Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Moudar
Advisor

SecureXL mode

Hi

I got a new 9400 gateway running 81.20 take 113.

After changing from User mode to kernel mode using cpconfig:

fwmode -s shows: User mode

Fwaccel stat shows: KPPAK

We are moving from 6500 running in kernel mode to 9400.

My plan is to use save configuration on 6500 and load configuration on 9400.

But 9400 seems refusing kernel mode or maybe it is so in that new gateway?

Choosing kernel-mode because we have a stable environment with 6500 running in kernel-mode

Does 9400 running user mode or kernel mode according to the above information? 

 

any ideas!

0 Kudos
10 Replies
Timothy_Hall
Legend Legend
Legend

"fwmode -s shows: User mode" indicates that USFW is set, which means your Firewall Worker Instances run in User Space.  This has been the default for some time, and there are not many good reasons to set kernel mode for your workers, as it will interfere with features such as Dynamic Split and Hyperflow.

"Fwaccel stat shows: KPPAK" means that SecureXL is running in kernel space.  In R81.20 and R82, by default, only Quantum Force 3900/9XXX/19XXX/29XXX appliances, as well as Lightspeed appliances, utilize UPPAK by default.  For the moment, you can set them back to use KPPAK, but this option will go away in R82.10, and UPPAK will become the default for all gateways, regardless of model or open hardware in that version.

Gaia 4.18 (R82) Immersion Tips, Tricks, & Best Practices Video Course
Now Available at https://shadowpeak.com/gaia4-18-immersion-course
0 Kudos
Moudar
Advisor

so if our 6500 is running kernel mode and the new 9400 is running user mode on both firewall and securexl,

moving the configuration from 6500 to 9400 will run smoothly and we do not need to do anything? Or we need to do some tweaks so that everything works?

0 Kudos
the_rock
Legend
Legend

Hey brother,

Just me personally, I would NOT assume that risk, better be sure and confirm with TAC.

Andy

0 Kudos
Timothy_Hall
Legend Legend
Legend

The 9400 will use UPPAK by default.  Prior to the replacement, familiarize yourself with the limitations of UPPAK in Section 4 here:

sk32578: SecureXL Mechanism

Note that some limitations listed here are included for completeness but have already been resolved. Please refer to the far right column to see which version may have resolved the issue, and ensure you are using the latest Recommended Jumbo HFA.  If any of these limitations are show-stoppers or you encounter problems, you may need to set your 9400 back to KPPAK mode.  Keep in mind that constantly high CPU utilization on your SND cores is expected behavior in UPPAK mode.

Gaia 4.18 (R82) Immersion Tips, Tricks, & Best Practices Video Course
Now Available at https://shadowpeak.com/gaia4-18-immersion-course
0 Kudos
the_rock
Legend
Legend

As Tim said though, by default it would use user mode.

Andy

0 Kudos
emmap
Employee
Employee

What does fwmode -s show on your 6500s? You should keep USFW on the 9000s, and the config should transfer over like for like, but with any hardware swap it's a good time to review the config and only copy over the stuff that you need. I would 'show configuration' on the old setup and copy/paste in only the stuff that is needed to the new gear.

0 Kudos
Moudar
Advisor

6500 shows:

[Expert@fw02:0]# fwmode -s
Firewall is Kernel mode

so you mean 9400 should never use kernel mode even if 6500 is kernel mode?

I used save configuration and load configuration and I will double check the config again line by line

 

 

0 Kudos
the_rock
Legend
Legend

From my R82 fw:


[Expert@CP-GW:0]# fwmode -s
Firewall is User mode
[Expert@CP-GW:0]# uname -a
Linux CP-GW 4.18.0-372.9.1cpx86_64 #1 SMP Thu Aug 28 16:01:06 IDT 2025 x86_64 x86_64 x86_64 GNU/Linux
[Expert@CP-GW:0]#

0 Kudos
the_rock
Legend
Legend

You can force it to load the config with below command in clish:

set clienv on-failure continue

save config

Andy

0 Kudos
Lesley
Authority Authority
Authority

  • By default, Quantum Force Appliances (9800, 9700, 9400, 9300, 9200, and 9100) run SecureXL in the User Space (UPPAK) Mode:
    • When the appliance runs the dedicated R81.20 Factory Image.
    • When the appliance runs the R81.20 Jumbo Hotfix Take 54 and higher.
  • Quantum Force Appliances in a Standalone deployment (9800, 9700, 9400, 9300, 9200, and 9100) run SecureXL in Kernel Mode (KPPAK).

How to change:

https://sc1.checkpoint.com/documents/Appliances/100G_Ports_AdminGuide/Content/Topics-100G-Card-AG/Se...

 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events