- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi i have upgraded a Cluster XL to 80.40
this cluster works only as firewall (NGTP or NGTX isn't active)
in the smartconsole is all green.
dns query from internal to external doesn't work when secure xl is enabled.
if i disable secure xl the dns querys are working.
have anyone the same problem?
how can i solve this? (have to wait for a new hotfix?)
thanx all, regards
flo
I had the same problem. But there is a solution to bypass the DNS server IP. You can bypass SecureXL (green flow in the picture) as described. This will use the F2F path instead of the acceleration path.
How to disable SecureXL for specific IP addresses? Edit the relevant table.def file, define the DNS Server IP addresses, whose traffic should not be accelerated. You can find more on this topic in this sk104468.
More read here:
- R80.x - Performance Tuning Tip - Control SecureXL / CoreXL Paths
- R80.x - Security Gateway Architecture (Logical Packet Flow)
Experiencing the same issue after upgrading a Cluster to R80.40.
Interestingly the DNS traffic goes through 2 x Clusters and the issue goes away after disabling SecureXL on one of them.
We are using a bind DNS server, same issue using forwarders or root hints.
Looks like the DNS reply packet is sent twice on the egress interface from the gateway, but is never visible in a tcpdump on the DNS server itself.
Also managed to get this working by enabling the IPS blade (previously had firewall + IA + Mobile access only).
fwaccel conns now shows the inbound and outbound connections with the 'S' flag (PXL enabled).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY