<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Accelerated SYNC Connections in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216234#M2629</link>
    <description>&lt;P&gt;From the very same SK I just gave you:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H3 id="Acceleration of packets"&gt;&lt;EM&gt;(1) Acceleration of packets&lt;/EM&gt;&lt;/H3&gt;
&lt;P&gt;&lt;EM&gt;When SecureXL is enabled, all packets should be accelerated,&amp;nbsp;&lt;STRONG&gt;except&lt;/STRONG&gt;&amp;nbsp;packets that match the following conditions:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;........&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;EM&gt;IPsec VPN Visitor Mode packets.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Visitor means TLS is used instead of IPsec, and it needs to be terminated on the FW itself, which basically falls into the same "no acceleration of packets going to and from FW" line.&lt;BR /&gt;&lt;BR /&gt;Disable Visitor Mode and see if it makes any difference.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Jun 2024 13:55:22 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2024-06-03T13:55:22Z</dc:date>
    <item>
      <title>Accelerated SYNC Connections</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216221#M2623</link>
      <description>&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;On Maestro R81.10 JHF Take 139, we are seeing a high rate of F2F traffic on the SGMs.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When we looked at fw_tab_t_connections_u (slow-path connections table) we saw that the SYNC connections comprise the majority of the total connections there. After that comes the interface that RA clients connect to.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SYNC interface:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;0&amp;nbsp; &amp;nbsp; x.x.x.15 &amp;nbsp; &amp;nbsp; &amp;nbsp; 50070&amp;nbsp; x.x.x.1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2010 &amp;nbsp; 6 &amp;nbsp; TCP Estab. &amp;nbsp; &amp;nbsp; &amp;nbsp; 3600/3600&amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp; Connection non-accel(EXFLAG set)&amp;nbsp; 4.88M &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.61GB &amp;nbsp; &amp;nbsp; &amp;nbsp; 16h50m30s &amp;nbsp; 0s&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The VLAN that RA clients connect to (shown as a.b.c.d, the e.f.g.h is a placeholder for arbitrary RA IPs):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line&amp;nbsp; 46: 0&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 5921 &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; 6 &amp;nbsp; TCP Estab. &amp;nbsp; &amp;nbsp; &amp;nbsp; 3598/3600&amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp; Local incoming conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.86M &amp;nbsp; &amp;nbsp; &amp;nbsp; 488.61MB &amp;nbsp; &amp;nbsp; 7h26m51s&amp;nbsp; &amp;nbsp; 2s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line&amp;nbsp; 62: 0&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 1653 &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; 6 &amp;nbsp; TCP Estab. &amp;nbsp; &amp;nbsp; &amp;nbsp; 3597/3600&amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp; Local incoming conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2.28M &amp;nbsp; &amp;nbsp; &amp;nbsp; 464.45MB &amp;nbsp; &amp;nbsp; 6h30m36s&amp;nbsp; &amp;nbsp; 2s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line&amp;nbsp; 79: 1&amp;nbsp; &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 5921 &amp;nbsp; 6 &amp;nbsp; Link&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line&amp;nbsp; 81: 0&amp;nbsp; &amp;nbsp; e.f.g.h&amp;nbsp; 53275 &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; 6 &amp;nbsp; TCP Estab. &amp;nbsp; &amp;nbsp; &amp;nbsp; 3595/3600&amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp; Local incoming conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 671.68K &amp;nbsp; &amp;nbsp; 193.26MB &amp;nbsp; &amp;nbsp; 7h1m5s&amp;nbsp; &amp;nbsp; &amp;nbsp; 5s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 216: 1&amp;nbsp; &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 53275&amp;nbsp; 6 &amp;nbsp; Link&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 255: 1&amp;nbsp; &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 1653 &amp;nbsp; 6 &amp;nbsp; Link&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 287: 1&amp;nbsp; &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 48395&amp;nbsp; 6 &amp;nbsp; Link&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 291: 1&amp;nbsp; &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 1858 &amp;nbsp; 6 &amp;nbsp; Link&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 315: 1&amp;nbsp; &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 8253 &amp;nbsp; 6 &amp;nbsp; Link&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 357: 0&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 3570 &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; 6 &amp;nbsp; TCP Estab. &amp;nbsp; &amp;nbsp; &amp;nbsp; 3593/3600&amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp; Local incoming conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.79K &amp;nbsp; &amp;nbsp; &amp;nbsp; 310.62KB &amp;nbsp; &amp;nbsp; 14m27s&amp;nbsp; &amp;nbsp; &amp;nbsp; 7s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 384: 1&amp;nbsp; &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 3570 &amp;nbsp; 6 &amp;nbsp; Link&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 394: 0&amp;nbsp; &amp;nbsp; e.f.g.h&amp;nbsp; 48395 &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; 6 &amp;nbsp; TCP Estab. &amp;nbsp; &amp;nbsp; &amp;nbsp; 3598/3600&amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp; Local incoming conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.71M &amp;nbsp; &amp;nbsp; &amp;nbsp; 390.99MB &amp;nbsp; &amp;nbsp; 8h46m4s &amp;nbsp; &amp;nbsp; 0s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 407: 0&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 1858 &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; 6 &amp;nbsp; TCP Estab. &amp;nbsp; &amp;nbsp; &amp;nbsp; 3598/3600&amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp; Local incoming conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.27M &amp;nbsp; &amp;nbsp; &amp;nbsp; 436.31MB &amp;nbsp; &amp;nbsp; 9h24m25s&amp;nbsp; &amp;nbsp; 0s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 486: 0&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 8253 &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; 6 &amp;nbsp; TCP Estab. &amp;nbsp; &amp;nbsp; &amp;nbsp; 3600/3600&amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp; Local incoming conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 591.67K &amp;nbsp; &amp;nbsp; 146.13MB &amp;nbsp; &amp;nbsp; 8h10m59s&amp;nbsp; &amp;nbsp; 0s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 518: 1&amp;nbsp; &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 9597 &amp;nbsp; 6 &amp;nbsp; Link&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 558: 1&amp;nbsp; &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 50137&amp;nbsp; 6 &amp;nbsp; Link&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 596: 0&amp;nbsp; &amp;nbsp; e.f.g.h&amp;nbsp; 50137 &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; 6 &amp;nbsp; TCP Estab. &amp;nbsp; &amp;nbsp; &amp;nbsp; 3600/3600&amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp; Local incoming conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 617.45K &amp;nbsp; &amp;nbsp; 250.11MB &amp;nbsp; &amp;nbsp; 10h50m53s &amp;nbsp; 0s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 646: 0&amp;nbsp; &amp;nbsp; e.f.g.h &amp;nbsp; 9597 &amp;nbsp; a.b.c.d &amp;nbsp; 443&amp;nbsp; &amp;nbsp; 6 &amp;nbsp; TCP Estab. &amp;nbsp; &amp;nbsp; &amp;nbsp; 3597/3600&amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp; Local incoming conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.43M &amp;nbsp; &amp;nbsp; &amp;nbsp; 348.83MB &amp;nbsp; &amp;nbsp; 8h13m47s&amp;nbsp; &amp;nbsp; 1s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 672: 0&amp;nbsp; &amp;nbsp; e.f.g.h&amp;nbsp; 18107 &amp;nbsp; a.b.c.d &amp;nbsp; 18234&amp;nbsp; 17&amp;nbsp; UDP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 33/40&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp; Local incoming conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 40B&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 7s&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 7s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Line 722: 0&amp;nbsp; &amp;nbsp; e.f.g.h&amp;nbsp; 18106 &amp;nbsp; a.b.c.d &amp;nbsp; 18234&amp;nbsp; 17&amp;nbsp; UDP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 12/40&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; N/A &amp;nbsp; &amp;nbsp; Local incoming conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 40B&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 28s &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 28s&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- The only enabled blades are fw, vpn, cvpn and identityServer.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Accept and NAT templates are enabled&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- We don’t see the IP a.b.c.d in the accelerated connections table&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- F2F stats:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;----------------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;F2F packets:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;--------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Violation &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Packets&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Violation &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Packets&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;--------------------&amp;nbsp; ---------------&amp;nbsp; &amp;nbsp; --------------------&amp;nbsp; ---------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Pkt has IP options&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; ICMP miss conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 262948&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;TCP-SYN miss conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 65008&amp;nbsp; &amp;nbsp; TCP-other miss conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 7605080&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;UDP miss conn &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1739604&amp;nbsp; &amp;nbsp; Other miss conn&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 883569&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;VPN returned F2F&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; Uni-directional viol&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Possible spoof viol&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 159585&amp;nbsp; &amp;nbsp; TCP state viol&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;SCTP state affecting&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; Out if not def/accl &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Bridge src=dst&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; Routing decision err&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Sanity checks failed&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; Fwd to non-pivot&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Broadcast/multicast &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; Cluster message &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4667249&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Cluster forward &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; Chain forwarding&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;F2V conn match pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; General reason&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Route changes &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; VPN multicast traffic &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;GTP non-accelerated &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&amp;nbsp; &amp;nbsp; Unresolved nexthop&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;----------------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;fwaccel stats -s&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;----------------------&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Accelerated conns/Total conns&amp;nbsp; &amp;nbsp; : 45/45 (100%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;LightSpeed conns/Total conns &amp;nbsp; &amp;nbsp; : 0/45 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Accelerated pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 8058132/29058892 (27%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;LightSpeed pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/29058892 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;F2Fed pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 21000760/29058892 (72%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;F2V pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 55079/29058892 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;CPASXL pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/29058892 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;PSLXL pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/29058892 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;CPAS pipeline pkts/Total pkts&amp;nbsp; &amp;nbsp; : 0/29058892 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;PSL pipeline pkts/Total pkts &amp;nbsp; &amp;nbsp; : 0/29058892 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;CPAS inline pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/29058892 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;PSL inline pkts/Total pkts &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/29058892 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;QOS inbound pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/29058892 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;QOS outbound pkts/Total pkts &amp;nbsp; &amp;nbsp; : 0/29058892 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Corrected pkts/Total pkts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 0/29058892 (0%)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After doing a little research I noticed that RA clients connect to a.b.c.d on port 443, instead of UDP 4500, although the vpnd process has this port open. Visitor Mode is enabled and UDP 4500 is NOT blocked.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I looked at vpnd.elg and noticed there are thousands of the following errors:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;CPRTI: got error 105 buffer is full&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;: No buffer space available&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;-- and --&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;&lt;SPAN&gt;Unable to open '/vs0/dev/fw6v0': Connection refused&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Not being sure, I opened a TAC case, here’s what they said:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- Upgrade the hardware specs (4 CPU - 8GB RAM)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- SYNC connections do not get accelerated (really? why?)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- “Unable to open '/vs0/dev/fw6v0': Connection refused” is a pdp problem and we should open a new ticket for VPN and pdp teams.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance for all the opinions and advice!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 13:13:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216221#M2623</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-06-03T13:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Accelerated SYNC Connections</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216227#M2624</link>
      <description>&lt;P&gt;I know they gave me the same answer before for sync connections not being accelerated and I think that is actually true, but maybe someone else can confirm 100%.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 13:26:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216227#M2624</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-03T13:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: Accelerated SYNC Connections</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216228#M2625</link>
      <description>&lt;P&gt;Do you think there is a documentation for why that might be the case? Or did they say why?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 13:28:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216228#M2625</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-06-03T13:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: Accelerated SYNC Connections</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216229#M2626</link>
      <description>&lt;P&gt;Sync traffic is not accelerated by definition, as it goes to or from FW itself. SecureXL can only accelerate some of the traffic that crosses the GW, and never traffic where GW is the source or destination.&lt;BR /&gt;&lt;BR /&gt;More info in&amp;nbsp;sk32578 and SecureXL ATRG&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 13:32:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216229#M2626</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-06-03T13:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Accelerated SYNC Connections</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216231#M2627</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;"beat" me for that answer, but thats exactly what they mentioned, the sk he gave and thats its not accelerated by default.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 13:37:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216231#M2627</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-03T13:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Accelerated SYNC Connections</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216233#M2628</link>
      <description>&lt;P&gt;Thank you for the answer and the sk.&lt;/P&gt;&lt;P&gt;What about the vpn connections that are not accelerated? How can we find out why port 443 is used, instead of 4500? Or turning off Visitor Mode cause issues with the clients that are connected on 443?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 13:48:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216233#M2628</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-06-03T13:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Accelerated SYNC Connections</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216234#M2629</link>
      <description>&lt;P&gt;From the very same SK I just gave you:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H3 id="Acceleration of packets"&gt;&lt;EM&gt;(1) Acceleration of packets&lt;/EM&gt;&lt;/H3&gt;
&lt;P&gt;&lt;EM&gt;When SecureXL is enabled, all packets should be accelerated,&amp;nbsp;&lt;STRONG&gt;except&lt;/STRONG&gt;&amp;nbsp;packets that match the following conditions:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;........&lt;/EM&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;EM&gt;IPsec VPN Visitor Mode packets.&lt;/EM&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Visitor means TLS is used instead of IPsec, and it needs to be terminated on the FW itself, which basically falls into the same "no acceleration of packets going to and from FW" line.&lt;BR /&gt;&lt;BR /&gt;Disable Visitor Mode and see if it makes any difference.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2024 13:55:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216234#M2629</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2024-06-03T13:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: Accelerated SYNC Connections</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216399#M2636</link>
      <description>&lt;P&gt;Thank you for clarification&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;&lt;P&gt;We disabled Visitor Mode and now it looks like this:&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;# vpn tu tlist&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;(0) Site-to-Site tunnels are up:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;IPSEC 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;NAT-T 0&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;(9) Number of Active Clients:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;NAT-T 9&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Visitor Mode 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;SSL 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;L2TP 0&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;StrongSwan 0&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;However, we still have the picture below and don't quite understand why.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26087i48435E61F994F52B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We still see massive SYNC traffic in slow-path connections table:&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;0 s.y.n.c 33016 s.y.n.c 2010 6 TCP Estab. 3600/3600 N/A Connection non-accel(EXFLAG set) 36.16M 11.60GB 121h11m39s 0s&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the same time we see the following lines, which is understandable since this is a big environment. But I want to understand if this traffic somehow adds up to SYNC traffic, because of topology sharing between the nodes.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Line 92: 0 x.y.z.f 0 224.0.0.5 0 89 59/60 N/A Connection non-accel(EXFLAG set) 599.79K 493.88MB 121h17m16s 1s &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Line 163: 0 x.y.z.f 0 224.0.0.6 0 89 55/60 N/A Connection non-accel(EXFLAG set) 413.84K 327.01MB 121h17m16s 5s &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Line 166: 0 x.y.z.f 0 224.0.0.5 0 89 59/60 N/A Connection non-accel(EXFLAG set) 604.22K 493.63MB 121h20m39s 1s &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Line 194: 0 x.y.z.f 0 224.0.0.6 0 89 54/60 N/A Connection non-accel(EXFLAG set) 426.94K 333.82MB 121h17m16s 5s &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Line 220: 0 x.y.z.f 0 224.0.0.5 0 89 59/60 N/A Connection non-accel(EXFLAG set) 604.09K 491.69MB 121h20m39s 1s &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Line 276: 0 x.y.z.f 0 224.0.0.6 0 89 58/60 N/A Connection non-accel(EXFLAG set) 440.15K 332.51MB 121h17m16s 2s &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Line 278: 0 x.y.z.f 0 224.0.0.6 0 89 60/60 N/A Connection non-accel(EXFLAG set) 427.81K 332.82MB 121h17m16s 0s &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Line 279: 0 x.y.z.f 0 224.0.0.6 0 89 60/60 N/A Connection non-accel(EXFLAG set) 440.37K 335.76MB 121h17m16s 0s &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Line 298: 0 x.y.z.f 0 224.0.0.5 0 89 59/60 N/A Connection non-accel(EXFLAG set) 601.53K 492.11MB 121h17m16s 1s &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Line 481: 0 x.y.z.f 0 224.0.0.6 0 89 57/60 N/A Connection non-accel(EXFLAG set) 441.06K 337.06MB 121h17m16s 3s &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Line 504: 0 x.y.z.f 0 224.0.0.5 0 89 59/60 N/A Connection non-accel(EXFLAG set) 600.22K 492.66MB 121h17m16s 1s &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Line 523: 0 x.y.z.f 0 224.0.0.5 0 89 59/60 N/A Connection non-accel(EXFLAG set) 603.21K 496.28MB 121h17m16s 1s&lt;/FONT&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Is there a way to solve this riddle?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 15:03:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216399#M2636</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2024-06-04T15:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: Accelerated SYNC Connections</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216401#M2638</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/102202"&gt;@kamilazat&lt;/a&gt;&amp;nbsp;I believe thats normal, as again, those wont be accelerated, so you wont see them as fast path.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 15:07:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Accelerated-SYNC-Connections/m-p/216401#M2638</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-04T15:07:20Z</dc:date>
    </item>
  </channel>
</rss>

