OK, I'm giving up as I can't understand why would most traffic be pushed via medium path in one of our perimeter GWs.
Setup: GW running R80.40 T139, blades enabled: fw urlf appi ips identityServer.
The only TP blade we have is IPS. Yet running ips off command makes no difference at all. Whilst fw amw unload restores expected state with most traffic being accelerated.
This does not really make sense as AMW unload should only affect TP blades except IPS. But they are not even enabled!
Here are two screenshots: before and after AMW unload:
When I look at actual connections - it's pretty much everything, even internal network to DNS is being sent to PXL.
I tried adding explicit TP policy to exclude all internal networks:
But still no joy.
What am I missing?? 🙂