<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SecureXL Templates show disabled in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187210#M34497</link>
    <description>&lt;P&gt;Yes, because the other firewalls received a full nonaccelerated policy install based on the number of changes you made.&amp;nbsp; But this one's last policy installation was transparently accelerated; you can only determine this if you look at the details of the install policy task where you will see a lightning bolt icon instead of the normal down-arrow.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've also seen other situations where CLI-level changes to the gateway or SMS don't "take" if the policy installation happens to be accelerated.&amp;nbsp; A forced full policy installation fixes it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk169096" target="_blank" rel="noopener"&gt;sk169096:&amp;nbsp;Accelerated&amp;nbsp;Install&amp;nbsp;Policy&amp;nbsp;for Access Control&amp;nbsp;Policy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk168055" target="_blank" rel="noopener"&gt;sk168055: SmartConsole shows "Security Gateway and Security Management&amp;nbsp;policy&amp;nbsp;versions are incompatible. Disable&amp;nbsp;Accelerated&amp;nbsp;Install&amp;nbsp;Policy&amp;nbsp;for this Security Gateway and install&amp;nbsp;policy&amp;nbsp;again. For more information, see sk168055."&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk180414" target="_blank" rel="noopener"&gt;sk180414:&amp;nbsp;Accelerated&amp;nbsp;policy&amp;nbsp;installation fails with "Policy&amp;nbsp;installation failed on gateway. If the problem persists contact Check Point support (Error code: 1-2000214)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I've gotten to the point where if I make any kind of configuration change that was not performed in the SmartConsole itself yet requires a policy reinstallation to take effect, I always force a full unaccelerated installation as a matter of course.&amp;nbsp; There is no way to permanently disable accelerated policy installs, nor any way to make that hidden checkbox "sticky".&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jul 2023 16:59:11 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2023-07-21T16:59:11Z</dc:date>
    <item>
      <title>SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187182#M34481</link>
      <description>&lt;P&gt;I'm doing some testing with SecureXL in our lab. Currently, output of fwaccel stat reads:&lt;/P&gt;
&lt;P&gt;xxxxxx&amp;gt; fwaccel stat&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|0 |KPPAK |enabled |eth1,eth2,eth3,eth4,Sync,|Acceleration,Cryptography |&lt;BR /&gt;| | | |Mgmt | |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,3DES,DES,AES-128,AES-256,|&lt;BR /&gt;| | | | |ESP,LinkSelection,DynamicVPN, |&lt;BR /&gt;| | | | |NatTraversal,AES-XCBC,SHA256, |&lt;BR /&gt;| | | | |SHA384,SHA512 |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;/P&gt;
&lt;P&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;Layer XXXXX_Policy Access Control disables template offloads from rule #106&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Drop Templates : disabled&lt;BR /&gt;NAT Templates : disabled by Firewall&lt;BR /&gt;Layer XXXXXX_Policy Access Control disables template offloads from rule #106&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;LightSpeed Accel : disabled&lt;BR /&gt;xxxxxxxx&amp;gt;&lt;/P&gt;
&lt;P&gt;And output of fwaccel stats -s:&lt;BR /&gt;xxxxxx&amp;gt; fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 25/1401 (1%)&lt;BR /&gt;LightSpeed conns/Total conns : 0/1401 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 2389860528/3129456116 (76%)&lt;BR /&gt;LightSpeed pkts/Total pkts : 0/3129456116 (0%)&lt;BR /&gt;F2Fed pkts/Total pkts : 739595588/3129456116 (23%)&lt;BR /&gt;F2V pkts/Total pkts : 176413090/3129456116 (5%)&lt;BR /&gt;CPASXL pkts/Total pkts : 0/3129456116 (0%)&lt;BR /&gt;PSLXL pkts/Total pkts : 2246244373/3129456116 (71%)&lt;BR /&gt;CPAS pipeline pkts/Total pkts : 0/3129456116 (0%)&lt;BR /&gt;PSL pipeline pkts/Total pkts : 0/3129456116 (0%)&lt;BR /&gt;CPAS inline pkts/Total pkts : 0/3129456116 (0%)&lt;BR /&gt;PSL inline pkts/Total pkts : 0/3129456116 (0%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/3129456116 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/3129456116 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/3129456116 (0%)&lt;BR /&gt;xxxxxxxxx&amp;gt;&lt;/P&gt;
&lt;P&gt;And output of fwaccel templates -s:&lt;BR /&gt;xxxxxxxxx&amp;gt; fwaccel templates -s&lt;/P&gt;
&lt;P&gt;Total number of templates: 198&lt;BR /&gt;xxxxxxxxxx&amp;gt;&lt;/P&gt;
&lt;P&gt;Rule #106 contains the service object ALL_DCE_RPC, so I understand why this disables templates. When I replace that serivce object with the application control object DCE-RPC Protocol, I get this:&lt;/P&gt;
&lt;P&gt;xxxxxxx&amp;gt; fwaccel stat&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|0 |KPPAK |enabled |eth1,eth2,eth3,eth4,Sync,|Acceleration,Cryptography |&lt;BR /&gt;| | | |Mgmt | |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,3DES,DES,AES-128,AES-256,|&lt;BR /&gt;| | | | |ESP,LinkSelection,DynamicVPN, |&lt;BR /&gt;| | | | |NatTraversal,AES-XCBC,SHA256, |&lt;BR /&gt;| | | | |SHA384,SHA512 |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;Accept Templates : disabled by Firewall&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;Drop Templates : disabled&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;NAT Templates : disabled by Firewall&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;LightSpeed Accel : disabled&lt;/FONT&gt;&lt;BR /&gt;xxxxxxxxx&amp;gt;&lt;/P&gt;
&lt;P&gt;and&lt;BR /&gt;xxxxxxxx&amp;gt; fwaccel stats -s&lt;BR /&gt;Accelerated conns/Total conns : 25/2067 (1%)&lt;BR /&gt;LightSpeed conns/Total conns : 0/2067 (0%)&lt;BR /&gt;Accelerated pkts/Total pkts : 2389988257/3129646869 (76%)&lt;BR /&gt;LightSpeed pkts/Total pkts : 0/3129646869 (0%)&lt;BR /&gt;F2Fed pkts/Total pkts : 739658612/3129646869 (23%)&lt;BR /&gt;F2V pkts/Total pkts : 176421134/3129646869 (5%)&lt;BR /&gt;CPASXL pkts/Total pkts : 0/3129646869 (0%)&lt;BR /&gt;PSLXL pkts/Total pkts : 2246359221/3129646869 (71%)&lt;BR /&gt;CPAS pipeline pkts/Total pkts : 0/3129646869 (0%)&lt;BR /&gt;PSL pipeline pkts/Total pkts : 0/3129646869 (0%)&lt;BR /&gt;CPAS inline pkts/Total pkts : 0/3129646869 (0%)&lt;BR /&gt;PSL inline pkts/Total pkts : 0/3129646869 (0%)&lt;BR /&gt;QOS inbound pkts/Total pkts : 0/3129646869 (0%)&lt;BR /&gt;QOS outbound pkts/Total pkts : 0/3129646869 (0%)&lt;BR /&gt;Corrected pkts/Total pkts : 0/3129646869 (0%)&lt;BR /&gt;xxxxxxxxx&amp;gt;&lt;/P&gt;
&lt;P&gt;and&lt;BR /&gt;xxxxxxx&amp;gt; fwaccel templates -s&lt;/P&gt;
&lt;P&gt;Total number of templates: 260&lt;BR /&gt;xxxxxxxx&amp;gt;&lt;/P&gt;
&lt;P&gt;The output of fwaccel stats -s and fwaccel templates -s seems to show SecureXL operating as expected, but notice the output of fwaccel stat shows all templates as disabled. Bug? I am running R81.10 with Jumbo HFA Take 95&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 14:16:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187182#M34481</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-07-21T14:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187188#M34485</link>
      <description>&lt;P&gt;I tested in R81.20 and same thing. I know of below sk, but I already have that configured&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk71200" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk71200&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 14:46:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187188#M34485</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-21T14:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187191#M34487</link>
      <description>&lt;P&gt;Thanks Andy. I noticed that sk is for NAT templates only, and for R80.20 and lower. It's odd, hoping it is just a display bug. When I was doing my testing, I had three rules with the ALL_DCE_RPC service. I removed one at a time, checked fwaccel stat each time. After I removed the first two, I saw the rule which disabled templates change. It was only after I removed the third and last instance that all templates showed as disabled. I even re-added the ALL_DCE_RPC service to the last rule, and the output of fwaccel stat returned to what I expected.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 14:57:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187191#M34487</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-07-21T14:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187192#M34488</link>
      <description>&lt;P&gt;Yea...I dont believe your version is the issue. Lets see if someone can confirm this.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 14:58:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187192#M34488</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-21T14:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187200#M34490</link>
      <description>&lt;P&gt;Force a full policy install to the gateway as shown below and check it again, it is likely that your last policy reinstallation was accelerated:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="force_unaccel.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21834iE89A9ACDF4D54CF5/image-size/large?v=v2&amp;amp;px=999" role="button" title="force_unaccel.png" alt="force_unaccel.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 15:15:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187200#M34490</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-07-21T15:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187201#M34491</link>
      <description>&lt;P&gt;Just tested, same thing.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 15:31:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187201#M34491</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-21T15:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187203#M34492</link>
      <description>&lt;P&gt;I don't even have that option for a policy install:&lt;/P&gt;
&lt;DIV id="tinyMceEditor_169d12d3dde1bbDavid_C1_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 15:45:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187203#M34492</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-07-21T15:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187207#M34494</link>
      <description>&lt;P&gt;Right-click on the gateway object on the Install Policy screen and you'll see the hidden checkbox.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 16:34:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187207#M34494</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-07-21T16:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187208#M34495</link>
      <description>&lt;P&gt;Hey that worked. I now have:&lt;/P&gt;
&lt;P&gt;xxxxx&amp;gt; fwaccel stat&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|0 |KPPAK |enabled |eth1,eth2,eth3,eth4,Sync,|Acceleration,Cryptography |&lt;BR /&gt;| | | |Mgmt | |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,3DES,DES,AES-128,AES-256,|&lt;BR /&gt;| | | | |ESP,LinkSelection,DynamicVPN, |&lt;BR /&gt;| | | | |NatTraversal,AES-XCBC,SHA256, |&lt;BR /&gt;| | | | |SHA384,SHA512 |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;/P&gt;
&lt;P&gt;Accept Templates : enabled&lt;BR /&gt;Drop Templates : disabled&lt;BR /&gt;NAT Templates : enabled&lt;BR /&gt;LightSpeed Accel : disabled&lt;BR /&gt;xxxxxxx&amp;gt;&lt;/P&gt;
&lt;P&gt;Curiously enough, on my&amp;nbsp;&lt;EM&gt;other&lt;/EM&gt; lab firewalls (same version) I essentially went through the process, and fwaccel stat showed "enabled" for Accept and NAT templates as expected.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 16:48:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187208#M34495</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-07-21T16:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187209#M34496</link>
      <description>&lt;P&gt;This is my output, even after disabling accelerated policy push&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;R81.20 jumbo 24&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Expert@quantum-firewall:0]# fwaccel stat&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|0 |KPPAK |enabled |eth0,eth1,eth2,eth3 |Acceleration,Cryptography |&lt;BR /&gt;| | | | | |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,3DES,DES,AES-128,AES-256,|&lt;BR /&gt;| | | | |ESP,LinkSelection,DynamicVPN, |&lt;BR /&gt;| | | | |NatTraversal,AES-XCBC,SHA256, |&lt;BR /&gt;| | | | |SHA384,SHA512 |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;/P&gt;
&lt;P&gt;Accept Templates : disabled by Firewall&lt;BR /&gt;Layer firewall_layer disables template offloads from rule #16&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;Drop Templates : enabled&lt;BR /&gt;NAT Templates : disabled by Firewall&lt;BR /&gt;Layer firewall_layer disables template offloads from rule #16&lt;BR /&gt;Throughput acceleration still enabled.&lt;BR /&gt;LightSpeed Accel : disabled&lt;BR /&gt;[Expert@quantum-firewall:0]#&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 16:57:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187209#M34496</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-21T16:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187210#M34497</link>
      <description>&lt;P&gt;Yes, because the other firewalls received a full nonaccelerated policy install based on the number of changes you made.&amp;nbsp; But this one's last policy installation was transparently accelerated; you can only determine this if you look at the details of the install policy task where you will see a lightning bolt icon instead of the normal down-arrow.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've also seen other situations where CLI-level changes to the gateway or SMS don't "take" if the policy installation happens to be accelerated.&amp;nbsp; A forced full policy installation fixes it.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk169096" target="_blank" rel="noopener"&gt;sk169096:&amp;nbsp;Accelerated&amp;nbsp;Install&amp;nbsp;Policy&amp;nbsp;for Access Control&amp;nbsp;Policy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk168055" target="_blank" rel="noopener"&gt;sk168055: SmartConsole shows "Security Gateway and Security Management&amp;nbsp;policy&amp;nbsp;versions are incompatible. Disable&amp;nbsp;Accelerated&amp;nbsp;Install&amp;nbsp;Policy&amp;nbsp;for this Security Gateway and install&amp;nbsp;policy&amp;nbsp;again. For more information, see sk168055."&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk180414" target="_blank" rel="noopener"&gt;sk180414:&amp;nbsp;Accelerated&amp;nbsp;policy&amp;nbsp;installation fails with "Policy&amp;nbsp;installation failed on gateway. If the problem persists contact Check Point support (Error code: 1-2000214)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I've gotten to the point where if I make any kind of configuration change that was not performed in the SmartConsole itself yet requires a policy reinstallation to take effect, I always force a full unaccelerated installation as a matter of course.&amp;nbsp; There is no way to permanently disable accelerated policy installs, nor any way to make that hidden checkbox "sticky".&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 16:59:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187210#M34497</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-07-21T16:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187211#M34498</link>
      <description>&lt;P&gt;Disabling accelerated policy push does not rectify a situation where a specific rule is being called out as halting templating, only the situation where "&lt;SPAN&gt;Accept Templates : disabled by Firewall" is being reported by &lt;STRONG&gt;fwaccel stat&lt;/STRONG&gt; with no specific rule number displayed.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 17:35:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187211#M34498</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-07-21T17:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187212#M34499</link>
      <description>&lt;P&gt;Right...I also followed things from below link, but same issue&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Accept-Templates-are-still-disabled-even-after-disabled-the/td-p/130426" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Accept-Templates-are-still-disabled-even-after-disabled-the/td-p/130426&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 17:36:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187212#M34499</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-21T17:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187213#M34500</link>
      <description>&lt;P&gt;Your message concerning templating is not the same as the thread OP, please provide a screenshot of rule 16 in your policy.&amp;nbsp; Accept Templates and NAT Templates will follow each other exactly, the issue with templating stopping is always in the Firewall/Network policy layer.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 18:14:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187213#M34500</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-07-21T18:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187214#M34501</link>
      <description>&lt;P&gt;Attached&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 18:20:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187214#M34501</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-21T18:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187217#M34502</link>
      <description>&lt;P&gt;Almost certainly service snmpXdmid is causing templating to stop at that rule, since it is DCE/RPC.&amp;nbsp; Also possibly service dhcpv6-relay which is allowing replies on any port and is also using a custom INSPECT protocol handler.&amp;nbsp; Any chance you can try pulling those two services out of that rule and move them further down?&amp;nbsp; There could possibly be other services in that same rule causing templating to stop as well, but those two in particular stand out to me.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 18:41:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187217#M34502</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-07-21T18:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187220#M34504</link>
      <description>&lt;P&gt;No dice...removed all snmp and dhcp services, same issue.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 19:32:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187220#M34504</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-21T19:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187221#M34505</link>
      <description>&lt;P&gt;Screw it...I removed all services, left services as "any"...bam, as Borat would say "GREAT SUCCESS' lol&lt;/P&gt;
&lt;P&gt;Now, shows enabled&lt;/P&gt;
&lt;P&gt;[Expert@quantum-firewall:0]# fwaccel stat&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|Id|Name |Status |Interfaces |Features |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;BR /&gt;|0 |KPPAK |enabled |eth0,eth1,eth2,eth3 |Acceleration,Cryptography |&lt;BR /&gt;| | | | | |&lt;BR /&gt;| | | | |Crypto: Tunnel,UDPEncap,MD5, |&lt;BR /&gt;| | | | |SHA1,3DES,DES,AES-128,AES-256,|&lt;BR /&gt;| | | | |ESP,LinkSelection,DynamicVPN, |&lt;BR /&gt;| | | | |NatTraversal,AES-XCBC,SHA256, |&lt;BR /&gt;| | | | |SHA384,SHA512 |&lt;BR /&gt;+---------------------------------------------------------------------------------+&lt;/P&gt;
&lt;P&gt;Accept Templates : enabled&lt;BR /&gt;Drop Templates : enabled&lt;BR /&gt;NAT Templates : enabled&lt;BR /&gt;LightSpeed Accel : disabled&lt;BR /&gt;[Expert@quantum-firewall:0]#&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2023 19:41:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187221#M34505</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-21T19:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187253#M34512</link>
      <description>&lt;P&gt;Your "Borat" solution really bugged me and I started to wonder if the relevant content in my &lt;A href="http://www.maxpowerfirewalls.com/gw-optimization-course.html" target="_blank" rel="noopener"&gt;Gateway Performance Optimization Course&lt;/A&gt; was complete and correct on this topic, so I labbed it up this morning.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a DCE/RPC object,&amp;nbsp;&lt;SPAN&gt;snmpXdmid definitely stopped templating.&amp;nbsp; The other offender turned out to be the service of type Other "SNMP-Read-Only" which invokes raw INSPECT code in its advanced properties.&amp;nbsp; While this situation was already mentioned in my course material, I have enhanced it with a screenshot and some revised content based on your experience.&amp;nbsp; Here are the updated pages, thanks for helping make the course better:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="templates1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21847i17F400DD17F65164/image-size/large?v=v2&amp;amp;px=999" role="button" title="templates1.png" alt="templates1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="templates2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21848i0DAA06E5FBC741AC/image-size/large?v=v2&amp;amp;px=999" role="button" title="templates2.png" alt="templates2.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2023 15:24:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187253#M34512</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-07-22T15:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL Templates show disabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187254#M34513</link>
      <description>&lt;P&gt;Thanks for all your hard work on that Tim! By the way, I found it odd that when I removed ALL dhcp and snmp services, it was still not working, so that logically tells me there had to be another service causing it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2023 16:13:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-Templates-show-disabled/m-p/187254#M34513</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-22T16:13:59Z</dc:date>
    </item>
  </channel>
</rss>

