Hi,
We have been upgrading our firewall to R80.30 and are happy with the results as SecureXL looks to be much better with the new mechanism it is using.
But with the issue which I have mentioned on the topic mainly wasn't as expected after the upgrade.
To give an idea , this was the output with r80.10
# fwaccel stats -s
Accelerated conns/Total conns : 45/47726 (0%)
Accelerated pkts/Total pkts : 1374948/85775878 (1%)
F2Fed pkts/Total pkts : 33538998/85775878 (39%)
PXL pkts/Total pkts : 50861932/85775878 (59%)
QXL pkts/Total pkts : 0/85775878 (0%)
R80.30
fwaccel stats -s
Accelerated conns/Total conns : 18446744073709551615/291 (0%)
Accelerated pkts/Total pkts : 3324649332/29928619281 (11%)
F2Fed pkts/Total pkts : 23351470604/29928619281 (78%)
F2V pkts/Total pkts : 1981021/29928619281 (0%)
CPASXL pkts/Total pkts : 0/29928619281 (0%)
PSLXL pkts/Total pkts : 3252499345/29928619281 (10%)
QOS inbound pkts/Total pkts : 0/29928619281 (0%)
QOS outbound pkts/Total pkts : 0/29928619281 (0%)
Corrected pkts/Total pkts : 0/29928619281 (0%)
As we are experiencing much more SecureXL handling traffic I expected it from this cluster but this is what we have. Also with the detailed output below, could anyone have any ideas to check out for?
Thank you
# enabled_blades
fw vpn urlf av appi ips identityServer anti_bot ThreatEmulation mon vpn
# fwaccel stat
+-----------------------------------------------------------------------------+
|Id|Name |Status |Interfaces |Features |
+-----------------------------------------------------------------------------+
|0 |SND |enabled |eth1,eth2,eth8,eth9, |
| | | |eth10,eth11,eth4,eth6, |
| | | |eth7,eth12 |Acceleration,Cryptography |
| | | | |Crypto: Tunnel,UDPEncap,MD5, |
| | | | |SHA1,NULL,3DES,DES,CAST, |
| | | | |CAST-40,AES-128,AES-256,ESP, |
| | | | |LinkSelection,DynamicVPN, |
| | | | |NatTraversal,AES-XCBC,SHA256 |
+-----------------------------------------------------------------------------+
Accept Templates : disabled by Firewall
Layer FW Security disables template offloads from rule #below rules on the rule set
Throughput acceleration still enabled.
Drop Templates : enabled
NAT Templates : disabled by Firewall
Layer FW Security disables template offloads from rule #below rules on the rule set
Throughput acceleration still enabled.
fwaccel stats -p
F2F packets:
--------------
Violation Packets Violation Packets
-------------------- --------------- -------------------- ---------------
pkt has IP options 23816 ICMP miss conn 132651663
TCP-SYN miss conn 84611629 TCP-other miss conn 22809840829
UDP miss conn 365313631 other miss conn 950684
VPN returned F2F 2716 uni-directional viol 0
possible spoof viol 0 TCP state viol 0
out if not def/accl 0 bridge, src=dst 0
routing decision err 0 sanity checks failed 0
fwd to non-pivot 0 broadcast/multicast 0
cluster message 60690169 cluster forward 0
chain forwarding 0 F2V conn match pkts 16262
general reason 0 route changes 0
# fw ctl pstat
System Capacity Summary:
Memory used: 6% (6345 MB out of 96499 MB) - below watermark
Concurrent Connections: 47573 (Unlimited)
Aggressive Aging is enabled, not active
Hash kernel memory (hmem) statistics:
Total memory allocated: 10116661248 bytes in 2469888 (4096 bytes) blocks using 1 pool
Total memory bytes used: 0 unused: 10116661248 (100.00%) peak: 2892273060
Total memory blocks used: 0 unused: 2469888 (100%) peak: 750073
Allocations: 313103958 alloc, 0 failed alloc, 290068681 free
System kernel memory (smem) statistics:
Total memory bytes used: 13060201248 peak: 13584325624
Total memory bytes wasted: 51590450
Blocking memory bytes used: 40931152 peak: 49913880
Non-Blocking memory bytes used: 13019270096 peak: 13534411744
Allocations: 275507555 alloc, 0 failed alloc, 275481277 free, 0 failed free
vmalloc bytes used: 12981572012 expensive: no
Kernel memory (kmem) statistics:
Total memory bytes used: 5215567944 peak: 6114904284
Allocations: 588597677 alloc, 0 failed alloc
565542883 free, 0 failed free
External Allocations: 16059184 for packets, 20259020 for SXL
Cookies:
660113400 total, 444458826 alloc, 444456842 free,
2563541669 dup, 3939842552 get, 2102265806 put,
908833439 len, 2170526108 cached len, 0 chain alloc,
0 chain free
Connections:
126589063 total, 78487631 TCP, 44113491 UDP, 3954893 ICMP,
33048 other, 6120 anticipated, 2 recovered, 47573 concurrent,
51300 peak concurrent
Fragments:
25749658 fragments, 12636569 packets, 56 expired, 0 short,
0 large, 0 duplicates, 0 failures
NAT:
-471034387/0 forw, -270524211/0 bckw, 801229606 tcpudp,
14133055 icmp, 82601856-71925803 alloc