- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
We recently upgraded from R80.40 to R81 and are still experiencing some issues. Here's our environment information:
- Cluster of two 5800 appliances running VSX
- A total of 10 vs systems
- Upgrade from R80.40 old kernel to R81 new kernel (3.10). Had to run a fresh install, vsx util upgrade, vsx util reconfigure
After upgrade was completed over the weekend, noticed on Monday internet traffic gradually slowing down until it totally stopped. After thorough analysis with the checkpoint professional services, we disabled securexl on the vs handling traffic out to the internet and that fixed the problem. Tried enabling securexl after increasing ws_max_sessions_per_conn and ws_max_timestamped_sessions_per_conn params but still experienced the same problem. Also noticed we are not able to run the cipher_util command. It comes back with a "Cannot access features configuration directory" message.
Without securexl on we are experiencing higher than usual cpu usage than normal on our perimeter web traffic gateway and cannot enable disable ciphers not being able to issue the ciphers_util command.
Summary:
- Can't run acceleration on web gateway traffic which hinders cpu usage
- Can't run ciphers_util command
I have created tickets with the TAC for each of these problems.
Want to know if anyone has experience similar issues.
Thanks!
Just curious...whats is CPU % difference when you have sxl on/off? Is it really significant?
It used to be 30-35 % during high use times before. Now we hit 90% during high usage times. Almost constantly over 50%.
That sounds pretty serious to me. What did TAC suggest so far?
No suggestions so far. Re-creating environment on their lab. Will most likely escalate the securexl issue.
Good idea.
issue has been resolved ? we are also planning to upgrade VSX from R80.40 to R81, bit worried after i seeing this post.
Issue has not been resolved yet. TAC is working on a fix for us and was supposed to be ready by past Thursday Sept 30th but haven't heard back from them. Will contact today to find out and get a status update.
Hello Carlos ,
We are not familiar with this issue , I will appreciate it if you share the SR # (you can also in PM).
SR#6-0002981704
Just so you know, the new(er) kernel was in R80.40 also.
TAC is definitely going to have to dig into the issue with SecureXL.
looks like still R81 is not recommended for VSX 🙄
Where precisely are you seeing a declaration that R81 is NOT recommended for VSX?
It's not clear, on the surface anyway, the issue in this thread has anything to do with VSX.
yes his environment similar to our setup and don't want to take any unnecessary risk related to production traffic.
TAC was supposed to deliver a fix last Thursday and they're still working on the fix. I'm also having issues with memory. VSX running web perimeter gateway handling https inspection and the one consuming the most CPU cycles have run out of memory twice now. Monitoring memory now. If it runs out of memory again will have to open another case with TAC for this memory issue.
please let us know the progress of the SR.
TAC produced a fix on 10/7/2021. I installed it early 10/8/2021 and so far it has fixed all issues. Currently running securexl with no problems reported thus far.
thanks for the update
Do we know if this will be integrated into the next R81 and R81.10 Jumbos? If so when?
Hi @genisis__ ,
Yes the fix will be part of next Jumbo release of both versions, i will update the thread once it will be released.
The ETA is very depend on testing cycles etc... so i can't give accurate estimation at the moment.
Thanks,
Ilya
thanks, hopefully it will be out soon.
Hi, should we can get a fix from TAC before the next GA of R81 Take XX ?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
18 | |
10 | |
6 | |
6 | |
6 | |
6 | |
6 | |
4 | |
3 | |
3 |
Tue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY