- Products
- Learn
- Local User Groups
- Partners
- More
The Great Exposure Reset
24 February 2026 @ 5pm CET / 11am EST
AI Security Masters E4:
Introducing Cyata - Securing the Agenic AI Era
AI Security Masters E3:
AI-Generated Malware
CheckMates Go:
CheckMates Fest
This scripts generated bunch of files for securexl stats. Example in my lab:
[Expert@CP-GW:0]# chmod 777 *
[Expert@CP-GW:0]# dos2unix *
dos2unix: converting file securexl.sh to Unix format ...
[Expert@CP-GW:0]# ls
securexl.sh
[Expert@CP-GW:0]# ./securexl.sh
[2026-02-20 17:00:38] Output directory: /var/log/securexl_audit_CP-GW_20260220_170038
[2026-02-20 17:00:38] Using IPv4 command: fwaccel
[2026-02-20 17:00:38] Using IPv6 command: fwaccel6 (enabled=1)
[2026-02-20 17:00:40] Creating tarball: /var/log/securexl_audit_CP-GW_20260220_170038.tar.gz
[2026-02-20 17:00:40] Done. Bundle: /var/log/securexl_audit_CP-GW_20260220_170038.tar.gz
[2026-02-20 17:00:40] NOTE: If conns output files show errors like 'parameter not supported', the gateway version may not support -m/-f flags as expected; the script keeps summaries regardless. [3](https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/PTG...)
[Expert@CP-GW:0]#
[Expert@CP-GW:0]# chmod 777 *
[Expert@CP-GW:0]# dos2unix *
dos2unix: converting file securexl_full_stats.sh to Unix format ...
[Expert@CP-GW:0]# ./securexl_full_stats.sh
[2026-02-20 17:02:12] Output directory: /var/log/securexl_stats_CP-GW_20260220_170212
[2026-02-20 17:02:12] Using: fwaccel (IPv4), fwaccel6 (IPv6) | MAX_TEMPLATE_ROWS=200 | INCLUDE_CONNS=0
[2026-02-20 17:02:31] Done. Bundle: /var/log/securexl_stats_CP-GW_20260220_170212.tgz
[2026-02-20 17:02:31] Tip: grep -R "Accelerated" -n /var/log/securexl_stats_CP-GW_20260220_170212/*.txt | head
[Expert@CP-GW:0]# cd /var/log/securexl_stats_CP-GW_20260220_170212
[Expert@CP-GW:0]# ls
00_env.txt 24_fwaccel_stats_notif.txt 32_fwaccel6_stats_pxl.txt
10_fwaccel_ver.txt 25_fwaccel_stats_reorder.txt 40_templates_accept_summary.txt
11_fwaccel_stat.txt 26_fwaccel_stats_pxl.txt 41_templates_accept_stats.txt
12_fwaccel6_stat.txt 27_fwaccel_stats_cluster.txt 42_templates_accept_top.txt
20_fwaccel_stats_summary.txt 28_fwaccel_stats_multicast.txt 43_templates_drop_top.txt
21_fwaccel_stats_legacy.txt 29_fwaccel_stats_nac.txt 60_fwaccel_dos_stats.txt
22_fwaccel_stats_drops.txt 30_fwaccel6_stats_summary.txt 61_fwaccel6_dos_stats.txt
23_fwaccel_stats_viol.txt 31_fwaccel6_stats_legacy.txt run.log
[Expert@CP-GW:0]# more 22_fwaccel_stats_drops.txt
### COMMAND: bash -lc fwaccel stats -d
### DATE: 2026-02-20T17:02:15-0500
Reason Value Reason Value
-------------------- --------------- -------------------- ---------------
General 0 CPASXL Decision 0
PSLXL Decision 0 UDP IS XL Decision 0
Clear Packet on VPN 0 Encryption Failed 0
Drop Template 0 Decryption Failed 0
Interface Down 0 Cluster Error 0
XMT Error 0 Anti-Spoofing 591004
Local Spoofing 0 Sanity Error 0
Monitored Spoofed 0 QoS Decision 0
QoS LLQ Decision 0 QoS Packet Rejected 0
C2S Violation 0 S2C Violation 0
Loop Prevention 0 DOS Fragments 0
DOS IP Options 0 DOS Deny Lists 0
DOS Penalty Box 0 DOS Rate Limiting 0
Syn Attack 0 Reorder 0
Virt Defrag Timeout 0 Invalid Interface 0
Null Routing info 0 Unable to get out ifn 0
Resource exhausted 0 Conn not found 0
Failed to del corr 0 Corr instead of conn 0
Del zombie conn fail 0 FW UUID no match 0
Offload mismatch 0 SIM init failed 0
Null stream init info 0 Unable to get CGNAT 0
Null stream app info 0 Failed get init info 0
Collid conn not found 0 Del collid conn fail 0
Add conn after collid 0 SEQ valid 0
Enqueue QoS failed 0 AUX CI null 0
Link dead 0 VPN packet too big 0
NAT64 failed 0 NAT46 failed 0
Packet > MTU 0 NAC validation 0
TCP state violation 0 Enforce packet 0
GTP check packet 0 Bridge route error 0
Route ifn changed 0 IP forwarding 0
Copy MACS failed 0 Fragments Drops 0
Send Notification 0 Conn not found RST 0
Forward to PPAK fail 0 Cluster forward fail 0
F2F before encrypt 0 Forward dst encrypt 0
Correction I/S fail 0 Do inbound F2F 0
Packet UDP failed 0 F2F not allowed 0
Do routing 0 Fanout won't F2F 0
SCTP validation fail 0 SCTP not data 0
Invalid TCP option 0 Invalid MSS option 0
Invalid MSS value 0 Invalid window scale 0
Invalid IP option 0 Invalid Ext header 0
Resume from Host err 0 Invalid ethertype 0
### EXIT CODE: 0
[Expert@CP-GW:0]#
[Expert@CP-GW:0]#
This scripts generated bunch of files for securexl stats. Example in my lab:
[Expert@CP-GW:0]# chmod 777 *
[Expert@CP-GW:0]# dos2unix *
dos2unix: converting file securexl.sh to Unix format ...
[Expert@CP-GW:0]# ls
securexl.sh
[Expert@CP-GW:0]# ./securexl.sh
[2026-02-20 17:00:38] Output directory: /var/log/securexl_audit_CP-GW_20260220_170038
[2026-02-20 17:00:38] Using IPv4 command: fwaccel
[2026-02-20 17:00:38] Using IPv6 command: fwaccel6 (enabled=1)
[2026-02-20 17:00:40] Creating tarball: /v
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY