156-215.80 · Question #299
The system administrator of a company is trying to find out why acceleration is not working for the traffic. The traffic is allowed according to the rule base and checked for viruses. But it is not…
The correct answer is D. The traffic is originating from the gateway itself. Check Point SecureXL cannot accelerate traffic that originates from the gateway itself, as acceleration only applies to traffic transiting through the gateway.
Question
The system administrator of a company is trying to find out why acceleration is not working for the traffic. The traffic is allowed according to the rule base and checked for viruses. But it is not accelerated. What is the most likely reason that the traffic is not accelerated?
Options
- AThere is a virus found. Traffic is still allowed but not accelerated
- BThe connection required a Security server
- CAcceleration is not enabled
- DThe traffic is originating from the gateway itself
How the community answered
(25 responses)- A8% (2)
- B4% (1)
- C4% (1)
- D84% (21)
Why each option
Check Point SecureXL cannot accelerate traffic that originates from the gateway itself, as acceleration only applies to traffic transiting through the gateway.
A detected virus would cause traffic to be blocked or quarantined rather than allowed-but-unaccelerated; virus detection does not produce an allow-without-acceleration outcome.
While requiring a legacy Security server can prevent SecureXL acceleration, the question's scenario involves an active virus scan and allowed traffic - gateway-originated traffic is the more specific and architecturally fundamental reason for the acceleration failure described.
If acceleration were globally disabled, all traffic would be unaccelerated, not just this specific flow - the question implies other traffic is being accelerated normally.
Check Point SecureXL acceleration works by offloading inspection to a specialized layer for transit traffic - packets traveling through the gateway from one interface to another. Traffic originating from the gateway's own processes or IP address bypasses SecureXL entirely because it is handled by the local OS network stack rather than the forwarding path that SecureXL intercepts, making acceleration architecturally impossible for locally generated traffic.
Concept tested: SecureXL acceleration exclusion for gateway-originated traffic
Source: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_PerformanceTuning_AdminGuide/Topics-PTG/SecureXL.htm
Topics
Community Discussion
No community discussion yet for this question.