{"id":1104,"date":"2019-03-19T15:56:24","date_gmt":"2019-03-19T15:56:24","guid":{"rendered":"http:\/\/www.ankenbrand24.de\/?page_id=1104"},"modified":"2019-03-19T16:04:53","modified_gmt":"2019-03-19T16:04:53","slug":"fw-monitor","status":"publish","type":"page","link":"https:\/\/www.ankenbrand24.de\/index.php\/articles\/check-point-articel\/performance-tuning\/fw-monitor\/","title":{"rendered":"FW Monitor"},"content":{"rendered":"\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<h2 class=\"message-subject\" style=\"text-align: center;\"><span class=\"lia-message-read\">R80.x Performance Tuning and Debug Tips \u2013 fw monitor<\/span><\/h2>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">R80.20 &#8211; fw monitor<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p><img loading=\"lazy\" class=\"alignnone  wp-image-1107\" src=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/monitor_1.png\" alt=\"\" width=\"269\" height=\"155\" srcset=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/monitor_1.png 449w, https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/monitor_1-150x87.png 150w\" sizes=\"(max-width: 269px) 100vw, 269px\" \/><\/p>\n<p><span style=\"color: #33cccc; font-size: 22px;\"><strong>Tip 1<\/strong><\/span><\/p>\n<p><span style=\"font-size: 15px;\">SecureXL has been significantly revised in R80.20. It now works in user space.&nbsp;This has also led to some changes in &#8220;fw monitor&#8221;.<\/span><\/p>\n<p><span style=\"font-size: 15px;\">Since R80.20&nbsp; &#8220;fw monitor&#8221; is able to show the traffic accelerated with SecureXL. Thus it is possible to see SecureXL (provide more performance<strong>)<\/strong>&nbsp;modules in fw monitor chain. For more informations revert to &#8220;SecureXL offloading chain modules&#8221; in this article. Now you can see that SecureXL is used, which increases the performance of the firewall.<br><br><\/span><span style=\"font-size: 15px;\">SecureXL &#8220;<span style=\"color: #ff0000;\"><strong>fwaccel off<\/strong><\/span>&#8221; does <span style=\"color: #ff0000;\"><strong>not<\/strong><\/span> have to be <span style=\"color: #ff0000;\"><strong>disabled on R80.20<\/strong><\/span> to run &#8220;fw monitor&#8221;. This is good for performance, so &#8220;fw monitor&#8221; does not affect performance any more.<\/span><\/p>\n<p># <span style=\"text-decoration: line-through; color: #ff0000;\"><strong>fwaccel off<\/strong><\/span> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;&nbsp; &gt;&nbsp;no longer necessary in R80.20 and above<\/p>\n<p># <strong>fw monitor -e &#8220;accept(&#8230;);&#8221;<\/strong><\/p>\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">R77.30 and R80.10 &#8211; fw monitor<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p><span style=\"font-size: 15px;\">On R77.30 and R80.10 only disabling SecureXL allows to see the complete connection in fw monitor, which may be required for troubleshooting purposes or revert to &#8220;<a class=\"link-titled\" title=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk104468&amp;partition=Advanced&amp;product=SecureXL%22\" href=\"https:\/\/supportcenter.checkpoint.com\/supportcenter\/portal?eventSubmit_doGoviewsolutiondetails=&amp;solutionid=sk104468&amp;partition=Advanced&amp;product=SecureXL%22\" target=\"_blank\" rel=\"noopener noreferrer\">How to disable SecureXL for specific IP addresses&#8221;<\/a>.<\/span><\/p>\n<p># <strong>fwaccel off<\/strong> &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;<\/p>\n<p># <strong>fw monitor -e &#8220;accept(&#8230;);&#8221;<\/strong><\/p>\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">New fw monitor inspection points in R80.20<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p><span style=\"color: #33cccc; font-size: 15px;\"><strong><span style=\"font-size: 22px;\">Tip 2<\/span><br><\/strong><\/span><\/p>\n<p><span style=\"font-size: 15px;\">Furthermore there are new fw monitor inspection points available:<br><\/span><\/p>\n<table class=\"j-table jiveBorder\" style=\"border: 1px solid #c6c6c6; width: 100%;\" width=\"100%\">\n<thead>\n<tr style=\"background-color: #efefef; height: 25px;\">\n<th style=\"width: 10%; height: 25px; border: 1px solid #dbdbdb; background-color: lightgray;\">Inspection point<\/th>\n<th style=\"width: 22%; height: 25px; border: 1px solid #dbdbdb; background-color: lightgray;\">Name of fw monitor inspection point<\/th>\n<th style=\"width: 53.6022%; height: 25px; border: 1px solid #dbdbdb; background-color: lightgray;\">Relation to firewall VM<\/th>\n<th style=\"width: 59.3978%; height: 25px; border: 1px solid #dbdbdb; background-color: lightgray;\">Available since version<\/th>\n<\/tr>\n<tr style=\"height: 27px;\">\n<td style=\"width: 10%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">i<\/td>\n<td style=\"width: 22%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Pre-Inbound<\/td>\n<td style=\"width: 53.6022%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Before the inbound FireWall VM<\/td>\n<td style=\"width: 59.3978%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">always<\/td>\n<\/tr>\n<tr style=\"height: 27px;\">\n<td style=\"width: 10%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">I<\/td>\n<td style=\"width: 22%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Post-Inbound<\/td>\n<td style=\"width: 53.6022%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">After the inbound FireWall VM<\/td>\n<td style=\"width: 59.3978%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">always<\/td>\n<\/tr>\n<tr style=\"height: 27px;\">\n<td style=\"width: 10%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\"><span style=\"color: #ff0000;\"><strong>id<\/strong><\/span><\/td>\n<td style=\"width: 22%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Pre-Inbound VPN<\/td>\n<td style=\"width: 53.6022%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Inbound before decrypt <\/td>\n<td style=\"width: 59.3978%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\"><span style=\"color: #ff0000;\"><strong>R80.20<\/strong><\/span><\/td>\n<\/tr>\n<tr style=\"height: 27px;\">\n<td style=\"width: 10%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\"><span style=\"color: #ff0000;\"><strong>ID<\/strong><\/span><\/td>\n<td style=\"width: 22%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Post-Inbound VPN<\/td>\n<td style=\"width: 53.6022%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Inbound after decrypt<\/td>\n<td style=\"width: 59.3978%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\"><span style=\"color: #ff0000;\"><strong>R80.20<\/strong><\/span><\/td>\n<\/tr>\n<tr style=\"height: 27px;\">\n<td style=\"width: 10%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\"><span style=\"color: #ff0000;\"><strong>iq<\/strong><\/span><\/td>\n<td style=\"width: 22%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Pre-Inbound QoS<\/td>\n<td style=\"width: 53.6022%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Inbound before QoS <\/td>\n<td style=\"width: 59.3978%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\"><span style=\"color: #ff0000;\"><strong>R80.20<\/strong><\/span><\/td>\n<\/tr>\n<tr style=\"height: 27px;\">\n<td style=\"width: 10%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\"><span style=\"color: #ff0000;\"><strong>IQ<\/strong><\/span><\/td>\n<td style=\"width: 22%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Post-Inbound QoS<\/td>\n<td style=\"width: 53.6022%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Inbound after QoS <\/td>\n<td style=\"width: 59.3978%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\"><span style=\"color: #ff0000;\"><strong>R80.20<\/strong><\/span><\/td>\n<\/tr>\n<tr style=\"height: 27px;\">\n<td style=\"width: 10%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">o<\/td>\n<td style=\"width: 22%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Pre-Outbound<\/td>\n<td style=\"width: 53.6022%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Before the outbound FireWall VM <\/td>\n<td style=\"width: 59.3978%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">always<\/td>\n<\/tr>\n<tr style=\"height: 27px;\">\n<td style=\"width: 10%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">O<\/td>\n<td style=\"width: 22%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Post-Outbound<\/td>\n<td style=\"width: 53.6022%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">After the outbound FireWall VM<\/td>\n<td style=\"width: 59.3978%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">always<\/td>\n<\/tr>\n<tr style=\"height: 27px;\">\n<td style=\"width: 10%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">\n<p><span style=\"color: #33cccc;\"><strong>e<\/strong><\/span><\/p>\n<p><span style=\"color: #ff0000;\"><strong>oe<\/strong><\/span><\/p>\n<\/td>\n<td style=\"width: 22%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Pre-Outbound VPN*<\/td>\n<td style=\"width: 53.6022%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">\n<p>Outbound before encrypt&nbsp;<\/p>\n<\/td>\n<td style=\"width: 59.3978%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">\n<p><span style=\"color: #00ccff;\"><strong>R80.10<\/strong><\/span><\/p>\n<p><span style=\"color: #ff0000;\"><strong>R80.20<\/strong><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 27px;\">\n<td style=\"width: 10%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">\n<p><span style=\"color: #33cccc;\"><strong>E<\/strong><\/span><\/p>\n<p><span style=\"color: #ff0000;\"><strong>OE<\/strong><\/span><\/p>\n<\/td>\n<td style=\"width: 22%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Post-Outbound VPN*<\/td>\n<td style=\"width: 53.6022%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">\n<p>Outbound after encrypt<\/p>\n<\/td>\n<td style=\"width: 59.3978%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">\n<p><span style=\"color: #33cccc;\"><strong>R80.10<\/strong><\/span><\/p>\n<p><span style=\"color: #ff0000;\"><strong>R80.20<\/strong><\/span><\/p>\n<\/td>\n<\/tr>\n<tr style=\"height: 27px;\">\n<td style=\"width: 10%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\"><span style=\"color: #ff0000;\"><strong>oq<\/strong><\/span><\/td>\n<td style=\"width: 22%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Pre-Outbound QoS<\/td>\n<td style=\"width: 53.6022%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Outbound before QoS<\/td>\n<td style=\"width: 59.3978%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\"><span style=\"color: #ff0000;\"><strong>R80.20<\/strong><\/span><\/td>\n<\/tr>\n<tr style=\"height: 27px;\">\n<td style=\"width: 10%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\"><span style=\"color: #ff0000;\"><strong>OQ<\/strong><\/span><\/td>\n<td style=\"width: 22%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Post-Outbound QoS<\/td>\n<td style=\"width: 53.6022%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\">Outbound after QoS<\/td>\n<td style=\"width: 59.3978%; height: 27px; border: 1px solid #dbdbdb; background-color: #ffffff;\"><span style=\"color: #ff0000;\"><strong>R80.20<\/strong><\/span><\/td>\n<\/tr>\n<\/thead>\n<\/table>\n<p>* The fw monitor inspection point is different in R80.10 (&#8220;e&#8221; or &#8220;E&#8221;) and R80.20 (&#8220;oe&#8221; and &#8220;OE&#8221;)<\/p>\n<p><span style=\"font-size: 15px;\">For more information, see <a title=\"\" href=\"http:\/\/supportcontent.checkpoint.com\/solutions?id=sk30583\" target=\"_blank\" rel=\"noopener noreferrer\">sk30583<\/a>, <a href=\"https:\/\/sc1.checkpoint.com\/documents\/R80.20_GA\/WebAdminGuides\/EN\/CP_R80.20_CLI_ReferenceGuide\/208177.htm\" target=\"_blank\" rel=\"noopener noreferrer\">fw monitor<\/a> or <a title=\"\" href=\"http:\/\/downloads.checkpoint.com\/dc\/download.htm?ID=9068\" target=\"_blank\" rel=\"noopener noreferrer\">How to use FW Monitor<\/a>.<\/span><\/p>\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">SecureXL offloading chain modules<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p><span style=\"color: #33cccc;\"><strong><span style=\"font-size: 22px;\">Tip 3<\/span><br><\/strong><\/span><\/p>\n<p>Like I said SecureXL has been significantly revised in R80.20. It now works in user space.&nbsp;This has also led to some changes in &#8220;fw monitor&#8221;<\/p>\n<p>There are new fw monitor chain (SecureXL) objects that do not run in the virtual machine.<\/p>\n<p><span style=\"font-size: 12.0pt;\"># <strong>fw ctl chain<\/strong><\/span> <span style=\"font-size: 12.0pt;\"><br><img loading=\"lazy\" class=\"alignnone size-full wp-image-1108\" src=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/monitor_2.png\" alt=\"\" width=\"685\" height=\"152\" srcset=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/monitor_2.png 685w, https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/monitor_2-150x33.png 150w\" sizes=\"(max-width: 685px) 100vw, 685px\" \/><br><\/span><span style=\"font-size: 12.0pt;\">The new fw monitor chain modules&nbsp;(SecureXL) do not run in the virtual machine (vm).<br><\/span><span style=\"color: red; font-size: 12.0pt;\"><strong>SecureXL inbound (sxl_in)<\/strong><\/span> <span style=\"font-size: 12.0pt;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&nbsp; &gt; Packet received in SecureXL from network<br><\/span><span style=\"color: red; font-size: 12.0pt;\"><strong>SecureXL inbound CT (sxl_ct)<\/strong><\/span><span style=\"font-size: 12.0pt; color: red;\">&nbsp;<\/span> <span style=\"font-size: 12.0pt;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&gt; Accelerated packets moved from inbound to outbound processing (post routing)<br><\/span><span style=\"color: red; font-size: 12.0pt;\"><strong>SecureXL outbound (sxl_out)<\/strong><\/span><span style=\"font-size: 12.0pt;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp;&gt; Accelerated packet starts outbound processing<br><\/span><span style=\"color: red; font-size: 12.0pt;\"><strong>SecureXL deliver (sxl_deliver)<\/strong><\/span> <span style=\"font-size: 12.0pt;\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &gt; SecureXL transmits accelerated packet<\/span><\/p>\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">New VM chain modules in R80.20<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p><span style=\"color: #33cccc;\"><strong><span style=\"font-size: 22px;\">Tip 4<\/span><br><\/strong><\/span><\/p>\n<p>There are more new chain modules in R80.20<\/p>\n<p><span style=\"color: red;\"><strong>vpn before offload (vpn_in)&nbsp;<\/strong><\/span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &nbsp; &gt; FW inbound preparing the tunnel for offloading the packet (along with the connection)<br><span style=\"color: red;\"><strong>fw offload inbound (offload_in)&nbsp;<\/strong><\/span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &gt; FW inbound that perform the offload<br><span style=\"color: red;\"><strong>fw post VM inbound&nbsp; (post_vm)&nbsp;<\/strong><\/span>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; &gt; Packet was not offloaded (slow path) &#8211; continue processing in FW inbound<\/p>\n<p># <strong>fw ctl chain<\/strong><strong>&nbsp;<br><img loading=\"lazy\" class=\"alignnone size-full wp-image-1109\" src=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/monitor_3.png\" alt=\"\" width=\"670\" height=\"72\" srcset=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/monitor_3.png 670w, https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/monitor_3-150x16.png 150w\" sizes=\"(max-width: 670px) 100vw, 670px\" \/><br><\/strong><\/p>\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">New fw monitor chain key (00000000)<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p><span style=\"color: #33cccc;\"><strong><span style=\"font-size: 22px;\">Tip 5<\/span><br><\/strong><\/span><\/p>\n<p><span style=\"font-size: 12.0pt;\">In Firewall kernel (now also SecureXL), each kernel is associated with a key (<span style=\"color: #ff0000;\">red<\/span>) witch specifies the type of traffic applicable to the chain modul.<\/span><\/p>\n<p><span style=\"font-size: 12.0pt;\">&nbsp;<\/span><span style=\"font-size: 12.0pt;\"># <strong>fw ctl chain<\/strong><\/span><span style=\"font-size: 12.0pt;\">&nbsp;<br><img loading=\"lazy\" class=\"alignnone size-full wp-image-1110\" src=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/monitor_4.png\" alt=\"\" width=\"695\" height=\"88\" srcset=\"https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/monitor_4.png 695w, https:\/\/www.ankenbrand24.de\/wp-content\/uploads\/2019\/03\/monitor_4-150x19.png 150w\" sizes=\"(max-width: 695px) 100vw, 695px\" \/><br><\/span><\/p>\n<table class=\"j-table jiveBorder\" style=\"border: 1px solid #c6c6c6; width: 45.8412%;\">\n<thead>\n<tr style=\"background-color: #efefef;\">\n<th style=\"width: 12%;\">Key<\/th>\n<th style=\"width: 30.8412%;\">Function<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 12%;\"><span style=\"font-family: terminal, monaco, monospace;\"><strong>ffffffff<\/strong><\/span><\/td>\n<td style=\"width: 30.8412%;\">IP Option Stip\/Restore<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12%;\"><span style=\"font-family: terminal, monaco, monospace;\"><strong>00000001<\/strong><\/span><\/td>\n<td style=\"width: 30.8412%;\">new processed flows<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12%;\"><span style=\"font-family: terminal, monaco, monospace;\"><strong>00000002<\/strong><\/span><\/td>\n<td style=\"width: 30.8412%;\">wire mode<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12%;\"><span style=\"font-family: terminal, monaco, monospace;\"><strong>00000003<\/strong><\/span><\/td>\n<td style=\"width: 30.8412%;\">will applied to all ciphered traffic (VPN)<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 12%;\"><span style=\"color: #ff0000; font-family: terminal, monaco, monospace;\"><strong>00000000<\/strong><\/span><\/td>\n<td style=\"width: 30.8412%;\">SecureXL offloading (<span style=\"color: #ff0000;\"><strong>new in R80.20+<\/strong><\/span>)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<table style=\"border: 1px solid #c6c6c6; border-collapse: separate; border-radius: 5px; background-color: #e15180; padding: 6px; text-indent: 10px;\" width=\"100%\">\n<thead>\n<tr>\n<th align=\"left\"><span style=\"color: #ffffff; font-size: large;\">References<\/span><\/th>\n<\/tr>\n<\/thead>\n<\/table>\n<p>R&amp;D meeting Israel<\/p>\n<p>Copyright by Heiko Ankenbrand 1994-2019<\/p>\n","protected":false},"excerpt":{"rendered":"<p>R80.x Performance Tuning and Debug Tips \u2013 fw monitor R80.20 &#8211; fw monitor Tip 1 SecureXL has been significantly revised in R80.20. It now works in user space.&nbsp;This has also led to some changes in &#8220;fw monitor&#8221;. Since R80.20&nbsp; &#8220;fw monitor&#8221; is able to show the traffic accelerated with SecureXL. Thus it is possible to<\/p>\n<p><a class=\"button\" href=\"https:\/\/www.ankenbrand24.de\/index.php\/articles\/check-point-articel\/performance-tuning\/fw-monitor\/\" title=\"More\">  Read More \u2192<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":1068,"menu_order":4,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/pages\/1104"}],"collection":[{"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/comments?post=1104"}],"version-history":[{"count":8,"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/pages\/1104\/revisions"}],"predecessor-version":[{"id":1117,"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/pages\/1104\/revisions\/1117"}],"up":[{"embeddable":true,"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/pages\/1068"}],"wp:attachment":[{"href":"https:\/\/www.ankenbrand24.de\/index.php\/wp-json\/wp\/v2\/media?parent=1104"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}