Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mikhail_Demin
Explorer

Traffic acceleration turn off

What'll happened when i'll perform "fwaccel off"? Gateway just will more slowly process  new connections?

0 Kudos
8 Replies
Chris_Atkinson
Employee Employee
Employee

 

As per sk162492 it will depend on the gateway version.

CCSM R77/R80/ELITE
0 Kudos
Mikhail_Demin
Explorer

Im my case version is 77.30
0 Kudos
Chris_Atkinson
Employee Employee
Employee

It will disable acceleration until turned back on or the gateway is rebooted, are you trying to troubleshoot something in particular?

Typically it is recommend to do this (only temporarily) out of peak times or with headroom to cater for a load increase.

CCSM R77/R80/ELITE
0 Kudos
Mikhail_Demin
Explorer

Yes, i want to perform this for troubleshoot something. Thanks!
0 Kudos
Timothy_Hall
Legend Legend
Legend

If after running fwaccel off you find that whatever issue you have is solved, instead of turning of SecureXL for all traffic permanently via cpconfig, consider excluding the problematic IP address(es) from acceleration as described here:

sk104468: How to disable SecureXL for specific IP addresses

After defining this exclusion everything matching it will always go F2F/slowpath, which has the side effect of making the matched traffic fully visible if using fw monitor.

Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm
Daniel_Kavan
Advisor
Advisor

I have a TAC case right now where 3 specific IP addresses are involved  all over port 8080, so I may use this.  This traffic started misbehaving right when we went from 5800 to 9300 appliances.  That being said what kind of debugs would be helpful in figuring out why acceleration isn't working for that traffic?      

0 Kudos
Timothy_Hall
Legend Legend
Legend

I assume you mean why these connections are misbehaving when partially/fully accelerated, this is not generally something you can troubleshoot easily without TAC as it can involve sim debugs which can easily hurt performance or kill the firewall. 

What you could do is get a packet capture with fw monitor -F and also run fw ctl zdebug + drop while trying the problematic accelerated connections.  Now put them into the slowpath via sk104468, run the debug commands again with the test traffic and see what is different.  However you need to be mindful of the order in which you run these two debugging commands as they can interfere with each other, see here: Max Capture Update 2: Debug Filter Battle -- fw monitor -F vs. fw ctl zdebug + drop

Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm
PhoneBoy
Admin
Admin

Generally you should not disable SecureXL except for troubleshooting as it will cause a pretty significant performance impact.
If disabling SecureXL solves an issue, then TAC should be involved.
Of course, since you're on an unsupported version now, you'll most likely have to upgrade to resolve the issue.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events