sk183337 - TCP and UDP traffic over VLAN IDs greater than 2048 does not pass through the Maestro Security Group when SecureXL works in the UPPAK mode

TCP and UDP traffic over VLAN IDs greater than 2048 does not pass through the Maestro Security Group when SecureXL works in the UPPAK mode

Product: Maestro HyperScale Firewall
Version: R81.20, R82.10
OS: Gaia
Last Modified: 2025-05-19

Symptoms

Cause

This issue occurs only in Maestro Security Groups - in both the Gateway mode and VSX mode.

TCP and UDP traffic goes through SecureXL (that is enabled by default). In a Maestro Security Group, due to an issue in handling VLAN traffic, accelerated traffic cannot pass through the Security Group in this scenario:

  1. The affected interfaces are configured with VLAN IDs greater than 2048.
  2. SecureXL works in the UPPAK mode.

ICMP traffic is not affected because it goes through the Slow Path (F2F) and bypasses SecureXL.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2025-04-09
Last Modified: 2025-05-19