SecureXL Debug Modules and Debug Flags
To see the available SecureXL Check Point product on a Security Gateway that accelerates IPv4 and IPv6 traffic that passes through a Security Gateway. debug modules and their debug flags, run the fwaccel dbg command.

Flag |
Description |
---|---|
|
Connection accounting information |
|
Anticipated connections |
|
Configuration of the SecureXL (for example, interfaces) |
|
Processing of connections |
|
Processing of connections |
|
Correction layer |
|
Currently not in use |
|
Deletion of connections |
|
Driver information |
|
Hash table |
|
Allocating IDs for a given range in Identity Awareness |
|
Initialization |
|
Changes in the configuration, which were initiated from the user space |
|
Connection table iterator |
|
Driver information |
|
Lock initializing and finalizing |
|
Processing of NAT connections |
|
Offloading of connections from the Firewall to the SecureXL |
|
Connections queue |
|
Related connections (such as FTP data connections) |
|
Handling of SecureXL ranges |
|
Printing of SecureXL ranges |
|
Handling of SecureXL routing |
|
Handling of SecureXL statistics |
|
Registering templates or connections for System Counters in Security Gateway |
|
Tags that were added to the packets by the SecureXL before forwarding |
|
Verification of sequence in TCP packets |
|
Updates of connections |
|
Utilization |

Flag |
Description |
---|---|
|
Connection accounting information |
|
BHM Statistics for each CPU |
|
|
|
Correction layer |
|
ClusterXL |
|
Packet delivery |
|
Packets dropped by SecureXL |
|
Reason for forwarding a packet to the Firewall |
|
Processing of fragments |
|
Processing of Generic Network Virtualization Encapsulation (Geneve) packets in GRE and VxLAN interfaces |
|
Processing of NAT connections |
|
Notifications sent to the Firewall |
|
Processing of packets |
|
PXL (PacketXL) handling - API between the SecureXL and |
|
|
|
Handling of SecureXL routing |
|
Handling of Stream Control Transmission Protocol (SCTP) packets |
|
Handling of SecureXL Anti-Spoofing |
|
Validation of sequence in TCP packets |
|
Validation of TCP state in TCP packets |
|
Validation of TCP packets |
|
Details of a packet |
|
Handling of VLAN tags |
|

Flag |
Description |
---|---|
|
Anticipated connections |
|
Deleting of data from the SecureXL database |
|
Retrieving of data from the SecureXL database |
|
Initializing and finalizing of SecureXL database |
|
"No Match Ranges" templates, which allow SecureXL Accept Templates for rules that contain Dynamic objects or Domain objects (or for rules located below such rules) |
|
"No Match Time" templates, which allow SecureXL Accept Templates for rules that contain Time objects (or for rules located below such rules) |
|
Operations on profile table |
|
Saving of data to the SecureXL database |
|
Handling of timeouts for SecureXL database entries |
|
Handling of SecureXL templates database |
|
General failures to process a packet |

Flag |
Description |
---|---|
|
Connection accounting information |
|
Adding of connections |
|
Offloading of VPN SA to SecureXL |
|
Configuration of the SecureXL (for example, interfaces) |
|
Deletion of connections |
|
Deletion of all VPN SAs from SecureXL |
|
Deletion of the SecureXL Templates |
|
Deletion of VPN SA from SecureXL |
|
Getting features buffer (in SecureXL initialization) |
|
Retrieving of SecureXL statistics |
|
Getting the connection state from SecureXL |
|
Some extra printouts when processing SecureXL tables |
|
Processing of GPRS Tunnelling Protocol (GTP) tunnel connections |
|
SecureXL infrastructure |
|
Enabling and disabling of SecureXL |
|
Prints additional verbose information about connections |
|
Prints additional information about SecureXL internals |
|
Notifications sent to the Firewall |
|
PXL (PacketXL) handling - API between the SecureXL and PSL (Packet Streaming Layer), which is a TCP Streaming engine that parses TCP streams |
|
QoS acceleration |
|
Prints statistics IDs that are reset |
|
Handling of SecureXL statistics |
|
Validation of sequence in TCP packets |
|
Tags that were added to the packets by the SecureXL before forwarding them to the Firewall |
|
Handling of SecureXL Templates |
|
Information about SecureXL Templates |
|
Update of SecureXL in ClusterXL Load Sharing |
|
Prints some text that shows if SecureXL updated information about interfaces |
|
|
|
Updates of connections |
|
Processing of VPN connection |

Flag |
Description |
---|---|
|
Prints additional information |
|
Information about Bond interfaces |
|
Information about packet processing in the backplane |
|
Information about packet processing in the backplane |
|
Currently is not used |
|
Information about packet drops in the backplane |
|
Information about ports from the NVIDIA ConnectX 100G Card's point of view |
|
Information about packet processing in the network interface |
|
Information about ports from the Host Security Appliance's point of view |
|
Information about packet processing in the NVIDIA ConnectX 100G Card |
|
Offloading of connections from the Host Security Appliance to the SecureXL |
|
Information about interfaces |
|
Information about slots and ports |
|
Information about slots in the Host Security Appliance |
|
Information about packet processing in the backplane |
|
Information about packet processing in the backplane |
|
Handling of multicast traffic |
|
Handling of next hop routing |
|
Information about packet processing in the NVIDIA ConnectX 100G Card |
|
Information about communication queues |
|
Information about packets in the communication queues |
|
Handling of general routing |
|
Detailed information about packet processing in the NVIDIA ConnectX 100G Card |
|
Handling of WRP interfaces in VSX |
|
Events in the known neighbors database |

Flag |
Description |
---|---|
|
Pattern Matcher |
|
Reordering of packets in queue |

Flag |
Description |
---|---|
|
Updating, adding, deleting of identities |
|
Updating, fetching, searching of identities |
|
|
|
Changes in the configuration, which were initiated from the user space |
|
Network Access Control |
|
Offloading of connections from the Firewall to the SecureXL |
|
Forwarding of connections to Firewall (when identity is not found or revoked, or NAC |
|
NAC packet-tagging verification |
|
Signing of packets |

Flag |
Description |
---|---|
|
VPN Link Selection |
|
Forwarding of packets between Cluster |
|
VPN Encryption routing information |
|
Processing of VPN connections |
|
Processing of VPN packets |

Flag |
Description |
---|---|
|
Processing of broadcast packets |
|
Information about queue buffers |
|
Information about queue clients |
|
General errors |
|
Information about expiration of queue items |
|
Initializing of queue |
|
Currently not in use |
|
Information about queue servers |
|
Information about sending messages in queue |
|
Additional information about sending messages in queue |

Flag |
Description |
---|---|
|
Currently not in use |
|
Detailed information about DoS Rate Limiting configuration. Important - This debug flag is not suitable for large traffic volumes because it prints a large number of messages. This causes high load on the CPU. |
|
Detailed information about DoS Rate Limiting packet flow. Important - This debug flag is not suitable for large traffic volumes because it prints a large number of messages. This causes high load on the CPU. |
|
Dropped packets |
|
Information about DoS Rate Limiting configuration in the Firewall kernel module |
|
Information about DoS Rate Limiting packet flow in the Firewall kernel module |
|
Information about DoS Rate Limiting configuration in the SecureXL kernel module |
|
Information about DoS Rate Limiting packet flow in the SecureXL kernel module |

Flag |
Description |
---|---|
|
Receiving and updating of Accelerated SYN Defender module's configuration |
|
Handling of TCP connections |
|
Initializing of the Accelerated SYN Defender module |
|
Prints time of the last sent monitor log and interval between the monitor logs |
|
Information about internal messages in the Accelerated SYN Defender module |
|
Handling of TCP packets |
|
Currently not in use |
|
Information about states of the Accelerated SYN Defender module |

Flag |
Description |
---|---|
|
Getting of Drop Templates |
|
Notifications about Drop Templates |
|
Information about Drop Templates |

Flag |
Description |
---|---|
|
Information about GTP tunnels in kernel tables |
|
Drops of GTP packets |
|
General information about APN and kernel tables |
|
Information about notification messages |
|
Processing of GTP packets |
|
APN information |
|
Operations in kernel tables |

Flag |
Description |
---|---|
|
Currently not in use |
|
Currently not in use |
|
Currently not in use |
|
Processing of connections |
|
Currently not in use |
|
Currently not in use |
|
General errors |
|
Currently not in use |
|
Currently not in use |
|
IOCTL control messages (communication between kernel and user space processes) |
|
Currently not in use |
|
Currently not in use |
|
Processing of packets |
|
Processing of packets |
|
Currently not in use |
|
Currently not in use |
|
Currently not in use |
|
Currently not in use |
|
Currently not in use |
|
Shows the selected CoreXL |
|
Currently not in use |
|
Currently not in use |

Reserved for future use.

Reserved for future use.

Reserved for future use.