- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hello,
I am trying to find out why LightSpeed acceleration is disabled on an appliance with lightspeed interfaces.
Version: R81.20 take 118
Running: Firewall/CoreXL in userspace and SecureXL in Kernel Space (Recommended by CP support due to performance issues with SecureXL in userspace, at this customer implementation)
I currently suspect that "Accept Templates : disabled by Firewall" this is causing Lightspeed acceleration to be disabled as well.
If this assumption is correct, then I think that this is a major limiting factor for using LightSpeed acceleration, as most of customers, that I have worked for has one or more rules in their policy, which disables accept templates, as there are quite a log list of features, which causes templating to be disabled.
fwaccel stat:
# fwaccel stat
+---------------------------------------------------------------------------------+
|Id|Name |Status |Interfaces |Features |
+---------------------------------------------------------------------------------+
|0 |KPPAK |enabled |Mgmt,eth3-01,Sync, |Acceleration,Cryptography |
| | | |eth3-02,eth1-01,eth4-01, | |
| | | |eth1-02 |Crypto: Tunnel,UDPEncap,MD5, |
| | | | |SHA1,3DES,DES,AES-128,AES-256,|
| | | | |ESP,LinkSelection,DynamicVPN, |
| | | | |NatTraversal,AES-XCBC,SHA256, |
| | | | |SHA384,SHA512 |
+---------------------------------------------------------------------------------+
Accept Templates : disabled by Firewall
Layer Network disables template offloads from rule #826
Throughput acceleration still enabled.
Drop Templates : enabled
NAT Templates : disabled by Firewall
Layer Network disables template offloads from rule #826
Throughput acceleration still enabled.
LightSpeed Accel : disabled
Best regards
Brian Hansen
Yes, Lightspeed is reliant on SecureXL accelerating connections.
Makes sense it would be disabled when templates are disabled.
Please review sk179432 to understand this further, UPPAK is needed.
Look for this row in the tables specifically:
Firewall Blade with Hardware Acceleration
Yes, Lightspeed is reliant on SecureXL accelerating connections.
Makes sense it would be disabled when templates are disabled.
Hi PhoneBoy,
Thank you for commenting.
I now managed to fix templating, but still LightSpeed accel is disabled. Any other ideas?
Best Regards
Brian Hansen
Hey Brian,
See if below helps.
https://community.checkpoint.com/t5/Security-Gateways/SecureXL-Templates-show-disabled/td-p/187182
https://support.checkpoint.com/results/sk/sk71200
The gateway should be running in UPPAK mode to fully leverage Lightspeed benefits.
What were the performance issues you encountered prior?
Hi Chris,
Also thank you for commenting 🙂
Unfortunately these performance issues and CP support involvement, was before my time with this customer and I do not know the specifics.
Although, I have also read that SecureXL in userspace should be preferred and also the default settings with new clean installs, then I do not expect it to be the reason that LightSpeed accel is disabled.
Is it your understanding that it could be the reason for the disabled state or "just" that it would be best to run in userspace ?
Best Regards
Brian Hansen
Please review sk179432 to understand this further, UPPAK is needed.
Look for this row in the tables specifically:
Firewall Blade with Hardware Acceleration
Apart from using UPPAK. Is your customer using VSX?
No they are not
I totally get the point Phoneboy made. That makes 100% sense.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 33 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 3 |
Mon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksMon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY