sk183181 - SecureXL in the User Mode (UPPAK) may have compatibility issues with R81.20 Jumbo Hotfix Take 96 and Take 98

SecureXL in the User Mode (UPPAK) may have compatibility issues with R81.20 Jumbo Hotfix Take 96 and Take 98

Product: SecureXL
Version: R81.20
OS: Gaia
Last Modified: 2025-06-23

Symptoms

Cause

Race condition may occur in the ADP acceleration driver when updating network routes for SecureXL in the User Mode (UPPAK) - see sk153832 section "(5) SecureXL Modes - KPPAK and UPPAK".

Affected versions:

How to check if your Security Gateway may be affected?

  1. Connect to the command line on the Security Gateway.

  2. Check the current R81.20 Jumbo Hotfix Accumulator Take:

    cpinfo -y all

  3. Check the current SecureXL mode:

    1. Run:

      fwaccel stat

    2. Examine the column "Name":

      • "KPPAK" means Kernel Mode - this SK article does not apply.
      • "UPPAK" means User Mode - this SK article applies.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions: Refer to sk168597 - How to install a Hotfix.

In case the Jumbo Hotfix Accumulator does not resolve the issue: Contact Check Point Support to get an additional Hotfix.

Workaround

This workaround is also available:

Configure the SecureXL to work in the Kernel Space (KPPAK) mode.

Important Note: Switching SecureXL to the Kernel Space (KPPAK) mode is not a recommended long-term solution. While it can serve as a temporary workaround, Check Point's official recommendation is to run SecureXL in the User Space (UPPAK) mode. If UPPAK is unstable, some customers have been advised to temporarily switch to KPPAK, but only if they are not using Lightspeed. Once UPPAK stability is ensured, customers should revert to UPPAK for optimal performance and compatibility.

Article Properties

Access Level: General
Status: Approved
Date Created: 2025-02-25
Last Modified: 2025-06-23