<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic can't enable USFW on openserver in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145490#M22928</link>
    <description>&lt;P&gt;CheckMates,&lt;/P&gt;
&lt;P&gt;we tried to enable USFW on an openserver running R81.10., with 2 cores.&lt;/P&gt;
&lt;P&gt;cpprod_util FwSetUsermode 1&lt;BR /&gt;cpprod_util FwSetUsfwMachine 1&lt;/P&gt;
&lt;P&gt;After reboot both values are back to "0"&lt;/P&gt;
&lt;P&gt;In the logs from starting we found "Toggling usermode might have an effect on GW CoreXL split", meaning something changed the values we set before.&amp;nbsp; Founf script "/var/opt/fw.boot/fw1boot" with the following entry:&lt;/P&gt;
&lt;P&gt;# Relevant only for Open Servers&lt;BR /&gt;# WA - until Open Servers will boot in Kerenl mode by default (appliance_config.xml)&lt;BR /&gt;# "Other" - can be Open Server or cloud, but cloud environment run only on kernel space anyway&lt;/P&gt;
&lt;P&gt;if [ "$OPEN_SERVER_OVERRIDE" == 0 ] &amp;amp;&amp;amp; [ "$MGMT" != 1 ] &amp;amp;&amp;amp; [[ ( "$ISSMTOPENSERVER" == "1" &amp;amp;&amp;amp; "$ALLOWED_CORES" -le "20") || ( $MANUFACTURER == "Other" &amp;amp;&amp;amp; "$ALLOWED_CORES" -le "40") ]] ; then&lt;BR /&gt;if [ "$USERMODE" == 1 ]; then&lt;BR /&gt;$CPDIR/bin/cpprod_util FwSetUsermode 0&lt;BR /&gt;$CPDIR/bin/cpprod_util FwSetUsfwMachine 0&lt;/P&gt;
&lt;P&gt;As a result USFW goes back to KMFW with only 2 cores....&lt;/P&gt;
&lt;P&gt;Question =&amp;gt; How to enable USFW on a 2 core Open Server ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Apr 2022 11:39:20 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2022-04-05T11:39:20Z</dc:date>
    <item>
      <title>can't enable USFW on openserver</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145490#M22928</link>
      <description>&lt;P&gt;CheckMates,&lt;/P&gt;
&lt;P&gt;we tried to enable USFW on an openserver running R81.10., with 2 cores.&lt;/P&gt;
&lt;P&gt;cpprod_util FwSetUsermode 1&lt;BR /&gt;cpprod_util FwSetUsfwMachine 1&lt;/P&gt;
&lt;P&gt;After reboot both values are back to "0"&lt;/P&gt;
&lt;P&gt;In the logs from starting we found "Toggling usermode might have an effect on GW CoreXL split", meaning something changed the values we set before.&amp;nbsp; Founf script "/var/opt/fw.boot/fw1boot" with the following entry:&lt;/P&gt;
&lt;P&gt;# Relevant only for Open Servers&lt;BR /&gt;# WA - until Open Servers will boot in Kerenl mode by default (appliance_config.xml)&lt;BR /&gt;# "Other" - can be Open Server or cloud, but cloud environment run only on kernel space anyway&lt;/P&gt;
&lt;P&gt;if [ "$OPEN_SERVER_OVERRIDE" == 0 ] &amp;amp;&amp;amp; [ "$MGMT" != 1 ] &amp;amp;&amp;amp; [[ ( "$ISSMTOPENSERVER" == "1" &amp;amp;&amp;amp; "$ALLOWED_CORES" -le "20") || ( $MANUFACTURER == "Other" &amp;amp;&amp;amp; "$ALLOWED_CORES" -le "40") ]] ; then&lt;BR /&gt;if [ "$USERMODE" == 1 ]; then&lt;BR /&gt;$CPDIR/bin/cpprod_util FwSetUsermode 0&lt;BR /&gt;$CPDIR/bin/cpprod_util FwSetUsfwMachine 0&lt;/P&gt;
&lt;P&gt;As a result USFW goes back to KMFW with only 2 cores....&lt;/P&gt;
&lt;P&gt;Question =&amp;gt; How to enable USFW on a 2 core Open Server ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 11:39:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145490#M22928</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-04-05T11:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: can't enable USFW on openserver</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145491#M22929</link>
      <description>&lt;P&gt;USFW on open server is only supported with 40 and more cores, look into&amp;nbsp;&lt;SPAN&gt;sk167052. Why do you need it for 2 cores only?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 12:06:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145491#M22929</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-04-05T12:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: can't enable USFW on openserver</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145494#M22930</link>
      <description>&lt;P&gt;No&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;, there is no statement in the sk that this is not supported. It's only not enabled by default.&lt;/P&gt;
&lt;P&gt;I know and I really understand that USFW is a little bit useless with only 2 cores. What we want to achieve... We want to use TLS1.3 inspection, which requires USFW enabled.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Threat-Prevention/HTTPS-inspection-of-TLS1-3-and-USFW/m-p/141737#M3553" target="_blank"&gt;https://community.checkpoint.com/t5/Threat-Prevention/HTTPS-inspection-of-TLS1-3-and-USFW/m-p/141737#M3553&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 12:16:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145494#M22930</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-04-05T12:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: can't enable USFW on openserver</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145495#M22931</link>
      <description>&lt;P&gt;Uh, yes, you are right.&lt;BR /&gt;&lt;BR /&gt;Try this:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;EM&gt;cpprod_util FwSetOverrideMode 1&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;cpprod_util FwSetUsermode 1&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;cpprod_util FwSetUsfwMachine 1&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;EM&gt;reboot&lt;/EM&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 05 Apr 2022 12:23:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145495#M22931</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-04-05T12:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: can't enable USFW on openserver</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145496#M22932</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;we saw this magic value "FwSetOverrideMode" and tried, looks good.&lt;/P&gt;
&lt;P&gt;Will this be the supported way to enable USFW on open server with less then 40 cores?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 12:31:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145496#M22932</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-04-05T12:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: can't enable USFW on openserver</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145498#M22933</link>
      <description>&lt;P&gt;For the &lt;U&gt;official answe&lt;/U&gt;r to this question, please &lt;U&gt;check with TAC&lt;/U&gt;. I think their answer will be the same though...&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 12:58:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/145498#M22933</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-04-05T12:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: can't enable USFW on openserver</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/163667#M29227</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;I just tried switching a HA cluster running R81.10 Take 79 from KMFW to USFW, this is open server. I used the new recommended method of using cpconfig -&amp;gt; (10) Check Point CoreXL -&amp;gt; (3) Change firewall mode.&lt;/P&gt;
&lt;P&gt;But upon boot, it seems to be some kind of check going on that reverts it back to KMFW automatically ($FWDIR/scripts/override_server_settings.sh?). Do you know if doing this manually via cpprod_util is expected to behave any differently? USFW is required in order to enable TLS 1.3 support for HTTPS Inspection (fwtls_enable_tlsio=1).&lt;/P&gt;
&lt;P&gt;With the push into USFW as default on appliances, it seems rather strange to enforce KMFW on open server in such a way. Especially when features such as TLS 1.3 requires USFW. Rather strange to not have the cpconfig -&amp;gt; (10) Check Point CoreXL -&amp;gt; (3) Change firewall mode way of doing things not sticking on open server. No need to have the option then.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 08:31:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/163667#M29227</guid>
      <dc:creator>RamGuy239</dc:creator>
      <dc:date>2022-11-30T08:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: can't enable USFW on openserver</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/163669#M29228</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I'm sorry for the above issue, it's indeed a bug, and we are already in the process of deploying the fix for it into our jumbo.&lt;BR /&gt;Please use the following command to change the open server to USFW&lt;/P&gt;
&lt;P&gt;1. cpprod_util FwSetOverrideMode 2&lt;BR /&gt;2. Use cpconfig to change the mode to USFW&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Nov 2022 08:44:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/can-t-enable-USFW-on-openserver/m-p/163669#M29228</guid>
      <dc:creator>shais</dc:creator>
      <dc:date>2022-11-30T08:44:04Z</dc:date>
    </item>
  </channel>
</rss>

