- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I hope someone can help me clarify how it is possible to restart an VS to make changes in fwkern.conf for that VS effective ?
I know it is possible to make changes on the fly, but in this SK it can only understand that it does not work when SecureXL is enabled ?
This is the SK where i want to enable this feature for only one VS: sk19746
Thanks!
@nooni kernel parameters set via „fw ctl set ….“ are set for all VS on a host. You can‘t set these kernel parameters only for one VS.
Regarding your mentioned article How to force a Security Gateway to send a TCP [RST] packet upon TCP connection expiration you can set your needed parameter for a specific system via GUIdbedit tool. If you only need the change from sk19746 this will be a better solution then setting kernel parameters via fwkern.conf.
Ask TAC - the sk19746 does not state that it is valid for VSX at all !
For such changes the machine must be rebooted (for it to be permanent).
In a cluster properly sized for failover scenarios this should be manageable within a maintenance window.
In other situations there is this process:
sk169472: How to restart a specific VSX Virtual System in R80.30 and higher
Hi,
Thanks for the SK. If the VS runs in a high availability setup, for example VSLS.
Will this cpstop/cpstart procedure change the behaviour on the current host the VS resides on ?
If the VS is active on host1 and you do cpstop it will be considered as down and startup at host2 ?
No, you only stop one residing on the physical member you are connected to.
I always do below option now if I have to do this, as it does NOT need cpstop;cpstart or reboot, applies right away and it actually takes care of the file on its own.
Connect to the command line on the Security Gateway / each Cluster Member.
Run this command:
fw ctl set -f int <Name_of_Kernel_Parameter> <Value_of_Kernel_Parameter>
Notes:
Reboot when possible.
https://support.checkpoint.com/results/sk/sk26202
Andy
Hi
Thanks, yes i am aware of that possibility but the SK stated that when using SecureXL a change in fwkern.conf was neccesary.
I never ever had to do that on regular fw, its possible might be different for VSX.
nice to know that there is newer way how to modify fwkern.conf 😄 I am still always updating fwkern.conf manually using vi 😄 Wondering if such a action is even supported (modify the fwkern file by your own) ...
That method works fine, never an issue, sometimes old school way is the best, haha : - )
@nooni kernel parameters set via „fw ctl set ….“ are set for all VS on a host. You can‘t set these kernel parameters only for one VS.
Regarding your mentioned article How to force a Security Gateway to send a TCP [RST] packet upon TCP connection expiration you can set your needed parameter for a specific system via GUIdbedit tool. If you only need the change from sk19746 this will be a better solution then setting kernel parameters via fwkern.conf.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 23 | |
| 15 | |
| 14 | |
| 12 | |
| 10 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY