- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Check Mates,
Can anyone explain what the F2F violation 'cluster message' means?
fwaccel stats -p
F2F packets:
--------------
Violation Packets Violation Packets
-------------------- --------------- -------------------- ---------------
pkt has IP options 227 ICMP miss conn 153026
TCP-SYN miss conn 327641 TCP-other miss conn 28868624
UDP miss conn 295417 other miss conn 10604
VPN returned F2F 0 uni-directional viol 0
possible spoof viol 11 TCP state viol 0
out if not def/accl 0 bridge, src=dst 0
routing decision err 0 sanity checks failed 0
fwd to non-pivot 0 broadcast/multicast 0
cluster message 207254 cluster forward 0
chain forwarding 0 F2V conn match pkts 89454
general reason 0 route changes 0
The ATRG sk for SecureXL explains most values, but not this one. I believe this should normally be 0, so I'm wondering why it's quite high.
F2F means "forwarded to Firewall", a.k.a "Slow Path". It applies to any packet that cannot or should not be accelerated.
The term is in fact mentioned in multiple guides and SecureKnowledge articles, for example, in sk153832, quoting:
"Firewall path / Slow path (F2F) - Packet flow when the SecureXL device is unable to process the packet (refer to sk32578 - SecureXL Mechanism). The packet is passed on to the CoreXL layer and then to one of the Core FW instances for full processing. This path also processes all packets when SecureXL is disabled."
Exactly the same statement is used in sk98722.
@Nik_Bloemers apologies, I must have misread you original questions.
There are two answers:
1. "Violations" here is not a good term. It generally applies to any packet that SXL cannot accelerate. It is meant as a "violation of acceleration". It does not mean there is anything wrong with the traffic.
2. Cluster messages are all CCP packets. They cannot be accelerates as they should go to CXL for the purposes of sync and health status monitoring.
Val is correct, that counter indicates the CCP traffic. Traffic that is addressed to the firewall itself (i.e. not transiting trying to reach a destination IP that is not the firewall) is never accelerated by SecureXL and always goes F2F. This is expected behavior.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 7 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY