<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RFC: R81 and USFW in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103131#M8131</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680"&gt;@HristoGrigorov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In “Kernel Mode Firewall” KMFW, the maximum number of running cores is limited to 40 because of the Linux/Intel limitation of 2GB kernel memory,and because CoreXL architecture needs to load a large driver (~42MB) dozens of times (according to the CPU number, and up to 40 times). Newer platforms that contain more than 40 cores e.g., 23900 or open server are not fully utilized. The solution of the problem is a firewall in the user mode of the Linux operating system. USFW “User Space Firewall” or UMFW stands for “User Mode Firewall”, and it is based on proven VSX code. This mode was introduced in R80.10. According to SK the UMFW is enabled from R80.30 by default and is customized via the installation process.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Nov 2020 12:29:02 GMT</pubDate>
    <dc:creator>HeikoAnkenbrand</dc:creator>
    <dc:date>2020-11-24T12:29:02Z</dc:date>
    <item>
      <title>RFC: R81 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103040#M8115</link>
      <description>&lt;P&gt;I have request for comment on following kernel change and how does it affect USFW in R81:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Added support for zeco (zero-copy) packets for&amp;nbsp;&lt;SPAN class="mc-variable Other_Vars.tp_cp variable"&gt;Check Point&lt;/SPAN&gt;&amp;nbsp;USFW (&lt;SPAN class="mc-variable Other_Vars.tp_fwcap variable"&gt;Firewall&lt;/SPAN&gt;&amp;nbsp;in usermode).&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 19:26:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103040#M8115</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-11-23T19:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: RFC: R81 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103075#M8122</link>
      <description>&lt;P&gt;Remember that USFW is basically modern VSX with a single gateway.&lt;BR /&gt;There are old customer releases that enable this in R77.30 VSX.&lt;BR /&gt;USFW is basically going to be the default in a future version.&lt;BR /&gt;I would therefore assume it should be supported with USFW unless explicitly noted otherwise.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 03:20:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103075#M8122</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-24T03:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: RFC: R81 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103076#M8123</link>
      <description>&lt;P&gt;I asked more like from technical point of view. Is it something developed by open source community and imported into your own kernel branch or was it entirely developed in house to enhance performance for USFW apps.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think USFW is not just a modern VSX anymore because in R81, TLS1.3 support works only in user space which is another interesting topic to discuss&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 04:28:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103076#M8123</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-11-24T04:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: RFC: R81 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103131#M8131</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680"&gt;@HristoGrigorov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In “Kernel Mode Firewall” KMFW, the maximum number of running cores is limited to 40 because of the Linux/Intel limitation of 2GB kernel memory,and because CoreXL architecture needs to load a large driver (~42MB) dozens of times (according to the CPU number, and up to 40 times). Newer platforms that contain more than 40 cores e.g., 23900 or open server are not fully utilized. The solution of the problem is a firewall in the user mode of the Linux operating system. USFW “User Space Firewall” or UMFW stands for “User Mode Firewall”, and it is based on proven VSX code. This mode was introduced in R80.10. According to SK the UMFW is enabled from R80.30 by default and is customized via the installation process.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 12:29:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103131#M8131</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2020-11-24T12:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: RFC: R81 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103176#M8138</link>
      <description>&lt;P&gt;Curious why this is a relevant detail (whether we are using an existing Open Source implementation or wrote our own).&lt;/P&gt;
&lt;P&gt;I'm assuming TLS1.3 related operations can only be done in userspace, which is what USFW is required for TLS1.3 inspection.&lt;BR /&gt;Like I said: USFW is going to be the default in future versions.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 18:43:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103176#M8138</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-24T18:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: RFC: R81 and USFW</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103182#M8139</link>
      <description>&lt;P&gt;Because we expect you to contribute it to open source community as many other vendors do (eg. Microsoft, IBM, etc) ?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 19:19:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/RFC-R81-and-USFW/m-p/103182#M8139</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-11-24T19:19:13Z</dc:date>
    </item>
  </channel>
</rss>

