<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic correction layer statistics in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/correction-layer-statistics/m-p/138983#M748</link>
    <description>&lt;P&gt;Please, can someone explain the correction layer statistics. In particular the "local asymmetric conns", are these common values?&lt;/P&gt;
&lt;P&gt;[Expert@??????ch01-01-ch01-02:0]# asg_blade_stats corr&lt;BR /&gt;1_02:&lt;/P&gt;
&lt;P&gt;Getting stats for SXL device 0, may take a few seconds...&lt;/P&gt;
&lt;P&gt;Cluster Correction Stats (All Traffic):&lt;BR /&gt;------------------------------------------------------&lt;BR /&gt;Sent packets: 2058184627 (125824132 with metadata)&lt;BR /&gt;Sent bytes: 2,138,385,116,358&lt;BR /&gt;Received packets: 902271628 (148901403 with metadata)&lt;BR /&gt;Received bytes: 871,614,646,160&lt;BR /&gt;Send errors: 0&lt;BR /&gt;Receive errors: 0&lt;BR /&gt;Local asymmetric conns: 7656898 &lt;STRONG&gt;&amp;lt;-&amp;nbsp;are this the current active asymmetric connection?&lt;/STRONG&gt;&lt;BR /&gt;ICMP ERROR forwarded packets: 0&lt;BR /&gt;ICMP ERROR forwarded bytes: 0&lt;BR /&gt;VS Stateless forwarded packets: 1743&lt;BR /&gt;VS Stateless forwarded bytes: 586,780&lt;/P&gt;
&lt;P&gt;We had problems with connections they are done hide NAT (everything is fine with only one gateway active)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jan 2022 10:59:24 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2022-01-20T10:59:24Z</dc:date>
    <item>
      <title>correction layer statistics</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/correction-layer-statistics/m-p/138983#M748</link>
      <description>&lt;P&gt;Please, can someone explain the correction layer statistics. In particular the "local asymmetric conns", are these common values?&lt;/P&gt;
&lt;P&gt;[Expert@??????ch01-01-ch01-02:0]# asg_blade_stats corr&lt;BR /&gt;1_02:&lt;/P&gt;
&lt;P&gt;Getting stats for SXL device 0, may take a few seconds...&lt;/P&gt;
&lt;P&gt;Cluster Correction Stats (All Traffic):&lt;BR /&gt;------------------------------------------------------&lt;BR /&gt;Sent packets: 2058184627 (125824132 with metadata)&lt;BR /&gt;Sent bytes: 2,138,385,116,358&lt;BR /&gt;Received packets: 902271628 (148901403 with metadata)&lt;BR /&gt;Received bytes: 871,614,646,160&lt;BR /&gt;Send errors: 0&lt;BR /&gt;Receive errors: 0&lt;BR /&gt;Local asymmetric conns: 7656898 &lt;STRONG&gt;&amp;lt;-&amp;nbsp;are this the current active asymmetric connection?&lt;/STRONG&gt;&lt;BR /&gt;ICMP ERROR forwarded packets: 0&lt;BR /&gt;ICMP ERROR forwarded bytes: 0&lt;BR /&gt;VS Stateless forwarded packets: 1743&lt;BR /&gt;VS Stateless forwarded bytes: 586,780&lt;/P&gt;
&lt;P&gt;We had problems with connections they are done hide NAT (everything is fine with only one gateway active)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 10:59:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/correction-layer-statistics/m-p/138983#M748</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-01-20T10:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: correction layer statistics</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/correction-layer-statistics/m-p/138998#M749</link>
      <description>&lt;P&gt;Which distribution mode is used?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_AdminGuide/Topics-Maestro-AG/NAT-and-Correction-Layer-on-Security-Gateway.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Maestro_AdminGuide/Topics-Maestro-AG/NAT-and-Correction-Layer-on-Security-Gateway.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jan 2022 12:53:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/correction-layer-statistics/m-p/138998#M749</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-01-20T12:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: correction layer statistics</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/correction-layer-statistics/m-p/139107#M760</link>
      <description>&lt;P&gt;The corrections table is there because in many cases when traffic is NATed, the return packet will hit a different security gateway. This is expected and why we have the corrections layer. It keeps track of all connections which it knows will have return packets will not hit the same gateway in the security group. When the return packet arrives, it utilizes the corrections table to determine which gateway should process the packet. It is then seamlessly forwards over dedicated VLANS in the downlink cables to the correct gateway.&lt;BR /&gt;&lt;BR /&gt;Your distribution mode will play a large part in what the size of this table will be based upon your traffic patterns. Regardless of table size, this correction process is extremely fast.&amp;nbsp; I can't say if that's a large or small number without more info, but I would imagine the value shown could be up to 100% of the total connections.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 20:09:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/correction-layer-statistics/m-p/139107#M760</guid>
      <dc:creator>Jeffrey_Fogel</dc:creator>
      <dc:date>2022-01-21T20:09:21Z</dc:date>
    </item>
  </channel>
</rss>

