> Source: [sk104679](https://support.checkpoint.com/results/sk/sk104679)

# sk104679 - SecureXL Accept Templates are not created when ISP Redundancy is enabled in Primary/Backup mode

| Property | Value |
|----------|-------|
| Solution ID | sk104679 |
| Date Created | 2015-02-10 |
| Last Modified | 2024-11-04 |
| Technical Level | General |

## Symptoms

- * Output of the '`top`' command on Security Gateway shows high CPU utilization by Soft IRQ, although SecureXL is enabled.

* Output of the '`fwaccel stats -s`' command shows that most of the traffic is "F2Fed".

* CPView utility ([sk101878](http://supportcontent.checkpoint.com/solutions?id=sk101878)) shows that most Forwarded traffic falls into these categories ('`I/S`' tab - '`SXL`' menu - '`F2F-Reasons`' menu):

  * TCP conn is F2Fed
  * UDP conn is F2Fed
  * other conn is F2Fed
* Output of the '`fwaccel stat`' command shows that either "Accept Templates" are "enabled", or "disabled" from a very high rule.

* Output of the '`fwaccel templates`' command shows very small number of templates, or none at all.

* SecureXL debug ('`fwaccel dbg -m general + template`') shows:

  ```
  
  get_conn_template: <dir 1, Source_IP:Source_Port -> Dest_IP:Dest_Port IPP 6> cannot be offloaded as template
  ... ... ... 
  cphwd_offload_conn: conn handled by ISP redundancy - cannot offload template!;
  ```

* Disabling the ISP Redundancy resolves the issue - most of the traffic is accelerated.

## Cause

By design, SecureXL Accept Templates are not offloaded to the Secure Gateway when ISP Redundancy is enabled in the Primary/Backup mode.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R80.10](https://support.checkpoint.com/results/sk/sk111841)
* [Jumbo Hotfix Accumulator for R77.30](https://support.checkpoint.com/results/sk/sk106162) starting from Take 15

**This is the improved Security Gateway behavior:**

* SecureXL Accept Templates will be created when ISP Redundancy is enabled in the Primary/Backup mode.
* Connections will be Forwarded to Firewall (F2F) when ISP Redundancy is enabled in the Load Sharing mode.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
