cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question

R80.20 SecureXL drop template support

Hi,

I was reading the "Performance Tuning Administration Guide R80.20" and pass by something that made me think about some upgrades that i will need to do on the next's months to R80.20 and push them forward until this is supported, at least on 2 of them that have a good amount of traffic droped by the SXL.

The drop template feature on SXL still not supported.

Does anyone know when it will be supported? mid 2019?

Regards

4 Replies
Admin
Admin

Re: R80.20 SecureXL drop template support

Further, when you issue the command fwaccel cfg -b on, you don't get a "not supported" error, it just silently fails.

However, I suspect Drop templates won't provide as much of a benefit in R80.20 as they did in previous releases.

This is because initial packets in R80.20 don't need to go F2F to be inspected.

0 Kudos
Admin
Admin

Re: R80.20 SecureXL drop template support

Update: Drop Templates are supported in R80.20.

Further: the comment in the docs about fwaccel cfg -b not being supported is erroneous and will be removed.

Doesn't explain what I saw, but if you're having issues, I recommend opening a support ticket.

Re: R80.20 SecureXL drop template support

Dameon Welch-Abernathy, Thanks for your reply's.

I wasn't able to test it, but I will in the meanwhile on my lab environment.

Dameon Welch-Abernathy wrote:

(...)

This is because initial packets in R80.20 don't need to go F2F to be inspected.

One more thing can you point me to where can i find the initial packets route, infografic or text described?

0 Kudos
Admin
Admin

Re: R80.20 SecureXL drop template support

This doesn't exactly show what I'm talking about, but:

Prior to R80.20, the design of SecureXL required the initial connection to be F2F so the SecureXL template could be created.

This was also required because certain low-level checks could not be done in kernel space.

Now that we've moved most of SecureXL into userspace, most of those checks can be done entirely there without taking the full hit of going F2F.