I have a HA cluster of Check Point 15,400's running 80.30 with JHA take 215.
[Expert@xxxxx]# enabled_blades
fw vpn ips identityServer vpn
[Expert@xxxxxx0]#
Hyperthreading and CoreXL are both enabled.
A month or so ago when I checked my SecureXL statistics about 70% of my traffic was being accelerated and now 100% of packets are taking the F2Fed. I am having a heck of a time trying to determine how literally no packets are being accelerated.
The only major things that have changed recently are IPS Protection - I make sure all protections with a critical performance rating are disabled , and JHA take 215.
[Expert@xxxxx]# fwaccel stat
+-----------------------------------------------------------------------------+
|Id|Name |Status |Interfaces |Features |
+-----------------------------------------------------------------------------+
|0 |SND |enabled |eth2-01,eth2-02,eth2-03, |
| | | |eth2-04,eth2-05,eth2-06, |
| | | |eth2-07,eth2-08,Sync |Acceleration,Cryptography |
| | | | |Crypto: Tunnel,UDPEncap,MD5, |
| | | | |SHA1,NULL,3DES,DES,CAST, |
| | | | |CAST-40,AES-128,AES-256,ESP, |
| | | | |LinkSelection,DynamicVPN, |
| | | | |NatTraversal,AES-XCBC,SHA256 |
+-----------------------------------------------------------------------------+
Accept Templates : enabled
Drop Templates : disabled
NAT Templates : enabled
[Expert@xxxxxx]# fwaccel stats -s
Accelerated conns/Total conns : 0/0 (0%)
Accelerated pkts/Total pkts : 0/2659685415 (0%)
F2Fed pkts/Total pkts : 2659685415/2659685415 (100%)
F2V pkts/Total pkts : 0/2659685415 (0%)
CPASXL pkts/Total pkts : 0/2659685415 (0%)
PSLXL pkts/Total pkts : 0/2659685415 (0%)
QOS inbound pkts/Total pkts : 0/2659685415 (0%)
QOS outbound pkts/Total pkts : 0/2659685415 (0%)
Corrected pkts/Total pkts : 0/2659685415 (0%)
[Expert@MAIN-EXT-FWA:0]#
[Expert@xxxx# fwaccel stats -p
F2F packets:
--------------
Violation Packets Violation Packets
-------------------- --------------- -------------------- ---------------
pkt has IP options 4197 ICMP miss conn 695465
TCP-SYN miss conn 6076140 TCP-other miss conn 829529441
UDP miss conn 1835183626 other miss conn 4260
VPN returned F2F 20 uni-directional viol 0
possible spoof viol 0 TCP state viol 0
SCTP state affecting 0 out if not def/accl 0
bridge, src=dst 0 routing decision err 0
sanity checks failed 0 fwd to non-pivot 0
broadcast/multicast 0 cluster message 38231619
cluster forward 0 chain forwarding 0
F2V conn match pkts 0 general reason 0
route changes 0