<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Kernel global parameters - the most useful settings in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16967#M2837</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are a couple of useful kernel variables mentioned here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2739"&gt;Best of CheckMates CLI&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that you can also dump every possible kernel variable (both for INSPECT and SecureXL/sim) as described here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33156&amp;amp;partition=Advanced&amp;amp;product=Security" style="max-width: 840px;"&gt;sk33156: Creating a file with &lt;STRONG&gt;all&lt;/STRONG&gt; the &lt;STRONG&gt;kernel&lt;/STRONG&gt; parameters and their values&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did this while performing research for my book and found all kinds of interesting undocumented variables...tweak them at your own risk though...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Second Edition of my "Max Power" Firewall Book&lt;BR /&gt;&lt;SPAN&gt;Now Available at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 16 Nov 2018 14:19:49 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2018-11-16T14:19:49Z</dc:date>
    <item>
      <title>Kernel global parameters - the most useful settings</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16964#M2834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the greatest thing with Check Point products is that you can deeply adapt and customize configuration to fit your needs.&lt;/P&gt;&lt;P&gt;Once, someone from Check Point told me "Check Point, it is a car with manual gear, you really decide how the gateway behaves". Ok why not, but let's stop here this automotive metaphore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing to adapt is kernel global parameters. Every Check Point engineer reguarly have to set specific value for specific architectures, specific constraints, ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See &lt;SPAN style="font-size: 11.0pt;"&gt;SK26202&lt;/SPAN&gt; to know how to set kernel global parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to start a discussion to gather recommandations about kernel parameters&lt;/P&gt;&lt;P&gt;The purpose is not to document here all possible parameters and values, but the most useful, based on your experience.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I start with 2 useful settings that I often configure in my cluster deployments :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;fwha_forw_packet_to_not_active&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Default value : 0. The active member&amp;nbsp; doesn't route packets to the standby member.&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Set it to "1" if you need to join standby's interfaces throught the active member&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;fw_allow_simultaneous_ping&lt;/SPAN&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Default value : 0. You can only ping the virtual IP of the cluster, not the real IP of the active member&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Set it to "1" and you'll ping both.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Based on your inputs, maybe we might then create a configuration script to automate some kernel settings. Open discussion.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Benoit&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2018 08:29:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16964#M2834</guid>
      <dc:creator>Benoit_Verove</dc:creator>
      <dc:date>2018-11-16T08:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Kernel global parameters - the most useful settings</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16965#M2835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's very hard to give "general" recommendations. We have 30+ firewalls in the network and we treat fwkern tweaking carefully as you may create problems if you set wrong parameter on wrong firewall - i.e. whether it's normal or VSX gateway, or chassis or management, what release it is running etc. You would need to keep separate tables depending on those inputs to start with and that might get messy.&lt;/P&gt;&lt;P&gt;But I would certainly recommend to keep your "own set" for your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One that could be fairly generic and we prefer it, is to monitor all VLANs in ClusterXL&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;fwha_monitor_all_vlan=1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Monitors all VLANs in ClusterXL - both in VSX mode and in Gateway mode. Used to discover issues with VLAN configurations or to make sure all VLANs are working properly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2018 09:53:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16965#M2835</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-11-16T09:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Kernel global parameters - the most useful settings</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16966#M2836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kaspars,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your input.&lt;/P&gt;&lt;P&gt;I completly agree : there isn't a single set of settings that could fit for all and such tweaking must be handle with care.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Benoit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2018 10:22:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16966#M2836</guid>
      <dc:creator>Benoit_Verove</dc:creator>
      <dc:date>2018-11-16T10:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Kernel global parameters - the most useful settings</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16967#M2837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are a couple of useful kernel variables mentioned here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2739"&gt;Best of CheckMates CLI&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that you can also dump every possible kernel variable (both for INSPECT and SecureXL/sim) as described here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33156&amp;amp;partition=Advanced&amp;amp;product=Security" style="max-width: 840px;"&gt;sk33156: Creating a file with &lt;STRONG&gt;all&lt;/STRONG&gt; the &lt;STRONG&gt;kernel&lt;/STRONG&gt; parameters and their values&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did this while performing research for my book and found all kinds of interesting undocumented variables...tweak them at your own risk though...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Second Edition of my "Max Power" Firewall Book&lt;BR /&gt;&lt;SPAN&gt;Now Available at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2018 14:19:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16967#M2837</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-11-16T14:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: Kernel global parameters - the most useful settings</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16968#M2838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;prior to R77.30, the most important parameter in fwkern.conf was "MAC magic" and "forward MAC magic".&lt;/P&gt;&lt;P&gt;Some additional parameters related to CUL mechanism and policy installation timeouts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2018 21:07:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16968#M2838</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-11-16T21:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Kernel global parameters - the most useful settings</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16969#M2839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like to add that&amp;nbsp;&lt;SPAN style="border: 0px; font-weight: bold;"&gt;&lt;STRONG&gt;fwha_forw_packet_to_not_active&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN style="font-size: 13px;"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;parameter&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is also connected with solution for many possible issues:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42733" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42733"&gt;Connection from one side of the ClusterXL destined to the physical IP address of a non-Active cluster member…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105539" style="color: #2989c5; text-decoration: none;" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105539"&gt;Simultaneously pinging the cluster members and the VIP address...&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97587" style="color: #2989c5; text-decoration: none;" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk97587"&gt;"Contract entitlement check failed" error on policy installation failure&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42695" style="color: #2989c5; text-decoration: none;" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42695"&gt;Cluster debug shows "FW-1: fwha_forw_ssl_handler: Rejecting ssl packets to a non-active member"&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk118801" style="color: #2989c5; text-decoration: none;" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk118801"&gt;"ERR_CONNECTION_REFUSED" error is displayed in web browser when connecting to Gaia Portal&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112724" style="color: #2989c5; text-decoration: none;" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112724"&gt;Updates For Anti-Virus/Anti-Bot/Application Control/URLF blades are not working on standby ClusterXL member&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42695" style="color: #2989c5; text-decoration: none;" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42695"&gt;Cluster debug shows "FW-1: fwha_forw_ssl_handler: Rejecting ssl packets to a non-active member"&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So, in my opinion, enabling this could be considered a "best practice" even.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Nov 2018 09:20:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16969#M2839</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-11-19T09:20:20Z</dc:date>
    </item>
    <item>
      <title>Re: Kernel global parameters - the most useful settings</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16970#M2840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Don't forget the MSS clamping parameters, specially when a VPN is in the picture you can solve a lot of problems, including performance, by adding MSS Clamping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk101219&amp;amp;partition=General&amp;amp;product=IPSec"&gt;New VPN features in VPN in R77.20&amp;nbsp;and later&lt;/A&gt;&lt;/P&gt;&lt;P&gt;This also requires some changes to another file&amp;nbsp;&lt;STRONG style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;EM&gt;simkern.conf&lt;/EM&gt;. &lt;/STRONG&gt;when applied to a VPN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2018 19:29:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Kernel-global-parameters-the-most-useful-settings/m-p/16970#M2840</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-11-20T19:29:17Z</dc:date>
    </item>
  </channel>
</rss>

