- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all 🙂
When the policy is installed in GW, the following message is generated in GW /var/log/messages.
kernel: [fw4_0];[ERROR]: up_fw_load_taditional_vpn_inspect_func_ids: failed to get inspect function CLIENT_ENCRYPT_SCV_W_SRVC_FUNC id0 x0a
kernel: [fw4_0];[ERROR]: up_fw_load_taditional_vpn_inspect_func_ids: failed to get inspect function IPPOOLS_ENCRYPT_WITH_SRVC_FUNC id0 x0a
kernel: [fw4_0];[ERROR]: up_fw_load_taditional_vpn_inspect_func_ids: failed to get inspect function ENCRYPT_WITH_SERVICE_FUNC id0x0a
kernel: [fw4_0];[ERROR]: up_fw_load_taditional_vpn_inspect_func_ids: failed to get inspect function RECORD_CONN_WITH_SCV_FUNC id0x0a
kernel: [fw4_0];[ERROR]: up_fw_load_taditional_vpn_inspect_func_ids: failed to get inspect function CLIENT_ENCRYPT_FUNC id0x0a
kernel: [fw4_0];[ERROR]: up_fw_load_taditional_vpn_inspect_func_ids: failed to get inspect function ENCRYPTION_FUNC id0x0a
kernel: [fw4_0];[ERROR]: up_fw_load_taditional_vpn_inspect_func_ids: failed to get inspect function IPPOOLS_ENCRYPTION_FUNC id0x0a
If you look at the above message, it looks like it is related to VPN, but
My customer is using GW blades only as 'Firewall'.
Do not use 'IPSec VPN' blades.
Has anyone seen messages like the above or know why they are generated?
Thank You.
These are related to Remote Access, I believe.
I assume you are also not using Mobile Access blade?
I see you've already opened a TAC case, which is what I would have suggested next.
As I wrote above, the blade is only using 'FireWall'.
As you said, I open a case to TAC and wait for an answer.
The OS version is R80.40, and the hotfix take is 94.
Looks to me like your policy package is set to use VPN "Traditional Mode" instead of the newer "Simplified Mode" introduced in R52 (even though the syslog messages have a typo in them). Under Manage Policies & Layers do you have this checkbox set:
Also check this Global Properties screen:
Timothy_Hall As you say
It is set to Traditional mode.
If you're certain this policy does not contain any VPN rules (with action Encrypt) then you can change the policy to Simplified Mode using the procedure in: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
That said, the time to convert to Simplified Mode is long overdue.
Simplified mode was introduced in NG FP2 (aka R52) and was formally deprecated in R8x.
I assume we will remove support for this feature entirely in an upcoming version.
Thanks to everyone who posted replies.
After activating vpn traditonal mode, I tested in my lab whether symptoms replicated, but the symptoms were not replicated.
I think you should check the TAC answer as well.
thanks.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 20 | |
| 16 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY