<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: orig_route_params kernel table in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222474#M42635</link>
    <description>&lt;P&gt;Got it, thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2024 14:38:10 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-08-01T14:38:10Z</dc:date>
    <item>
      <title>orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222262#M42575</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would like to know what is the kernel table "orig_route_params" used for? I understand it is basically ARP table for SecureXL, but when I open it I only see IP addresses in hex format and IP address of one of the gateway's interfaces. How to interpret this table?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Igor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 14:59:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222262#M42575</guid>
      <dc:creator>imamuzic</dc:creator>
      <dc:date>2024-07-30T14:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222294#M42583</link>
      <description>&lt;P&gt;Appears to be related to SecureXL and VPN based on various SK articles.&lt;BR /&gt;I imagine it's a similar format to the connections table.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 16:30:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222294#M42583</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-30T16:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222299#M42584</link>
      <description>&lt;P&gt;You can try below and see what you get.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@CP-GW:0]# fw tab -f -t orig_route_params&lt;BR /&gt;Using cptfmt&lt;BR /&gt;Formatting table's data - this might take a while...&lt;/P&gt;
&lt;P&gt;localhost:&lt;BR /&gt;Date: Jul 30, 2024&lt;BR /&gt;13:44:28 5 N/A 3 172.16.10.249 &amp;gt; N/A LogId: &amp;lt;max_null&amp;gt;; ContextNum: &amp;lt;max_null&amp;gt;; OriginSicName: &amp;lt;max_null&amp;gt;; : (+)====================================(+); Table_Name: orig_route_params; : (+); Attributes: dynamic, id 442, attributes: keep, sync, kbuf 1, expires never, , hashsize 16384, limit 10200; LastUpdateTime: 30Jul2024 13:44:28; ProductName: VPN-1 &amp;amp; FireWall-1; ProductFamily: Network;&lt;BR /&gt;[Expert@CP-GW:0]#&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 17:45:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222299#M42584</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-30T17:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222300#M42585</link>
      <description>&lt;P&gt;his sk also may be helpful.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk116453" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk116453&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2024 17:47:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222300#M42585</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-30T17:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222337#M42594</link>
      <description>&lt;P&gt;Yes, but what these IP addresses represents? In my output some of them are known IKE peers, but some of them are public IP addresses that are non existent neither as objects or log entries.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 08:04:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222337#M42594</guid>
      <dc:creator>imamuzic</dc:creator>
      <dc:date>2024-07-31T08:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222412#M42613</link>
      <description>&lt;P&gt;VPN is definitely handled in SecureXL.&lt;BR /&gt;Check fwaccel conns output and see if there are any matches for other IPs.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 21:53:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222412#M42613</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-31T21:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222413#M42614</link>
      <description>&lt;P&gt;Sorry mate, totally forgot to test this today. Let me set up bogus VPN community and run the command again and I will update shortly.&lt;/P&gt;
&lt;P&gt;Apologies again.&lt;/P&gt;
&lt;P&gt;Update...ran the command after creating test vpn community and it showed the IPs there. I will run it again in the morning.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 22:39:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222413#M42614</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-31T22:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222469#M42631</link>
      <description>&lt;P&gt;I've found only one match between SecureXL (fwaccell conns) and "&lt;SPAN&gt;orig_route_params" table and&amp;nbsp;&lt;/SPAN&gt;this is an IP address of another IKE peer. All other IP addresses found in the "&lt;SPAN&gt;orig_route_params&lt;/SPAN&gt;&amp;nbsp;" table are either local or remote IKE peers or public IP address I'm unable to reference to neither Interoperable objects or Gateways.&lt;/P&gt;&lt;P&gt;I would conclude that these unrelatable addresses are in the table because these are about unknown IKE end points attempting unsuccessful&amp;nbsp; IKE negotiation with the gateway, but then how come that there is no Log record about this?&lt;/P&gt;&lt;P&gt;Without these unrelatable addresses in the table I would conclude that this table simply stores IP addresses of either local or remote IKE Check Point locally managed&amp;nbsp; peers as these are SecureXL acceeleated IKE sessions, while 3rd party VPN peer's IKE sessions are handled by IKE VPN deamon and therefore should not be seen in the "&lt;SPAN&gt;orig_route_params" table, at least I figured so from Timothy_Hall's post on similar subject.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 14:14:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222469#M42631</guid>
      <dc:creator>imamuzic</dc:creator>
      <dc:date>2024-08-01T14:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222470#M42632</link>
      <description>&lt;P&gt;Thats actually a good point, I saw the same in my lab and Azure lab as well, but could not see any logs for it either.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/52172"&gt;@imamuzic&lt;/a&gt;&amp;nbsp;Whats the link to Tim's post about it?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 14:14:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222470#M42632</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-01T14:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222473#M42634</link>
      <description>&lt;P&gt;Here you go:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Problem-with-MAC-address-on-the-wrong-interface/td-p/101589" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Problem-with-MAC-address-on-the-wrong-interface/td-p/101589&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 14:23:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222473#M42634</guid>
      <dc:creator>imamuzic</dc:creator>
      <dc:date>2024-08-01T14:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222474#M42635</link>
      <description>&lt;P&gt;Got it, thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 14:38:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222474#M42635</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-01T14:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222509#M42641</link>
      <description>&lt;P&gt;Might be worth a TAC case to investigate this more closely.&lt;BR /&gt;&lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2024 16:24:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222509#M42641</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-01T16:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222546#M42651</link>
      <description>&lt;P&gt;TAC brought me here actually &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; because we have an issue covered probably by sk&lt;SPAN&gt;180956, I asked 2 times TAC engineer why the issue is related to IPSec NAT-T and what is the purpose of the "orig_route_params" table and got 0 answers, so I was forced to investigate it by myself and so far concluded that this must be related to SecureXL IKE session acceleration and IPSec acceleration, but since SecureXL handles TCP/UDP only and NAT-T encapsulates ESP into UDP it must be why this SK is about NAT-T, although I'm confused a little bit because SecureXL actually accelerates ESP packets too...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So, this is why I came here hopping someone (from R&amp;amp;D perhaps) will clarify the&amp;nbsp;sk180956 and "orig_route_params" table to me.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 08:16:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222546#M42651</guid>
      <dc:creator>imamuzic</dc:creator>
      <dc:date>2024-08-02T08:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222567#M42658</link>
      <description>&lt;P&gt;Lets hope so...My understanding is also based on reading about it, it has to do vpn/sxl, but clarification would be nice.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 11:44:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222567#M42658</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-02T11:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222600#M42667</link>
      <description>&lt;P&gt;It's definitely related to SecureXL and VPN based on the various SKs and SRs I looked at.&lt;BR /&gt;I'll see if I can get an answer from someone in R&amp;amp;D about it.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 18:15:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/222600#M42667</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-02T18:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/223339#M42827</link>
      <description>&lt;P&gt;&lt;SPAN&gt;orig_route_params&lt;/SPAN&gt;&amp;nbsp;maps the routing information (inbound interface, next-hop-router L2 addr) and the NAT-T source port to&amp;nbsp; how the NAT-T packet entered the gateway from the peer.&lt;BR /&gt;This is done so the gateway can send reply with same routing the packet as entered, and with peer’s current NAT-T port.&lt;BR /&gt;This applies for both Site-to-Site with DAIP gateways and Client-to-Site VPN.&lt;BR /&gt;&lt;BR /&gt;So what’s in it?&lt;BR /&gt;The keys are the OM IP and user md5 in case of Endpoint. In case of DAIP the key is the DAIP ID.&lt;BR /&gt;The values including the port and the routing data (in kbuf as it includes the MAC address).&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 14:52:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/223339#M42827</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-12T14:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: orig_route_params kernel table</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/223429#M42839</link>
      <description>&lt;P&gt;Thank you for the thorough explanation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Igor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 07:45:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/orig-route-params-kernel-table/m-p/223429#M42839</guid>
      <dc:creator>imamuzic</dc:creator>
      <dc:date>2024-08-13T07:45:52Z</dc:date>
    </item>
  </channel>
</rss>

