<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fw ctl fast_accel - some traffic still going slow path in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/105287#M8339</link>
    <description>&lt;P&gt;Hi Timothy,&lt;/P&gt;&lt;P&gt;I'm glad that once I can share something with You &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Output is form fw_mux command that is not documented. I get know about it on TAC Academy with really good coach Alon form CheckPoint HQ. As You probably notice there is no connections with flag F listed any more in &lt;SPAN&gt;fwaccel conns&lt;/SPAN&gt;. The only way I know to print all connections F2F and PXL is that new command (&lt;STRONG&gt;fw_mux&lt;/STRONG&gt;&lt;STRONG&gt; all &amp;gt; file.txt&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;I try to debug a little more with TAC because service looks very standard as in default settings, IPS exceptions between this internal networks is added and yet with 1433 there is a problem. Was hoping that somebody can read something more form that output. Later I try to play with kernel debug but I have to do it some filters.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Rafal&lt;/P&gt;</description>
    <pubDate>Sun, 13 Dec 2020 19:27:56 GMT</pubDate>
    <dc:creator>Rafal_N</dc:creator>
    <dc:date>2020-12-13T19:27:56Z</dc:date>
    <item>
      <title>fw ctl fast_accel - some traffic still going slow path</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/105183#M8329</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I'm using fast_accel for few months and it works fine with backup traffic, cifs/smb etc but in heavy_conection there are still traffic to DB servers. Issue is with internal traffic ms sql (tcp 1433). It still produce some CPU spikes.&lt;/P&gt;&lt;P&gt;Some days ago I found out fw_mux command and it looks that every connection with tcp 1433 it is not accelerated. Can any one help me figure out what can cause that??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;R80.30 take 219 kernel 2.6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;fw ctl fast_accel show_state&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;fw fast_accel: The feature state is: enabled.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;------------------------------------ FIREWALL FAST ACCEL TABLE ------------------------&lt;BR /&gt;# Source IP Destination IP D-Port Protocol Hit count&lt;BR /&gt;---- ------------------ ------------------ ------ -------- -----------&lt;BR /&gt;19) 192.168.184.0/22 192.168.184.0/22 any 6 9686885&lt;BR /&gt;20) 192.168.0.0/16 192.168.0.0/16 1433 6 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN class="uiOutputText"&gt;Two examples form fw_mux&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;Connection: &amp;lt;dir 0, 192.168.184.90:41622 -&amp;gt; 192.168.186.20:1433 IPP 6&amp;gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;VM_Connection: &amp;lt;dir 1, 192.168.184.90:41622 -&amp;gt; 192.168.186.20:1433 IPP 6&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Info:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;Path: Slow&lt;/STRONG&gt;, Streaming mode: PSL, InZone: INTERNAL_ZONE, OutZone: UNDEFINED_ZONE, Num of registered apps: 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Rule id: 59, ref count: 2, mux state flags: VM_CONN_WAS_SET ,INSPECT_C2S ,INSPECT_S2C.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;APPS:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;ADVP: app_flags: INSPECT_BOTH, C2S byte skip: 0, S2C byte skip: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;TIER1: app_flags: NO_FLAGS, C2S byte skip: 0, S2C byte skip: 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;Connection: &amp;lt;dir 0, 192.168.100.95:40600 -&amp;gt; 192.168.186.20:1433 IPP 6&amp;gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;VM_Connection: &amp;lt;dir 1, 192.168.100.95:40600 -&amp;gt; 192.168.186.20:1433 IPP 6&amp;gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Info:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Path: Slow, Streaming mode: PSL, InZone: INTERNAL_ZONE, OutZone: UNDEFINED_ZONE, Num of registered apps: 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Rule id: 59, ref count: 2, mux state flags: VM_CONN_WAS_SET ,INSPECT_C2S ,INSPECT_S2C.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;APPS:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;ADVP: app_flags: INSPECT_BOTH, C2S byte skip: 0, S2C byte skip: 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;TIER1: app_flags: NO_FLAGS, C2S byte skip: 0, S2C byte skip: 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Any ideas? hints where should I look for?&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Rafal&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 21:40:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/105183#M8329</guid>
      <dc:creator>Rafal_N</dc:creator>
      <dc:date>2020-12-11T21:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl fast_accel - some traffic still going slow path</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/105196#M8330</link>
      <description>&lt;P&gt;Is it all connections on 1433 not being accelerated or specific ones?&lt;BR /&gt;Recommend a TAC case here.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2020 01:58:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/105196#M8330</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-12T01:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl fast_accel - some traffic still going slow path</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/105236#M8334</link>
      <description>&lt;P&gt;If traffic has to go F2F/slowpath, it cannot be forced into the SXL/accelerated path with fast_accel and will still go F2F.&amp;nbsp; If you can figure out why the SQL traffic is going F2F and fix that, fast_accel should start working.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First off, may I ask how you are getting that "fw_mux" output?&amp;nbsp; I don't recognize it.&lt;/P&gt;
&lt;P&gt;To get the traffic out of F2F, check the following two things:&lt;/P&gt;
&lt;P&gt;1) In the service matching TCP port 1433 try removing any overrides like this, as it is fairly typical to override and increase the session timeout beyond the default on SQL services:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SQL.png" style="width: 592px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9688iB59B8AF45C2D0E36/image-size/large?v=v2&amp;amp;px=999" role="button" title="SQL.png" alt="SQL.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) If you have IPS enabled, check for enabled IPS signatures involving SQL that have a Performance Impact rating of Critical or High.&amp;nbsp; Try disabling them in whatever IPS profile(s) your gateway is using, as one or more of these signatures may be pulling that SQL traffic into F2F.&amp;nbsp; Here are the relevant signatures I see here in my lab:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SQL_IPS.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9690iA123E07E3F7B195D/image-size/large?v=v2&amp;amp;px=999" role="button" title="SQL_IPS.png" alt="SQL_IPS.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If neither of these suggestions help or are not relevant to your environment, please provide the output of command &lt;STRONG&gt;enabled_blades&lt;/STRONG&gt; so I can see what features you have enabled.&lt;/P&gt;
&lt;P&gt;Beyond that TAC will need to run a kernel debug to determine why this SQL traffic is going F2F.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2020 13:36:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/105236#M8334</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-12-12T13:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl fast_accel - some traffic still going slow path</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/105287#M8339</link>
      <description>&lt;P&gt;Hi Timothy,&lt;/P&gt;&lt;P&gt;I'm glad that once I can share something with You &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Output is form fw_mux command that is not documented. I get know about it on TAC Academy with really good coach Alon form CheckPoint HQ. As You probably notice there is no connections with flag F listed any more in &lt;SPAN&gt;fwaccel conns&lt;/SPAN&gt;. The only way I know to print all connections F2F and PXL is that new command (&lt;STRONG&gt;fw_mux&lt;/STRONG&gt;&lt;STRONG&gt; all &amp;gt; file.txt&lt;/STRONG&gt;)&lt;/P&gt;&lt;P&gt;I try to debug a little more with TAC because service looks very standard as in default settings, IPS exceptions between this internal networks is added and yet with 1433 there is a problem. Was hoping that somebody can read something more form that output. Later I try to play with kernel debug but I have to do it some filters.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Rafal&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 19:27:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/105287#M8339</guid>
      <dc:creator>Rafal_N</dc:creator>
      <dc:date>2020-12-13T19:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl fast_accel - some traffic still going slow path</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/132825#M19717</link>
      <description>&lt;P&gt;Hi Rafal,&lt;/P&gt;&lt;P&gt;Did you find any solution to this? I am just starting to try to accelerate ms-sql-s (1433) myself and see 0 hits in 'fw ctl fast_accel show_table' output. I'll open a TAC case as well.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 15:41:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/132825#M19717</guid>
      <dc:creator>miguel</dc:creator>
      <dc:date>2021-10-28T15:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl fast_accel - some traffic still going slow path</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/132827#M19718</link>
      <description>&lt;P&gt;Just check history SR with TAC we had some remote sessions. Didn't find any solution other then clearing all connection form connections table. Please be careful because it will cause all connection to be reestablish.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;fw tab -t connections -x&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm not sure if I solve it at all but I can share with You SR number (pm) and maybe there will be some internal notes made by TAC engineer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Oct 2021 16:12:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/fw-ctl-fast-accel-some-traffic-still-going-slow-path/m-p/132827#M19718</guid>
      <dc:creator>Rafal_N</dc:creator>
      <dc:date>2021-10-28T16:12:21Z</dc:date>
    </item>
  </channel>
</rss>

