Configuring SecureXL
The Gaia First Time Configuration Wizard automatically installs, enables, and configures SecureXL on your Security Gateway. No additional configuration is required.
SecureXL can work in these modes:
|
Note - For the required Jumbo Hotfix Accumulator, see sk179432. |
SecureXL Mode |
Description |
---|---|
User Mode (UPPAK) |
On the supported Check Point Appliances (see Introduction), SecureXL runs as processes in the user space (UPPAK - "User Space Performance Pack"). This mode increases performance and unlocks more advanced features in SecureXL. UPPAK is the default mode after you install the required Jumbo Hotfix Accumulator (unless you enabled features that do not support SecureXL UPPAK - see Known Limitations). |
Kernel Mode (KPPAK) |
SecureXL runs as a kernel module in the kernel space (KPPAK - "Kernel Space Performance Pack"). |
SecureXL in Kernel Mode (KPPAK)
SecureXL runs as a kernel module in the kernel space (KPPAK - "Kernel Space Performance Pack").

SecureXL kernel modules:
SecureXL in Kernel Mode uses these kernel modules:
-
$PPKDIR/boot/modules/sim_kern_64_3_10_64.o
-
$PPKDIR/boot/modules/sim_kern_64_3_10_64_v6.o
SecureXL configuration file:
SecureXL in Kernel Mode uses this configuration file for its parameters:
-
$PPKDIR/conf/simkern.conf
SecureXL in User Mode (UPPAK)
SecureXL runs as processes in the user space (UPPAK - "User Space Performance Pack").

Limitations when SecureXL works in User Mode (UPPAK):
See Known Limitations > Section SecureXL.
SecureXL user space processes:
SecureXL in User Mode uses these processes and log files:
Process |
Log File |
Description |
---|---|---|
|
|
The main SecureXL process. |
|
N / A |
The Watch Dog process that monitors the main SecureXL process " If the main process crashes, this Watch Dog process starts it again. |
|
N / A |
Starts the main SecureXL process " |
SecureXL configuration file:
SecureXL in User Mode uses this configuration file for its parameters:
-
$PPKDIR/conf/simkern.conf
SecureXL core dump files:
SecureXL in User Mode creates these files when its user space processes crash:
-
/var/log/dump/usermode/usim_x86.<PID>.core
-
/var/log/dump/usermode/lcore-worker<ID>.core
-
/var/log/dump/usermode/fwk_snd<ID>.core
-
/var/log/usim_crash/crash_list
Viewing the Current SecureXL Mode

Step |
Instructions |
|
---|---|---|
1 |
Connect to the command line on your Security Gateway. |
|
2 |
Log in to Gaia Clish, or Expert mode. |
|
3 |
Examine the SecureXL status and mode.
|
|
4 |
Examine the column Name:
|
For information about the "fwaccel
" command, see the Performance Tuning Administration Guide for your version.
Example output:
Changing the Current SecureXL Mode
You can change the current SecureXL mode between User Mode (UPPAK) and Kernel Mode (KPPAK).
It is possible to enable the SecureXL User Mode (UPPAK) only if the Security Gateway does not run features that do not support SecureXL UPPAK. See Known Limitations.
When SecureXL works in User Mode (UPPAK), it does not allow you to enable features that UPPAK does not support.

Step |
Instructions |
||
---|---|---|---|
1 |
Connect to the command line on your Security Gateway / each Cluster Member. |
||
2 |
Log in to Gaia Clish, or Expert mode. |
||
3 |
Run:
|
||
4 |
Enter the number of the Check Point SecureXL option. |
||
5 |
The menu shows the current SecureXL mode. |
||
6 |
Enter the number of the Change SecureXL Mode option. |
||
7 |
Enter y to confirm the change. |
||
8 |
Exit from the |
||
9 |
Reboot.
|
||
10 |
Examine the SecureXL status and mode:
|
For information about the "fwaccel
" command, see the Performance Tuning Administration Guide for your version.
Disabling SecureXL
It is not supported to disable SecureXL. You can disable SecureXL only if Check Point Support explicitly instructs you to do so for debug purposes. |

Starting from R80.20, you can disable the SecureXL only temporarily.
The SecureXL starts automatically when you start Check Point services (with the cpstart
command), or reboot the Security Gateway (Scalable Platform Security Group Member).
|
Important:
|
For information about the "fwaccel
" command, see the Performance Tuning Administration Guide for your version.

Step |
Instructions |
|
---|---|---|
1 |
Connect to the command line on your Security Gateway. |
|
2 |
Log in to Gaia Clish, or Expert mode. |
|
3 |
Examine the SecureXL status.
|
|
4 |
Disable the SecureXL.
|
|
5 |
Examine the SecureXL status.
|

Step |
Instructions |
|
---|---|---|
1 |
Connect to the command line on your Security Gateway. |
|
2 |
Log in to Gaia Clish, or Expert mode. |
|
3 |
Examine the SecureXL status.
|
|
4 |
Disable the SecureXL.
|
|
5 |
Examine the SecureXL status.
|

Step |
Instructions |
|
---|---|---|
1 |
Connect to the command line on your Security Gateway. |
|
2 |
Log in to Gaia Clish, or Expert mode. |
|
3 |
Examine the SecureXL status.
|
|
4 |
Enable the SecureXL.
|
|
5 |
Examine the SecureXL status.
|

Step |
Instructions |
|
---|---|---|
1 |
Connect to the command line on your Security Gateway. |
|
2 |
Log in to Gaia Clish, or Expert mode. |
|
3 |
Examine the SecureXL status.
|
|
4 |
Enable the SecureXL.
|
|
5 |
Examine the SecureXL status.
|
SecureXL KPPAK / UPPAK Modes and Firewall KSFW / USFW Modes
For information about Firewall modes, refer to sk167052.
Firewall Mode |
SecureXL User Mode (UPPAK) |
SecureXL Kernel Mode (KPPAK) |
---|---|---|
Firewall User Mode (USFW) |
Supported |
Supported |
Firewall Kernel Mode (KSFW) |
Not supported |
Supported |