sk184356 - Firewall Drop Optimization in R82.10 and higher
Firewall Drop Optimization in R82.10 and higher
Solution
Note - For the R81.20 and R82 versions, see sk175006.
Table of Contents:
- Introduction
- Limitations
- Enabling Firewall Drop Templates
- CLI Commands
- Kernel Parameters
- Common Issues
- Kernel Debug
Introduction
If you configure explicit rules in an Access Control policy with the Action "Drop", then Firewall updates SecureXL (by offloading Firewall Drop Templates) about each new connection that it dropped based on these rules. SecureXL drops all subsequent packets in these and similar connections (from the same Source IP address to the same Destination IP address, to the same Destination Port, over the same Protocol). This way, Security Gateway does not spend its resources to match packets of such connections.
R82.10 introduces the redesigned Drop Optimization feature for Access Control policy. The new design supports more acceleration use cases (such as Security Zones, Access Roles, Time) and offloads the traffic to ASIC-powered network cards.
Note - In R82.10, the Drop Templates feature is part of the Firewall kernel (the "VM" chain).
Limitations
- The Security Gateway cannot offload drop templates for all rules starting from the first rule that in the column "Services and Applications" contains a service of type "Other Service" in which a "Match" expression is configured.
- The Security Gateway cannot offload a drop template for a rule that in the column "Services and Applications" contains one of these services: traceroute, DHCP services.
Enabling Firewall Drop Templates
By default, this feature is disabled.
- From the left panel, click Gateways & Servers.
- Double-click the Security Gateway / Cluster object.
- In the left panel, click Optimizations.
- In the Firewall Policy Optimization section, select Enable drop optimization.
- Click OK.
- Install the Access Control Policy.
CLI Commands
Use the commands below on the Security Gateway to see the applicable information about Firewall Drop Templates.
| Command | Description |
fw templates |
Recommended command. Shows existing Firewall Drop Templates in the global kernel table. |
fwaccel templates -c |
Alternative command. Shows existing Firewall Drop Templates in the global kernel table. |
fw tab -t fw_generic_mode_drop_templates -u |
Prints the global kernel table with drop templates. |
fwaccel stat |
Shows if any Access Control rules are preventing the offloading of drop templates from the Firewall to SecureXL. This output helps identify Access Control rules that contain services with match expressions that disable template optimization. |
cpview |
Shows comprehensive statistics for Drop Templates: Network > Templates > Drop-Templates See sk101878. |
Kernel Parameters
The table below describes kernel parameters on the Security Gateway that control the Drop Optimization feature.
For procedures about working with kernel parameters, see the Security Gateway Administration Guide for your version.
Important - Do not change these values unless Check Point Support explicitly tells you to do so.
| Kernel Parameter | Default Value | Valid Values | Description |
fw_generic_mode_drop_templates_enabled |
1 | 0, 1 | Enables (1) and disables (0) the Generic Mode Drop Templates. |
fw_generic_mode_drop_templates_expire_time |
3 | 0 - (232-1) | Specifies the entry expiration time (in seconds) in the kernel table that holds Drop Templates. 1. When the Security Gateway drops the first packet of a connection, it offloads the Drop Template. 2. During this expiration time, the Security Gateway continues to drop packets of this connection. 3. After this time expires, the Drop Template expires, and the Security Gateway performs full rulebase match again. |
fw_generic_mode_drop_templates_keep |
1 | 0, 1 | Specifies whether to keep (1) or delete (0) all existing Drop Templates during the policy installation. Important - Do not change this value unless explicitly instructed by Check Point Support. |
fw_generic_mode_drop_templates_table_limit_size |
0 | 0 - (232-1) | Specifies the size of the global kernel table that holds Drop Templates. 0 = unlimited. |
fw_generic_mode_drop_templates_table_hashsize |
0 | 0 - (232-1) | Specifies the size of the auto-calculated hash. Important: - 0 = automatically calculated. - Do not change this value unless explicitly instructed by Check Point Support. - The higher this value, the more memory is used. |
fw_generic_mode_drop_templates_stats_expire_time |
300 | 0 - (232-1) | Specifies the entry expiration time (in seconds) in the global kernel table with statistics (for tools such as CPView, Skyline) |
fw_generic_mode_drop_templates_stats_table_limit_size |
25000 | 0 - (232-1) | Specifies the size of the global kernel table with statistics. Important: - Do not change this value unless explicitly instructed by Check Point Support. - The higher this value, the more memory is used. |
fw_generic_mode_drop_templates_stats_table_hashsize |
512 | 0 - (232-1) | Specifies the size of the kernel table with statistics hash. Important: - Do not change this value unless explicitly instructed by Check Point Support. - The higher this value, the more memory is used. |
Common Issues
| # | Issue | Description |
| 1 | Drop Templates are not being created | Symptoms: The expected drop template is not found in the global kernel table. Possible Causes: - The connection matches a service or a rule with specific restrictions (e.g., traceroute, DHCP). - Memory allocation failure during template creation. Next Steps: Check if the connection matches any restrictive services or rules. Ensure the Security Gateway has enough available memory for template creation. |
| 2 | Traffic is not matched to a Drop Template | Symptoms: Traffic that should be dropped is not being matched by the existing Drop Template. Possible Causes: - Drop Template expired. - Connection parameters do not match exactly. Next Steps: 1. Check template expiration settings. Verify the connection parameters against the expected template parameters. |
| 3 | Memory Issues | Symptoms: Memory allocation failures, high memory usage. Possible Causes: - Excessive memory consumption by other processes. - Memory leaks in software. - Insufficient RAM. Next Steps: 1. Optimize or restart processes that consume memory at an excessive level. 2. Install more RAM. |
Kernel Debug
For complete explanations about the kernel debug procedure, see the Security Gateway Administration Guide for your version.
fw ctl debug 0fw ctl debug -buf 8200fw ctl debug -m UP + sec_rb probtrc infofw ctl debug -m fw + conn vm log drop drop_tmplfw ctl kdebug -T -f >& /var/log/debug.txt &- Replicate the issue - pass the traffic that explicit rules must drop
fw ctl debug 0- Examine the output file
/var/log/debug.txt