sk184356 - Firewall Drop Optimization in R82.10 and higher

Firewall Drop Optimization in R82.10 and higher

Solution

Note - For the R81.20 and R82 versions, see sk175006.

Table of Contents:

Introduction

If you configure explicit rules in an Access Control policy with the Action "Drop", then Firewall updates SecureXL (by offloading Firewall Drop Templates) about each new connection that it dropped based on these rules. SecureXL drops all subsequent packets in these and similar connections (from the same Source IP address to the same Destination IP address, to the same Destination Port, over the same Protocol). This way, Security Gateway does not spend its resources to match packets of such connections.

R82.10 introduces the redesigned Drop Optimization feature for Access Control policy. The new design supports more acceleration use cases (such as Security Zones, Access Roles, Time) and offloads the traffic to ASIC-powered network cards.

Note - In R82.10, the Drop Templates feature is part of the Firewall kernel (the "VM" chain).

Limitations

Enabling Firewall Drop Templates

By default, this feature is disabled.

  1. From the left panel, click Gateways & Servers.
  2. Double-click the Security Gateway / Cluster object.
  3. In the left panel, click Optimizations.
  4. In the Firewall Policy Optimization section, select Enable drop optimization.
  5. Click OK.
  6. Install the Access Control Policy.

CLI Commands

Use the commands below on the Security Gateway to see the applicable information about Firewall Drop Templates.

Command Description
fw templates Recommended command.
Shows existing Firewall Drop Templates in the global kernel table.
fwaccel templates -c Alternative command.
Shows existing Firewall Drop Templates in the global kernel table.
fw tab -t fw_generic_mode_drop_templates -u Prints the global kernel table with drop templates.
fwaccel stat Shows if any Access Control rules are preventing the offloading of drop templates from the Firewall to SecureXL.
This output helps identify Access Control rules that contain services with match expressions that disable template optimization.
cpview Shows comprehensive statistics for Drop Templates:
Network > Templates > Drop-Templates
See sk101878.

Kernel Parameters

The table below describes kernel parameters on the Security Gateway that control the Drop Optimization feature.

For procedures about working with kernel parameters, see the Security Gateway Administration Guide for your version.

Important - Do not change these values unless Check Point Support explicitly tells you to do so.

Kernel Parameter Default Value Valid Values Description
fw_generic_mode_drop_templates_enabled 1 0, 1 Enables (1) and disables (0) the Generic Mode Drop Templates.
fw_generic_mode_drop_templates_expire_time 3 0 - (232-1) Specifies the entry expiration time (in seconds) in the kernel table that holds Drop Templates.
1. When the Security Gateway drops the first packet of a connection, it offloads the Drop Template.
2. During this expiration time, the Security Gateway continues to drop packets of this connection.
3. After this time expires, the Drop Template expires, and the Security Gateway performs full rulebase match again.
fw_generic_mode_drop_templates_keep 1 0, 1 Specifies whether to keep (1) or delete (0) all existing Drop Templates during the policy installation.
Important - Do not change this value unless explicitly instructed by Check Point Support.
fw_generic_mode_drop_templates_table_limit_size 0 0 - (232-1) Specifies the size of the global kernel table that holds Drop Templates.
0 = unlimited.
fw_generic_mode_drop_templates_table_hashsize 0 0 - (232-1) Specifies the size of the auto-calculated hash.
Important:
- 0 = automatically calculated.
- Do not change this value unless explicitly instructed by Check Point Support.
- The higher this value, the more memory is used.
fw_generic_mode_drop_templates_stats_expire_time 300 0 - (232-1) Specifies the entry expiration time (in seconds) in the global kernel table with statistics (for tools such as CPView, Skyline)
fw_generic_mode_drop_templates_stats_table_limit_size 25000 0 - (232-1) Specifies the size of the global kernel table with statistics.
Important:
- Do not change this value unless explicitly instructed by Check Point Support.
- The higher this value, the more memory is used.
fw_generic_mode_drop_templates_stats_table_hashsize 512 0 - (232-1) Specifies the size of the kernel table with statistics hash.
Important:
- Do not change this value unless explicitly instructed by Check Point Support.
- The higher this value, the more memory is used.

Common Issues

# Issue Description
1 Drop Templates are not being created Symptoms:
The expected drop template is not found in the global kernel table.
Possible Causes:
- The connection matches a service or a rule with specific restrictions (e.g., traceroute, DHCP).
- Memory allocation failure during template creation.
Next Steps:
Check if the connection matches any restrictive services or rules.
Ensure the Security Gateway has enough available memory for template creation.
2 Traffic is not matched to a Drop Template Symptoms:
Traffic that should be dropped is not being matched by the existing Drop Template.
Possible Causes:
- Drop Template expired.
- Connection parameters do not match exactly.
Next Steps:
1. Check template expiration settings.

Verify the connection parameters against the expected template parameters.
3 Memory Issues Symptoms:
Memory allocation failures, high memory usage.
Possible Causes:
- Excessive memory consumption by other processes.
- Memory leaks in software.
- Insufficient RAM.
Next Steps:
1. Optimize or restart processes that consume memory at an excessive level.
2. Install more RAM.

Kernel Debug

For complete explanations about the kernel debug procedure, see the Security Gateway Administration Guide for your version.

  1. fw ctl debug 0
  2. fw ctl debug -buf 8200
  3. fw ctl debug -m UP + sec_rb probtrc info
  4. fw ctl debug -m fw + conn vm log drop drop_tmpl
  5. fw ctl kdebug -T -f >& /var/log/debug.txt &
  6. Replicate the issue - pass the traffic that explicit rules must drop
  7. fw ctl debug 0
  8. Examine the output file /var/log/debug.txt