When setting up the new CCSE R81.10 class lab exercises I ran into this somewhat strange interaction between the new Accelerated Policy Install feature and SecureXL templates which does not appear to be documented.
The lab scenario was adding the ALL_DCE_RPC service to a policy rule then install policy, and once this was done as expected all SecureXL templating is halted at that rule (#4 in this case) as shown by fwaccel stat:
![acc1.png acc1.png](/t5/image/serverpage/image-id/15215iE98DE6ED321B487A/image-size/large?v=v2&px=999)
Next step was to remove the ALL_DCE_RPC service from rule #4 and reinstall policy (which turned out to be accelerated), but once this was finished fwaccel stat was then showing the following, indicating that all SecureXL Accept/NAT templating was COMPLETELY dead and not just disabled from rule #4:
![acc2.png acc2.png](/t5/image/serverpage/image-id/15216i23F663565ED884C3/image-size/large?v=v2&px=999)
Needless to say this had me scratching my head trying to figure out what happened. However once I realized that the prior policy installation was accelerated, it was just a matter of forcing an unaccelerated policy install (even with no other changes), which is performed by right-clicking on the gateway icon on the Install Policy screen like this and then hitting the Install button:
![acc3.png acc3.png](/t5/image/serverpage/image-id/15217i5A01032287356867/image-size/large?v=v2&px=999)
Once that was done normal SecureXL templating was restored. Hopefully this will help someone else as fwaccel stat simply showing that templates were "disabled by firewall" with no further information was a tad confusing.
Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm