<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Copying DiffServ code from IP-header to IPSec-header in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/101871#M4366</link>
    <description>&lt;P&gt;Im SMB documentation, a chapter like the one for GAiA "QoS Advanced QoS Policy Management - Differentiated Services (DiffServ)" does not exist, and i think that is because Embedded GAiA has only a subset of features implemented to keep the small footprint. The sk105722 reffered by you has Platform / Model : All, so i have asked for feedback concerning support on SMB devices. But according to sk104861, use of the feature has only been possible since R77.30 !&lt;/P&gt;
&lt;P&gt;Further, in sk105380 i see for SMB:&lt;/P&gt;
&lt;P&gt;Centrally managed SMB appliance can be configured to use Delay Sensitivity and Differential Services marking features only under Express QoS mode. Configuration is done in "Advanced" section of QoS action configuration window which is unique for Edge/SG80 appliances. Under Traditional QoS mode only Best Effort QoS class is supported, using other classes will disable QoS policy.&lt;/P&gt;
&lt;P&gt;QoS supports marking the traffic with Differential Services (DiffServ) tags and preserving existing DiffServ tags. QoS does not support matching packets based on DiffServ tagging.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Nov 2020 14:33:43 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2020-11-12T14:33:43Z</dc:date>
    <item>
      <title>Copying DiffServ code from IP-header to IPSec-header</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/101870#M4365</link>
      <description>&lt;P&gt;Hello everyone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have some QoS question. As i think traffic handling on CP consist of: firstly adding QoS parameters to IP-header and secondly there is encryption of packet. Also parameter&amp;nbsp;&lt;STRONG&gt;:ipsec.copy_TOS_to_outer&lt;/STRONG&gt; allows to copy DiffServ code from IP-header to IPSec-header. I turned on this parameter on the relevant GW (1490 appliance) on my SMS and install the policy (according to which traffic should be marked DiffServ code cs5), but traffic from GW is still marking by DiffServ code by default (cs0). I don't understand why.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 13:48:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/101870#M4365</guid>
      <dc:creator>mikdemin</dc:creator>
      <dc:date>2020-11-12T13:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: Copying DiffServ code from IP-header to IPSec-header</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/101871#M4366</link>
      <description>&lt;P&gt;Im SMB documentation, a chapter like the one for GAiA "QoS Advanced QoS Policy Management - Differentiated Services (DiffServ)" does not exist, and i think that is because Embedded GAiA has only a subset of features implemented to keep the small footprint. The sk105722 reffered by you has Platform / Model : All, so i have asked for feedback concerning support on SMB devices. But according to sk104861, use of the feature has only been possible since R77.30 !&lt;/P&gt;
&lt;P&gt;Further, in sk105380 i see for SMB:&lt;/P&gt;
&lt;P&gt;Centrally managed SMB appliance can be configured to use Delay Sensitivity and Differential Services marking features only under Express QoS mode. Configuration is done in "Advanced" section of QoS action configuration window which is unique for Edge/SG80 appliances. Under Traditional QoS mode only Best Effort QoS class is supported, using other classes will disable QoS policy.&lt;/P&gt;
&lt;P&gt;QoS supports marking the traffic with Differential Services (DiffServ) tags and preserving existing DiffServ tags. QoS does not support matching packets based on DiffServ tagging.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 14:33:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/101871#M4366</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-11-12T14:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: Copying DiffServ code from IP-header to IPSec-header</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/101923#M4367</link>
      <description>&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;I'm interested on marking traffic with special DiffServ Code, not matching.&lt;/P&gt;&lt;P&gt;With regads to last paragrraph as i understand correctly that Express QoS mode only supports in SG80 and UTM-1 Edge appliances and not supports in 1490 appliance?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 20:14:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/101923#M4367</guid>
      <dc:creator>mikdemin</dc:creator>
      <dc:date>2020-11-12T20:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: Copying DiffServ code from IP-header to IPSec-header</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/101930#M4368</link>
      <description>&lt;P&gt;I would assume this is also true for 1490.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 21:33:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/101930#M4368</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-11-12T21:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Copying DiffServ code from IP-header to IPSec-header</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/102153#M4371</link>
      <description>&lt;P&gt;Ok. I'm understand that i must to create a new QoS policy package in Express Mode. But i also have a one question. For example, i create a new QoS policy package in Express Mode with one rule on one link and configure 80k kbps as guaranteed in action column. So then what i must configure in QoS tab in Topology of the relevant interface? I'm add the relevant QoS Class in this tab (REA Beeline). So what the guarantee bandwidth for this QoS class i must configure? The same 80k kpbs that i configure in rule? I'm attach the screenshots of the QoS rule and QoS tab of the relevant interface.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 12:09:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/102153#M4371</guid>
      <dc:creator>mikdemin</dc:creator>
      <dc:date>2020-11-16T12:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: Copying DiffServ code from IP-header to IPSec-header</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/104395#M4454</link>
      <description>&lt;P&gt;I have asked for feedback in sk105722 concerning support on SMB devices and received the following answer:&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: Arial, sans-serif; font-size: small; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration: none; display: inline !important; float: none;"&gt;SecureKnowledge solution ID: sk105722&amp;nbsp; and Title: "How to configure Check Point Security Gateway to copy DiffServ mark between packet's headers" has now been edited based on your feedback.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="caret-color: #000000; color: #000000; font-family: Arial, sans-serif; font-size: small; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; background-color: #ffffff; text-decoration: none; display: inline !important; float: none;"&gt;This article is supported on centrally-managed SMB appliances starting from version R77.20.20. It is not supported on locally managed appliances.&lt;BR style="caret-color: #000000; color: #000000; font-family: Arial, sans-serif; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;" /&gt;For traffic with pre-existing diffserv marks, default behavior is to copy diffserv mark to encapsulated traffic on outgoing and not to copy from encapsulated or incoming traffic.&amp;nbsp;&lt;BR style="caret-color: #000000; color: #000000; font-family: Arial, sans-serif; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; text-decoration: none;" /&gt;Enabling copying diffserv marks from incoming encapsulated traffic or decrypted traffic can be done via GuiDbEdit, as described in sk105722.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Anyway, only copying or removing DiffServ code is possible, not actively marking traffic.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2020 09:33:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/104395#M4454</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-12-06T09:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Copying DiffServ code from IP-header to IPSec-header</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/104475#M4455</link>
      <description>&lt;P&gt;Thanks a lot for update! In this case i'll have to organize marking on my Cisco devices.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 09:51:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Copying-DiffServ-code-from-IP-header-to-IPSec-header/m-p/104475#M4455</guid>
      <dc:creator>mikdemin</dc:creator>
      <dc:date>2020-12-07T09:51:53Z</dc:date>
    </item>
  </channel>
</rss>

