- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
AI Security Masters
LGTM: Bypassing an LLM Build Gate
When Prompt Injection Fails
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
CheckMates Go:
Half is Not Enough
Hello,
I am trying to find out why LightSpeed acceleration is disabled on an appliance with lightspeed interfaces.
Version: R81.20 take 118
Running: Firewall/CoreXL in userspace and SecureXL in Kernel Space (Recommended by CP support due to performance issues with SecureXL in userspace, at this customer implementation)
I currently suspect that "Accept Templates : disabled by Firewall" this is causing Lightspeed acceleration to be disabled as well.
If this assumption is correct, then I think that this is a major limiting factor for using LightSpeed acceleration, as most of customers, that I have worked for has one or more rules in their policy, which disables accept templates, as there are quite a log list of features, which causes templating to be disabled.
fwaccel stat:
# fwaccel stat
+---------------------------------------------------------------------------------+
|Id|Name |Status |Interfaces |Features |
+---------------------------------------------------------------------------------+
|0 |KPPAK |enabled |Mgmt,eth3-01,Sync, |Acceleration,Cryptography |
| | | |eth3-02,eth1-01,eth4-01, | |
| | | |eth1-02 |Crypto: Tunnel,UDPEncap,MD5, |
| | | | |SHA1,3DES,DES,AES-128,AES-256,|
| | | | |ESP,LinkSelection,DynamicVPN, |
| | | | |NatTraversal,AES-XCBC,SHA256, |
| | | | |SHA384,SHA512 |
+---------------------------------------------------------------------------------+
Accept Templates : disabled by Firewall
Layer Network disables template offloads from rule #826
Throughput acceleration still enabled.
Drop Templates : enabled
NAT Templates : disabled by Firewall
Layer Network disables template offloads from rule #826
Throughput acceleration still enabled.
LightSpeed Accel : disabled
Best regards
Brian Hansen
Yes, Lightspeed is reliant on SecureXL accelerating connections.
Makes sense it would be disabled when templates are disabled.
Please review sk179432 to understand this further, UPPAK is needed.
Look for this row in the tables specifically:
Firewall Blade with Hardware Acceleration
Yes, Lightspeed is reliant on SecureXL accelerating connections.
Makes sense it would be disabled when templates are disabled.
Hi PhoneBoy,
Thank you for commenting.
I now managed to fix templating, but still LightSpeed accel is disabled. Any other ideas?
Best Regards
Brian Hansen
Hey Brian,
See if below helps.
https://community.checkpoint.com/t5/Security-Gateways/SecureXL-Templates-show-disabled/td-p/187182
https://support.checkpoint.com/results/sk/sk71200
The gateway should be running in UPPAK mode to fully leverage Lightspeed benefits.
What were the performance issues you encountered prior?
Hi Chris,
Also thank you for commenting 🙂
Unfortunately these performance issues and CP support involvement, was before my time with this customer and I do not know the specifics.
Although, I have also read that SecureXL in userspace should be preferred and also the default settings with new clean installs, then I do not expect it to be the reason that LightSpeed accel is disabled.
Is it your understanding that it could be the reason for the disabled state or "just" that it would be best to run in userspace ?
Best Regards
Brian Hansen
Please review sk179432 to understand this further, UPPAK is needed.
Look for this row in the tables specifically:
Firewall Blade with Hardware Acceleration
Apart from using UPPAK. Is your customer using VSX?
No they are not
I totally get the point Phoneboy made. That makes 100% sense.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 34 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 3 |
Thu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEAThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEATue 06 Oct 2026 @ 02:00 PM (EDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus AMERAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY