# User Space Firewall (USFW) support on Security Gateways

## Solution

**Table of Contents:**

- Introduction
- Motivation
- Security Gateways and the USFW state
- Best Practices
- Changing the CoreXL Firewall Mode
- Known Limitations
- Firewall USFW / KSFW modes and SecureXL KPPAK / UPPAK modes

### Introduction

User Space Firewall (USFW) is the infrastructure in which Check Point Firewall instances run in user space mode.

**Important:**

- In versions R82.10 and higher, the Firewall runs only in the User Space Firewall mode (USFW). The Kernel Space Firewall mode (KSFW) does not exist anymore.
- In VSX Gateways, USFW is the only Firewall mode available.

### Motivation

- Improved memory utilization on Security Gateways with many CPU cores.
- Improved debugging tools and newly supported features.

### Security Gateways and the USFW state

- Starting in [Check Point R82](https://support.checkpoint.com/results/sk/sk181127), USFW is enabled by default on all Check Point Appliances, Virtual Machines, and Open Servers.
- In versions R82.10 and higher,  KSFW mode is not supported.
- In versions R81.20-R82, you can switch between USFW and KSFW.

### Best Practices

> In versions R82 and lower, use the factors listed below to select the best CoreXL Firewall mode for your Security Gateway - User Space (USFW) or Kernel Space (KSFW):
>
>|     |     |     |
>| --- | --- | --- |
>| Factor | Testing command | Recommended<br>Firewall<br>mode |
>| 80% or more of the traffic undergoes the Fast / Accelerated path | `fwaccel stats -s` | KSFW |
>| 70% or more of the traffic undergoes the Firewall / Slow path | `fwaccel stats -s` | KSFW |
>| 30% or more of the traffic undergoes the PXL / Medium path | `fwaccel stats -s` | **USFW** |
>| Security Gateway is configured with more CoreXL SND instances than CoreXL Firewall instances,<br>or when CoreXL SND instances are the bottleneck | `fw ctl affinity -l -r` | KSFW |
>| Security Gateway is configured with more than 38 CoreXL Firewall instances | `fw ctl affinity -l -r` | **USFW** |
>
> For information about traffic paths, refer to [sk153832 - ATRG: SecureXL for R80.20 and higher](https://support.checkpoint.com/results/sk/sk153832#TOC02) \> section "SecureXL Definitions".

### Changing the CoreXL Firewall Mode in versions R82 and lower

> - To change the Firewall mode in versions R81.10 and higher:
>
>   |     |     |
>   | --- | --- |
>   | Procedure | Instructions |
>   | Recommended | 1. Connect to the command line on the Security Gateway / each Cluster Member.<br>  2. Run: <br>     <br>     `cpconfig`<br>  3. Enter the number of the **Check Point CoreXL** option.<br>  4. Enter **3** to select **Change firewall mode**.<br>  5. Follow the instructions on the screen.<br>  6. Exit from the `cpconfig` menu.<br>  7. Reboot.<br>     <br>     In a cluster, this can cause a failover. |
>   | Optional | 1. Connect to the command line on the Security Gateway / each Cluster Member.<br>  2. Log in to the Expert mode.<br>  3. See the available CLI options: <br>     <br>     `fwmode -h`<br>  4. Run the applicable command:<br>     <br>     `fwmode <option>`<br>  5. Reboot.<br>     <br>     In a cluster, this can cause a failover. |
>
> - To change the Firewall mode in versions R81, R80.40, and R80.30, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/).

### Known Limitations

> |     |     |     |     |
> | --- | --- | --- | --- |
> | Known Limitations | Description | Affected versions | Mitigation |
> | Large Scale VPN (LSV) | Large Scale VPN suffers from latency that results in disconnections of VPN clients | R80.40<br>and<br>R80.30 3.10 | For R80.40:<br>Use the latest R80.40 Jumbo Hotfix<br>If the issue persists, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/)<br>For R80.30 3.10:<br>[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) |
> | Cannot change the Firewall mode from USFW to KSFW on a Security Gateways:<br>- With fewer than 40 CPU cores<br>- With HyperThreading enabled | A crash occurs during boot after you changed the Firewall mode from USFW to KSFW and rebooted, while the HyperThreading is enabled | R80.30 3.10 | Disable Hyper Threading before changing the mode from USFW to KSFW |
> | Cannot change the Firewall mode from USFW to KSFW on Security Gateways:<br>- With more than 40 CPU cores<br>- With HyperThreading disabled | A crash occurs during boot after you changed the Firewall mode from USFW to KSFW and rebooted, while the HyperThreading is disabled | R80.40<br>and<br>R80.30 3.10 | Changing the Firewall mode is not supported in this scenario |
> | CloudGuard Network Security Gateways do not support USFW in versions R81 and lower. |  | R81<br>and<br>R80.40<br>and<br>R80.30 3.10 | USFW is not supported in this scenario |

### Firewall KSFW / USFW modes and SecureXL KPPAK / UPPAK modes

> For information about SecureXL KPPAK / UPPAK modes, refer to [sk153832 - ATRG: SecureXL for R80.20 and higher](https://support.checkpoint.com/results/sk/sk153832#TOC05) \> section "SecureXL Modes - KPPAK and UPPAK".
>
> **Note:** Starting in [Check Point R82.10](https://support.checkpoint.com/results/sk/sk183506), SecureXL runs only in the User Space mode (UPPAK) on all Check Point Appliances, Virtual Machines, and Open Servers.
>
> |     |     |     |
> | --- | --- | --- |
> |  | SecureXL<br>User Space Mode<br>(UPPAK) | SecureXL<br>Kernel Space Mode <br>(KPPAK) |
> | Firewall User Space Mode (USFW) | Supported | Supported |
> | Firewall Kernel Space Mode (KSFW) | **Not supported** | Supported |

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

Access LevelGeneral

StatusApproved by TAC

Date Created2020-05-24

Last Modified2026-05-20
