- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
When setting up the new CCSE R81.10 class lab exercises I ran into this somewhat strange interaction between the new Accelerated Policy Install feature and SecureXL templates which does not appear to be documented.
The lab scenario was adding the ALL_DCE_RPC service to a policy rule then install policy, and once this was done as expected all SecureXL templating is halted at that rule (#4 in this case) as shown by fwaccel stat:
Next step was to remove the ALL_DCE_RPC service from rule #4 and reinstall policy (which turned out to be accelerated), but once this was finished fwaccel stat was then showing the following, indicating that all SecureXL Accept/NAT templating was COMPLETELY dead and not just disabled from rule #4:
Needless to say this had me scratching my head trying to figure out what happened. However once I realized that the prior policy installation was accelerated, it was just a matter of forcing an unaccelerated policy install (even with no other changes), which is performed by right-clicking on the gateway icon on the Install Policy screen like this and then hitting the Install button:
Once that was done normal SecureXL templating was restored. Hopefully this will help someone else as fwaccel stat simply showing that templates were "disabled by firewall" with no further information was a tad confusing.
I thougth it was a RnD easter eeg feature to force non accellerated policy ??
I ser page 14 tells more about this non accelerated access policy. 😂
http://downloads.checkpoint.com/dc/download.htm?ID=108670
Hi @Timothy_Hall ,
Can you please share which JHF is installed? as i tried same procedure now in my lab and it works fine, unless i'm missing some steps in your scenario:).
Thanks,
Ilya
R81.10 Jumbo HFA Take 30
Thanks indeed replicates, i will take it tomorrow with our RnD to resolved it.
Thanks again for your feedback !!!
I also saw same behavior in R81.10 lab (2 single gateways + mgmt).
I'd also like to request a way to permanently disable accelerated policy installs due to my latest run in with this feature:
FYI this templating issue appears to be fixed in R81.20 GA, not sure about whether the fix is included in a R81.10 Jumbo HFA; I don't see any reference to it as of R81.10 Jumbo Take 81. @Ilya_Yusupov?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 20 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY