<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does the Medium Path (PXL) and Content Inspection work with R80 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17813#M3029</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And by the way, Medium Path works exactly the same way in R80 as in R77 and below.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Aug 2018 07:27:52 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2018-08-08T07:27:52Z</dc:date>
    <item>
      <title>How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17811#M3027</link>
      <description>&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67985_pastedImage_1.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the exact processing of the flow with CoreXL and SecureXL? How are the packages processed here?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Q: Why this question?&lt;BR /&gt;A: There are several articles in the forum that currently discuss this thema.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;References to the articles:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/5083" target="_blank"&gt;Check Point Threat Prevention Packet Flow and Architecture - 09-04-2017 (&lt;/A&gt;&lt;A href="https://community.checkpoint.com/migrated-users/43160" target="_blank"&gt;Moti Sagey&lt;/A&gt; &lt;A href="https://community.checkpoint.com/thread/5083" target="_blank"&gt;)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3041" target="_blank"&gt;R80.x Security Gateway Architecture (Logical Packet Flow) - 07-28-2018 (&amp;nbsp;&lt;/A&gt;&lt;A href="https://community.checkpoint.com/migrated-users/55229" target="_blank"&gt;Heiko Ankenbrand&lt;/A&gt; &lt;A href="https://community.checkpoint.com/docs/DOC-3041" target="_blank"&gt;)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/thread/8763" target="_blank"&gt;Simplified Packet Flow document - 08-06-2018 (&amp;nbsp;&lt;/A&gt;&lt;A href="https://community.checkpoint.com/migrated-users/2138" target="_blank"&gt;Valeri Loukine&lt;/A&gt;&amp;nbsp;)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3061" target="_blank"&gt;Security Gateway Packet Flow and Acceleration - with Diagrams - 08-06.2018 (&lt;/A&gt;&lt;A href="https://community.checkpoint.com/migrated-users/2138" target="_blank"&gt;Valeri Loukine&lt;/A&gt; &lt;A href="https://community.checkpoint.com/docs/DOC-3061" target="_blank"&gt;)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;References to SK's:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98722#Introduction" rel="nofollow" target="_blank"&gt;SecureKnowledge: SecureXL&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98737" rel="nofollow" target="_blank"&gt;SecureKnowledge: CoreXL&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;To avoid confusing all users, I think we should clarify this in this article. &lt;BR /&gt;&lt;BR /&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 15px;"&gt;&lt;A href="https://community.checkpoint.com/migrated-users/55229" target="_blank"&gt;Heiko&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 19:58:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17811#M3027</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-20T19:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17812#M3028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://community.checkpoint.com/migrated-users/55229" target="_blank"&gt;Heiko Ankenbrand&lt;/A&gt;, I love the sketch. Apparently you are not only a talented engineer but also a gifted artist. Do you have it in a good resolution?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, to your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SecureXL is the acceleration technology Check Point developed to speed up stateful inspection of authorized connections (packet acceleration) and, in some cases, opening new connections by bypassing slower FW kernel inspection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CoreXL is an add-on that allows utilizing multiple cores for FW processing. It removes a critical FW kernel inspection limitation. By design and because of the nature of kernel memory utilization, a specific connection flow can only be inspected by a single CPU core. CoreXL adds a decision point (SND) allowing sticky static load balancing by designating particular connections to different CPU cores. This decision is being made by SND on the first packet arrival and is based on specific parameters (IPs and ports).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For that specific reason Check Point does not put CoreXL decision point on the packet flow diagram. To do so in a correct, you would have to multiply FW path sections per CPU and put the decision on top of everything, including SecureXL path. Such diagram would be too confusing and impractical to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As an add-on, CoreXL is only effective in tackling traffic with many different sources and destinations. In a rare case where there is only one source and one destination, the flow will hit a single core all the time, and the single core FW kernel bottleneck will still be unavoidable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have already answered this question in&amp;nbsp;&lt;A href="https://community.checkpoint.com/docs/DOC-3061-security-gateway-packet-flow-and-acceleration-with-diagrams" target="_blank"&gt;https://community.checkpoint.com/docs/DOC-3061-security-gateway-packet-flow-and-acceleration-with-diagrams&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:07:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17812#M3028</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-06-21T09:07:47Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17813#M3029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And by the way, Medium Path works exactly the same way in R80 as in R77 and below.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2018 07:27:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17813#M3029</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-08T07:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17814#M3030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the praise and thank you for the explanation. My little daughter helped me to colored the article picture. &lt;SPAN&gt;I can't do this so well&lt;/SPAN&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with you on all counts with one small exception. I have been working with Check Point since about 1998 and have seen all versions since version 3. I have seen a lot of pictures and illustrations on the topic, which try to map the problem with SecureXL, CoreXL and even ClusterXL (see Googel pictures).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I haven't found in the past is an overview of everything. Many users who are new to Check Point products have the problem to understand the context clearly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My idea was to create an overview that describes both worlds. Therefore I tried to unite both worlds in one overview during my vacation (about 24 hours)&amp;nbsp;&lt;A href="https://community.checkpoint.com/docs/DOC-3041"&gt;R80.x Security Gateway Architecture (Logical Packet Flow)&lt;/A&gt;&amp;nbsp; .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since there are both worlds (SecureXL and CoreXL), there must also be a way to map them schematically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hand the ball over to you or Check Point! Do you have an overview that describes this or can we do it together in the Checkmates forum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this is extremely important for all checkmates and all other Check Point users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That would be the challenge for everyone here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/55229"&gt;Heiko&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2018 08:36:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17814#M3030</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-08-08T08:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17815#M3031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now, I do need this picture in high res, please. We will print it out and put on the wall at Check Point. No kidding&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2018 08:51:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17815#M3031</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-08T08:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17816#M3032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As for the matter, we do have plenty of diagrams for CoreXL and packet flows. The issue is, CoreXL decision is made per connection and then maintained per packet. For that reason, it is impossible to put it into packet based diagram. It is just a different dimension. If we agree on this point, everything else fits into place perfectly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2018 08:55:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17816#M3032</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-08T08:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17817#M3033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Give use a A0 (Europe's largest paper format)&amp;nbsp;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #333333; font-family: 'Helvetica Neue',Helvetica,Arial,'Lucida Grande',sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;diagram.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #333333; font-family: 'Helvetica Neue',Helvetica,Arial,'Lucida Grande',sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;"&gt;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/laugh.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2018 11:20:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17817#M3033</guid>
      <dc:creator>Paul__G_</dc:creator>
      <dc:date>2018-08-08T11:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17818#M3034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unless we&amp;nbsp;don't need&amp;nbsp;to make sense out of it later on, that's hardly a solution &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2018 12:08:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17818#M3034</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-08T12:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17819#M3035</link>
      <description>&lt;P&gt;&amp;gt; As an add-on, CoreXL is only effective in tackling traffic with many different sources and destinations. In a rare case where there is only one source and one destination, the flow will hit a single core all the time, and the single core FW kernel bottleneck will still be unavoidable.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This statement is true by default on R77.30, however the Dynamic Dispatcher can be enabled to more evenly balance traffic load amongst the Firewall Workers based on their load.&amp;nbsp; Note that a single "elephant flow" connection can still fully saturate a single Firewall Worker, but new connections will "run away" from the saturated core.&amp;nbsp; In addition once a worker core is fully saturated Priority Queuing becomes active to ensure various "control" traffic like routing updates, SSH sessions, etc are processed in a timely fashion.&amp;nbsp; The Dynamic Dispatcher is not enabled by default on R80.10+ gateway and later.&amp;nbsp; &lt;A style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105261&amp;amp;partition=General&amp;amp;product=CoreXL%22" target="_blank" rel="noopener"&gt;sk105261: CoreXL &lt;STRONG&gt;Dynamic&lt;/STRONG&gt; &lt;STRONG&gt;Dispatcher&lt;/STRONG&gt; in R77.30 / R80.10 and above&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also the recent charts created by &lt;A href="https://community.checkpoint.com/migrated-users/54411" target="_blank" rel="noopener"&gt;Heiko Ankenbrand&lt;/A&gt;‌ are great and have inevitably led to a discussion of the Medium Path (PXL) inner workings.&amp;nbsp; When writing my book I noticed that there was very little documentation about the Medium Path beyond the fact that it was there, and that it implements PSL for the various "Deep Inspection" blades like APCL and Threat Prevention.&amp;nbsp; When asked in class about the difference between PXL and F2F, I would (somewhat inaccurately) gloss over PXL/PSL as an "optimized, shortened sequence of chain modules" whereas traffic going F2F/CPAS would pass through all chain modules as shown by &lt;STRONG&gt;fw ctl chain&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not to rain on everyone's parade as these discussions are great, but there are big changes coming to the Medium Path and SecureXL in R80.20 that can be summarized with this screenshot:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67971_paths.jpg" border="0" alt="" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would seem that the Medium Path has been broken up into several new paths that are being tracked separately, which makes my designation of process space on the firewall as the "fourth path" in the second edition of my book particularly unfortunate.&amp;nbsp; Still in the process of working out all the SecureXL changes for R80.20 that were probably undertaken to support the new Falcon accelerator cards and updated kernel; the R80.20 addendum for my book is looking like it is going to be quite lengthy...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--&lt;BR /&gt;Second Edition of my "Max Power" Firewall Book&lt;BR /&gt;Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank" rel="noopener"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2019 12:56:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17819#M3035</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-10-28T12:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17820#M3036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; color: #333333;"&gt;&lt;EM&gt;&amp;gt; Note that a single "elephant flow" connection can still fully saturate a single Firewall Worker&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Yes, &lt;A href="https://community.checkpoint.com/migrated-users/41625"&gt;Timothy Hall&lt;/A&gt;‌ that was what I meant. Say you open a single iperf flow, you hit the same CPU.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;And thanks for mentioning Medium Path, that's a tough one. I can see here PSLXL and CPASXL that are both two different ways of streaming, both belonging to the Medium Path.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2018 13:59:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17820#M3036</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-08T13:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17821#M3037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;A _jive_internal="true" data-containerid="-1" data-containertype="-1" data-objectid="41625" data-objecttype="3" href="https://community.checkpoint.com/people/thalld401179d-0d5b-369d-a0f2-387c3ef54533"&gt;Timothy&lt;/A&gt;&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, it has been an interesting process in the last few days and nights to reproduce everything correctly in the flowchart. Thanks again to &lt;A href="https://community.checkpoint.com/migrated-users/2138"&gt;Valeri Loukine&lt;/A&gt;&amp;nbsp;, because he supports me well. But all in all, after 20 years of Check Point Firewall, I have once again dealt with the subject in depth. Yes, I also noticed that there are differences between R77.30, R80.10 and R80.20EA by SecureXL. I think we can take a closer look here soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/55229"&gt;Heiko&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2018 14:05:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17821#M3037</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-08-08T14:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17822#M3038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem sir, we are here to help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2018 15:14:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17822#M3038</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-08T15:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17823#M3039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great discussion. There are also subtle differences between R77.30 and R80.10 that are difficult to capture in a flow chart. For instance, in general, in R80.10 there is less reliance on INSPECT handlers which would logically follow the F2F path. This is covered in &lt;A _jive_internal="true" href="https://community.checkpoint.com/thread/6165-services-applications-and-logs-in-sync-in-the-unified-policy"&gt;Services, Applications and Logs in Sync in the Unified Policy&lt;/A&gt;, but summarized below. When cloned and matched by protocol signature, then these would be handled by the CMI and Pattern Matcher signatures.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In R77 with separate policies for firewall and Application Control &amp;amp; URL Filtering there are Services Objects for the firewall policy and Network Service applications for the Application Control policy. In R80.10 this duplication is eliminated and the number of protocol handlers available in the advanced settings for the firewall service objects is reduced from over 200 to less than 20. In its place the default is to match by port in the service object and as an option to clone the service object and enable match by protocol signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. also would like a higher resolution of that picture for my cube &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2018 16:29:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17823#M3039</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2018-08-08T16:29:56Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17824#M3040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Heiko, you can try labeling this image, as it allows for a better spacial perception of the traffic flows using different paths:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Image result for highway intersection picture" src="https://i0.wp.com/usa.streetsblog.org/wp-content/uploads/sites/5/2014/06/55fb18a3ce341ac0883d85da0dd92c75.jpg" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2018 18:03:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17824#M3040</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2018-08-08T18:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17825#M3041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not only that, &lt;A href="https://community.checkpoint.com/migrated-users/2030"&gt;Bob Bent&lt;/A&gt;‌&lt;BR /&gt;&lt;BR /&gt;In R80.X FW Kernel has a new logical debug module called &lt;STRONG&gt;UP&lt;/STRONG&gt; which does most of the heavy lifting for policy inspection and rule matching and only returns the match decision to old classic &lt;STRONG&gt;fw&lt;/STRONG&gt;. Not to mention rulebase matching logic changed.&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 06:02:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17825#M3041</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-09T06:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17826#M3042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;lol&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 06:03:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17826#M3042</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-09T06:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17827#M3043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How about this pic, &lt;A href="https://community.checkpoint.com/migrated-users/55229"&gt;Heiko Ankenbrand&lt;/A&gt;‌? Can we have it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 06:40:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17827#M3043</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-09T06:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17828#M3044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/41625"&gt;Timothy Hall&lt;/A&gt;&amp;nbsp; has raised an interesting point (fw ctl chain).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A very important point in "fw ctl chain" is the following. Very little is mentioned in the documentaries and forums. I find this point very important when considering and debugging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It describes the flow through the chain for specific packages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(00000001) new processed flows&lt;BR /&gt;(00000002) previous processed flows&lt;BR /&gt;(00000003) ciphered traffic&lt;BR /&gt;(ffffffff) Everything&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See Picture from fw ctl chain&lt;IMG __jive_id="67972" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67972_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;I look more and more closely here while debugging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is, can something be used here to make statements about PXL for example "(00000002) previous processed flow"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Or is my thinking wrong!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What I noticed is that I no longer see the parameter (00000002) for R80 in the chain. But it can also be a coincidence:-)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If necessary we should do this independently in another article to understand the depth here.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/55229"&gt;Heiko&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 06:51:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17828#M3044</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-08-09T06:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17829#M3045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is changed &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 06:53:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17829#M3045</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-08-09T06:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: How does the Medium Path (PXL) and Content Inspection work with R80</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17830#M3046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, markings&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;00000002 are for those chains that are working in a "wire" mode. Indeed the chain wire_vm is not loaded in your case.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 07:30:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-does-the-Medium-Path-PXL-and-Content-Inspection-work-with/m-p/17830#M3046</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-09T07:30:17Z</dc:date>
    </item>
  </channel>
</rss>

