- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi
I got a new 9400 gateway running 81.20 take 113.
After changing from User mode to kernel mode using cpconfig:
fwmode -s shows: User mode
Fwaccel stat shows: KPPAK
We are moving from 6500 running in kernel mode to 9400.
My plan is to use save configuration on 6500 and load configuration on 9400.
But 9400 seems refusing kernel mode or maybe it is so in that new gateway?
Choosing kernel-mode because we have a stable environment with 6500 running in kernel-mode
Does 9400 running user mode or kernel mode according to the above information?
any ideas!
"fwmode -s shows: User mode" indicates that USFW is set, which means your Firewall Worker Instances run in User Space. This has been the default for some time, and there are not many good reasons to set kernel mode for your workers, as it will interfere with features such as Dynamic Split and Hyperflow.
"Fwaccel stat shows: KPPAK" means that SecureXL is running in kernel space. In R81.20 and R82, by default, only Quantum Force 3900/9XXX/19XXX/29XXX appliances, as well as Lightspeed appliances, utilize UPPAK by default. For the moment, you can set them back to use KPPAK, but this option will go away in R82.10, and UPPAK will become the default for all gateways, regardless of model or open hardware in that version.
so if our 6500 is running kernel mode and the new 9400 is running user mode on both firewall and securexl,
moving the configuration from 6500 to 9400 will run smoothly and we do not need to do anything? Or we need to do some tweaks so that everything works?
Hey brother,
Just me personally, I would NOT assume that risk, better be sure and confirm with TAC.
Andy
The 9400 will use UPPAK by default. Prior to the replacement, familiarize yourself with the limitations of UPPAK in Section 4 here:
Note that some limitations listed here are included for completeness but have already been resolved. Please refer to the far right column to see which version may have resolved the issue, and ensure you are using the latest Recommended Jumbo HFA. If any of these limitations are show-stoppers or you encounter problems, you may need to set your 9400 back to KPPAK mode. Keep in mind that constantly high CPU utilization on your SND cores is expected behavior in UPPAK mode.
As Tim said though, by default it would use user mode.
Andy
What does fwmode -s show on your 6500s? You should keep USFW on the 9000s, and the config should transfer over like for like, but with any hardware swap it's a good time to review the config and only copy over the stuff that you need. I would 'show configuration' on the old setup and copy/paste in only the stuff that is needed to the new gear.
6500 shows:
[Expert@fw02:0]# fwmode -s
Firewall is Kernel mode
so you mean 9400 should never use kernel mode even if 6500 is kernel mode?
I used save configuration and load configuration and I will double check the config again line by line
From my R82 fw:
[Expert@CP-GW:0]# fwmode -s
Firewall is User mode
[Expert@CP-GW:0]# uname -a
Linux CP-GW 4.18.0-372.9.1cpx86_64 #1 SMP Thu Aug 28 16:01:06 IDT 2025 x86_64 x86_64 x86_64 GNU/Linux
[Expert@CP-GW:0]#
You can force it to load the config with below command in clish:
set clienv on-failure continue
save config
Andy
How to change:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
15 | |
12 | |
8 | |
6 | |
6 | |
6 | |
5 | |
5 | |
4 | |
3 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY