> Source: [sk180298](https://support.checkpoint.com/results/sk/sk180298)

# sk180298 - "Userspace PPAK was disabled due to repeated crashes" message on a Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk180298 |
| Date Created | 2022-11-21 |
| Last Modified | 2025-04-15 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * The output of the "`fwaccel stat`" command shows:

  1. The word "KPPAK" in the "Name" column (meaning, SecureXL works in the Kernel Space Mode).

  2. This message:

     ```
     
     WARNING: Userspace PPAK was disabled due to repeated crashes.
              Disabled at: &ltDate Time>
              Refer to sk179432 for more information.
     ```

* The message "*Userspace PPAK was disabled due to repeated crashes*" also appears in:

  * On the console during boot
  * In the output of the "`mq_mng -o`" command
  * In the "`cpconfig`" menu in the sub-menu "`Change SecureXL Mode`"

## Cause

On supported Check Point appliances, SecureXL can work in two modes - User Space Mode (UPPAK), and Kernel Space Mode (KPPAK).

When a Security Gateway detects repeated instability in SecureXL while it works in the User Space Mode (SecureXL user space process(es) crashed 3 times during the last 60 minutes), the Security Gateway changes the SecureXL mode from User Space (UPPAK) to Kernel Space (KPPAK).

## Solution

When the UPPAK process crash (**usim_x86)** a core file will be created in /var/log/dump/usermode/

Example:  
/var/log/dump/usermode/usim_x86.77990.core.gz  

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

<br />

Note:  
To change the SecureXL mode from Kernel Space (KPPAK) to User Space (UPPAK):

1. Connect to the command line on your Security Gateway.

2. Log in to Gaia Clish, or Expert mode.

3. Run:

   `cpconfig`
4. Enter the number of the **Check Point SecureXL** option.

5. The menu shows the current SecureXL mode.

6. Enter the number of the **Change SecureXL Mode** option.

7. Enter **y** to confirm the change.

8. Exit from the *cpconfig* menu.

9. Reboot.

10. Examine the SecureXL status and mode:

    `fwaccel stat`

<br />

**Related Documentation:**

* [sk176466 - Check Point LightSpeed Appliances](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk176466)
* [sk179432 - Software Releases for Quantum LightSpeed Appliances QLS250 / QLS450 / QLS650 / QLS800](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk179432)
* [sk180299 - High CPU utilization when SecureXL works in User Space Mode (UPPAK)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk180299)
* [NVIDIA ConnectX 100G QSFP28 2-Port Card Administration Guide](https://sc1.checkpoint.com/documents/Appliances/NVIDIA_ConnectX_QSFP28_100G_AdminGuide/Default.htm)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
