<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: F2F cluster message in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/F2F-cluster-message/m-p/72803#M14766</link>
    <description>I am well aware of what F2F means, but I want to understand what the 'cluster message' violation reason entails.</description>
    <pubDate>Tue, 21 Jan 2020 08:40:29 GMT</pubDate>
    <dc:creator>Nik_Bloemers</dc:creator>
    <dc:date>2020-01-21T08:40:29Z</dc:date>
    <item>
      <title>F2F cluster message</title>
      <link>https://community.checkpoint.com/t5/General-Topics/F2F-cluster-message/m-p/72798#M14761</link>
      <description>&lt;P&gt;Hello Check Mates,&lt;/P&gt;&lt;P&gt;Can anyone explain what the F2F violation 'cluster message' means?&lt;/P&gt;&lt;P&gt;fwaccel stats -p&lt;BR /&gt;F2F packets:&lt;BR /&gt;--------------&lt;BR /&gt;Violation Packets Violation Packets&lt;BR /&gt;-------------------- --------------- -------------------- ---------------&lt;BR /&gt;pkt has IP options 227 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ICMP miss conn 153026&lt;BR /&gt;TCP-SYN miss conn 327641 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP-other miss conn 28868624&lt;BR /&gt;UDP miss conn &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 295417 other miss conn 10604&lt;BR /&gt;VPN returned F2F 0 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; uni-directional viol 0&lt;BR /&gt;possible spoof viol 11 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TCP state viol 0&lt;BR /&gt;out if not def/accl 0 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bridge, src=dst 0&lt;BR /&gt;routing decision err 0 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sanity checks failed 0&lt;BR /&gt;fwd to non-pivot 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; broadcast/multicast 0&lt;BR /&gt;&lt;STRONG&gt;cluster message 207254&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cluster forward 0&lt;BR /&gt;chain forwarding 0 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; F2V conn match pkts 89454&lt;BR /&gt;general reason 0 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; route changes 0&lt;/P&gt;&lt;P&gt;The ATRG sk for SecureXL explains most values, but not this one. I believe this should normally be 0, so I'm wondering why it's quite high.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 08:10:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/F2F-cluster-message/m-p/72798#M14761</guid>
      <dc:creator>Nik_Bloemers</dc:creator>
      <dc:date>2020-01-21T08:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: F2F cluster message</title>
      <link>https://community.checkpoint.com/t5/General-Topics/F2F-cluster-message/m-p/72800#M14763</link>
      <description>&lt;P&gt;F2F means "forwarded to Firewall", a.k.a "Slow Path". It applies to any packet that cannot or should not be accelerated.&lt;/P&gt;
&lt;P&gt;The term is in fact mentioned in multiple guides and SecureKnowledge articles, for example, in&amp;nbsp;sk153832, quoting:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;"Firewall path&lt;/STRONG&gt;&amp;nbsp;/&amp;nbsp;&lt;STRONG&gt;Slow path&lt;/STRONG&gt;&amp;nbsp;(&lt;STRONG&gt;F2F&lt;/STRONG&gt;) - Packet flow when the SecureXL device is unable to process the packet (refer to&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32578" target="_blank" rel="noopener"&gt;sk32578 - SecureXL Mechanism&lt;/A&gt;). The packet is passed on to the CoreXL layer and then to one of the Core FW instances for full processing. This path also processes all packets when SecureXL is disabled."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Exactly the same statement is used in sk98722.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 08:25:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/F2F-cluster-message/m-p/72800#M14763</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-01-21T08:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: F2F cluster message</title>
      <link>https://community.checkpoint.com/t5/General-Topics/F2F-cluster-message/m-p/72803#M14766</link>
      <description>I am well aware of what F2F means, but I want to understand what the 'cluster message' violation reason entails.</description>
      <pubDate>Tue, 21 Jan 2020 08:40:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/F2F-cluster-message/m-p/72803#M14766</guid>
      <dc:creator>Nik_Bloemers</dc:creator>
      <dc:date>2020-01-21T08:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: F2F cluster message</title>
      <link>https://community.checkpoint.com/t5/General-Topics/F2F-cluster-message/m-p/72815#M14770</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/29143"&gt;@Nik_Bloemers&lt;/a&gt;&amp;nbsp;apologies, I must have misread you original questions.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;There are two answers:&lt;/P&gt;
&lt;P&gt;1. "Violations" here is not a good term. It generally applies to any packet that SXL cannot accelerate. It is meant as a "violation of acceleration". It does not mean there is anything wrong with the traffic.&lt;/P&gt;
&lt;P&gt;2. Cluster messages are all CCP packets. They cannot be accelerates as they should go to CXL for the purposes of sync and health status monitoring.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 09:16:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/F2F-cluster-message/m-p/72815#M14770</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-01-21T09:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: F2F cluster message</title>
      <link>https://community.checkpoint.com/t5/General-Topics/F2F-cluster-message/m-p/72861#M14785</link>
      <description>&lt;P&gt;Val is correct, that counter indicates the CCP traffic.&amp;nbsp; Traffic that is addressed to the firewall itself (i.e. not transiting trying to reach a destination IP that is not the firewall) is never accelerated by SecureXL and always goes F2F.&amp;nbsp; This is expected behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jan 2020 14:42:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/F2F-cluster-message/m-p/72861#M14785</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-01-21T14:42:17Z</dc:date>
    </item>
  </channel>
</rss>

