- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All.
Is it available some document or content about fw ctl chain outputs? I'd like to understant deeply all columns and fields (module, chain position, function pointer, mode, etc). The concept about chain modules is a bit complicated.
Regards.
Hi @valterj,
Unfortunately, there is no overview of the chain modules.
However, you can find some information in the CCTE training materials.
I have written a few articles on the new parameters. Maybe that will help you:
- R8x - Security Gateway Architecture (Logical Packet Flow)
- R80.20 - New FW Monitor inspection points
- R80.20 - New Chain Modules?
- R80.20 - SecureXL + new chain modules + fw monitor
You can also found more information here:
Performance Tuning R81 Administration Guide -> fw monitor
SecureXL has been significantly revised in R80.20. It now works in user space. This has also led to some changes in "fw monitor"
There are new fw monitor chain (SecureXL) objects that do not run in the virtual machine.
The new fw monitor chain modules (SecureXL) do not run in the virtual machine (vm).
SecureXL inbound (sxl_in) > Packet received in SecureXL from network
SecureXL inbound CT (sxl_ct) > Accelerated packets moved from inbound to outbound processing (post routing)
SecureXL outbound (sxl_out) > Accelerated packet starts outbound processing
SecureXL deliver (sxl_deliver) > SecureXL transmits accelerated packet
There are more new chain modules in R80.20
vpn before offload (vpn_in) > FW inbound preparing the tunnel for offloading the packet (along with the connection)
fw offload inbound (offload_in) > FW inbound that perform the offload
fw post VM inbound (post_vm) > Packet was not offloaded (slow path) - continue processing in FW inbound
---
There are new fw monitor inspection points when a packet passes through a R80.20+ Security Gateway:
| Inspection point | Name of fw monitor inspection point | Relation to firewall VM | Available since version |
|---|---|---|---|
| i | Pre-Inbound | Before the inbound FireWall VM (for example, eth1:i) |
always |
| I | Post-Inbound | After the inbound FireWall VM (for example, eth1:I) |
always |
| id | Pre-Inbound VPN | Inbound before decrypt (for example, eth1:id) |
R80.20 |
| ID | Post-Inbound VPN | Inbound after decrypt (for example, eth1:ID) |
R80.20 |
| iq | Pre-Inbound QoS | Inbound before QoS (for example, eth1:iq) |
R80.20 |
| IQ | Post-Inbound QoS | Inbound after QoS (for example, eth1:IQ) |
R80.20 |
| o | Pre-Outbound | Before the outbound FireWall VM (for example, eth1:o) |
always |
| O | Post-Outbound | After the outbound FireWall VM (for example, eth1:O) |
always |
|
e oe |
Pre-Outbound VPN |
Outbound before encrypt (for example, (for example, |
R80.10 R80.20 |
|
E OE |
Post-Outbound VPN |
Outbound after encrypt (for example, (for example, |
R80.10 R80.20 |
| oq | Pre-Outbound QoS | Outbound before QoS (for example, eth1:oq) |
R80.20 |
| OQ | Post-Outbound QoS | Outbound after QoS (for example, eth1:OQ) |
R80.20 |
---
New in R80.20+:
In Firewall kernel (now also SecureXL), each kernel is associated with a key witch specifies the type of traffic applicable to the chain modul.
| Key | Function |
|---|---|
| ffffffff | all packets |
| 00000001 | stateful mode |
| 00000002 | wire mode |
| 00000003 | all packets |
| 00000000 | SecureXL offloading |
I wonder where did you get this Heiko 🙂
I have changed it!
Sorry, copy and paste issue 😉
For example, if you add "fw monitor" chain hooks in a certain position, they will also appear as "fff...ff", which means, your understanding of that key is a guess. "00..01" is also just stateful mode, nothing else. "00..00" is indeed used to for re-injecting accelerated traffic back to SXL.
Heiko explained it better than anyone would...but sadly, there is no official CP document explaining the output of fw ctl chain as he stated.
Though, I did find below and it seems very informative:
A detailed description of the inspection points would be very helpful. Maybe is there a good PDF document or SK that Check Point can publish?
I appreciate your curiosity. The exact output is only relevant to kernel developers and TAC, and might only complicate things, but here is your answer:
1 – stateful mode
2 – wired mode
3 – all packets
fff...ff – al packets (same as 3)
Some additional info about the models themselves is here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Once again, unless you are debugging a support case, this is 90% irrelevant
Perfect. I was just trying to understant better how chain modules and inspection happens.
Regards.
Valter Junior
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 18 | |
| 15 | |
| 13 | |
| 12 | |
| 10 | |
| 6 | |
| 5 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY