- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
I got this message today when configuring my 9700 appliances:
RTGRTG0019 SecureXL is in User Space mode, BFD is not supported. Consult SK179432 for more details.
I'm running R81.20 on JHF99.
When will BFD be supported in SecureXL User Space?
In latest JHFs I believe it is possible to activate it if you start in KPPAK mode then move to UPPAK.
Please clarify further with TAC as needed.
If this is supported by Check Point I'll give it a try.
You can seek an official statement of support from TAC.
Believe the blocking error will be removed in a future JHF per PRJ-60023
It's working now indeed. I'll contact support about this. Thank you Chris.
Was not aware of this particular UPPAK limitation, thanks for bringing it to the attention of the community.
From a documentation perspective it's only outlined here currently for awareness:
Yes but the UPPAK limitations are also separately described in Section 4 of sk32578: SecureXL Mechanism. These two lists do not always seem to contain the same information which I found quite confusing while preparing my "Be your Own TAC Part Deux" presentation. It would be nice if these two lists could be unified into a single authoritative source.
Agreed, I already requested the SK referenced in the error above be updated.
Hello,
Even on latest JHF_take 99, you cannot switch back to UPPAK when using BFD. We were hit with this- sk183181
and we change the secureXL to KPPAK and in between had to configure BFD. But now since sk183181 is released, thought the issue is fixed and could change it back to UPPAK, but BFD config dont allow it back. Does anyone know how can we remove the config for BFD from gaia clish:
"set ip-reachability-detection bfd detect-multiplier 3", i tried different keywords, but nothing works.
Any suggestion is greatly appreciated.
Regards,
Lolith
Your order of operations is a little unclear. Note the process above was starting with T99 not some previous configuration.
Did you try the "default" key word with that command or setting the value to 10?
If the problem persists please contact TAC for assistance.
Hello Chris,
What I meant to say, due to this bug under sk183181, we have to change it to KPPAK to stablise our environment when we were on JHF_98. Then in between we enabled BFD. Now since take 99 was released, we were hoping to change it back to UPPAK, but it won't allow us to change it to UPPAK when this BFD config is present.
I will give it a shot with default. But still the BFD won't be supported in UPPAK mode as per design I believe.
Regards,
Lolith
This limitation will be formally removed in the near future, this thread described a work around in the interim.
Now solved - PRJ-60023 in JHF T101 for R81.20
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
19 | |
14 | |
7 | |
7 | |
6 | |
6 | |
6 | |
4 | |
4 | |
4 |
Mon 22 Sep 2025 @ 03:00 PM (CEST)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security EMEAMon 22 Sep 2025 @ 02:00 PM (EDT)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security AMERTue 23 Sep 2025 @ 06:00 PM (IDT)
Under the Hood: CloudGuard Network Security for Nutanix - Overview, Onboarding, and Best PracticesMon 22 Sep 2025 @ 03:00 PM (CEST)
Defending Hyperconnected AI-Driven Networks with Hybrid Mesh Security EMEAWed 24 Sep 2025 @ 03:00 PM (CEST)
Bereit für NIS2: Strategische Werkzeuge für Ihre Compliance-Reise 2025Thu 25 Sep 2025 @ 03:00 PM (IDT)
NIS2 Compliance in 2025: Tactical Tools to Assess, Secure, and ComplyAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY