<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fw ctl chain in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188602#M31622</link>
    <description>&lt;P&gt;So as i gone though the&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597" target="_blank" rel="noopener"&gt;@Timothy_Hall&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; Post, its mentioned&amp;nbsp;that when non-accelerated packet travel&amp;nbsp;through&amp;nbsp;firewall&amp;nbsp; it get inspected/checked at four inspection point with&amp;nbsp;fw monitor.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Lets take below example to understand it more clearly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Client Server" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21965i539FEA37A933D3DD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="C S architecture.PNG" alt="Client Server" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Client Server&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;so as per the above diagram client server architecture. we have firewall in between both, and iIoO mentioned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;lets take TCP three way handshake as example in this architecture&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SYN : - eth1 : - pre-inbound "i"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth1 : - post-Inbound "I"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth2 : - pre-outbound "o"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth2 : - post-Outbound "O"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;SYN ACK : - eth2 : - pre-inbound "i"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth 2 : - post-Inbound "I"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth 1 : - Pre-outbound "o"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth 1 : - post-Outbound "O"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;ACK : -&amp;nbsp; eth1 : - pre-inbound "i" &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;eth1 : - Post-inbound "I"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;eth2 : - pre-outbound "o"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;eth2 : - post-outbound "O"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Now here at individual inspection point different2 parameters get checked/inspected as below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;&lt;U&gt;Between i &amp;amp; I&amp;nbsp;&amp;nbsp;&lt;/U&gt;(at client side)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Inbound anti-spoofing&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Geo policy&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;HTTPS/VPN decryption&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;State table lookup (connection table)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Access control policy&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Destination NAT&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;TP policy&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class="lia-align-center"&gt;&lt;U&gt;&lt;STRONG&gt;Between I &amp;amp; o&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;IP Routing&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-center"&gt;&lt;U&gt;&lt;STRONG&gt;Between o &amp;amp; O&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;STRONG&gt;(at Server side)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Outbound Anti-spoofing&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;HTTPS/VPN Encryption&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Source NAT&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kindly correct&amp;nbsp;if if i am going wrong .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks !&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Aug 2023 16:54:41 GMT</pubDate>
    <dc:creator>pavan_kalal</dc:creator>
    <dc:date>2023-08-03T16:54:41Z</dc:date>
    <item>
      <title>fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188572#M31610</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone please explain about the fw monitor ?&lt;/P&gt;&lt;P&gt;traffic get inspected at 4 inspection point with fw monitor as below&lt;/P&gt;&lt;P&gt;i: - pre-inbound&lt;/P&gt;&lt;P&gt;I: - post-inbound&lt;/P&gt;&lt;P&gt;o: - pre-outbound&lt;/P&gt;&lt;P&gt;O: - post-outbound.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now i want to understand what are the parameters get checked at each inspection point ?&lt;/P&gt;&lt;P&gt;also want to understand how to reach (fw ctl chain).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 14:17:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188572#M31610</guid>
      <dc:creator>pavan_kalal</dc:creator>
      <dc:date>2023-08-03T14:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188574#M31611</link>
      <description>&lt;P&gt;Lots of posts about this, but below are 2 best ones (in my opinion)&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/fw-ctl-chain/m-p/125264" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/fw-ctl-chain/m-p/125264&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Check-Point-Inspection-points-iIoO/td-p/34938" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Check-Point-Inspection-points-iIoO/td-p/34938&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;No one explains this better than&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 14:23:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188574#M31611</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-03T14:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188584#M31614</link>
      <description>&lt;P&gt;By the way, if you simply search for fw ctl chain in below field, so many useful things come up.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21964i5A9B2D474F7C7FF6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 14:49:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188584#M31614</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-03T14:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188602#M31622</link>
      <description>&lt;P&gt;So as i gone though the&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597" target="_blank" rel="noopener"&gt;@Timothy_Hall&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; Post, its mentioned&amp;nbsp;that when non-accelerated packet travel&amp;nbsp;through&amp;nbsp;firewall&amp;nbsp; it get inspected/checked at four inspection point with&amp;nbsp;fw monitor.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Lets take below example to understand it more clearly.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Client Server" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21965i539FEA37A933D3DD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="C S architecture.PNG" alt="Client Server" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Client Server&lt;/span&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;so as per the above diagram client server architecture. we have firewall in between both, and iIoO mentioned.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;lets take TCP three way handshake as example in this architecture&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SYN : - eth1 : - pre-inbound "i"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth1 : - post-Inbound "I"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth2 : - pre-outbound "o"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth2 : - post-Outbound "O"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;SYN ACK : - eth2 : - pre-inbound "i"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth 2 : - post-Inbound "I"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth 1 : - Pre-outbound "o"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; eth 1 : - post-Outbound "O"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;ACK : -&amp;nbsp; eth1 : - pre-inbound "i" &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;eth1 : - Post-inbound "I"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;eth2 : - pre-outbound "o"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;eth2 : - post-outbound "O"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;SPAN&gt;Now here at individual inspection point different2 parameters get checked/inspected as below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-center"&gt;&lt;STRONG&gt;&lt;U&gt;Between i &amp;amp; I&amp;nbsp;&amp;nbsp;&lt;/U&gt;(at client side)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Inbound anti-spoofing&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Geo policy&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;HTTPS/VPN decryption&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;State table lookup (connection table)&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Access control policy&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Destination NAT&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;TP policy&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class="lia-align-center"&gt;&lt;U&gt;&lt;STRONG&gt;Between I &amp;amp; o&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;IP Routing&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-center"&gt;&lt;U&gt;&lt;STRONG&gt;Between o &amp;amp; O&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;STRONG&gt;(at Server side)&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Outbound Anti-spoofing&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;HTTPS/VPN Encryption&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Source NAT&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Kindly correct&amp;nbsp;if if i am going wrong .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks !&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 16:54:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188602#M31622</guid>
      <dc:creator>pavan_kalal</dc:creator>
      <dc:date>2023-08-03T16:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188603#M31623</link>
      <description>&lt;P&gt;That looks right to me.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 16:57:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188603#M31623</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-03T16:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188606#M31624</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18403"&gt;@pavan_kalal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not to advertise Tim's book now, but I guarantee you, below is SOOOO WORTH the money. The amount of useful things you can find in the book cant be described with words. I strongly recommend it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.amazon.ca/Max-Power-2020-Optimization-Welch-Abernathy/dp/1652347704/ref=sr_1_1?crid=1U198C9NIZUEI&amp;amp;keywords=timothy+hall&amp;amp;qid=1691083758&amp;amp;sprefix=timothy+hall%2Caps%2C103&amp;amp;sr=8-1#customerReviews" target="_blank"&gt;https://www.amazon.ca/Max-Power-2020-Optimization-Welch-Abernathy/dp/1652347704/ref=sr_1_1?crid=1U198C9NIZUEI&amp;amp;keywords=timothy+hall&amp;amp;qid=1691083758&amp;amp;sprefix=timothy+hall%2Caps%2C103&amp;amp;sr=8-1#customerReviews&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 17:31:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188606#M31624</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-03T17:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188842#M31658</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;can you please help me understanding the fw ctl output ?&lt;/P&gt;&lt;P&gt;I mean so far we discussed i understood about the inspection point’s of fw monitor and the different parameters get inspected at each point.&lt;/P&gt;&lt;P&gt;now i want to know how to read the output of fw ctl chain ? &amp;nbsp;Below&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;PRE&gt;[Expert@MyGW:0]# fw ctl chain&lt;/PRE&gt;&lt;PRE&gt;in chain (17):&lt;/PRE&gt;&lt;PRE&gt;        0: -7fffffff (0000000000000000) (00000000) &lt;SPAN class=""&gt;SecureXL&lt;/SPAN&gt; inbound (sxl_in)&lt;/PRE&gt;&lt;PRE&gt;        1: -7ffffffe (0000000000000000) (00000000) &lt;SPAN class=""&gt;SecureXL&lt;/SPAN&gt; inbound CT (sxl_ct)&lt;/PRE&gt;&lt;PRE&gt;        2: -7f800000 (ffffffff8b6718c0) (ffffffff) IP Options Strip (in) (ipopt_strip)&lt;/PRE&gt;&lt;PRE&gt;        3: -70000000 (ffffffff8b6774d0) (ffffffff) &lt;STRONG&gt;fwmonitor (i/f side)&lt;/STRONG&gt;&lt;/PRE&gt;&lt;PRE&gt;        4: - 1fffff8 (ffffffff8b66f6f0) (00000001) Stateless verifications (in) (asm)&lt;/PRE&gt;&lt;PRE&gt;        5: - 1fffff7 (ffffffff8b66f210) (00000001) fw multik misc proto forwarding&lt;/PRE&gt;&lt;PRE&gt;        6:         0 (ffffffff8b8506a0) (00000001) fw VM inbound  (fw)&lt;/PRE&gt;&lt;PRE&gt;        7:         2 (ffffffff8b671d10) (00000001) fw SCV inbound (scv)&lt;/PRE&gt;&lt;PRE&gt;        8:         4 (ffffffff8b061ed0) (00000003) QoS inbound offload chain module&lt;/PRE&gt;&lt;PRE&gt;        9:         5 (ffffffff8b564d30) (00000003) fw offload inbound (offload_in)&lt;/PRE&gt;&lt;PRE&gt;        10:        10 (ffffffff8b842710) (00000001) fw post VM inbound  (post_vm)&lt;/PRE&gt;&lt;PRE&gt;        11:    100000 (ffffffff8b7fd6c0) (00000001) fw accounting inbound (acct)&lt;/PRE&gt;&lt;PRE&gt;        12:  22000000 (ffffffff8b0638d0) (00000003) QoS slowpath inbound chain mod (fg_sched)&lt;/PRE&gt;&lt;PRE&gt;        13:  70000000 (ffffffff8b6774d0) (ffffffff) &lt;STRONG&gt;fwmonitor (IP  side)&lt;/STRONG&gt;&lt;/PRE&gt;&lt;PRE&gt;        14:  7f730000 (ffffffff8b3c40b0) (00000001) passive streaming (in) (pass_str)&lt;/PRE&gt;&lt;PRE&gt;        15:  7f750000 (ffffffff8b0e5b40) (00000001) TCP streaming (in) (cpas)&lt;/PRE&gt;&lt;PRE&gt;        16:  7f800000 (ffffffff8b671870) (ffffffff) IP Options Restore (in) (ipopt_res)&lt;/PRE&gt;&lt;PRE&gt;out chain (16):&lt;/PRE&gt;&lt;PRE&gt;        0: -7f800000 (ffffffff8b6718c0) (ffffffff) IP Options Strip (out) (ipopt_strip)&lt;/PRE&gt;&lt;PRE&gt;        1: -70000000 (ffffffff8b6774d0) (ffffffff) &lt;STRONG&gt;fwmonitor (i/f side)&lt;/STRONG&gt;&lt;/PRE&gt;&lt;PRE&gt;        2: - 1fffff0 (ffffffff8b0d0190) (00000001) TCP streaming (out) (cpas)&lt;/PRE&gt;&lt;PRE&gt;        3: - 1ffff50 (ffffffff8b3c40b0) (00000001) passive streaming (out) (pass_str)&lt;/PRE&gt;&lt;PRE&gt;        4: - 1f00000 (ffffffff8b66f6f0) (00000001) Stateless verifications (out) (asm)&lt;/PRE&gt;&lt;PRE&gt;        5: -     1ff (ffffffff8aeec0a0) (00000001) NAC Packet Outbound (nac_tag)&lt;/PRE&gt;&lt;PRE&gt;        6:         0 (ffffffff8b8506a0) (00000001) fw VM outbound (fw)&lt;/PRE&gt;&lt;PRE&gt;        7:        10 (ffffffff8b842710) (00000001) fw post VM outbound  (post_vm)&lt;/PRE&gt;&lt;PRE&gt;        8:  15000000 (ffffffff8b062540) (00000003) QoS outbound offload chain modul (fg_pol)&lt;/PRE&gt;&lt;PRE&gt;        9:  21000000 (ffffffff8b0638d0) (00000003) QoS slowpath outbound chain mod (fg_sched)&lt;/PRE&gt;&lt;PRE&gt;        10:  70000000 (ffffffff8b6774d0) (ffffffff) &lt;STRONG&gt;fwmonitor (IP side)&lt;/STRONG&gt;&lt;/PRE&gt;&lt;PRE&gt;        11:  7f000000 (ffffffff8b7fd6c0) (00000001) fw accounting outbound (acct)&lt;/PRE&gt;&lt;PRE&gt;        12:  7f700000 (ffffffff8b0e4660) (00000001) TCP streaming post VM (cpas)&lt;/PRE&gt;&lt;PRE&gt;        13:  7f800000 (ffffffff8b671870) (ffffffff) IP Options Restore (out) (ipopt_res)&lt;/PRE&gt;&lt;PRE&gt;        14:  7f900000 (0000000000000000) (00000000) &lt;SPAN class=""&gt;SecureXL&lt;/SPAN&gt; outbound (sxl_out)&lt;/PRE&gt;&lt;PRE&gt;        15:  7fa00000 (0000000000000000) (00000000) &lt;SPAN class=""&gt;SecureXL&lt;/SPAN&gt; deliver (sxl_deliver)&lt;/PRE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 08 Aug 2023 04:22:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188842#M31658</guid>
      <dc:creator>pavan_kalal</dc:creator>
      <dc:date>2023-08-08T04:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: fw ctl chain</title>
      <link>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188941#M31687</link>
      <description>&lt;P&gt;Bookmark this link, it explains EVERYTHING &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://dkcheckpoint.blogspot.com/2016/07/chapter-2-chain-module.html" target="_blank"&gt;https://dkcheckpoint.blogspot.com/2016/07/chapter-2-chain-module.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2023 12:31:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/fw-ctl-chain/m-p/188941#M31687</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-08T12:31:02Z</dc:date>
    </item>
  </channel>
</rss>

