Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Timothy_Hall
MVP Gold
MVP Gold
Jump to solution

R82 - vpn accel is deprecated?

In R82, the vpn accel command appears to be deprecated.  This command was useful for disabling SecureXL VPN acceleration for a specific VPN peer for testing without affecting other VPN peers.  It looks like the only way now is to disable acceleration for all VPN tunnels and peers with fw ctl set -f int vpn_accel 0 (assuming that still works?).

Am I missing something, or is there no replacement available for vpn accel off [PeerIP]?

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization
1 Solution

Accepted Solutions
Timothy_Hall
MVP Gold
MVP Gold

I was able to answer my own question with some lab testing. There is no way to disable VPN acceleration without breaking VPNs completely that I can see, definitely in R82.10 and possibly starting in R82.  DO NOT USE fw ctl set -f int vpn_accel 0! An excerpt from my book is below. I'm not exactly sure what the thought process was for taking this diagnostic capability away (unless there is some kind of undocumented procedure to accomplish it):

The following command is supposed to disable SecureXL acceleration of all VPNs for testing purposes, but will immediately kill all existing VPN tunnels, and keep any new ones from starting successfully. In my lab testing, using fw ctl set -f int vpn_accel 0 in R82.10 Jumbo HFA Take 26 immediately BROKE ALL VPNs even after the firewall was rebooted, with errors such as "encryption failure: fw does not take care of ESP, expected SecureXL to encrypt" and "tunnel is accelerated but packet was not decrypted by SecureXL". To temporarily disable acceleration of VPNs by SecureXL for testing purposes, contact the TAC. USE THE ABOVE COMMAND AT YOUR OWN RISK!

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization

View solution in original post

0 Kudos
4 Replies
Lesley
MVP Platinum
MVP Platinum

In https://support.checkpoint.com/results/sk/sk151114 it should still be there even for R82.10.

Do any other commands still give output? If you run the command do you get any error or output at all?

I dont see any open bugs related to this issue

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
Timothy_Hall
MVP Gold
MVP Gold

UPPAK/KPPAK mode doesn't seem to matter either.

vpnaccel.pngvpnaccel.png

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization
0 Kudos
Lesley
MVP Platinum
MVP Platinum

Okay, let me try a couple tomorrow to run this command. If I get the same the SK needs to be updated.

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
Timothy_Hall
MVP Gold
MVP Gold

I was able to answer my own question with some lab testing. There is no way to disable VPN acceleration without breaking VPNs completely that I can see, definitely in R82.10 and possibly starting in R82.  DO NOT USE fw ctl set -f int vpn_accel 0! An excerpt from my book is below. I'm not exactly sure what the thought process was for taking this diagnostic capability away (unless there is some kind of undocumented procedure to accomplish it):

The following command is supposed to disable SecureXL acceleration of all VPNs for testing purposes, but will immediately kill all existing VPN tunnels, and keep any new ones from starting successfully. In my lab testing, using fw ctl set -f int vpn_accel 0 in R82.10 Jumbo HFA Take 26 immediately BROKE ALL VPNs even after the firewall was rebooted, with errors such as "encryption failure: fw does not take care of ESP, expected SecureXL to encrypt" and "tunnel is accelerated but packet was not decrypted by SecureXL". To temporarily disable acceleration of VPNs by SecureXL for testing purposes, contact the TAC. USE THE ABOVE COMMAND AT YOUR OWN RISK!

New Book: "Max Power 2026" Coming Soon
Check Point Firewall Performance Optimization
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events