<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HCP-X...The Leading Edge in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/246938#M48166</link>
    <description>&lt;P&gt;I cant seem to find that sk, either by opening the link or searching for it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 21 Apr 2025 18:36:04 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-04-21T18:36:04Z</dc:date>
    <item>
      <title>HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/246866#M48138</link>
      <description>&lt;P&gt;So interestingly there appears to be some extra not-yet-published leading edge tests that can be added on to the standard &lt;STRONG&gt;hcp&lt;/STRONG&gt; command with the &lt;STRONG&gt;--tac&lt;/STRONG&gt; option once &lt;STRONG&gt;hcp&lt;/STRONG&gt; has been updated to the latest version:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk183223" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk183223: HealthCheck Point Addon&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I always found it interesting to informally track what new tests are added to &lt;STRONG&gt;hcp&lt;/STRONG&gt; with each new update as these tend to be driven by what current cases TAC is seeing, and in some cases has tipped me off to an issue even before an SK article was created or a Checkmates post appeared.&amp;nbsp; So let's take a look at these leading-edge TAC tests that aren't run by default!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;EDIT: There is no need to download a new copy of hcp with curl_cli as shown in this screenshot, please see my follow-up post below.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hcptac1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30267i6DEDFD8B115171B8/image-size/large?v=v2&amp;amp;px=999" role="button" title="hcptac1.png" alt="hcptac1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;EDIT: There is no need to download a new copy of hcp with curl_cli as shown in this screenshot, please see my follow-up post below.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Some definitely juicy ones here:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Missing routes from kernel&lt;/STRONG&gt; which I actually mentioned in my &lt;A href="https://community.checkpoint.com/t5/General-Topics/Be-Your-Own-TAC-Part-Deux-Americas-Advanced-Gateway/m-p/245032" target="_blank" rel="noopener"&gt;Be Your Own TAC Part Deux&lt;/A&gt; presentation due to an unreachable next-hop address&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;IKEv2 Narrowing Issue Detection&lt;/STRONG&gt; which was a major VPN interoperability issue at one point&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Dynamic Balancing and GNAT Validation&lt;/STRONG&gt; which I assume is checking for a situation where Dynamic Balancing/Split is disabled to to GNAT being off (which happens on gateways with less than 8 cores even if they support Dynamic Split)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;dynamic_split --z occurrences&lt;/STRONG&gt; not completely sure here, perhaps if split flapping was detected and an anti-flap penalty was enforced?&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;ARP Drops&lt;/STRONG&gt; assume this is due to invalid next hops (&lt;SPAN&gt;sk182582)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;RAD Tests&lt;/STRONG&gt; Oh yes definitely...&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The cool part is if you aren't sure exactly what a certain hcp test means (even if it is a TAC test), you can always go look at the python source code for the test itself and see precisely what it is looking for here:&amp;nbsp;&lt;STRONG&gt;/etc/hcp/tests/*/*.py&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 12:07:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/246866#M48138</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-04-28T12:07:24Z</dc:date>
    </item>
    <item>
      <title>Re: HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/246934#M48163</link>
      <description>&lt;P&gt;I quite like how much data HCP can collect.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 17:17:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/246934#M48163</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-21T17:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/246938#M48166</link>
      <description>&lt;P&gt;I cant seem to find that sk, either by opening the link or searching for it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 18:36:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/246938#M48166</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-21T18:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/246940#M48167</link>
      <description>&lt;P&gt;Odd, it was there Saturday but now I can't see it either.&amp;nbsp; There wasn't much in that SK other than the command I used in the screenshot to update hcp, and a mention of the --tac option.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 18:47:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/246940#M48167</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-04-21T18:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/246941#M48168</link>
      <description>&lt;P&gt;No worries! Yes, I ran the command you gave in your screenshot in one of my R82 lab fws and worked great.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 18:49:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/246941#M48168</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-21T18:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/247448#M48328</link>
      <description>&lt;P&gt;So after some more investigation performed while updating my &lt;A href="http://www.maxpowerfirewalls.com/gw-optimization-course.html" target="_blank" rel="noopener"&gt;Gateway Performance Optimization Course&lt;/A&gt;, it looks like takes 76 and higher of &lt;STRONG&gt;hcp&lt;/STRONG&gt; have the TAC tests capability built-in, and there is no need to download a different version of hcp as shown in my original posting's screenshot.&amp;nbsp; Here is the new page from my course for future reference:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hcptactests.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30336i26F7C4864265F046/image-size/large?v=v2&amp;amp;px=999" role="button" title="hcptactests.png" alt="hcptactests.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 27 Apr 2025 18:25:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/247448#M48328</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-04-27T18:25:25Z</dc:date>
    </item>
    <item>
      <title>Re: HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/247449#M48329</link>
      <description>&lt;P&gt;Thanks for that Tim!&lt;/P&gt;</description>
      <pubDate>Sun, 27 Apr 2025 19:26:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/247449#M48329</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-27T19:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/247686#M48378</link>
      <description>&lt;P&gt;Oh wow! This is nice! &amp;nbsp;An extra 100 oddball tests available!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;hcp -l --tac |awk -F "|" ' $3 ~ /TAC/ { print $0 }' |wc -l
100
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nice find! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 16:04:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/247686#M48378</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-04-29T16:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/247706#M48381</link>
      <description>&lt;P&gt;good find!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 17:23:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/247706#M48381</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-29T17:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/247707#M48382</link>
      <description>&lt;P&gt;Yep just remember these TAC tests are not supported (don't bug TAC if you see a failure of one of these) and can change at any time!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 18:06:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/247707#M48382</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-04-29T18:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/247708#M48383</link>
      <description>&lt;P&gt;I ran it on few fws and no issues.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 18:13:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/247708#M48383</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-29T18:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/258009#M50590</link>
      <description>&lt;P&gt;Note that the SK is currently internal and may be made available to a wider audience in the future.&amp;nbsp; No ETA currently.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 14:38:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/258009#M50590</guid>
      <dc:creator>kingCommaAndrew</dc:creator>
      <dc:date>2025-09-23T14:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: HCP-X...The Leading Edge</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/258010#M50591</link>
      <description>&lt;P&gt;Yes, but it was briefly exposed. These types of posts are the result of my weekly review of all SKs, which helps keep my &lt;A href="https://shadowpeak.com/check-point-training" target="_self"&gt;Gateway Performance Optimization Course&lt;/A&gt;&amp;nbsp;fully up to date.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Sep 2025 14:42:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/HCP-X-The-Leading-Edge/m-p/258010#M50591</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-09-23T14:42:26Z</dc:date>
    </item>
  </channel>
</rss>

