sk167052 - User Space Firewall (USFW) support on Security Gateways
User Space Firewall (USFW) support on Security Gateways
Solution
Table of Contents:
- Introduction
- Motivation
- Security Gateways and the USFW state
- Best Practices
- Changing the CoreXL Firewall Mode
- Known Limitations
- Firewall USFW / KSFW modes and SecureXL KPPAK / UPPAK modes
Introduction
User Space Firewall (USFW) is the infrastructure in which Check Point Firewall instances run in user space mode.
Important:
- In versions R82.10 and higher, the Firewall runs only in the User Space Firewall mode (USFW). The Kernel Space Firewall mode (KSFW) does not exist anymore.
- In VSX Gateways, USFW is the only Firewall mode available.
Motivation
- Improved memory utilization on Security Gateways with many CPU cores.
- Improved debugging tools and newly supported features.
Security Gateways and the USFW state
- Starting in Check Point R82, USFW is enabled by default on all Check Point Appliances, Virtual Machines, and Open Servers.
- In versions R82.10 and higher, KSFW mode is not supported.
- In versions R81.20-R82, you can switch between USFW and KSFW.
Best Practices
In versions R82 and lower, use the factors listed below to select the best CoreXL Firewall mode for your Security Gateway - User Space (USFW) or Kernel Space (KSFW):
Factor Testing command Recommended
Firewall
mode80% or more of the traffic undergoes the Fast / Accelerated path fwaccel stats -sKSFW 70% or more of the traffic undergoes the Firewall / Slow path fwaccel stats -sKSFW 30% or more of the traffic undergoes the PXL / Medium path fwaccel stats -sUSFW Security Gateway is configured with more CoreXL SND instances than CoreXL Firewall instances,
or when CoreXL SND instances are the bottleneckfw ctl affinity -l -rKSFW Security Gateway is configured with more than 38 CoreXL Firewall instances fw ctl affinity -l -rUSFW For information about traffic paths, refer to sk153832 - ATRG: SecureXL for R80.20 and higher > section "SecureXL Definitions".
Changing the CoreXL Firewall Mode in versions R82 and lower
To change the Firewall mode in versions R81.10 and higher:
Procedure Instructions Recommended 1. Connect to the command line on the Security Gateway / each Cluster Member.
2. Run:
cpconfig
3. Enter the number of the Check Point CoreXL option.
4. Enter 3 to select Change firewall mode.
5. Follow the instructions on the screen.
6. Exit from thecpconfigmenu.
7. Reboot.
In a cluster, this can cause a failover.Optional 1. Connect to the command line on the Security Gateway / each Cluster Member.
2. Log in to the Expert mode.
3. See the available CLI options:
fwmode -h
4. Run the applicable command:
fwmode <option>
5. Reboot.
In a cluster, this can cause a failover.To change the Firewall mode in versions R81, R80.40, and R80.30, contact Check Point Support.
Known Limitations
Known Limitations Description Affected versions Mitigation Large Scale VPN (LSV) Large Scale VPN suffers from latency that results in disconnections of VPN clients R80.40
and
R80.30 3.10For R80.40:
Use the latest R80.40 Jumbo Hotfix
If the issue persists, contact Check Point Support
For R80.30 3.10:
Contact Check Point SupportCannot change the Firewall mode from USFW to KSFW on a Security Gateways:
- With fewer than 40 CPU cores
- With HyperThreading enabledA crash occurs during boot after you changed the Firewall mode from USFW to KSFW and rebooted, while the HyperThreading is enabled R80.30 3.10 Disable Hyper Threading before changing the mode from USFW to KSFW Cannot change the Firewall mode from USFW to KSFW on Security Gateways:
- With more than 40 CPU cores
- With HyperThreading disabledA crash occurs during boot after you changed the Firewall mode from USFW to KSFW and rebooted, while the HyperThreading is disabled R80.40
and
R80.30 3.10Changing the Firewall mode is not supported in this scenario CloudGuard Network Security Gateways do not support USFW in versions R81 and lower. R81
and
R80.40
and
R80.30 3.10USFW is not supported in this scenario
Firewall KSFW / USFW modes and SecureXL KPPAK / UPPAK modes
For information about SecureXL KPPAK / UPPAK modes, refer to sk153832 - ATRG: SecureXL for R80.20 and higher > section "SecureXL Modes - KPPAK and UPPAK".
Note: Starting in Check Point R82.10, SecureXL runs only in the User Space mode (UPPAK) on all Check Point Appliances, Virtual Machines, and Open Servers.
SecureXL
User Space Mode
(UPPAK)SecureXL
Kernel Space Mode
(KPPAK)Firewall User Space Mode (USFW) Supported Supported Firewall Kernel Space Mode (KSFW) Not supported Supported
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access LevelGeneral
StatusApproved by TAC
Date Created2020-05-24
Last Modified2026-05-20