<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interpreting fwaccel conns in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interpreting-fwaccel-conns/m-p/227525#M43783</link>
    <description>&lt;P&gt;thanks for this explanation and confirmation&lt;/P&gt;</description>
    <pubDate>Mon, 23 Sep 2024 09:52:11 GMT</pubDate>
    <dc:creator>waschminator</dc:creator>
    <dc:date>2024-09-23T09:52:11Z</dc:date>
    <item>
      <title>Interpreting fwaccel conns</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interpreting-fwaccel-conns/m-p/227186#M43779</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;if i check out fwaccel conns i get 2 entries per session. fine so far. the weird thing: it is hwoing the same througput in both directions ...this is incorrect in theory.&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are talking of a filetransfer here and i would have expected maybe 494 GB in one directon and in the other direction maybe 100Mbyte becuase this are just ACKs. can anybody explain this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.101.68.43 2049 10.222.242.148 34889 6 .........T.L.........&amp;nbsp; 494.05GB 0s 11h28m51s 86400/86400&lt;BR /&gt;10.222.242.148 34889 10.101.68.43 2049 6 .........T...........&amp;nbsp; &amp;nbsp;494.05GB 0s 11h28m51s 86400/86400&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 11:01:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interpreting-fwaccel-conns/m-p/227186#M43779</guid>
      <dc:creator>waschminator</dc:creator>
      <dc:date>2024-09-19T11:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: Interpreting fwaccel conns</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interpreting-fwaccel-conns/m-p/227256#M43780</link>
      <description>&lt;P&gt;Not sure it's actually supposed to show the directional volume or not.&lt;BR /&gt;This probably needs a TAC case to confirm the correct/expected behavior.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2024 15:22:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interpreting-fwaccel-conns/m-p/227256#M43780</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-19T15:22:32Z</dc:date>
    </item>
    <item>
      <title>Re: Interpreting fwaccel conns</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interpreting-fwaccel-conns/m-p/227325#M43781</link>
      <description>&lt;P&gt;thx for reply. it seems that the amount of transported traffic is correct. only the bidirectional stuff seems to be incorrect. but i guess it has something todo with the way this connection is handled within this table.&lt;/P&gt;&lt;P&gt;let´s see if somebody else has experience. worst case i ask our support partner or vendor.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2024 06:50:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interpreting-fwaccel-conns/m-p/227325#M43781</guid>
      <dc:creator>waschminator</dc:creator>
      <dc:date>2024-09-20T06:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Interpreting fwaccel conns</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interpreting-fwaccel-conns/m-p/227374#M43782</link>
      <description>&lt;P&gt;The key is the "L" (link) flag on one of those entries in your screenshot.&amp;nbsp; SecureXL and Check Point in general track what we would consider a "connection" as separate flows of packets.&amp;nbsp; For a connection not subject to NAT there are just two flows (c2s and s2c).&amp;nbsp; The second line in your output is the original initiating c2s flow (looks like the 10.222 host initiated a NFS connection to 10.101), and the first line is the corresponding linked s2c response flow for that single NFS connection.&amp;nbsp; Because the two flows are linked together as being associated with the same connection, many of their elements such as consumed bandwidth, idle timeout, and duration are synchronized which is why they are the same value.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 12:41:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interpreting-fwaccel-conns/m-p/227374#M43782</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-10-01T12:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Interpreting fwaccel conns</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interpreting-fwaccel-conns/m-p/227525#M43783</link>
      <description>&lt;P&gt;thanks for this explanation and confirmation&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 09:52:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Interpreting-fwaccel-conns/m-p/227525#M43783</guid>
      <dc:creator>waschminator</dc:creator>
      <dc:date>2024-09-23T09:52:11Z</dc:date>
    </item>
  </channel>
</rss>

