<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error due to SecureXL in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243697#M47372</link>
    <description>&lt;P&gt;No, if you have to disable SecureXL it's a bug or misconfiguration that should be taken with TAC.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Mar 2025 05:15:40 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2025-03-13T05:15:40Z</dc:date>
    <item>
      <title>Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243689#M47365</link>
      <description>&lt;P&gt;Hello, everyone.&lt;/P&gt;
&lt;P&gt;One question, is it advisable to disable SecureXL?&lt;/P&gt;
&lt;P&gt;We have a problem in which our CCTV server cannot 'visualize' the IP cameras it has hooked.&lt;/P&gt;
&lt;P&gt;The only way to solve the error, and have video of the IP cameras is if we disable SecureXL.&lt;/P&gt;
&lt;P&gt;Is this something 'expected' in CP equipment? I am referring to the fact that SecureXL is often the cause of problems with certain types of traffic.&lt;/P&gt;
&lt;P&gt;What would be the right way to fix this error permanently? &lt;BR /&gt;I currently have version R81.20.&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 02:04:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243689#M47365</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-03-13T02:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243692#M47368</link>
      <description>&lt;P&gt;The software is coded and tested with the assumption that SXL is enabled. It is not recommended to leave it off. Highly recommended to tackle this one with TAC so that we can fix it properly.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 02:25:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243692#M47368</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-03-13T02:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243694#M47370</link>
      <description>&lt;P&gt;Disabling SecureXL for certain connections is not a solution that can be considered as 'permanent'?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 03:06:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243694#M47370</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-03-13T03:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243697#M47372</link>
      <description>&lt;P&gt;No, if you have to disable SecureXL it's a bug or misconfiguration that should be taken with TAC.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 05:15:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243697#M47372</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-03-13T05:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243714#M47378</link>
      <description>&lt;P&gt;I also suggest contacting TAC to resolve the issue.&lt;/P&gt;
&lt;P&gt;A workaround could be to exclude specific traffic from SecureXL:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk104468" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk104468&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 10:15:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243714#M47378</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2025-03-13T10:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243715#M47379</link>
      <description>&lt;P&gt;It may be the constant workaround - disabling SecureXL completely is no way to go. But a TAC case might be the proper process - but try to exclude the traffic now quickly so you can turn SecureXL on again.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 10:29:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243715#M47379</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-03-13T10:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243720#M47382</link>
      <description>&lt;P&gt;Our CP is in R82 version, managed by a Smar-1 Cloud. &lt;BR /&gt;Then the TAC has to give us a solution, since it is not recommended to have the SXL off right?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 11:37:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243720#M47382</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-03-13T11:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243723#M47384</link>
      <description>&lt;P&gt;I would follow sk&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/585"&gt;@Tal_Paz-Fridman&lt;/a&gt;&amp;nbsp;provided. What is the exact issue when sxl is enabled? Yes, it can be disabled permanently, but I would NOT do that.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 11:46:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243723#M47384</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-13T11:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243768#M47400</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82839"&gt;@Matlu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe fast_accel worths a try&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk156672" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk156672&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 19:55:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243768#M47400</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-03-13T19:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243769#M47401</link>
      <description>&lt;P&gt;Thats a good idea.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 20:07:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243769#M47401</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-13T20:07:45Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243770#M47402</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Is there any way to “validate” if the SXL is “dumping” traffic, when it is active?&lt;/P&gt;
&lt;P&gt;It seems that tshoot commands like tcpdump or fw ctl zdebug, don't exactly “see” traffic that may be being dropped by the SXL.&lt;/P&gt;
&lt;P&gt;So, what commands can help you, to validate if SXL is being the problem for a particular traffic?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 21:40:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243770#M47402</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-03-13T21:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243771#M47403</link>
      <description>&lt;P&gt;You need to use the command &lt;STRONG&gt;fw ctl zdebug + drop&lt;/STRONG&gt; to also see any drops occurring in SecureXL, although they are usually much more rare than drops in the main INSPECT code.&lt;/P&gt;
&lt;P&gt;The best way to determine if SecureXL is the source of your problem is to leave the questionable connections in the slowpath (no offloading to the Medium or Fast paths allowed) and see if the situation improves.&amp;nbsp;&amp;nbsp;sk104468: How to&amp;nbsp;exclude&amp;nbsp;traffic from&amp;nbsp;SecureXL&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 21:55:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243771#M47403</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-03-13T21:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243772#M47404</link>
      <description>&lt;P&gt;Here's a good place to start:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_PerformanceTuning_AdminGuide/Topics-PTG/SecureXL-Debug/SecureXL-Debug-Procedure.htm" target="_blank"&gt;SecureXL Debug Procedure&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;However as everyone has suggested, best to engage TAC, ensure your running latest recommended Jumbo etc as this will be a first step suggestion from TAC.&lt;BR /&gt;&lt;BR /&gt;Last time I had an issue with SecureXL it was on R7x.x and the issue was resolve by upgrading to the latest version at the time.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 21:59:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243772#M47404</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-03-13T21:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243774#M47405</link>
      <description>&lt;P&gt;It's a little weird.&lt;/P&gt;
&lt;P&gt;I used the command you recommend, my destination was an IP camera.&lt;/P&gt;
&lt;P&gt;When we have the SXL enabled on the CP, the CCTV server cannot see the video from the camera, but the command&lt;/P&gt;
&lt;P&gt;fw ctl zdebug + drop | grep &amp;lt;IP CAMERA&amp;gt; ... at that time it shows me nothing.&lt;/P&gt;
&lt;P&gt;It is as if for the FW everything is working fine.&lt;/P&gt;
&lt;P&gt;Then, when we disable the SXL, immediately the CCTV server retrieves the video from the camera.&lt;/P&gt;
&lt;P&gt;Only the “fw ctl zdebug + drop” is the command that helps to detect if it is the SXL that is giving problems?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 22:04:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243774#M47405</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2025-03-13T22:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243775#M47406</link>
      <description>&lt;P&gt;When sxl is on, you probably would need to do sxl debugs.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 22:35:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243775#M47406</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-13T22:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243777#M47407</link>
      <description>&lt;P&gt;If you see nothing in the &lt;STRONG&gt;fw ctl zdebug + drop&lt;/STRONG&gt; that means no Check Point code (SecureXL/INSPECT) is dropping that traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I have to ask, are you on a Quantum Force 9000/19000/29000 or Lightspeed appliance?&lt;/P&gt;
&lt;P&gt;Is this traffic multicast?&amp;nbsp; It could be getting dropped in the Gaia OS itself due to some kind of problematic interaction with SecureXL.&amp;nbsp; Only way to know for sure is set up a &lt;STRONG&gt;fw monitor -F&lt;/STRONG&gt; with SecureXL enabled and see if the problematic traffic is hitting inspection points iI but failing to re-enter at o.&amp;nbsp; There have been issues in the past with SecureXL and multicast.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 23:43:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243777#M47407</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-03-13T23:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243781#M47410</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/82839"&gt;@Matlu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_PerformanceTuning_AdminGuide/Topics-PTG/SecureXL-Debug/SecureXL-Debug-Procedure.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_PerformanceTuning_AdminGuide/Topics-PTG/SecureXL-Debug/SecureXL-Debug-Procedure.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 02:09:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243781#M47410</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-14T02:09:27Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243826#M47424</link>
      <description>&lt;P&gt;Tim - valid point about mcast, we had issues in the past where the Checkpoint was a RP and after engaging TAC it was determined this was a bug, but we never had issues with mcast being passed through the appliances, assuming correct policy is in place.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 14:21:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243826#M47424</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-03-14T14:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Error due to SecureXL</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243830#M47426</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Any luck with this or still same issue?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 16:50:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Error-due-to-SecureXL/m-p/243830#M47426</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-14T16:50:43Z</dc:date>
    </item>
  </channel>
</rss>

