> Source: [sk167052](https://support.checkpoint.com/results/sk/sk167052)

# sk167052 - User Space Firewall (USFW) support on Security Gateways

| Property | Value |
|----------|-------|
| Solution ID | sk167052 |
| Date Created | 2020-05-24 |
| Last Modified | 2026-05-20 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

**Table of Contents:**

* Introduction
* Motivation
* Security Gateways and the USFW state
* Best Practices
* Changing the CoreXL Firewall Mode
* Known Limitations
* Firewall USFW / KSFW modes and SecureXL KPPAK / UPPAK modes

<br />

### Introduction {#TOC01}

User Space Firewall (USFW) is the infrastructure in which Check Point Firewall instances run in user space mode.

**Important:**

* In versions R82.10 and higher, the Firewall runs only in the User Space Firewall mode (USFW). The Kernel Space Firewall mode (KSFW) does not exist anymore.
* In VSX Gateways, USFW is the only Firewall mode available.

<br />

### Motivation {#TOC02}

* Improved memory utilization on Security Gateways with many CPU cores.
* Improved debugging tools and newly supported features.

<br />

### Security Gateways and the USFW state {#TOC03}

* Starting in [Check Point R82](https://support.checkpoint.com/results/sk/sk181127), USFW is enabled by default on all Check Point Appliances, Virtual Machines, and Open Servers.
* In versions R82.10 and higher, KSFW mode is not supported.
* In versions R81.20-R82, you can switch between USFW and KSFW.  

<br />

### Best Practices {#TOC04}

> In versions R82 and lower, use the factors listed below to select the best CoreXL Firewall mode for your Security Gateway - User Space (USFW) or Kernel Space (KSFW):
>
> |-----------------------------------------------------------------------------------------------------------------------------------------------|-------------------------|---------------------------|
> | Factor                                                                                                                                        | Testing command         | Recommended Firewall mode |
> | 80% or more of the traffic undergoes the Fast / Accelerated path                                                                              | `fwaccel stats -s`      | KSFW                      |
> | 70% or more of the traffic undergoes the Firewall / Slow path                                                                                 | `fwaccel stats -s`      | KSFW                      |
> | 30% or more of the traffic undergoes the PXL / Medium path                                                                                    | `fwaccel stats -s`      | **USFW**                  |
> | Security Gateway is configured with more CoreXL SND instances than CoreXL Firewall instances, or when CoreXL SND instances are the bottleneck | `fw ctl affinity -l -r` | KSFW                      |
> | Security Gateway is configured with more than 38 CoreXL Firewall instances                                                                    | `fw ctl affinity -l -r` | **USFW**                  |
>
> For information about traffic paths, refer to [sk153832 - ATRG: SecureXL for R80.20 and higher](https://support.checkpoint.com/results/sk/sk153832#TOC02) \> section "SecureXL Definitions".

<br />

### Changing the CoreXL Firewall Mode in versions R82 and lower {#TOC05}

> * To change the Firewall mode in versions R81.10 and higher:
>
>   |-------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
>   | Procedure   | Instructions                                                                                                                                                                                                                                                                                                                                  |
>   | Recommended | 1. Connect to the command line on the Security Gateway / each Cluster Member. 2. Run: `cpconfig` 3. Enter the number of the **Check Point CoreXL** option. 4. Enter **3** to select **Change firewall mode**. 5. Follow the instructions on the screen. 6. Exit from the `cpconfig` menu. 7. Reboot. In a cluster, this can cause a failover. |
>   | Optional    | 1. Connect to the command line on the Security Gateway / each Cluster Member. 2. Log in to the Expert mode. 3. See the available CLI options: `fwmode -h` 4. Run the applicable command: `fwmode <`*option*`>` 5. Reboot. In a cluster, this can cause a failover.                                                                            |
>
> * To change the Firewall mode in versions R81, R80.40, and R80.30, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/).

<br />

### Known Limitations {#TOC06}

> |----------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------|--------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | Known Limitations                                                                                                                      | Description                                                                                                                         | Affected versions              | Mitigation                                                                                                                                                                                                                                                                     |
> | Large Scale VPN (LSV)                                                                                                                  | Large Scale VPN suffers from latency that results in disconnections of VPN clients                                                  | R80.40 and R80.30 3.10         | For R80.40: Use the latest R80.40 Jumbo Hotfix If the issue persists, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) For R80.30 3.10: [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) |
> | Cannot change the Firewall mode from USFW to KSFW on a Security Gateways: * With fewer than 40 CPU cores * With HyperThreading enabled | A crash occurs during boot after you changed the Firewall mode from USFW to KSFW and rebooted, while the HyperThreading is enabled  | R80.30 3.10                    | Disable Hyper Threading before changing the mode from USFW to KSFW                                                                                                                                                                                                             |
> | Cannot change the Firewall mode from USFW to KSFW on Security Gateways: * With more than 40 CPU cores * With HyperThreading disabled   | A crash occurs during boot after you changed the Firewall mode from USFW to KSFW and rebooted, while the HyperThreading is disabled | R80.40 and R80.30 3.10         | Changing the Firewall mode is not supported in this scenario                                                                                                                                                                                                                   |
> | CloudGuard Network Security Gateways do not support USFW in versions R81 and lower.                                                    |                                                                                                                                     | R81 and R80.40 and R80.30 3.10 | USFW is not supported in this scenario                                                                                                                                                                                                                                         |

<br />

### Firewall KSFW / USFW modes and SecureXL KPPAK / UPPAK modes {#TOC07}

> For information about SecureXL KPPAK / UPPAK modes, refer to [sk153832 - ATRG: SecureXL for R80.20 and higher](https://support.checkpoint.com/results/sk/sk153832#TOC05) \> section "SecureXL Modes - KPPAK and UPPAK".  
>
> **Note:** Starting in [Check Point R82.10](https://support.checkpoint.com/results/sk/sk183506), SecureXL runs only in the User Space mode (UPPAK) on all Check Point Appliances, Virtual Machines, and Open Servers.
>
> |-----------------------------------|----------------------------------|------------------------------------|
> |                                   | SecureXL User Space Mode (UPPAK) | SecureXL Kernel Space Mode (KPPAK) |
> | Firewall User Space Mode (USFW)   | Supported                        | Supported                          |
> | Firewall Kernel Space Mode (KSFW) | **Not supported**                | Supported                          |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
