- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hello,
I am trying to find out why LightSpeed acceleration is disabled on an appliance with lightspeed interfaces.
Version: R81.20 take 118
Running: Firewall/CoreXL in userspace and SecureXL in Kernel Space (Recommended by CP support due to performance issues with SecureXL in userspace, at this customer implementation)
I currently suspect that "Accept Templates : disabled by Firewall" this is causing Lightspeed acceleration to be disabled as well.
If this assumption is correct, then I think that this is a major limiting factor for using LightSpeed acceleration, as most of customers, that I have worked for has one or more rules in their policy, which disables accept templates, as there are quite a log list of features, which causes templating to be disabled.
fwaccel stat:
# fwaccel stat
+---------------------------------------------------------------------------------+
|Id|Name |Status |Interfaces |Features |
+---------------------------------------------------------------------------------+
|0 |KPPAK |enabled |Mgmt,eth3-01,Sync, |Acceleration,Cryptography |
| | | |eth3-02,eth1-01,eth4-01, | |
| | | |eth1-02 |Crypto: Tunnel,UDPEncap,MD5, |
| | | | |SHA1,3DES,DES,AES-128,AES-256,|
| | | | |ESP,LinkSelection,DynamicVPN, |
| | | | |NatTraversal,AES-XCBC,SHA256, |
| | | | |SHA384,SHA512 |
+---------------------------------------------------------------------------------+
Accept Templates : disabled by Firewall
Layer Network disables template offloads from rule #826
Throughput acceleration still enabled.
Drop Templates : enabled
NAT Templates : disabled by Firewall
Layer Network disables template offloads from rule #826
Throughput acceleration still enabled.
LightSpeed Accel : disabled
Best regards
Brian Hansen
Yes, Lightspeed is reliant on SecureXL accelerating connections.
Makes sense it would be disabled when templates are disabled.
Please review sk179432 to understand this further, UPPAK is needed.
Look for this row in the tables specifically:
Firewall Blade with Hardware Acceleration
Yes, Lightspeed is reliant on SecureXL accelerating connections.
Makes sense it would be disabled when templates are disabled.
Hi PhoneBoy,
Thank you for commenting.
I now managed to fix templating, but still LightSpeed accel is disabled. Any other ideas?
Best Regards
Brian Hansen
Hey Brian,
See if below helps.
https://community.checkpoint.com/t5/Security-Gateways/SecureXL-Templates-show-disabled/td-p/187182
https://support.checkpoint.com/results/sk/sk71200
The gateway should be running in UPPAK mode to fully leverage Lightspeed benefits.
What were the performance issues you encountered prior?
Hi Chris,
Also thank you for commenting 🙂
Unfortunately these performance issues and CP support involvement, was before my time with this customer and I do not know the specifics.
Although, I have also read that SecureXL in userspace should be preferred and also the default settings with new clean installs, then I do not expect it to be the reason that LightSpeed accel is disabled.
Is it your understanding that it could be the reason for the disabled state or "just" that it would be best to run in userspace ?
Best Regards
Brian Hansen
Please review sk179432 to understand this further, UPPAK is needed.
Look for this row in the tables specifically:
Firewall Blade with Hardware Acceleration
Apart from using UPPAK. Is your customer using VSX?
No they are not
I totally get the point Phoneboy made. That makes 100% sense.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 76 | |
| 28 | |
| 13 | |
| 12 | |
| 12 | |
| 12 | |
| 9 | |
| 8 | |
| 8 | |
| 7 |
Tue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 21 Apr 2026 @ 05:00 PM (IDT)
AI Security Masters E7: How CPR Broke ChatGPT's Isolation and What It Means for YouTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY