An administrator is troubleshooting a Check Point Security Gateway that is experiencing performance degradation. The administrator runs 'fwaccel stats -s' and notices a high number of 'Non-accelerated conns' with the reason 'P' (Policy). Which of the following is the most likely cause for this?
The 'P' flag indicates that the connection is not accelerated due to policy, which often means the rule requires deep packet inspection or logging that SecureXL cannot handle. For example, rules with 'X11' or other application-layer inspection force the connection to be processed by the Firewall Kernel. This is a common reason for non-accelerated connections with the 'P' reason code. The administrator should review the policy to identify such rules.
Why this answer
The 'P' reason code in 'fwaccel stats -s' indicates that connections are not accelerated because of policy settings, such as rules that require deep packet inspection or logging. This is common when rules include application control, content inspection, or other features that SecureXL cannot offload. The administrator should examine the security policy to find rules that enforce such inspections and consider whether they are necessary.
Other reason codes like 'C' for crypto or 'S' for services point to different causes, so the 'P' flag specifically directs attention to policy.
Exam trap
The trap here is assuming that any non-acceleration is due to encryption or services, when the 'P' flag specifically points to policy-driven deep inspection.