<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: prefer security /prefer connectivity in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165178#M70123</link>
    <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can confirm "connectivity" at least for 64k and R80.20SP Jumbo HFA Take 331&lt;/P&gt;&lt;P&gt;g_fw ctl get int fwha_ips_reject_on_failover&lt;BR /&gt;-*- 10 blades: 1_01 1_02 1_03 1_04 1_05 2_01 2_02 2_03 2_04 2_05 -*-&lt;BR /&gt;fwha_ips_reject_on_failover = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Dec 2022 14:05:53 GMT</pubDate>
    <dc:creator>Alexander_Wilke</dc:creator>
    <dc:date>2022-12-14T14:05:53Z</dc:date>
    <item>
      <title>prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/164916#M70113</link>
      <description>&lt;P&gt;hello support,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; may i know the scenario and what kind of scenario we can use prefer security ?&lt;/P&gt;&lt;P&gt;and what kind of scenario we can use prefer connectivity ? what are the benefits if we use both of the parameter?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 02:36:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/164916#M70113</guid>
      <dc:creator>umar7</dc:creator>
      <dc:date>2022-12-13T02:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/164924#M70114</link>
      <description>&lt;P&gt;I assume you are referring to IPS blade setting on the gateway...there is an option there which is by default to prefer connectivity upon cluster failover even if IPS protections cant be guaranteed OR prefer security, which would close connections if IPS protections cant be guaranteed. Now, if you are speaking generally, it really depends who you ask. Of course, in todays world, more than ever before, security is way too important to overlook, but then if you think of connectivity, its literally something most companies require constantly. So, all in all, both are super important, but again, opinions might be split on this one.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 03:19:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/164924#M70114</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-13T03:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/164928#M70115</link>
      <description>&lt;P&gt;hello rock,&lt;/P&gt;&lt;P&gt;thanks for the update ,&lt;/P&gt;&lt;P&gt;correct me if i am wrong&lt;/P&gt;&lt;P&gt;if i select the prefer connectivity , during the failover it simply switch the connection to standby device it ensure there is no connectivity issue failover&amp;nbsp;&lt;/P&gt;&lt;P&gt;if i select the prefer security , during the failover it simply drop the current connection it will not ensure the connectivity right&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;above i mentioned is correct rock ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 03:55:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/164928#M70115</guid>
      <dc:creator>umar7</dc:creator>
      <dc:date>2022-12-13T03:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/164931#M70116</link>
      <description>&lt;P&gt;I attached the screenshot for your reference, hope its helpful.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18762i313B54F061191004/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 04:03:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/164931#M70116</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-13T04:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/164939#M70117</link>
      <description>&lt;P&gt;&lt;SPAN&gt;sk60160 provides some additional insight further to that provided by Andy.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 05:00:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/164939#M70117</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-12-13T05:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165010#M70118</link>
      <description>&lt;P&gt;You sort of got it : - ). So for prefer connectivity, yes, thats correct, IF your cluster is fully functional, then when failover happens, it will work fine if that option is selected. Now, IF prefer security is selected, does not mean current connections will close, ONLY ones for which IPS signatures can not be applied to/guaranteed. Personally, I would leave it to "prefer connectivity", which is default, as lets be honest, you do NOT want people "screaming" at you because their connections are failing : - )&lt;/P&gt;
&lt;P&gt;By the way, sk&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;provided also explains that. I would listen to him, he is EXCELLENT, very smart guy!&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 11:42:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165010#M70118</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-13T11:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165058#M70119</link>
      <description>&lt;P&gt;One interesting side effect of "prefer connectivity" is that while the connection will be continued upon ClusterXL failover, it cannot be inspected by streaming (either active or passive) anymore.&amp;nbsp; As a result the connection will be offloaded into the SXL/Accelerated Path on the newly-active member.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This looks very strange when you are watching a high-speed transfer that is subject to streaming inspection and a failover occurs; the speed of the transfer doubles or triples!&amp;nbsp; Interestingly if you fail back over to the original member streaming inspection resumes (assuming the member has not been rebooted or otherwise cleared its state table) and the transfer speed drops back to what it was before.&amp;nbsp; Was definitely a WTF moment when I first saw this effect, as causing a failover would massively speed up big transfers!&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 14:51:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165058#M70119</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-12-13T14:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165080#M70120</link>
      <description>&lt;P&gt;O wow, thanks for that Tim, thats super interesting &lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 16:53:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165080#M70120</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-13T16:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165157#M70121</link>
      <description>&lt;P&gt;What to use if you are running a 64k Scalable Plattform which is only a "Single" / "Standard" Gateway Object in SmartConsole and you can not select the options? Probably same for Maestro.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However 64k/Maestro may have failovers in the same "Chassis" or from one chassis to another. What will apply?&lt;BR /&gt;Prefer connectifity or prefer security?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 12:14:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165157#M70121</guid>
      <dc:creator>Alexander_Wilke</dc:creator>
      <dc:date>2022-12-14T12:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165176#M70122</link>
      <description>&lt;P&gt;The default on SP/Maestro is prefer connectivity.&amp;nbsp; At least in R80.30SP the command was&amp;nbsp;&lt;STRONG&gt;asg_ips_failover_behavior&lt;/STRONG&gt; &lt;STRONG&gt;{connectivity | security}&lt;/STRONG&gt; and you could check the current state with command &lt;STRONG&gt;g_fw ctl get int fwha_ips_reject_on_failover&lt;/STRONG&gt;, 0 is prefer connectivity, 1 is prefer security.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 14:38:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165176#M70122</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-12-14T14:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165178#M70123</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can confirm "connectivity" at least for 64k and R80.20SP Jumbo HFA Take 331&lt;/P&gt;&lt;P&gt;g_fw ctl get int fwha_ips_reject_on_failover&lt;BR /&gt;-*- 10 blades: 1_01 1_02 1_03 1_04 1_05 2_01 2_02 2_03 2_04 2_05 -*-&lt;BR /&gt;fwha_ips_reject_on_failover = 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2022 14:05:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165178#M70123</guid>
      <dc:creator>Alexander_Wilke</dc:creator>
      <dc:date>2022-12-14T14:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165535#M70124</link>
      <description>&lt;P&gt;hello&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 09:08:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165535#M70124</guid>
      <dc:creator>umar7</dc:creator>
      <dc:date>2023-04-05T09:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165612#M70125</link>
      <description>&lt;P&gt;hello&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 09:09:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165612#M70125</guid>
      <dc:creator>umar7</dc:creator>
      <dc:date>2023-04-05T09:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165613#M70126</link>
      <description>&lt;P&gt;can i get an update from above questions?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 01:47:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165613#M70126</guid>
      <dc:creator>umar7</dc:creator>
      <dc:date>2022-12-20T01:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165614#M70127</link>
      <description>&lt;P&gt;I cant give you answers to those, as I never tested option to prefer security, as default one is what everyone leaves it to. You would need to try it out and see the behavior.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 01:57:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165614#M70127</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-20T01:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165615#M70128</link>
      <description>&lt;P&gt;hello rock,&lt;/P&gt;&lt;P&gt;thanks for the update .&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 02:09:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165615#M70128</guid>
      <dc:creator>umar7</dc:creator>
      <dc:date>2022-12-20T02:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165616#M70129</link>
      <description>&lt;P&gt;hi all,&lt;/P&gt;&lt;P&gt;if any one know the behavior and above questions answer .kindly let me know .&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2022 02:25:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165616#M70129</guid>
      <dc:creator>umar7</dc:creator>
      <dc:date>2022-12-20T02:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: prefer security /prefer connectivity</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165731#M70130</link>
      <description>&lt;P&gt;The kinds of failures that are being discussed here are related to the clustering technology known as ClusterXL.&lt;BR /&gt;Many, many things outside of the control of the Check Point configuration can cause ClusterXL to “fail over” to another device.&lt;BR /&gt;It obviously has an impact on the IPS service, which requires the same gateway to process the connection (thus why the Prefer Connectivity/Security option exists).&lt;/P&gt;
&lt;P&gt;3 minutes and 11 seconds doesn’t sound unreasonable if their test of “IPS service failure” was a reboot of the primary gateway.&lt;BR /&gt;There are other reasons a failover can occur that don’t involve a reboot (for example, disabling/unplugging a cable on a NIC, or something else that prevents the gateways from seeing each other).&lt;BR /&gt;I would want to know precisely how they are testing this.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Dec 2022 01:45:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/prefer-security-prefer-connectivity/m-p/165731#M70130</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-21T01:45:31Z</dc:date>
    </item>
  </channel>
</rss>

