| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| There was a diag option of fwaccel command in R60. It was very helpful for rulebase optimization for SecureXL. Unfortunately this option was removed in R65. Anybody knows if exists an utility with same functionality for R65? |
| |||
| I think you are looking for "fwaccel stat", gives output like the following: Accelerator Status : on Templates : disabled by FireWall-1 starting from rule #17 Accelerator Features : Accounting, NAT, Cryptography, Routing, HasClock, Templates, Synchronous, IdleDetection, Sequencing, TcpStateDetect, AutoExpire, DelayedNotif, TcpStateDetectV2, CPLS, WireMode Cryptography Features : Tunnel, UDPEncapsulation, MD5, SHA1, NULL, 3DES, DES, CAST, CAST-40, AES-128, AES-256, ESP, LinkSelection, DynamicVPN, NatTraversal, EncRouting As you can see, on this firewall, SecureXL is disabled from rule 17 onwards (due to client authentication). |
![]() |
| Thread Tools | |
| Display Modes | |
| |