<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Imbalance of f2f and accelerated traffic between security group members in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Imbalance-of-f2f-and-accelerated-traffic-between-security-group/m-p/210692#M2480</link>
    <description>&lt;P&gt;&lt;SPAN&gt;I see a big imbalance in fwaccel stats -s output from two SGMs (Maestro R81.10 JHF Take95). There are no other members in the SG. Here are the outputs:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Member 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;----------------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;fwaccel stats -s&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;----------------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Accelerated conns/Total conns&amp;nbsp; &amp;nbsp; : 0/0 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;LightSpeed conns/Total conns &amp;nbsp; &amp;nbsp; : 0/0 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Accelerated pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;LightSpeed pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;F2Fed pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 73614996/73614996 (100%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;F2V pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;CPASXL pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;PSLXL pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;CPAS pipeline pkts/Total pkts&amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;PSL pipeline pkts/Total pkts &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;CPAS inline pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;PSL inline pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;QOS inbound pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;QOS outbound pkts/Total pkts &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Corrected pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Member 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;----------------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;fwaccel stats -s&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;----------------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Accelerated conns/Total conns&amp;nbsp; &amp;nbsp; : 4476/4498 (99%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;LightSpeed conns/Total conns &amp;nbsp; &amp;nbsp; : 0/4498 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Accelerated pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 1779594854/2163662486 (82%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;LightSpeed pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;F2Fed pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 384067632/2163662486 (17%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;F2V pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 58094845/2163662486 (2%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;CPASXL pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;PSLXL pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 15942198/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;CPAS pipeline pkts/Total pkts&amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;PSL pipeline pkts/Total pkts &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;CPAS inline pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;PSL inline pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;QOS inbound pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;QOS outbound pkts/Total pkts &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Corrected pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Accept and NAT Templates are enabled on both members. They both appear as Active-Active in cphaprob state output, which, I assume, is expected. However, I’m having a hard time understanding the underlying reason for this behavior. Is this by design or am I missing something?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;By the way, I remember reading a post by Tim Hall mentioning that seeing 100% f2f traffic can be expected, but I couldn’t find any resources to either explain it or back it up. Maybe it could be related to my case.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Apr 2024 13:05:58 GMT</pubDate>
    <dc:creator>kamilazat</dc:creator>
    <dc:date>2024-04-08T13:05:58Z</dc:date>
    <item>
      <title>Imbalance of f2f and accelerated traffic between security group members</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Imbalance-of-f2f-and-accelerated-traffic-between-security-group/m-p/210692#M2480</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I see a big imbalance in fwaccel stats -s output from two SGMs (Maestro R81.10 JHF Take95). There are no other members in the SG. Here are the outputs:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Member 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;----------------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;fwaccel stats -s&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;----------------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Accelerated conns/Total conns&amp;nbsp; &amp;nbsp; : 0/0 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;LightSpeed conns/Total conns &amp;nbsp; &amp;nbsp; : 0/0 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Accelerated pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;LightSpeed pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;F2Fed pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 73614996/73614996 (100%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;F2V pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;CPASXL pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;PSLXL pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;CPAS pipeline pkts/Total pkts&amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;PSL pipeline pkts/Total pkts &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;CPAS inline pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;PSL inline pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;QOS inbound pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;QOS outbound pkts/Total pkts &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Corrected pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/73614996 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Member 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;----------------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;fwaccel stats -s&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;----------------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Accelerated conns/Total conns&amp;nbsp; &amp;nbsp; : 4476/4498 (99%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;LightSpeed conns/Total conns &amp;nbsp; &amp;nbsp; : 0/4498 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Accelerated pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 1779594854/2163662486 (82%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;LightSpeed pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;F2Fed pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 384067632/2163662486 (17%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;F2V pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 58094845/2163662486 (2%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;CPASXL pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;PSLXL pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 15942198/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;CPAS pipeline pkts/Total pkts&amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;PSL pipeline pkts/Total pkts &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;CPAS inline pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;PSL inline pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;QOS inbound pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;QOS outbound pkts/Total pkts &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;Corrected pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/2163662486 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Accept and NAT Templates are enabled on both members. They both appear as Active-Active in cphaprob state output, which, I assume, is expected. However, I’m having a hard time understanding the underlying reason for this behavior. Is this by design or am I missing something?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;By the way, I remember reading a post by Tim Hall mentioning that seeing 100% f2f traffic can be expected, but I couldn’t find any resources to either explain it or back it up. Maybe it could be related to my case.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 13:05:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Imbalance-of-f2f-and-accelerated-traffic-between-security-group/m-p/210692#M2480</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-04-08T13:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Imbalance of f2f and accelerated traffic between security group members</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Imbalance-of-f2f-and-accelerated-traffic-between-security-group/m-p/210708#M2481</link>
      <description>&lt;P&gt;Try resetting the counters and then seeing again, you might get a similar number but best to start from scratch&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;g_fwaccel stats -r&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Might be possible that member 2 is processing most of the traffic, perhaps check "asg perf -v -p -c"&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 14:18:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Imbalance-of-f2f-and-accelerated-traffic-between-security-group/m-p/210708#M2481</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2024-04-08T14:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Imbalance of f2f and accelerated traffic between security group members</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Imbalance-of-f2f-and-accelerated-traffic-between-security-group/m-p/210709#M2482</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First check if both members are sync and if they can see the total of packet "asg perf -v" if you can see there are let say 2k packets and 100 are on SGM1 and 1900 on SGM, yes are not balance but if you have like 10 and only 2/8 is not big deal, also check the size of the packet. and if the secureXL is enable on both.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also fwaccel stats -s is not the right way to measure the balance of traffic should be asg perf -v&lt;/P&gt;
&lt;P&gt;Check if you have the L4 enabled on system as well&lt;/P&gt;
&lt;P&gt;gclish -c "show distribution l4-mode"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 14:20:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Imbalance-of-f2f-and-accelerated-traffic-between-security-group/m-p/210709#M2482</guid>
      <dc:creator>Dario_Perez</dc:creator>
      <dc:date>2024-04-08T14:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Imbalance of f2f and accelerated traffic between security group members</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Imbalance-of-f2f-and-accelerated-traffic-between-security-group/m-p/210713#M2483</link>
      <description>&lt;P&gt;100% F2F/slowpath is expected on a standby member of a traditional ClusterXL HA cluster because it is only handling connections to and from itself in standby mode, and those non-transiting connections are always handled F2F.&lt;/P&gt;
&lt;P&gt;For Maestro specifically it is possible that the orchestrator is not sending any connections to member 1, and therefore it is only handling connections to and from itself such as HyperSync.&amp;nbsp; Is there a reasonable diversity of IP addresses talking to each other through the security group?&amp;nbsp; Or is this a lab environment with only a few stations passing traffic?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Use the &lt;STRONG&gt;asg search&lt;/STRONG&gt; command to take a quick look at what transiting connections (if any) are being handled on member 1.&amp;nbsp; Would also recommend running &lt;STRONG&gt;show distribution verification verbose&lt;/STRONG&gt; to ensure you don't have a distribution issue, here are the two pages from my &lt;A href="http://www.maxpowerfirewalls.com/gw-optimization-course.html" target="_blank" rel="noopener"&gt;Gateway Performance Optimization Course&lt;/A&gt; covering these commands for Maestro:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="maestro_A.png" style="width: 952px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25195i64DB3C492BB1EF45/image-size/large?v=v2&amp;amp;px=999" role="button" title="maestro_A.png" alt="maestro_A.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 14:30:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Imbalance-of-f2f-and-accelerated-traffic-between-security-group/m-p/210713#M2483</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-04-08T14:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Imbalance of f2f and accelerated traffic between security group members</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Imbalance-of-f2f-and-accelerated-traffic-between-security-group/m-p/210786#M2484</link>
      <description>&lt;P&gt;Thank you for the information. We are in the process of a production environment analysis. It's a relatively big environment, and I can see close to 1000 different IPs on accelerated connections list. I think the answer for me lies somewhere in distribuion modes, which I'm not even sure if configured at all.&lt;/P&gt;&lt;P&gt;At the same time, your explanation about the non-transiting traffic would explain the 100% f2f, and the number of the packets (73m on M1 vs 2b on M2).&lt;BR /&gt;&lt;BR /&gt;Thank you again for the information!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 08:28:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Imbalance-of-f2f-and-accelerated-traffic-between-security-group/m-p/210786#M2484</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-04-09T08:28:58Z</dc:date>
    </item>
  </channel>
</rss>

