<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Securexl R80.30 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/82069#M16585</link>
    <description>&lt;P&gt;hi, Thanks for the information. When i will have a maintenance windows, I will apply this modification.&lt;/P&gt;</description>
    <pubDate>Thu, 16 Apr 2020 06:38:06 GMT</pubDate>
    <dc:creator>LaurentFr</dc:creator>
    <dc:date>2020-04-16T06:38:06Z</dc:date>
    <item>
      <title>Securexl R80.30</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/81527#M16469</link>
      <description>&lt;P&gt;Hi, i have two firewall with weird numbers :&lt;/P&gt;&lt;P&gt;1 firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;fwaccel stat&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;|0 |SND |enabled |eth5,eth1,eth6,eth2,eth3,|&lt;BR /&gt;| | | |eth4 |Acceleration,Cryptography |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,NULL,3DES,DES,CAST, |&lt;BR /&gt;| | | | |CAST-40,AES-128,AES-256,ESP, |&lt;BR /&gt;| | | | |LinkSelection,DynamicVPN, |&lt;BR /&gt;| | | | |NatTraversal,AES-XCBC,SHA256 |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;/P&gt;&lt;P&gt;Accept Templates : enabled&lt;BR /&gt;Drop Templates : disabled&lt;BR /&gt;NAT Templates : enabled&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 3803/38042 (9%)&lt;BR /&gt;Accelerated pkts/Total pkts : 476758453777/898329277875 (53%)&lt;BR /&gt;F2Fed pkts/Total pkts : 475374045/898329277875 (0%)&lt;BR /&gt;F2V pkts/Total pkts : 3137871726/898329277875 (0%)&lt;BR /&gt;CPASXL pkts/Total pkts : 0/898329277875 (0%)&lt;BR /&gt;PSLXL pkts/Total pkts : 421095450053/898329277875 (46%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/898329277875 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/898329277875 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/898329277875 (0%)&lt;/P&gt;&lt;P&gt;enabled_blades&lt;BR /&gt;fw vpn mon vpn&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2nd firewall (the rule 244 is the last before the drop rule)&lt;/P&gt;&lt;P&gt;&amp;nbsp;fwaccel stat&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;BR /&gt;|0 |SND |enabled |eth1,eth2,eth3,Mgmt |Acceleration,Cryptography |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,NULL,3DES,DES,CAST, |&lt;BR /&gt;| | | | |CAST-40,AES-128,AES-256,ESP, |&lt;BR /&gt;| | | | |LinkSelection,DynamicVPN, |&lt;BR /&gt;| | | | |NatTraversal,AES-XCBC,SHA256 |&lt;BR /&gt;+-----------------------------------------------------------------------------+&lt;/P&gt;&lt;P&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;Layer FwInternetIPSEC Security disables template offloads from rule #244&amp;nbsp;&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Drop Templates : enabled&lt;BR /&gt;NAT Templates : disabled by Firewall&lt;BR /&gt;Layer FwInternetIPSEC Security disables template offloads from rule #244&lt;BR /&gt;Throughput acceleration still enabled.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 728/3817 (19%)&lt;BR /&gt;Accelerated pkts/Total pkts : 65933847419/111490474546 (59%)&lt;BR /&gt;F2Fed pkts/Total pkts : 22602056/111490474546 (0%)&lt;BR /&gt;F2V pkts/Total pkts : 81009543/111490474546 (0%)&lt;BR /&gt;CPASXL pkts/Total pkts : 0/111490474546 (0%)&lt;BR /&gt;PSLXL pkts/Total pkts : 45534025071/111490474546 (40%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 28690657512/111490474546 (25%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 37344603189/111490474546 (33%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/111490474546 (0%)&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;enabled_blades&lt;BR /&gt;fw vpn ips qos mon vpn&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have an idea as to why the numbers are so low (especially for&amp;nbsp;Accelerated conns/Total conns) ?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Apr 2020 07:35:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/81527#M16469</guid>
      <dc:creator>LaurentFr</dc:creator>
      <dc:date>2020-04-10T07:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: Securexl R80.30</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/81585#M16490</link>
      <description>IPS and QoS are enabled on the second firewall.&lt;BR /&gt;That's going to reduce the number of fully accelerated connections.&lt;BR /&gt;&lt;BR /&gt;The first firewall has a significant amount of PXL traffic for only having FW, VPN, and Monitoring.&lt;BR /&gt;What services are in your policy?&lt;BR /&gt;</description>
      <pubDate>Sat, 11 Apr 2020 04:37:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/81585#M16490</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-11T04:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: Securexl R80.30</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/81589#M16491</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please disable tls parser on both gw's:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;fw ctl set int&amp;nbsp;&lt;SPAN&gt;tls_parser_enable 0.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Apr 2020 04:52:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/81589#M16491</guid>
      <dc:creator>Ilya_Yusupov</dc:creator>
      <dc:date>2020-04-11T04:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Securexl R80.30</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/81751#M16535</link>
      <description>&lt;P&gt;hi first, thanks for answer.&lt;/P&gt;&lt;P&gt;On the second firewall i have the blade ips activate but not threat prevention policy push on the gateway and i have a few rule for QoS (&amp;lt;10 rules) but a lots of vpn.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;On the first&amp;nbsp; firewall, it s a firewall between internet and our web proxy (we have 50 rule). It 's principaly webservices (http/https).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 09:33:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/81751#M16535</guid>
      <dc:creator>LaurentFr</dc:creator>
      <dc:date>2020-04-14T09:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: Securexl R80.30</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/81752#M16536</link>
      <description>&lt;P&gt;Hi what is&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;tls_parser ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 08:16:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/81752#M16536</guid>
      <dc:creator>LaurentFr</dc:creator>
      <dc:date>2020-04-14T08:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Securexl R80.30</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/81795#M16546</link>
      <description>&lt;P&gt;See this thread, it is a known issue with certain combinations of blades enabled that can cause high PSLXL levels:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/First-impressions-R80-30-on-gateway-one-step-forward-one-or-two/m-p/72593?search-action-id=14282273522&amp;amp;search-result-uid=72593" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/First-impressions-R80-30-on-gateway-one-step-forward-one-or-two/m-p/72593&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 12:05:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/81795#M16546</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-04-14T12:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Securexl R80.30</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/82069#M16585</link>
      <description>&lt;P&gt;hi, Thanks for the information. When i will have a maintenance windows, I will apply this modification.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 06:38:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Securexl-R80-30/m-p/82069#M16585</guid>
      <dc:creator>LaurentFr</dc:creator>
      <dc:date>2020-04-16T06:38:06Z</dc:date>
    </item>
  </channel>
</rss>

