Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Bernardes
Advisor
Advisor

Disable All Traffic Inspection

Dear all,

Is there a way to make the Check Point firewall act only as a router for a specific scope?

I know it's possible to define network scopes and disable, for example, the inspection of Threat Prevention blades, but even so, traffic will still be inspected to match with a rule in the rule base and decide what to do.

But what I would like to know is if it is possible to completely turn off any type of inspection for one or more specific network segments, so that the firewall only routes these packets and nothing else, to save processing power.

Is this possible? If so, how would it be done?

Thank You!

0 Kudos
4 Replies
Chris_Atkinson
Employee Employee
Employee

Look into fast_accel refer: sk156672

CCSM R77/R80/ELITE
CheckPointerXL
Advisor
Advisor

i think the Null_Profile is the best approach here

0 Kudos
Timothy_Hall
Legend Legend
Legend

Fast_accel would be more appropriate than a null profile in this case.  A null profile only disables Deep Inspection performed by Threat Prevention, but other Access Control Medium Path blades such as APCL/URLF will still perform their Deep Inspection duties on the traffic.  Forcing the traffic out of the Medium Path into the fastpath via fast_accel completely disables all Deep Inspection for both Access Control & Threat Prevention.  The only caveat is that traffic requiring F2F/slowpath handling cannot be forced into the fastpath.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
CheckPointerXL
Advisor
Advisor

thanks for clarification

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events