<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New SecureXL path in R80.20 (CPASXL) in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30853#M6451</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;F2V is a decryption module in your case. Considering you need to decrypt before making a decision to inspect or not, lower F2F rate makes perfect sense. Some decrypted packages may still be accelerated without any need for further inspection in F2F path&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Jan 2019 06:18:43 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2019-01-09T06:18:43Z</dc:date>
    <item>
      <title>New SecureXL path in R80.20 (CPASXL)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30842#M6440</link>
      <description>&lt;P&gt;What I notice more and more in the last years is CPAS (&lt;SPAN style="color: #4e4e4e; font-size: 15px;"&gt;Check Point&lt;/SPAN&gt; Active Streaming).&amp;nbsp;With increased https, the firewall workers are more and more stressed if https inspection is enabled. Now also CPAS use the SecureXL path in R80.20. CPAS works through the F2F path in R80.10 and R77.30. Now &lt;STRONG&gt;CPASXL&lt;/STRONG&gt; is offered in &lt;STRONG&gt;SecureXL&lt;/STRONG&gt; path &lt;STRONG&gt;in R80.20&lt;/STRONG&gt;. This should lead to a higher performance. "fwaccel stats -s" shows the new path in R80.20. I think PXL was renamed to PSLXL. This is from my point of view the politically correct better term.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #4e4e4e; font-size: 15px;"&gt;Check Point Active Streaming active streaming allow the changing of data and play the role of “man in the middle”. Several protocols uses CPAS, for example: Client Authentication, VoIP (SIP, Skinny/SCCP, H.323, etc.), Data Leak Prevention (DLP) blade, Security Servers processes, etc. I think it's not to be underestimated in tuning.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #4e4e4e; font-size: 15px;"&gt;# &lt;STRONG&gt;fwaccel stats -s&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #4e4e4e; font-size: 15px;"&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71003_pastedImage_2.png" border="0" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have already discussed this here with &lt;SPAN class=""&gt;&lt;A href="https://community.checkpoint.com/people/thalld401179d-0d5b-369d-a0f2-387c3ef54533" data-userid="41625" data-username="thalld401179d-0d5b-369d-a0f2-387c3ef54533" target="_blank"&gt;Timothy Hall &lt;/A&gt;&lt;/SPAN&gt;&lt;A href="https://community.checkpoint.com/videos/7989" target="_blank"&gt;Security Gateway Performance Optimization Excerpt&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe Check Point can give us more information here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had adapt CPASXL and PSLXL to the following article:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3041" target="_blank"&gt;R80.x Security Gateway Architecture (Logical Packet Flow)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3073" target="_blank"&gt;R80.x Security Gateway Architecture (Content Inspection)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 20:22:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30842#M6440</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-20T20:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: New SecureXL path in R80.20 (CPASXL)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30843#M6441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Heiko,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the information, thats an interesting finding. Do you have any idea, what the "F2V" is? Another acceleration path?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="SecureXL Paths" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/71019_2018-09-28 10_43_07-A-GUI - VMware Workstation.png" /&gt;&lt;/P&gt;&lt;P&gt;I hope that Check Point can add some information here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 08:46:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30843#M6441</guid>
      <dc:creator>Martin_Krolikow</dc:creator>
      <dc:date>2018-09-28T08:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: New SecureXL path in R80.20 (CPASXL)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30844#M6442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;F2V - Forward to VPN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 10:51:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30844#M6442</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-09-28T10:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: New SecureXL path in R80.20 (CPASXL)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30845#M6443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, Valeri! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 10:52:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30845#M6443</guid>
      <dc:creator>Martin_Krolikow</dc:creator>
      <dc:date>2018-09-28T10:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: New SecureXL path in R80.20 (CPASXL)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30846#M6444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 11:00:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30846#M6444</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-09-28T11:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: New SecureXL path in R80.20 (CPASXL)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30847#M6445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now you can see in R80.20 the "F2F streaming path" and "medium streaming path" for PSL and CPAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# fwaccel stat&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="71036" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71036_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be a R80.20 fan!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nice, nice, nice!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will adapt "inline streaming path" and "medium streaming path" to the following article:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2030" data-containertype="14" data-objectid="3041" data-objecttype="102" href="https://community.checkpoint.com/docs/DOC-3041-r80x-security-gateway-architecture-logical-packet-flow"&gt;R80.x Security Gateway Architecture (Logical Packet Flow)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" data-containerid="2030" data-containertype="14" data-objectid="3073" data-objecttype="102" href="https://community.checkpoint.com/docs/DOC-3073-r80x-security-gateway-architecture-content-inspection"&gt;R80.x Security Gateway Architecture (Content Inspection)&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="" data-containerid="-1" data-containertype="-1" data-objectid="55229" data-objecttype="3" href="https://community.checkpoint.com/people/h.ank2614aef2-c5d1-3f73-bbbd-45c59b9e2728"&gt;Heiko&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 11:48:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30847#M6445</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-09-28T11:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: New SecureXL path in R80.20 (CPASXL)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30848#M6446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i would not do that. both are parts of PXL&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 12:03:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30848#M6446</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-09-28T12:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: New SecureXL path in R80.20 (CPASXL)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30849#M6447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A _jive_internal="true" data-avatarid="2183" data-externalid="" data-online="false" data-presence="null" data-userid="2138" data-username="vlouk80ce7dc1-40a3-44d6-a227-b5782636a5cb" href="https://community.checkpoint.com/people/vlouk80ce7dc1-40a3-44d6-a227-b5782636a5cb"&gt;Valeri,&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not change the drawing:-)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have only included the new designations in the text.&lt;BR /&gt;- PSLXL&lt;BR /&gt;- CPASXL&lt;BR /&gt;- Medium Streaming Path&amp;nbsp;&amp;nbsp; &amp;gt; for medium path&lt;/P&gt;&lt;P&gt;- Inline Streaming Path&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt; for F2F path&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="" data-containerid="-1" data-containertype="-1" data-objectid="55229" data-objecttype="3" href="https://community.checkpoint.com/people/h.ank2614aef2-c5d1-3f73-bbbd-45c59b9e2728"&gt;Heiko&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 12:11:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30849#M6447</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-09-28T12:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: New SecureXL path in R80.20 (CPASXL)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30850#M6448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have commented on one of your documents already. It is not about the drawing, it is about correct terminology&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 12:17:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30850#M6448</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-09-28T12:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: New SecureXL path in R80.20 (CPASXL)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30851#M6449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exciting command show's anti spoofing ranges:-)&lt;/P&gt;&lt;P&gt;You have to take a closer look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# &lt;STRONG&gt;fwaccel ranges&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="71038" class="image-1 jive-image" height="329" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71038_pastedImage_1.png" width="316" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="" data-containerid="-1" data-containertype="-1" data-objectid="55229" data-objecttype="3" href="https://community.checkpoint.com/people/h.ank2614aef2-c5d1-3f73-bbbd-45c59b9e2728"&gt;Heiko&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2018 14:24:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30851#M6449</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-09-28T14:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: New SecureXL path in R80.20 (CPASXL)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30852#M6450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is F2V used for HTTPS inspection as well?&amp;nbsp; I have HTTPS inspection enabled on an R80.20 firewall, but no VPN functions, yet 73% of my packets are hitting F2V:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@&amp;lt;removed&amp;gt;]# fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 0/6762 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 136454042/718363754 (18%)&lt;BR /&gt;F2Fed pkts/Total pkts : 445455764/718363754 (62%)&lt;BR /&gt;F2V pkts/Total pkts : 527371395/718363754 (73%)&lt;BR /&gt;CPASXL pkts/Total pkts : 9670829/718363754 (1%)&lt;BR /&gt;PSLXL pkts/Total pkts : 126783119/718363754 (17%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/718363754 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/718363754 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/718363754 (0%)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure how 62% can be F2Fed and 73% be F2V.&amp;nbsp; Must be some sort of overlap, or fuzzy math&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2019 19:27:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30852#M6450</guid>
      <dc:creator>phlrnnr</dc:creator>
      <dc:date>2019-01-08T19:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: New SecureXL path in R80.20 (CPASXL)</title>
      <link>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30853#M6451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;F2V is a decryption module in your case. Considering you need to decrypt before making a decision to inspect or not, lower F2F rate makes perfect sense. Some decrypted packages may still be accelerated without any need for further inspection in F2F path&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2019 06:18:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/New-SecureXL-path-in-R80-20-CPASXL/m-p/30853#M6451</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-01-09T06:18:43Z</dc:date>
    </item>
  </channel>
</rss>

