plan to address this load, but in the meantime, I have a question.&lt;/P&gt;&lt;P&gt;During a policy push, we see that SecureXL disables (normal and expected) from any where to 30-50 seconds.&amp;nbsp; Our application teams report latency and reduced connections during this time period.&amp;nbsp; We've been asked to try to eliminate this application "blip".&amp;nbsp; It seems that R80.20 would help, as policy push with 80.20 no longer disabled SecureXL.&amp;nbsp; However, we are worried that we would be shifting the problem somewhere else in the policy install chain.&amp;nbsp; Does anyone have experience with improved policy install times, and less application impact when moving from 77.30 to 80.20?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 22 May 2019 13:20:40 GMT</pubDate>
    <dc:creator>Mike_Jones</dc:creator>
    <dc:date>2019-05-22T13:20:40Z</dc:date>
    <item>
      <title>SecureXL disabling during policy push causing application issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-disabling-during-policy-push-causing-application-issues/m-p/54106#M4102</link>
      <description>&lt;P&gt;We have an R77.30 Gateway that is under heavy load.&amp;nbsp; We have performed tuning, and have plan to address this load, but in the meantime, I have a question.&lt;/P&gt;&lt;P&gt;During a policy push, we see that SecureXL disables (normal and expected) from any where to 30-50 seconds.&amp;nbsp; Our application teams report latency and reduced connections during this time period.&amp;nbsp; We've been asked to try to eliminate this application "blip".&amp;nbsp; It seems that R80.20 would help, as policy push with 80.20 no longer disabled SecureXL.&amp;nbsp; However, we are worried that we would be shifting the problem somewhere else in the policy install chain.&amp;nbsp; Does anyone have experience with improved policy install times, and less application impact when moving from 77.30 to 80.20?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2019 13:20:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-disabling-during-policy-push-causing-application-issues/m-p/54106#M4102</guid>
      <dc:creator>Mike_Jones</dc:creator>
      <dc:date>2019-05-22T13:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL disabling during policy push causing application issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-disabling-during-policy-push-causing-application-issues/m-p/54370#M4116</link>
      <description>&lt;P&gt;There are two factors to the policy installation process:&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Policy verification and compilation&lt;/STRONG&gt;: This covers the process of validating there are no rules hidden by another (rule X hides rule Y for service Z) and compiling the policy for installation to the Security Gateway. This should be faster in R80.x.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Policy push to gateway&lt;/STRONG&gt;: Aside from the SecureXL-related changes in R80.20, this process is largely unchanged from past versions (i.e. it's still pushing the full policy, not a delta).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In general, the target is for policy installs to take no more than 2 minutes.&lt;BR /&gt;If your policy installs in R80.x are taking significantly longer than that, a TAC case should be opened.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2019 07:27:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-disabling-during-policy-push-causing-application-issues/m-p/54370#M4116</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-05-28T07:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL disabling during policy push causing application issues</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-disabling-during-policy-push-causing-application-issues/m-p/54464#M4118</link>
      <description>&lt;P&gt;To expand on what Dameon said, the cause of latency/loss during policy installation could be caused by the need to restart SecureXL in R80.10 and earlier.&amp;nbsp; However based on my experience it is much more likely that the connection rematch operation on the gateway is the root cause of what you are seeing.&amp;nbsp; On your gateway/cluster object on the Connection Persistence screen under Advanced, change the setting from "rematch connections" to "keep all connections".&amp;nbsp; Then push policy twice, do you see a big reduction in latency/loss with the second policy push?&lt;/P&gt;
&lt;P&gt;If that doesn't help, the next place to look (especially if there is lots of packet loss) is for RX-DRPs racking up during a policy push via the &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt; command.&amp;nbsp; If you are piling up a lot of these during a policy push, this is one of the very limited situations where increasing the size of the network interface ring buffers might be appropriate.&amp;nbsp; But I would strongly advise doing some performance tuning of the gateway first, as increasing ring buffer sizes is typically a last resort and can cause other issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 May 2019 15:20:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-disabling-during-policy-push-causing-application-issues/m-p/54464#M4118</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-05-27T15:20:20Z</dc:date>
    </item>
  </channel>
</rss>

