<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fwaccel does not seems to be running on R81 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106898#M20468</link>
    <description>&lt;P&gt;Did you look into here?&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112454" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112454&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jan 2021 15:17:08 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2021-01-04T15:17:08Z</dc:date>
    <item>
      <title>fwaccel does not seems to be running on R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106774#M20442</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like fwaccel dos rate cidr rules does not seems to be running on firewall. I guess I configured those correctly but I see still traffic is being passed. Am I missing anything here?&lt;/P&gt;&lt;P&gt;Here is the rule&lt;/P&gt;&lt;P&gt;operation=add uid=&amp;lt;5feea76f,00000000,8805a8c0,000036f4&amp;gt; target=all timeout=1309 action=drop log=regular comment=isnti-threat-intel-block service=any source=cidr:30.40.50.0/24 pkt-rate=0&lt;/P&gt;&lt;P&gt;# fwaccel dos config get&lt;BR /&gt;rate limit: enabled (with policy)&lt;BR /&gt;rule cache: enabled&lt;BR /&gt;pbox: enabled&lt;BR /&gt;deny list: enabled (with policy)&lt;BR /&gt;drop frags: disabled&lt;BR /&gt;drop opts: disabled&lt;BR /&gt;internal: disabled&lt;BR /&gt;monitor: disabled&lt;BR /&gt;log drops: enabled&lt;BR /&gt;log pbox: enabled&lt;BR /&gt;notif rate: 100 notifications/second&lt;BR /&gt;pbox rate: 500 packets/second&lt;BR /&gt;pbox tmo: 180 seconds&lt;/P&gt;&lt;P&gt;So my source here is 30.40.50.104 and trying to reach to 192.168.5.129 which is behind 100.101.102.136 FW R81&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jan 2021 04:48:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106774#M20442</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-01-01T04:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: fwaccel does not seems to be running on R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106775#M20443</link>
      <description>&lt;P&gt;Is it working if you add rule explicitly for&amp;nbsp;&lt;SPAN&gt;30.40.50.104 ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jan 2021 06:45:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106775#M20443</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2021-01-01T06:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: fwaccel does not seems to be running on R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106777#M20444</link>
      <description>&lt;P&gt;Yes it does with deny rule but not with dos rate rule&lt;/P&gt;&lt;P&gt;operation=add uid=&amp;lt;5feed217,00000000,8805a8c0,00007b70&amp;gt; target=all timeout=469 action=drop log=regular comment=Test service=any source=range:30.40.50.104 pkt-rate=0&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jan 2021 07:41:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106777#M20444</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-01-01T07:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: fwaccel does not seems to be running on R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106884#M20464</link>
      <description>&lt;P&gt;Looking at the output of "fwaccel dos config get" I see that enforcement for internal interfaces is disabled (which is the default behavior).&lt;/P&gt;
&lt;P&gt;Is it possible that the traffic from 30.40.50.0/24 is arriving at an internal interface?&amp;nbsp; sk112454 has details on this:&amp;nbsp; look for the paragraph titled "Enable Enforcement for Internal Interfaces"&lt;/P&gt;
&lt;P&gt;Also, I see you rule is configured to have a timeout.&amp;nbsp; Note that the timeout is in seconds.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 12:40:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106884#M20464</guid>
      <dc:creator>Eric_Dale</dc:creator>
      <dc:date>2021-01-04T12:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: fwaccel does not seems to be running on R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106894#M20466</link>
      <description>&lt;P&gt;This is not the case for sure. I confirmed that traffic is coming through external network. And yes even tried enabling the flag --enable-internal-network however even after that traffic was not getting blocked.&lt;/P&gt;&lt;P&gt;Is this a bug?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 14:53:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106894#M20466</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-01-04T14:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: fwaccel does not seems to be running on R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106898#M20468</link>
      <description>&lt;P&gt;Did you look into here?&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112454" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112454&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 15:17:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106898#M20468</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-01-04T15:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: fwaccel does not seems to be running on R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106901#M20469</link>
      <description>&lt;P&gt;Assuming your rule UID is "&amp;lt;5feea76f,00000000,8805a8c0,000036f4&amp;gt;", does &lt;STRONG&gt;fwaccel dos rate counters "&amp;lt;5feea76f,00000000,8805a8c0,000036f4&amp;gt;"&lt;/STRONG&gt; return any data?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If not, then what happens if you try to run the command &lt;STRONG&gt;fwaccel_dos_rate_install&lt;/STRONG&gt; in expert mode?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 15:20:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106901#M20469</guid>
      <dc:creator>Eric_Dale</dc:creator>
      <dc:date>2021-01-04T15:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: fwaccel does not seems to be running on R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106905#M20470</link>
      <description>&lt;P&gt;It seems like you created the rule using "fwaccel dos rate add".&amp;nbsp;&amp;nbsp; If you used "fw samp" to create the rule, then the problem may be that you need to perform a "flush true".&lt;/P&gt;
&lt;P&gt;For reference, here's what I see when I create a similar rule (using fwaccel dos rate add) and then do &lt;STRONG&gt;watch -n .1 'fwaccel dos rate counters "&amp;lt;5ff335d1,00000000,335016ac,0000723b&amp;gt;"':&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;==================================================&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Rule UID: &amp;lt;5ff335d1,00000000,335016ac,0000723b&amp;gt;&lt;BR /&gt;Policy: 2&lt;BR /&gt;FW Index: -1&lt;BR /&gt;SecureXL Index: 1&lt;BR /&gt;Timeout: unlimited&lt;BR /&gt;Max Concurrent Connections: unlimited&lt;BR /&gt;New Connection Rate: unlimited&lt;BR /&gt;Packet Rate: 0&lt;BR /&gt;Byte Rate: unlimited&lt;BR /&gt;Max Concurrent Connections Ratio: unlimited&lt;BR /&gt;New Connection Rate Ratio: unlimited&lt;BR /&gt;Packet Rate Ratio: unlimited&lt;BR /&gt;Byte Rate Ratio: unlimited&lt;BR /&gt;Action: drop&lt;BR /&gt;Log Type: regular&lt;BR /&gt;Concurrent Connections: 0&lt;BR /&gt;Connection Rate: 0&lt;BR /&gt;Packets: 5&lt;BR /&gt;Bytes: 490&lt;BR /&gt;Violated Limits: packets-per-second &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;==================================================&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The "violated limits" line item should indicate that the rule is being violated, but only while packets are being sent from the blocked host.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 15:44:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106905#M20470</guid>
      <dc:creator>Eric_Dale</dc:creator>
      <dc:date>2021-01-04T15:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: fwaccel does not seems to be running on R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106916#M20472</link>
      <description>&lt;P&gt;well&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/39958"&gt;@Eric_Dale&lt;/a&gt;&amp;nbsp;this only happens with fwaccel dos and I am trying to achieve for networks since I am already using fwaccel dos deny for hosts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 17:04:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106916#M20472</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-01-04T17:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: fwaccel does not seems to be running on R81</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106917#M20473</link>
      <description>&lt;P&gt;Let me try with counters and keep you posted.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2021 17:05:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fwaccel-does-not-seems-to-be-running-on-R81/m-p/106917#M20473</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-01-04T17:05:05Z</dc:date>
    </item>
  </channel>
</rss>

