- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello everyone,
I have a question about which mode the cluster is working in. I will share my scenario with you.
My environment has a VSX (VSLS) cluster with 2 (two) VSs. I am on version R81.20 JHF 92. My appliance model is 9400 with 20 CPUs. My main VS has 14 dedicated CPU cores.
I am facing a performance problem in this main VS, where we have peaks of ~80% CPU and in some cases there is low network performance.
I was checking the acceleration section and came across the following information in cpview:
UPPAK Status Off (!)
I checked the SecureXL status and it shows the following information:
[Expert@fw1]# fwaccel stat
+---------------------------------------------------------------------------------+
|Id|Name |Status |Interfaces |Features | +--------------------------------------------------------------------------------+
|0 |KPPAK* |enabled | |Acceleration,Cryptography |
| | | | | |
| | | | |Crypto: Tunnel,UDPEncap,MD5, |
| | | | |SHA1,3DES,DES,AES-128,AES-256,|
| | | | |ESP,LinkSelection,DynamicVPN, |
| | | | |NatTraversal,AES-XCBC,SHA256, |
| | | | |SHA384,SHA512 |
+--------------------------------------------------------------------------------+
* WARNING: (null).
* Disabled at: Tue Feb 25 08:41:35 2025
*Refer to sk179432 for more information.
Accept Templates : enabled
Drop Templates : enabled
NAT Templates : enabled
LightSpeed Accel : disabled
[Expert@fw1]#
I noticed that the SecureXL operating mode is "Kernel Mode".
I checked the firewall CLI to make sure which mode is active and I saw that it was User Mode.
[Expert@fw1]# cpprod_util FwIsUsermode
1
1 = User Mode Firewall
0 = Kernel Mode Firewall
I also ran the fwaccel stat command on vs 0 and it showed the following information:
fwaccel stat
+---------------------------------------------------------------------------------+
|Id|Name |Status |Interfaces |Features |
+---------------------------------------------------------------------------------+
|0 |KPPAK* |enabled |Sync,Mgmt,eth1-05, |Acceleration,Cryptography |
| | | |eth1-01,eth1-06,eth1-02 | |
| | | | |Crypto: Tunnel,UDPEncap,MD5, |
| | | | |SHA1,3DES,DES,AES-128,AES-256,|
| | | | |ESP,LinkSelection,DynamicVPN, |
| | | | |NatTraversal,AES-XCBC,SHA256, |
| | | | |SHA384,SHA512 |
+--------------------------------------------------------------------------------+
* WARNING: SecureXL User Space Mode was disabled. Reason: .
* Disabled at: Tue Feb 25 08:41:35 2025
*Refer to sk179432 for more information.
Accept Templates : enabled
Drop Templates : disabled
NAT Templates : enabled
The result above informs that User Space mode has been disabled but does not explain why.
I would like your help to better understand this information.
I believe this is because you have a feature enabled that UPPAK does not support (sk179432 and sk32578 section 4) or the usim daemon has crashed repeatedly. Anything in these directories?
I took a look at the two SKs you sent and did not identify any incompatibility with the enabled features. All the functions active in the gateway are supported.
Regarding the directories, I did not find any information:
ls -lha /var/log/dump/usermode/usim*
ls: cannot access /var/log/dump/usermode/usim*: No such file or directory
ls -lha /var/log/usim_crash/crash_list
ls: cannot access /var/log/usim_crash/crash_list: No such file or directory
Do you have any other suggestions to consider?
Strange that it is not reporting the reason UPPAK is disabled, does the date it was disabled roughly correlate with when the system was first booted up? Curious to know if it disabled UPPAK around boot time (which I would assume means an incompatible feature was detected) or if UPPAK was enabled originally then got disabled (which could be due to instability).
Anything interesting in /var/log/usim_x86.elg, /var/log/messages, or $FWDIR/log/fwk.elg around the time it was reported as disabled?
Strange that it's not reporting the reason UPPAK is disabled, does the date it was disabled roughly correlate to when the system was first booted? Curious if it disabled UPPAK close to the time of boot (which I assume means an incompatible feature was detected) or if UPPAK was originally enabled and then disabled (which could be due to instability).
Anything interesting in /var/log/usim_x86.elg, /var/log/messages or $FWDIR/log/fwk.elg around the time it was reported as disabled?
I've attached a printout of the /var/log/usim_x86.elg and $FWDIR/log/fwk.elg files. At the end of the /var/log/usim_x86.elg file there seems to be some memory issue.
Hmm not sure those log files are useful, there is little documentation for the guts of UPPAK right now and you must have a Quantum Force or Lightspeed appliance to enable UPPAK (can't do it in VMware) so looks like it is time to get in touch with TAC. Hopefully showing them this thread will help speed things along.
I have opened a ticket with TAC and now i´m just waiting for a feedback.
Hello @jslimma_soloiro
Did you have any response from TAC?
I have a similar issue: Quantum Force 9700, VSX in cluster HA, SecureXL enabled in KPPAK with Firewall in User Space mode.
Regards,
Edgar
If your Jumbo level is the latest recommended please take it internally with TAC though HCP should typically help to highlight any crashes / coredumps.
The combination you've noted is not unexpected and could be the result of configuration in some cases (refer: sk167052 - just above the Note).
@edgarp make sure your customer has a separate TAC case opened for that.
Just to clarify a point you'll see a table at the end of sk167052
KPPAK/UPPAK are different things from KSFW/USFW.
I understand that it´s different and now i´m waiting for a feedback from TAC.
Thanks
USFW effectively moves the firewall workers to userspace.
While we introduced USFW in the R80.x timeframe, it's been used for VSX since R75.40.
It's not the issue here.
UPPAK moves SecureXL itself into userspace.
For a detailed discussion, listen here: https://community.checkpoint.com/t5/CheckMates-Go-Cyber-Security/S07E03-What-is-UPPAK/ba-p/245115/ju...
While it is expected to be the default mode/supported everywhere in upcoming versions, it is not supported everywhere in all situations currently.
Please review this SK for details: https://support.checkpoint.com/results/sk/sk32578
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
10 | |
7 | |
7 | |
6 | |
5 | |
5 | |
5 | |
5 | |
5 | |
4 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY