sk183181 - SecureXL in the User Mode (UPPAK) may have compatibility issues with R81.20 Jumbo Hotfix Take 96 and Take 98
SecureXL in the User Mode (UPPAK) may have compatibility issues with R81.20 Jumbo Hotfix Take 96 and Take 98
Product: SecureXL
Version: R81.20
OS: Gaia
Last Modified: 2025-06-23
Symptoms
- Security Gateway with the R81.20 Jumbo Hotfix Accumulator Takes 96 and Take 98 may crash frequently when SecureXL works in the User Mode (UPPAK).
Cause
Race condition may occur in the ADP acceleration driver when updating network routes for SecureXL in the User Mode (UPPAK) - see sk153832 section "(5) SecureXL Modes - KPPAK and UPPAK".
- In Take 96, the process
usim_x86crashes with a core dump file in the/var/log/dump/usermode/directory. - In Take 98, the Security Gateway crashes with a VMcore dump file in the
/var/log/crash/<DATE>/vmcore/directory.
Affected versions:
- R81.20 Jumbo Hotfix Accumulator Take 96
- R81.20 Jumbo Hotfix Accumulator Take 98
How to check if your Security Gateway may be affected?
Connect to the command line on the Security Gateway.
Check the current R81.20 Jumbo Hotfix Accumulator Take:
cpinfo -y allCheck the current SecureXL mode:
Run:
fwaccel statExamine the column "Name":
- "KPPAK" means Kernel Mode - this SK article does not apply.
- "UPPAK" means User Mode - this SK article applies.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 14
- Jumbo Hotfix Accumulator for R81.20 starting from Take 99
- Jumbo Hotfix Accumulator for R81.10 starting from Take 177
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions: Refer to sk168597 - How to install a Hotfix.
In case the Jumbo Hotfix Accumulator does not resolve the issue: Contact Check Point Support to get an additional Hotfix.
Workaround
This workaround is also available:
Configure the SecureXL to work in the Kernel Space (KPPAK) mode.
Important Note: Switching SecureXL to the Kernel Space (KPPAK) mode is not a recommended long-term solution. While it can serve as a temporary workaround, Check Point's official recommendation is to run SecureXL in the User Space (UPPAK) mode. If UPPAK is unstable, some customers have been advised to temporarily switch to KPPAK, but only if they are not using Lightspeed. Once UPPAK stability is ensured, customers should revert to UPPAK for optimal performance and compatibility.
Article Properties
Access Level: General
Status: Approved
Date Created: 2025-02-25
Last Modified: 2025-06-23