Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
PecenkA
Participant
Jump to solution

PPPoE is not supported with SecureXL User Space mode on 3950, R82.10?

Hello. We received our new 3950 security gateway and I'm trying to configure it to replace out locally managed 910. I only have experience with locally managed appliances so far (700, 900 and 1500 series).

I only configured some basic things for now:
- installed Security management Server VM
- installed Smart Console on my PC
- set some interfaces and VLANs on 3950

I have not yet joined 3950 to Security management Server.

When I try to add a new PPPoE interface from web interface of 3950 I get the message "PPPoE is not supported with SecureXL User Space mode". What do I need to do to make it work? Join it to management server and work from there? Something else? The PPPoE interface is our backup internet connection.

0 Kudos
2 Solutions

Accepted Solutions
PecenkA
Participant

Findings after some light reading:

R82.10 default is UPPAK.

cpconfig does not show "change SecureXL Mode" option.

Accordign to this sk32578 - SecureXL Mechanism SecureXL should disable itself on PPPoE interface.

No closer to solution.

Edit:
After some more light reading i found the R82.10 release notes:
Early AvailabilitySoftware Changes in R82.10
R82.10 Release Notes | 13
Security Gateway
n On Check Point Appliances, Virtual Machines, and Open Servers:
l Firewall runs only in the User Space Firewall mode (USFW).
The Kernel Space Firewall mode (KSFW) does not exist anymore.
See sk167052.
l SecureXL runs only in the User Mode (UPPAK).
The Kernel Mode (KPPAK) does not exist anymore.

 

So. No PPPoE? We'll be returning the product in that case.

View solution in original post

0 Kudos
TomCulley
Employee
Employee

Hi @PecenkA!

I was able to replicate this in R82.10 build 271.

Looking into some notes from my TAC colleagues, it seems this behavior is now fixed in R82.10 build 464.
I've just deployed it on my own 3920, and PPPoE configured as expected.

Give it a try and let us know how you get on 😊

Fast Deployment Package (TGZ): https://support.checkpoint.com/results/download/140674
Offline Upgrade Package (TAR): https://support.checkpoint.com/results/download/140665
Clean Install ISO file: https://support.checkpoint.com/results/download/140660 

View solution in original post

0 Kudos
4 Replies
PecenkA
Participant

Findings after some light reading:

R82.10 default is UPPAK.

cpconfig does not show "change SecureXL Mode" option.

Accordign to this sk32578 - SecureXL Mechanism SecureXL should disable itself on PPPoE interface.

No closer to solution.

Edit:
After some more light reading i found the R82.10 release notes:
Early AvailabilitySoftware Changes in R82.10
R82.10 Release Notes | 13
Security Gateway
n On Check Point Appliances, Virtual Machines, and Open Servers:
l Firewall runs only in the User Space Firewall mode (USFW).
The Kernel Space Firewall mode (KSFW) does not exist anymore.
See sk167052.
l SecureXL runs only in the User Mode (UPPAK).
The Kernel Mode (KPPAK) does not exist anymore.

 

So. No PPPoE? We'll be returning the product in that case.

0 Kudos
PatrickHen
Participant

Found that out for a 3920 on which I tried to configure PPPoE today...

0 Kudos
TomCulley
Employee
Employee

Hi @PecenkA!

I was able to replicate this in R82.10 build 271.

Looking into some notes from my TAC colleagues, it seems this behavior is now fixed in R82.10 build 464.
I've just deployed it on my own 3920, and PPPoE configured as expected.

Give it a try and let us know how you get on 😊

Fast Deployment Package (TGZ): https://support.checkpoint.com/results/download/140674
Offline Upgrade Package (TAR): https://support.checkpoint.com/results/download/140665
Clean Install ISO file: https://support.checkpoint.com/results/download/140660 

0 Kudos
PecenkA
Participant

Hi. We're using the latest 464 since day one of release. PPPoE works fine.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events