<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-Space firewall support for R80.30 3.10 and above in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103528#M19917</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/13287"&gt;@Borut&lt;/a&gt;&amp;nbsp;The mentioned SK is now in review and may be changed, as the info there is not 100% accurate. We do plan to make USFW mode default in the upcoming releases, for all platforms.&lt;BR /&gt;&lt;BR /&gt;Once again, if you have a need to run TLS 1.3 on open server today, reach out to the local office and raise a request. Should be relatively easy to handle. If you need any further assistance, feel free to PM me any time.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Nov 2020 12:05:36 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2020-11-27T12:05:36Z</dc:date>
    <item>
      <title>User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/86906#M17446</link>
      <description>&lt;P&gt;User-space Firewall (USFW) is a stable and mature infrastructure that allows Check Point Firewall instances to run in user-space mode, It has been used for several years now on VSX.&lt;/P&gt;
&lt;P&gt;As such, Check Point decided to gradually move appliances to utilize USFW starting R80.30 3.10&lt;/P&gt;
&lt;P&gt;The motivation for the USFW infrastructure development:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Support a large number of FW instances.&lt;/LI&gt;
&lt;LI&gt;Quick process recovery upon a failure or a crash.&lt;/LI&gt;
&lt;LI&gt;Faster development of new features.&lt;/LI&gt;
&lt;LI&gt;Improve system traceability, reduce troubleshooting time.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;FAQ:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q&lt;/STRONG&gt;: Which Security Gateways/Appliances can utilize USFW?&lt;BR /&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;: For the list of Security Gateways and appliances that support USFW refer to &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167052" target="_self"&gt;sk167052&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q&lt;/STRONG&gt;: My Gateway is running only 4 cores / VM, why is my machine running in USFW?&lt;BR /&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;: USFW will gradually become the default mode in future releases, new appliance models are designed and shipped configured to use USFW as the default mode.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q&lt;/STRONG&gt;: Most of my traffic is handled through the SecureXL Fast path, will I benefit from USFW? &amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;: SecureXL on USFW mode runs in kernel mode, traffic will be accelerated (in kernel) efficiently similar to the Kernel Mode&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q&lt;/STRONG&gt;: Is there any reason to switch back to Kernel mode?&lt;BR /&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;: Check Point is gradually transferring to USFW mode. It is preferred and best practice to keep the security GW in its default mode, yet it will be possible to switch to kernel mode – please see &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167052" target="_self"&gt;SK167052&lt;/A&gt; for more details.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q&lt;/STRONG&gt;: How do I determine if the Security Gateway runs using USFW?&lt;BR /&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;: Run “cpprod_util FwIsUSFW”&amp;nbsp; (1 = USFW)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Q&lt;/STRONG&gt;: Does a USFW work the same as it works with VSX? Do the same limitations apply?&lt;BR /&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;: Although USFW is using a similar infrastructure as used with VSX, the limitations are different. Refer to &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167052" target="_self"&gt;sk167052&lt;/A&gt; for USFW known limitations. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For any additional questions, feel free to tag me in your USFW posts.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 14:27:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/86906#M17446</guid>
      <dc:creator>shais</dc:creator>
      <dc:date>2020-06-01T14:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/86965#M17449</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/44392"&gt;@shais&lt;/a&gt;, may you please clarify how is USFW affecting CPU usage ? There were reports that on some appliances enabling USFW causes much higher processor utilization compared to KSFW.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 17:18:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/86965#M17449</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-06-01T17:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/86994#M17455</link>
      <description>&lt;P&gt;Just to mention that in theory with USFW enabled it should be possible to replace relevant fw modules without OS reboot &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 05:18:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/86994#M17455</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-06-02T05:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/87006#M17461</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/18680"&gt;@HristoGrigorov&lt;/a&gt;, what are you trying to say?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 06:59:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/87006#M17461</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-06-02T06:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/87039#M17465</link>
      <description>&lt;DIV&gt;
&lt;P&gt;&lt;SPAN&gt;USFW&amp;nbsp;should not impact the CPU, we've identified few USFW specific cases that cause excessive CPU utilization and they were fixed and integrated to our Jumbo hotfixes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If we still have such issues, please contact support and allow us to investigate the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As for your input regarding replacement&amp;nbsp;of FW modules without reboot - You are correct that USFW open this possibility&amp;nbsp;for us and we indeed taking this into consideration&amp;nbsp;and validation&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 02 Jun 2020 09:16:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/87039#M17465</guid>
      <dc:creator>shais</dc:creator>
      <dc:date>2020-06-02T09:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/87045#M17467</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;I mean that it is possible to replace and reload user space binaries without OS reboot. With some downtime of course but still it will be much quicker. It is at least technologically possible.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 10:02:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/87045#M17467</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-06-02T10:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103038#M19870</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a newly installed 6700 firewall cluster which came installed with User mode disabled. We have noticed high CPU spikes causing high CPU and affecting user experience. Does changing from kernel mode to User mode will have any adverse effect for 12 core firewall.&amp;nbsp; Is there any sk on how to change on a 6700 appliances?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 19:15:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103038#M19870</guid>
      <dc:creator>Hug_for_my_Bug</dc:creator>
      <dc:date>2020-11-23T19:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103039#M19871</link>
      <description>&lt;P&gt;You must first investigate what is the reason for these CPU spikes. USFW is not really faster than KMFW. In fact it is a bit slower. It has other advantages though, supports large number of CPUs and system does not reboot in case of fwk crash.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 19:21:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103039#M19871</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-11-23T19:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103080#M19875</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9795"&gt;@Hug_for_my_Bug&lt;/a&gt;&amp;nbsp;USFW only makes sense, from a performance perspective, with systems having more than 40 cores. Not your case.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 06:52:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103080#M19875</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-11-24T06:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103521#M19913</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/44392"&gt;@shais&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed, that in R80.30 USFW was supported on open servers, but with R80.40 it's only supported on machines with 40+ cores. Is that an appliance sales push decision or a technical one? Val is also stating, that performance gains are only observable on machines with more than 40 cores.&lt;/P&gt;&lt;P&gt;What about HTTPS inspection? If I understand correctly TLS 1.3 native support (without downgrading to TLS 1.2) is only possible in USFW. Does that mean there will be no realistic possibility to have native TLS 1.3 support on open servers?&lt;/P&gt;&lt;P&gt;Best regards&lt;BR /&gt;Borut&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 11:00:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103521#M19913</guid>
      <dc:creator>Borut</dc:creator>
      <dc:date>2020-11-27T11:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103523#M19914</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/13287"&gt;@Borut&lt;/a&gt;&amp;nbsp;It always helps to tag people you mention &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I believe, the limitation of support with R80.40 and up comes mostly from QA effort. We can only support what's being tested thoroughly. If you have an actual and important use case, raise it with the local CP office as RFE.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Concerning the general plans to support TLS 1.3 on open servers with less than 40 cores, I have reached out to R&amp;amp;D. I will let you know when they answer.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 11:41:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103523#M19914</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-11-27T11:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103525#M19916</link>
      <description>&lt;P&gt;Sorry&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;No use cases yet, since majority of the internet still supports TLS 1.2. Just wondering about the times when that isn't the case anymore.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 11:58:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103525#M19916</guid>
      <dc:creator>Borut</dc:creator>
      <dc:date>2020-11-27T11:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103528#M19917</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/13287"&gt;@Borut&lt;/a&gt;&amp;nbsp;The mentioned SK is now in review and may be changed, as the info there is not 100% accurate. We do plan to make USFW mode default in the upcoming releases, for all platforms.&lt;BR /&gt;&lt;BR /&gt;Once again, if you have a need to run TLS 1.3 on open server today, reach out to the local office and raise a request. Should be relatively easy to handle. If you need any further assistance, feel free to PM me any time.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 12:05:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103528#M19917</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-11-27T12:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103532#M19918</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think no assistance is necessary right now, since it does not brake anything. Thanks for the inquiry and your time.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 12:41:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103532#M19918</guid>
      <dc:creator>Borut</dc:creator>
      <dc:date>2020-11-27T12:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103548#M19925</link>
      <description>&lt;P&gt;No problem, we are here to help&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 15:15:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/103548#M19925</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-11-27T15:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/115967#M21592</link>
      <description>&lt;P&gt;Neither this page, the referenced sk167052, or the R80.40 next gen security gateway documentation provide any guidance on how to enable this... I am &lt;EM&gt;guessing&lt;/EM&gt; setting FwSetUsfwMachine=1?&lt;/P&gt;&lt;P&gt;cpprod_util 2&amp;gt;&amp;amp;1 | grep -i usfw&lt;BR /&gt;FwIsUsfwMachine no-parameter integer-output&lt;BR /&gt;FwIsUsfwMDTDisabled no-parameter integer-output&lt;BR /&gt;FwIsUsfwEpoll no-parameter integer-output&lt;BR /&gt;FwIsUSFW no-parameter integer-output&lt;BR /&gt;FwSetUsfwMDTDisable integer-parameter no-output&lt;BR /&gt;FwSetUsfwEpoll integer-parameter no-output&lt;BR /&gt;FwSetUsfwMachine integer-parameter no-output&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 22:09:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/115967#M21592</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2021-04-13T22:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/115976#M21594</link>
      <description>&lt;P&gt;As noted in my book, generally you should not change the default state of USFW unless under the direction of TAC.&amp;nbsp; The rules about whether USFW will be enabled by default are complicated and were initially revealed in my posting below after a chat with Check Point R&amp;amp;D:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/USFW-on-appliances-with-less-than-40-cores/m-p/86089/highlight/true#M17278" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/USFW-on-appliances-with-less-than-40-cores/m-p/86089/highlight/true#M17278&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The latest updates conerning this are contained in this SK:&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167052&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank" rel="noopener"&gt;sk167052: Check Point User-Space &lt;STRONG&gt;firewall&lt;/STRONG&gt; support for R80.30 3.10 and higher&lt;/A&gt;&amp;nbsp; Assume that USFW will be enabled by default on all new firewall appliance models going forward.&lt;/P&gt;
&lt;P&gt;However if you want to manually toggle the state of USFW, the &lt;STRONG&gt;cpprod_util&lt;/STRONG&gt; commands you need to use are mentioned here in an excellent article by&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21670"&gt;@HeikoAnkenbrand&lt;/a&gt;:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-User-Mode-Firewall-vs-Kernel-Mode/m-p/70759/highlight/true#M14330" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/General-Topics/R80-x-Performance-Tuning-Tip-User-Mode-Firewall-vs-Kernel-Mode/m-p/70759/highlight/true#M14330&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 03:19:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/115976#M21594</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-04-14T03:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: User-Space firewall support for R80.30 3.10 and above</title>
      <link>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/116146#M21640</link>
      <description>&lt;P&gt;Hi Timothy,&lt;/P&gt;&lt;P&gt;Thanks for the information. The environment in question is a 5800 cluster recently upgraded to R80.40 (latest GA jumbo), one of the devices listed as not defaulting to USFW but able to move to it. PSLXL packets are up around 60%, well above the 30% indicated in sk167052 where USFW is the preferred mode. I'll raise a SR and see what TAC have to say.&lt;/P&gt;&lt;P&gt;The referenced sk149973 in Heiko Ankenbrand's post has now been made Check Point internal-only - although his post still describes how to enable USFW &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Thu, 15 Apr 2021 21:16:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/User-Space-firewall-support-for-R80-30-3-10-and-above/m-p/116146#M21640</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2021-04-15T21:16:28Z</dc:date>
    </item>
  </channel>
</rss>

