Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
hcampuzano
Participant

Bypass all Blades for a source subnet.

Hello community.
I'd like to ask if there's a way to skip all Blades for a specific sub net to a specific destination, like making the firewall to act as a router for that particular sub nets / hosts.
I was asked to do so as part of an active troubleshooting and I was told it can be done on the CLI.
I've been searching on line but had no luck.
Is it possible? Is there any documentation about it?

 

0 Kudos
3 Replies
Timothy_Hall
Legend Legend
Legend

Add a rule at the top of your firewall policy accepting all traffic between the subnets in question, then force the traffic into the fastpath where there will be minimal further enforcement:

sk156672: SecureXL Fast Accelerator (fw fast_accel) for R80.20 and above

It isn't quite acting as "just a router" but it is pretty close.  Only catch is if the traffic is in the slowpath/F2F it cannot be forced to the fastpath using this technique.

Attend my Gateway Performance Optimization R81.20 course
CET (Europe) Timezone Course Scheduled for July 1-2
0 Kudos
hcampuzano
Participant

Thank you very much for your input.
Is there a way to validate if the packets are going it the slowpath?

0 Kudos
Machine_Head
Collaborator
Collaborator

run "fwaccel conns | grep x.x.x.x". THis is the SecureXL table, means the connection is going medium/fast path. It should be most of the traffic

If your connection is there it can be accelerated with fast_accel.

 

You can check if the connection is in the fw connection table with "fw ctl conntab"

 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Wed 21 May 2025 @ 11:30 AM (CDT)

    Tempe: Hybrid Mesh

    Tue 03 Jun 2025 @ 06:00 PM (EDT)

    Montreal: CPX Recap

    Tue 10 Jun 2025 @ 06:00 PM (EDT)

    Quebec City: CPX Recap
    CheckMates Events