<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SecureXL Templates 61000/64000 in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SecureXL-Templates-61000-64000/m-p/25525#M1943</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; color: #1f497d;"&gt;g_fwaccell templates shows all connection templates. Sounds like the system creates 6M templates for this one connection. I would like to understand what kind of connection that might be. A template is created whenever a source port can be masked out (DIP, DPORT and SIP stay the same) and the system works as intended.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Sep 2018 18:02:29 GMT</pubDate>
    <dc:creator>Lari_Luoma</dc:creator>
    <dc:date>2018-09-14T18:02:29Z</dc:date>
    <item>
      <title>SecureXL Templates 61000/64000</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SecureXL-Templates-61000-64000/m-p/25522#M1940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;Hi all,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;Should the value in the ‘Conns’ column of a SecureXL template be counted as&amp;nbsp; a concurrent connection or an indicator how many connections used the particular template? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;For example; for a particular vs I have approx. 50.000 connections in the fw1 &amp;amp; SecureXL connections table (asg_conns). However according ‘asg perf’ output there are over 6.000.000 concurrent connections for that specific vs. This is caused by one particular connection &amp;nbsp;which is accelerated and templated and has the value of 6.000.000 in the ‘Conns’ column. Each time the firewall policy is installed or SecureXL&amp;nbsp; is enabled/disabled the template is cleared and after a week or so the concurrent connections is back around 6 million and increasing. As result SNMP and ‘asg alert’ send email alerts due to the high amount of concurrent of connections which causes noise for the firewall administrator since there is no high load. As workaround the firewall administrator pushes the firewall policy every few days to clear the templates. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;Is this behavior expected or something cosmetic? According TAC (last year), it works as designed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;As a solution we can assign a inspect handler (i.e. SIP) to the service so that each connection is forced to F2F, &amp;nbsp;but again this should not the be to way to solve this issue. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;Anyone else experience this behavior?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;Thank,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.0pt;"&gt;Andre &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2018 06:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SecureXL-Templates-61000-64000/m-p/25522#M1940</guid>
      <dc:creator>Andre_K</dc:creator>
      <dc:date>2018-09-10T06:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates 61000/64000</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SecureXL-Templates-61000-64000/m-p/25523#M1941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't fully understand the problem. You said that there is one connection that causes 6M connections in the connections table. Sounds weird. Can you elaborate this or provide a screenshot? Which command did you use to get the "conns" value?&lt;/P&gt;&lt;P&gt;SecureXL is restarted in policy push, so it's normal that the templates get cleared.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Sep 2018 14:48:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SecureXL-Templates-61000-64000/m-p/25523#M1941</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2018-09-14T14:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates 61000/64000</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SecureXL-Templates-61000-64000/m-p/25524#M1942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none; display: inline !important; float: none;"&gt;Hi Lari,&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV style="caret-color: #000000; color: #000000; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt; &lt;/DIV&gt;&lt;DIV style="caret-color: #000000; color: #000000; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt;Thank you for your reply. I was referring to 6M connections in the ‘Conns’ column for one particular connection when executing the command ‘g_fwaccel templates’ and there are approx 50K connections in &amp;nbsp;the acceleration/fw connections table combined; when executing the command ‘asg_conns'. I am aware that the SecureXL templates are resetted each time a policy install is executed. As mentioned, that is the current workaround for the firewall administrators to get rid of the concurrent connections notifications generated by the chassis.&amp;nbsp;&lt;/DIV&gt;&lt;DIV style="caret-color: #000000; color: #000000; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt; &lt;/DIV&gt;&lt;DIV style="caret-color: #000000; color: #000000; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt;In a nutshell: each connection that passes the specific SecureXL template is added to the conns column and counted as an concurrent connection. The value of the Conns column keeps increasing and does not time out until a policy push. The chassis marks this somehow as an active connections and at the end of the week the template has 6M hits. &amp;nbsp;When executing the command ‘asg perf -vs all -vv’ it shows that there are 6M concurrent connections for that particular VS with only 50K entries in the combined connections table. (and the throughput for that VS is less than a Mb)&lt;/DIV&gt;&lt;DIV style="caret-color: #000000; color: #000000; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt; &lt;/DIV&gt;&lt;DIV style="caret-color: #000000; color: #000000; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt;Unfortunately I am not entitled to share any screenshots with the public.&lt;/DIV&gt;&lt;DIV style="caret-color: #000000; color: #000000; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt; &lt;/DIV&gt;&lt;DIV style="caret-color: #000000; color: #000000; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt;Thanks again.&lt;/DIV&gt;&lt;DIV style="caret-color: #000000; color: #000000; font-family: Helvetica; font-size: 12px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;"&gt; &lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Sep 2018 15:09:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SecureXL-Templates-61000-64000/m-p/25524#M1942</guid>
      <dc:creator>Andre_K</dc:creator>
      <dc:date>2018-09-14T15:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates 61000/64000</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SecureXL-Templates-61000-64000/m-p/25525#M1943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt; color: #1f497d;"&gt;g_fwaccell templates shows all connection templates. Sounds like the system creates 6M templates for this one connection. I would like to understand what kind of connection that might be. A template is created whenever a source port can be masked out (DIP, DPORT and SIP stay the same) and the system works as intended.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Sep 2018 18:02:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SecureXL-Templates-61000-64000/m-p/25525#M1943</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2018-09-14T18:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates 61000/64000</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SecureXL-Templates-61000-64000/m-p/25526#M1944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 8.5pt; color: #004380;"&gt;It’s a connection initiated by a 3prd party which performs remote monitoring by using endpoint monitoring agents. The SIP, DIP and DPORT are indeed the same and the template works as intended. However when that specific template is used and the connection passed through the firewall does this still count as a concurrent connection? I will see if the 3&lt;SUP&gt;rd&lt;/SUP&gt; party is able to adjust their tressholds and see if they can monitor less aggressive. On my next visit to Tel Aviv in the near future I will make sure I run this by the high-end team. Thanks again for your input Lari. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2018 05:17:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/SecureXL-Templates-61000-64000/m-p/25526#M1944</guid>
      <dc:creator>Andre_K</dc:creator>
      <dc:date>2018-09-17T05:17:50Z</dc:date>
    </item>
  </channel>
</rss>

