<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SecureXL mode in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258178#M50620</link>
    <description>&lt;P&gt;"&lt;STRONG&gt;fwmode -s&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;shows: User mode" indicates that USFW is set, which means your Firewall Worker Instances run in User Space.&amp;nbsp; This has been the default for some time, and there are not many good reasons to set kernel mode for your workers, as it will interfere with features such as Dynamic Split and Hyperflow.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"&lt;STRONG&gt;Fwaccel stat&lt;/STRONG&gt;&amp;nbsp;shows: KPPAK" means that SecureXL is running in kernel space.&amp;nbsp; In R81.20 and R82, by default, only Quantum Force 3900/9XXX/19XXX/29XXX appliances, as well as Lightspeed appliances, utilize UPPAK by default.&amp;nbsp; For the moment, you can set them back to use KPPAK, but this option will go away in R82.10, and UPPAK will become the default for all gateways, regardless of model or open hardware in that version.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Sep 2025 12:33:36 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2025-09-25T12:33:36Z</dc:date>
    <item>
      <title>SecureXL mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258165#M50616</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I got a new &lt;STRONG&gt;9400&lt;/STRONG&gt; gateway running 81.20 take 113.&lt;/P&gt;
&lt;P&gt;After changing from User mode to kernel mode using &lt;STRONG&gt;cpconfig&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fwmode -s&lt;/STRONG&gt; shows: User mode&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Fwaccel stat&lt;/STRONG&gt; shows: KPPAK&lt;/P&gt;
&lt;P&gt;We are moving from 6500 running in kernel mode to 9400.&lt;/P&gt;
&lt;P&gt;My plan is to use &lt;STRONG&gt;save configuration&lt;/STRONG&gt; on 6500 and l&lt;STRONG&gt;oad configuration&lt;/STRONG&gt; on 9400.&lt;/P&gt;
&lt;P&gt;But 9400 seems refusing kernel mode or maybe it is so in that new gateway?&lt;/P&gt;
&lt;P&gt;Choosing kernel-mode because we have a stable environment with 6500 running in kernel-mode&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Does 9400 running user mode or kernel mode according to the above information?&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;any ideas!&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 09:01:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258165#M50616</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-09-25T09:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258178#M50620</link>
      <description>&lt;P&gt;"&lt;STRONG&gt;fwmode -s&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;shows: User mode" indicates that USFW is set, which means your Firewall Worker Instances run in User Space.&amp;nbsp; This has been the default for some time, and there are not many good reasons to set kernel mode for your workers, as it will interfere with features such as Dynamic Split and Hyperflow.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"&lt;STRONG&gt;Fwaccel stat&lt;/STRONG&gt;&amp;nbsp;shows: KPPAK" means that SecureXL is running in kernel space.&amp;nbsp; In R81.20 and R82, by default, only Quantum Force 3900/9XXX/19XXX/29XXX appliances, as well as Lightspeed appliances, utilize UPPAK by default.&amp;nbsp; For the moment, you can set them back to use KPPAK, but this option will go away in R82.10, and UPPAK will become the default for all gateways, regardless of model or open hardware in that version.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 12:33:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258178#M50620</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-09-25T12:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258181#M50623</link>
      <description>&lt;P&gt;You can force it to load the config with below command in clish:&lt;/P&gt;
&lt;P&gt;set clienv on-failure continue&lt;/P&gt;
&lt;P&gt;save config&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 12:47:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258181#M50623</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-25T12:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258185#M50624</link>
      <description>&lt;P&gt;so if our 6500 is running kernel mode and the new 9400 is running user mode on both firewall and securexl,&lt;/P&gt;
&lt;P&gt;moving the configuration from 6500 to 9400 will run smoothly and we do not need to do anything? Or we need to do some tweaks so that everything works?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 13:02:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258185#M50624</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-09-25T13:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258187#M50625</link>
      <description>&lt;P&gt;Hey brother,&lt;/P&gt;
&lt;P&gt;Just me personally, I would NOT assume that risk, better be sure and confirm with TAC.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 13:04:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258187#M50625</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-25T13:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258194#M50628</link>
      <description>&lt;P&gt;The 9400 will use UPPAK by default.&amp;nbsp; Prior to the replacement, familiarize yourself with the limitations of UPPAK in Section 4 here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk32578" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk32578: SecureXL Mechanism&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Note that some limitations listed here are included for completeness but have already been resolved. Please refer to the far right column to see which version may have resolved the issue, and ensure you are using the latest Recommended Jumbo HFA.&amp;nbsp; If any of these limitations are show-stoppers or you encounter problems, you may need to set your 9400 back to KPPAK mode.&amp;nbsp; Keep in mind that constantly high CPU utilization on your SND cores is expected behavior in UPPAK mode.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 13:14:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258194#M50628</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2025-09-25T13:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258271#M50645</link>
      <description>&lt;P&gt;As Tim said though, by default it would use user mode.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 23:54:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258271#M50645</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-25T23:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258281#M50649</link>
      <description>&lt;P&gt;What does fwmode -s show on your 6500s? You should keep USFW on the 9000s, and the config should transfer over like for like, but with any hardware swap it's a good time to review the config and only copy over the stuff that you need. I would 'show configuration' on the old setup and copy/paste in only the stuff that is needed to the new gear.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 03:21:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258281#M50649</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-09-26T03:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258298#M50650</link>
      <description>&lt;P&gt;6500 shows:&lt;/P&gt;
&lt;LI-CODE lang="python"&gt;[Expert@fw02:0]# fwmode -s
Firewall is Kernel mode&lt;/LI-CODE&gt;
&lt;P&gt;so you mean 9400 should never use kernel mode even if 6500 is kernel mode?&lt;/P&gt;
&lt;P&gt;I used save configuration and load configuration and I will double check the config again line by line&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 10:16:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258298#M50650</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-09-26T10:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258307#M50653</link>
      <description>&lt;P&gt;From my R82 fw:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;[Expert@CP-GW:0]# fwmode -s&lt;BR /&gt;Firewall is User mode&lt;BR /&gt;[Expert@CP-GW:0]# uname -a&lt;BR /&gt;Linux CP-GW 4.18.0-372.9.1cpx86_64 #1 SMP Thu Aug 28 16:01:06 IDT 2025 x86_64 x86_64 x86_64 GNU/Linux&lt;BR /&gt;[Expert@CP-GW:0]#&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 12:37:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258307#M50653</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-26T12:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: SecureXL mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258379#M50666</link>
      <description>&lt;UL&gt;
&lt;LI&gt;By default, Quantum Force Appliances (9800, 9700, 9400, 9300, 9200, and 9100) run SecureXL in the User Space (UPPAK) Mode:
&lt;UL&gt;
&lt;LI&gt;When the appliance runs the dedicated R81.20 Factory Image.&lt;/LI&gt;
&lt;LI&gt;When the appliance runs the R81.20 Jumbo Hotfix Take 54 and higher.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Quantum Force Appliances in a Standalone deployment (9800, 9700, 9400, 9300, 9200, and 9100) run SecureXL in Kernel Mode (KPPAK).&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;How to change:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Appliances/100G_Ports_AdminGuide/Content/Topics-100G-Card-AG/SecureXL-Configuration.htm?tocpath=_____5" target="_blank"&gt;https://sc1.checkpoint.com/documents/Appliances/100G_Ports_AdminGuide/Content/Topics-100G-Card-AG/SecureXL-Configuration.htm?tocpath=_____5&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Sep 2025 18:42:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/SecureXL-mode/m-p/258379#M50666</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-09-27T18:42:00Z</dc:date>
    </item>
  </channel>
</rss>

