sk167052 - User Space Firewall (USFW) support on Security Gateways

User Space Firewall (USFW) support on Security Gateways

Solution

Table of Contents:

Introduction

User Space Firewall (USFW) is the infrastructure in which Check Point Firewall instances run in user space mode.

Important:

Motivation

Security Gateways and the USFW state

Best Practices

In versions R82 and lower, use the factors listed below to select the best CoreXL Firewall mode for your Security Gateway - User Space (USFW) or Kernel Space (KSFW):

Factor Testing command Recommended
Firewall
mode
80% or more of the traffic undergoes the Fast / Accelerated path fwaccel stats -s KSFW
70% or more of the traffic undergoes the Firewall / Slow path fwaccel stats -s KSFW
30% or more of the traffic undergoes the PXL / Medium path fwaccel stats -s USFW
Security Gateway is configured with more CoreXL SND instances than CoreXL Firewall instances,
or when CoreXL SND instances are the bottleneck
fw ctl affinity -l -r KSFW
Security Gateway is configured with more than 38 CoreXL Firewall instances fw ctl affinity -l -r USFW

For information about traffic paths, refer to sk153832 - ATRG: SecureXL for R80.20 and higher > section "SecureXL Definitions".

Changing the CoreXL Firewall Mode in versions R82 and lower

Known Limitations

Known Limitations Description Affected versions Mitigation
Large Scale VPN (LSV) Large Scale VPN suffers from latency that results in disconnections of VPN clients R80.40
and
R80.30 3.10
For R80.40:
Use the latest R80.40 Jumbo Hotfix
If the issue persists, contact Check Point Support
For R80.30 3.10:
Contact Check Point Support
Cannot change the Firewall mode from USFW to KSFW on a Security Gateways:
- With fewer than 40 CPU cores
- With HyperThreading enabled
A crash occurs during boot after you changed the Firewall mode from USFW to KSFW and rebooted, while the HyperThreading is enabled R80.30 3.10 Disable Hyper Threading before changing the mode from USFW to KSFW
Cannot change the Firewall mode from USFW to KSFW on Security Gateways:
- With more than 40 CPU cores
- With HyperThreading disabled
A crash occurs during boot after you changed the Firewall mode from USFW to KSFW and rebooted, while the HyperThreading is disabled R80.40
and
R80.30 3.10
Changing the Firewall mode is not supported in this scenario
CloudGuard Network Security Gateways do not support USFW in versions R81 and lower. R81
and
R80.40
and
R80.30 3.10
USFW is not supported in this scenario

Firewall KSFW / USFW modes and SecureXL KPPAK / UPPAK modes

For information about SecureXL KPPAK / UPPAK modes, refer to sk153832 - ATRG: SecureXL for R80.20 and higher > section "SecureXL Modes - KPPAK and UPPAK".

Note: Starting in Check Point R82.10, SecureXL runs only in the User Space mode (UPPAK) on all Check Point Appliances, Virtual Machines, and Open Servers.

SecureXL
User Space Mode
(UPPAK)
SecureXL
Kernel Space Mode
(KPPAK)
Firewall User Space Mode (USFW) Supported Supported
Firewall Kernel Space Mode (KSFW) Not supported Supported

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access LevelGeneral

StatusApproved by TAC

Date Created2020-05-24

Last Modified2026-05-20