<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.20 Securexl not disable in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34933#M2840</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you tell me how to add this script?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Mar 2019 04:38:26 GMT</pubDate>
    <dc:creator>sam_huang</dc:creator>
    <dc:date>2019-03-05T04:38:26Z</dc:date>
    <item>
      <title>R80.20 Securexl not disable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34930#M2837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will R80.20! How do we completely shut down securexl&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 17:36:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34930#M2837</guid>
      <dc:creator>sam_huang</dc:creator>
      <dc:date>2019-02-21T17:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Securexl not disable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34931#M2838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know, in cpconfig this option is no longer available ! Find the&amp;nbsp;reference in&amp;nbsp;Next Generation Security Gateway Guide R80.20 p.235 - there is no possibility anymore to permanently disable SecureXL. Of course, you could write a cron job script testing the SecureXL state and issuing fwaccel off if needed, as any reboot will turn SecureXL on again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2019 12:39:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34931#M2838</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-02-22T12:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Securexl not disable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34932#M2839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can't completely shut down SecureXL in R80.20.&lt;/P&gt;&lt;P&gt;For what reason do you wish to shut down SecureXL?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Feb 2019 11:43:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34932#M2839</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-02-23T11:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Securexl not disable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34933#M2840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you tell me how to add this script?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2019 04:38:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34933#M2840</guid>
      <dc:creator>sam_huang</dc:creator>
      <dc:date>2019-03-05T04:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Securexl not disable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34934#M2841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the problem can be solved by disabling SecureXL, then it's a bug and it needs to be brought through the TAC.&lt;/P&gt;&lt;P&gt;Why are you asking for SecureXL to be permanently disabled?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Mar 2019 05:55:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34934#M2841</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-05T05:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Securexl not disable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34935#M2842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;More infos to R80.20+ SecureXL you found here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-3180"&gt;R80.20 SecureXL + new chain modules + fw monitor&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do not turn SecureXL off completely.&lt;/P&gt;&lt;P&gt;Disable SecureXL for singel IP addresses with problems.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:59:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34935#M2842</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-10T09:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Securexl not disable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34936#M2843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SK:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL&amp;quot;" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL&amp;quot;"&gt;How to disable SecureXL for specific IP addresses&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:03:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/34936#M2843</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-10T10:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Securexl not disable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/59801#M4522</link>
      <description>&lt;P&gt;I also need option to permanently disable SecureXL as it produces lots of problems when HTTPS inspection is enabled.&lt;/P&gt;&lt;P&gt;I have at least two customers who are running HTTPS inspection without problems when SecureXL is disabled. They have strong enough boxes that acceleration is not needed at this point.&lt;/P&gt;&lt;P&gt;So turning off SecureXL permanently is must have feature by my opinion.&lt;/P&gt;&lt;P&gt;Disabling SecureXL for specific IP addresses sounds promising but it is unusable until network addresses are permited, so we can exclude whole subnets from acceleration.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;--&lt;BR /&gt;Marko&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 10:54:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/59801#M4522</guid>
      <dc:creator>Marko_Keca</dc:creator>
      <dc:date>2019-08-07T10:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Securexl not disable</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/59814#M4523</link>
      <description>&lt;P&gt;If you find yourself having to disable SecureXL in R80.20+, the best course of action is to open a TAC case so the problem can be identified and fixed.&amp;nbsp; Disabling SecureXL long-term in R80.20+ is not a good idea and will eventually get you into further trouble.&lt;/P&gt;
&lt;P&gt;However in the interim, there is a workaround for disabling SecureXL upon bootup on R80.20+ in this thread:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/R80-20-SIT-Tunnel/m-p/28139" target="_blank"&gt;https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/R80-20-SIT-Tunnel/m-p/28139&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;While your box may be "strong enough" to handle the workload without the SecureXL functions throughput acceleration and rulebase accept templating (session rate acceleration), keep in mind that disabling SecureXL will also disable automatic interface affinity and Multi-Queue.&amp;nbsp; This will cause all SoftIRQ processing for all interfaces to happen on the lowest-numbered SND/IRQ core, typically CPU #0 which can easily get overloaded in this situation.&amp;nbsp; After disabling SecureXL keep an eye on the RX-DRP counter reported by command &lt;STRONG&gt;netstat -ni&lt;/STRONG&gt;, if the RX-DRP rate rises above 0.1% on any interface you will need to define manual interface affinity via the &lt;STRONG&gt;fw ctl affinity -i&lt;/STRONG&gt; command and the &lt;STRONG&gt;fwaffinity.conf&lt;/STRONG&gt; file (not the&lt;STRONG&gt; sim affinity&lt;/STRONG&gt; command since SecureXL is disabled) to manually spread SoftIRQ processing around on the SND/IRQ cores.&amp;nbsp; Disabling SecureXL and defining manual interface affinity is not a path I would recommend going down if it can be avoided.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 12:30:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-20-Securexl-not-disable/m-p/59814#M4523</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-08-07T12:30:49Z</dc:date>
    </item>
  </channel>
</rss>

