> Source: [sk160352](https://support.checkpoint.com/results/sk/sk160352)

# sk160352 - Traffic drops when SecureXL is enabled on VSX after upgrade to R80.20 / R80.30

| Property | Value |
|----------|-------|
| Solution ID | sk160352 |
| Date Created | 2019-08-14 |
| Last Modified | 2025-05-18 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Traffic starts dropping on VSX when SecureXL is enabled, and starts working again when SecureXL is disabled.
* The impacted traffic goes from a VS through a VR/VSW. The VR/VSW has bond interface which functions as external interface.
* SecureXL debugs (according to sk31404) shows this message:   
  `
  fwmultik_f2p_routing: fw_os_route_retrieve_streaming failed`

## Cause

In R80.20 and above, when SecureXL is enabled the traffic is moved directly from the Virtual system to the external interface of the virtual switch or router and not through the wrp/wrpj interfaces.

When SecureXL is on, If the bond (of the VSW/VR) is missing from the output of '*#fw ctl iflist*' from the VS context (the VS which leads to the VSW/VR), it causes traffic to drop before it can reach the external interface.

Note: When secureXL is off, The traffic goes through different interfaces: wrp and wrpj of the VS and VSW/VR. Hence, even if the bond interface is missing from the output of '#fw ctl iflist' of the problematic VS, the traffic goes smoothly

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) from Take 50
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) from Take 117

<!-- -->

For **other [supported](http://www.checkpoint.com/support-services/support-life-cycle-policy/index.html) versions** , Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

Related Solution: - [sk160333: Traffic drop on R80.20 Security Gateway when SecureXL is enabled](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160333)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
