<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabling SecureXL on SMB Appliance (R80.20.5)? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84814#M3521</link>
    <description>&lt;P&gt;Yes, that was the correct table.def&lt;/P&gt;</description>
    <pubDate>Mon, 11 May 2020 09:00:26 GMT</pubDate>
    <dc:creator>Martin_Seeger</dc:creator>
    <dc:date>2020-05-11T09:00:26Z</dc:date>
    <item>
      <title>Disabling SecureXL on SMB Appliance (R80.20.5)?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84667#M3506</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;how can I exclude IP addresses or ranges from SecureXL on the SMB appliances with R80.20.5?&lt;/P&gt;&lt;P&gt;My management is R80.40.&lt;/P&gt;&lt;P&gt;I followed &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk104468&amp;amp;partition=Advanced&amp;amp;product=SecureXL" target="_self"&gt;sk104468&lt;/A&gt; and edited "table.def" but when I check according to the SK on the gateway I get the following result:&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;# fw tab -t f2f_addresses&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;localhost:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;STRONG&gt;&amp;nbsp;Table f2f_addresses not loaded: Invalid argument&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;My best guess is that I got hold of the wrong "table.def" as there are several available:&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;/opt/CPsuite-R80.40/fw1/lib/table.def&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;/opt/CPR7520CMP-R80.40/lib/table.def&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;/opt/CPR7540CMP-R80.40/lib/table.def&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;/opt/CPR76CMP-R80.40/lib/table.def&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;/opt/CPSFWR77CMP-R80.40/lib/table.def&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;/opt/CPSFWR80CMP-R80.40/lib/table.def&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;/opt/CPR77CMP-R80.40/lib/table.def&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;/opt/CPR75CMP-R80.40/lib/table.def&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;/opt/CPNGXCMP-R80.40/lib/table.def&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;/opt/CPSG80CMP-R80.40/lib/table.def&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;/opt/CPR71CMP-R80.40/lib/table.def&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;/opt/CPSG80R75CMP-R80.40/lib/table.def&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I used the first one as it seemed the obvious choice for R80 policy targets. Unluckily &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk98339" target="_self"&gt;sk98339&lt;/A&gt; is not updated to include R80.40 as management or R80.20 SMB as target yet.&lt;/P&gt;&lt;P&gt;Yours, Martin&lt;/P&gt;&lt;P&gt;P.S. If the question is "Why the hell do I want to disable SecureXL?" In my setup some services are not working properly. When I disable SecureXL to debug the connections, they start working. Unluckily I have not found a way to disable SecureXL permanently. When I do "fwaccel off" it turns itself "on" again after a few hours (I have no idea how or why).&lt;/P&gt;&lt;P&gt;P.P.S. Migrated from a 1470 with R77.20 to a 1550 with R80.20.5 about a week ago. This has been a lot more painful than expected. But I want to play with Layered Policies, so I have to go that way.&lt;/P&gt;</description>
      <pubDate>Sat, 09 May 2020 12:13:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84667#M3506</guid>
      <dc:creator>Martin_Seeger</dc:creator>
      <dc:date>2020-05-09T12:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SecureXL on SMB Appliance (R80.20.5)?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84672#M3509</link>
      <description>Believe the correct one for SMB devices running R80 is: /opt/CPSFWR80CMP-R80.40/lib/table.def &lt;BR /&gt;&lt;BR /&gt;And yes, with the redesign of SecureXL IN R80.20, we don't allow permanent disabling of SecureXL any longer (applies to regular gateways too).&lt;BR /&gt;We consider things solved by disabling SecureXL to be bugs that need to be fixed.</description>
      <pubDate>Sat, 09 May 2020 14:04:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84672#M3509</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-09T14:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SecureXL on SMB Appliance (R80.20.5)?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84803#M3517</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;yes, I would agree that those are things that are needed to be fixed. But I don't want to open two many SRs in parallel, so I was looking for a quick fix.&lt;/P&gt;&lt;P&gt;I take a look what happens when I use that table.de and will report here.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;Yours, Martin&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 07:30:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84803#M3517</guid>
      <dc:creator>Martin_Seeger</dc:creator>
      <dc:date>2020-05-11T07:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SecureXL on SMB Appliance (R80.20.5)?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84810#M3519</link>
      <description>&lt;P&gt;It may also be worthwhile testing with the latest&amp;nbsp;&lt;SPAN&gt;Build 992001169 (refer sk164912).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 08:32:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84810#M3519</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-05-11T08:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SecureXL on SMB Appliance (R80.20.5)?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84814#M3521</link>
      <description>&lt;P&gt;Yes, that was the correct table.def&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 09:00:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84814#M3521</guid>
      <dc:creator>Martin_Seeger</dc:creator>
      <dc:date>2020-05-11T09:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SecureXL on SMB Appliance (R80.20.5)?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84815#M3522</link>
      <description>&lt;P&gt;Thank you!&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hadn't seen that a new version is out.&lt;/P&gt;&lt;P&gt;Unluckily the &lt;A href="https://supportcenter.checkpoint.com/supportcenter/secureKnowledgeRss" target="_self"&gt;RSS-Feeds from SecureKnowledge&lt;/A&gt; is currently broken (SR 6-0001991921 is already open):&amp;nbsp; &lt;A href="https://validator.w3.org/feed/check.cgi?url=https%3A%2F%2Fsupportcenter.checkpoint.com%2Fsupportcenter%2FsecureKnowledgeRss" target="_self"&gt;https://validator.w3.org/feed/check.cgi?url=https%3A%2F%2Fsupportcenter.checkpoint.com%2Fsupportcenter%2FsecureKnowledgeRss&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Through the RSS feed I usually see every new version coming out (every changed SK generates an entry).&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 09:06:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84815#M3522</guid>
      <dc:creator>Martin_Seeger</dc:creator>
      <dc:date>2020-05-11T09:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SecureXL on SMB Appliance (R80.20.5)?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84817#M3524</link>
      <description>&lt;P&gt;I would suggest the easy way from&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/SMB-Appliances-and-SMP/SecureXL-amp-CoreXL-on-SMB-devices/td-p/39531" target="_blank"&gt;https://community.checkpoint.com/t5/SMB-Appliances-and-SMP/SecureXL-amp-CoreXL-on-SMB-devices/td-p/39531&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 09:14:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84817#M3524</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-05-11T09:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SecureXL on SMB Appliance (R80.20.5)?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84819#M3525</link>
      <description>Yep, I had a similar "fix". But that felt very "hacky" to me. Furthermore with R80.20.05 SecureXL re-enables itself after a few hours, so I had to start a background process that would disable it automagically again.&lt;BR /&gt;&lt;BR /&gt;At that point I created this thread, as wrestling for control with your own system is never a good idea ;-).</description>
      <pubDate>Mon, 11 May 2020 09:49:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84819#M3525</guid>
      <dc:creator>Martin_Seeger</dc:creator>
      <dc:date>2020-05-11T09:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SecureXL on SMB Appliance (R80.20.5)?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84823#M3526</link>
      <description>Brute force approach at the moment:&lt;BR /&gt;&lt;BR /&gt;# fw tab -t f2f_addresses&lt;BR /&gt;localhost:&lt;BR /&gt;-------- f2f_addresses --------&lt;BR /&gt;static, id 250&lt;BR /&gt;&amp;lt;00000000, ffffffff&amp;gt;&lt;BR /&gt;&lt;BR /&gt;Will report on the effect later tonight.</description>
      <pubDate>Mon, 11 May 2020 10:21:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84823#M3526</guid>
      <dc:creator>Martin_Seeger</dc:creator>
      <dc:date>2020-05-11T10:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SecureXL on SMB Appliance (R80.20.5)?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84836#M3528</link>
      <description>With the correct table.def my workaround is functional. SecureXL is "enabled" but my services are working. Managed to squeeze in a reboot to update to the newest firmware.&lt;BR /&gt;&lt;BR /&gt;The hard part will be to remove the exceptions for SecureXL step by step and locate the real problems.</description>
      <pubDate>Mon, 11 May 2020 13:19:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84836#M3528</guid>
      <dc:creator>Martin_Seeger</dc:creator>
      <dc:date>2020-05-11T13:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling SecureXL on SMB Appliance (R80.20.5)?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84885#M3534</link>
      <description>It's better to use table.def to disable SecureXL acceleration for traffic from a problematic host than disable it globally. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Mon, 11 May 2020 23:34:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Disabling-SecureXL-on-SMB-Appliance-R80-20-5/m-p/84885#M3534</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-11T23:34:46Z</dc:date>
    </item>
  </channel>
</rss>

