<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clarification Needed on fwaccel stat in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252954#M42400</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/100677"&gt;@RemoteUser&lt;/a&gt;&amp;nbsp;even if &lt;STRONG&gt;fwaccel stat&lt;/STRONG&gt; reports "Accept templates: enabled",&amp;nbsp; the&amp;nbsp;"Accelerated conns/Total conns" part of &lt;STRONG&gt;fwaccel stats -s&lt;/STRONG&gt;&amp;nbsp;may always report zero, and &lt;STRONG&gt;fwaccel templates -s&lt;/STRONG&gt; may perennially report zero as well.&amp;nbsp; This can be diagnosed with the &lt;STRONG&gt;fwaccel templates -R&lt;/STRONG&gt; option added in R81.20, which will report a high percentage of "Prevented by Policy rules".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This situation is not the end of the world, and simply means that for the start of every new connection, a full rulebase lookup against the Firewall blade will always be required in the F2F/slowpath, with no accept template formation or matching possible.&amp;nbsp; This is generally caused by at least one of the following situations being present:&lt;/P&gt;
&lt;P&gt;1) In your first layer (ordered mode), or top/parent layer (non-sub-rules for inline mode), you have any blade other than Firewall enabled.&amp;nbsp; &amp;nbsp;If you do this the templating rate will always be zero, as enabling any other blades in that top/first layer makes matching against entities other than IP addresses and port numbers possible, which accept templating cannot handle.&lt;/P&gt;
&lt;P&gt;2) Use of services in a rule with "Protocol Signature" set in their Advanced Properties; this option is never enabled by default.&amp;nbsp; Utilization of these services in the policy will need to invoke Medium Path streaming to complete that first rulebase lookup for a new connection, which causes dramatically more CPU overhead and is wholly incompatible with the use of accept templates.&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jul 2025 14:16:50 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2025-07-10T14:16:50Z</dc:date>
    <item>
      <title>Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252862#M42374</link>
      <description>&lt;P data-start="87" data-end="193"&gt;Hi,&lt;BR data-start="90" data-end="93" /&gt;What does this indicate? It's not very clear to me do we need to make any changes?&lt;BR data-start="177" data-end="180" /&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;Layer Policy Security disables template offloads from rule #xxxx&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Drop Templates : disabled&lt;BR /&gt;NAT Templates : disabled by Firewall&lt;BR /&gt;Layer Policy Security disables template offloads from rule #xxxx&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;LightSpeed Accel : disabled&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 14:35:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252862#M42374</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-07-09T14:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252864#M42375</link>
      <description>&lt;P&gt;Did you read&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk32578" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk32578: SecureXL Mechanism&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 14:39:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252864#M42375</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-07-09T14:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252865#M42376</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;BR /&gt;Yes, but what is mean&amp;nbsp;&lt;SPAN&gt;disables template offloads from rule #xxxx?&lt;BR /&gt;It's affects something or not?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 14:57:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252865#M42376</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-07-09T14:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252866#M42377</link>
      <description>&lt;P&gt;I would say if anyone on this planet can explain this perfectly, its&amp;nbsp;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 15:09:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252866#M42377</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-09T15:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252867#M42378</link>
      <description>&lt;P&gt;Remove rule&amp;nbsp;&lt;SPAN&gt;#xxxx if it is not needed, or move it all the way down in rulebase.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Most of the time rule contains traceroute or ALL_DCE_RPC ports for Windows&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Show the relevant rule. After this rule no performance optimization. All rules below&amp;nbsp;#xxxx&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 15:17:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252867#M42378</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-07-09T15:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252868#M42379</link>
      <description>&lt;P&gt;What is the rule# relative to the policy size?&lt;/P&gt;
&lt;P&gt;Commonly this would be due to a specific objects like DCOM, RPC, DCE, snmp-readonly, rip-response which are optimally put lower in the rule base but other potential reasons are documented in sk32578.&lt;/P&gt;
&lt;P&gt;You can move the rule lower down or remove offending object to improve templating.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 15:33:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252868#M42379</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-07-09T15:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252869#M42380</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Make sure this is enabled (what I attached)&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 15:52:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252869#M42380</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-09T15:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252870#M42381</link>
      <description>&lt;P&gt;Also, can you send output of below?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@R82:0]# fwaccel templates&lt;BR /&gt;The templates table is empty&lt;BR /&gt;[Expert@R82:0]# fwaccel templates -s&lt;/P&gt;
&lt;P&gt;Total number of templates: 0&lt;BR /&gt;[Expert@R82:0]#&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 15:58:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252870#M42381</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-09T15:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252872#M42382</link>
      <description>&lt;P&gt;That's in my cluster it's not enable..&lt;BR /&gt;What is the purpose of this?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 16:33:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252872#M42382</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-07-09T16:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252874#M42383</link>
      <description>&lt;P&gt;this is the rule, maybe this service it's the root cause:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AD_dec.png" style="width: 629px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30919iD202472C2DA5DB43/image-size/large?v=v2&amp;amp;px=999" role="button" title="AD_dec.png" alt="AD_dec.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 16:34:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252874#M42383</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-07-09T16:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252875#M42384</link>
      <description>&lt;DIV id="mc-main-content" role="main"&gt;
&lt;UL class="listbullet"&gt;
&lt;LI class="listbullet"&gt;&lt;STRONG class="bold"&gt;Firewall Policy Optimization&lt;/STRONG&gt;
&lt;P class="listcontinue"&gt;Enable or disable firewall drop optimization to improve gateway resource consumption during periods of heavy traffic load. Let SecureXL handle traffic that the firewall policy determines should be dropped.&lt;/P&gt;
&lt;P class="listcontinue"&gt;Not enabling this option means that only &lt;STRONG class="bold"&gt;Allowed&lt;/STRONG&gt; connections are off loaded to SecureXL, leaving the gateway to handle connections that should be dropped or rejected. For more, see:&lt;/P&gt;
&lt;UL class="listbullet2"&gt;
&lt;LI class="listbullet2"&gt;&lt;A class="tpjumpexternaltemplate" href="https://support.checkpoint.com/results/sk/sk90861" target="_blank" rel="noopener"&gt;sk90861&lt;/A&gt;&lt;/LI&gt;
&lt;LI class="listbullet2"&gt;&lt;A class="tpjumpexternaltemplate" href="https://support.checkpoint.com/results/sk/sk90941" target="_blank" rel="noopener"&gt;sk90941&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;</description>
      <pubDate>Wed, 09 Jul 2025 16:35:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252875#M42384</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-09T16:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252876#M42385</link>
      <description>&lt;P&gt;What happens to the rules that come after this one? This is what I want to understand?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 16:35:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252876#M42385</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-07-09T16:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252878#M42386</link>
      <description>&lt;P&gt;so nowadays it would always seem better to enable it....&lt;BR /&gt;thanks a lot&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 16:39:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252878#M42386</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-07-09T16:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252879#M42387</link>
      <description>&lt;P&gt;Yes, I would, 100%&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jul 2025 16:43:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252879#M42387</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-09T16:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252907#M42391</link>
      <description>&lt;P&gt;The main outcome is that your policy has a rule with one of the SecureXL limitations affecting acceleration with templates. Below that rule, templates will not be applied. Depending on how many rules are in your rulebase and how high that limiting rule is placed in your policy, it may negatively affect the performance of your GW. From reading the discussion, I see that the DCE-RPC service is most probably the root cause.&lt;BR /&gt;&lt;BR /&gt;The recommendation is to see if you can remove or edit this rule to overcome the limitation (for example, change DCE to ANY)&amp;nbsp; or push it as deep as possible in your rulebase.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 08:05:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252907#M42391</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-10T08:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252922#M42393</link>
      <description>&lt;P&gt;I put in disable the rule affected.&lt;BR /&gt;I have one question... If under the rule affected i have a lot vpn s2s, it's possible that those rule may be affected or not?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 09:53:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252922#M42393</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-07-10T09:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252925#M42394</link>
      <description>&lt;P&gt;After disabling the rule and re-installing the policy, check fwaccel stat again to see if there is any other issue with templates.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 10:25:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252925#M42394</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-10T10:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252926#M42395</link>
      <description>&lt;P&gt;After disabling the rule, now it's semmes ok&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 10:26:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252926#M42395</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-07-10T10:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252927#M42396</link>
      <description>&lt;P&gt;Now, you get your answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 10:27:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252927#M42396</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-10T10:27:56Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Needed on fwaccel stat</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252930#M42397</link>
      <description>&lt;P&gt;Great job bro!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 11:43:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Needed-on-fwaccel-stat/m-p/252930#M42397</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-10T11:43:54Z</dc:date>
    </item>
  </channel>
</rss>

