<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SecureXL NAT Template on SMB (1100) gateway in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76741#M3120</link>
    <description>&lt;P&gt;On a contrary, when centrally managed there are few tricks to optimize SecureXL, especially when HTTPS-I is involved. I managed to optimize SecureXL so much that the load dropped like in half now. What I did was to very carefully read Timothy Hall's posts here about it and then do a little bit of experimentation.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt; I may write about my finding next week if I have the time...&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Feb 2020 17:32:37 GMT</pubDate>
    <dc:creator>HristoGrigorov</dc:creator>
    <dc:date>2020-02-28T17:32:37Z</dc:date>
    <item>
      <title>SecureXL NAT Template on SMB (1100) gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76678#M3115</link>
      <description>&lt;P&gt;So on a small single core gateway (1130) I have SecureXL running for what its worth but the NAT Template is disabled.&lt;/P&gt;&lt;P&gt;Is it worth turning it on?&lt;/P&gt;&lt;P&gt;Is it worth running SecureXL at all?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 12:06:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76678#M3115</guid>
      <dc:creator>listtc</dc:creator>
      <dc:date>2020-02-28T12:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL NAT Template on SMB (1100) gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76680#M3116</link>
      <description>&lt;P&gt;Usually, you do not use Hide NAT or Static NAT with need of a&amp;nbsp;&lt;SPAN&gt;high session rate on 1100&amp;nbsp;appliances ! So NAT templates are not necessary. Running SecureXL, on the other hand, can be very valuable - but the performance gain also depends much on the used traffic mix.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 12:18:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76680#M3116</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-02-28T12:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL NAT Template on SMB (1100) gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76689#M3117</link>
      <description>I have 2 of the 1100s both supporting 20 user offices with general internet behind Hide NAT.&lt;BR /&gt;Typically under 3000 connections.&lt;BR /&gt;Just trying to do best optimisation for this units until I can replace them</description>
      <pubDate>Fri, 28 Feb 2020 13:00:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76689#M3117</guid>
      <dc:creator>listtc</dc:creator>
      <dc:date>2020-02-28T13:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL NAT Template on SMB (1100) gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76694#M3118</link>
      <description>&lt;P&gt;I would advise to stay away from NAT templates as long as there are no traffic issues - i would not think that it could gain perceptible performance gains, but when in strong need, it could be tested. With 1100s, you usually just keep SecureXL on and forget all optimization...&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 13:12:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76694#M3118</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-02-28T13:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL NAT Template on SMB (1100) gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76739#M3119</link>
      <description>Other than avoiding services that can't be accelerated by SecureXL (especially when centrally managed), there's not much in the way of performance optimization you can do on the SMB appliances.&lt;BR /&gt;</description>
      <pubDate>Fri, 28 Feb 2020 16:57:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76739#M3119</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-28T16:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL NAT Template on SMB (1100) gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76741#M3120</link>
      <description>&lt;P&gt;On a contrary, when centrally managed there are few tricks to optimize SecureXL, especially when HTTPS-I is involved. I managed to optimize SecureXL so much that the load dropped like in half now. What I did was to very carefully read Timothy Hall's posts here about it and then do a little bit of experimentation.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt; I may write about my finding next week if I have the time...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 17:32:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76741#M3120</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-02-28T17:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL NAT Template on SMB (1100) gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76747#M3123</link>
      <description>I'm reading Tim Hall's book avidly and going through the whole estate from 13500s to 1130s.&lt;BR /&gt;the 1100 need to be retied but in the meantime....</description>
      <pubDate>Fri, 28 Feb 2020 18:07:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76747#M3123</guid>
      <dc:creator>listtc</dc:creator>
      <dc:date>2020-02-28T18:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL NAT Template on SMB (1100) gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76748#M3124</link>
      <description>&lt;P&gt;Yeah, Tim's book is like the holy bible of CheckPoint firewalls. Don't dare to call yourself CPFW admin if you've never read it.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 18:17:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76748#M3124</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-02-28T18:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL NAT Template on SMB (1100) gateway</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76750#M3125</link>
      <description>You can still do some level of performance troubleshooting.&lt;BR /&gt;I did take Tim's commands and make an SMB version here: &lt;A href="https://community.checkpoint.com/t5/SMB-Appliances-and-SMP/Super-Seven-Performance-Assessment-Commands-SMB-Edition/m-p/73078" target="_blank"&gt;https://community.checkpoint.com/t5/SMB-Appliances-and-SMP/Super-Seven-Performance-Assessment-Commands-SMB-Edition/m-p/73078&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You certainly can't change the core split because there's not enough cores for that.&lt;BR /&gt;And certainly a lot of the stuff unrelated to Check Point is also relevant.&lt;BR /&gt;&lt;BR /&gt;In any case, I'd love to see what you came up with in general.&lt;BR /&gt;I'm sure folks would benefit from it, and maybe Tim could borrow a few notes for the next version(s) of his book. &lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;</description>
      <pubDate>Fri, 28 Feb 2020 18:43:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SecureXL-NAT-Template-on-SMB-1100-gateway/m-p/76750#M3125</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-28T18:43:46Z</dc:date>
    </item>
  </channel>
</rss>

