> Source: [sk184356](https://support.checkpoint.com/results/sk/sk184356)

# sk184356 - Firewall Drop Optimization in R82.10 and higher

| Property | Value |
|----------|-------|
| Solution ID | sk184356 |
| Date Created | 2025-11-20 |
| Last Modified | 2025-12-29 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10 |
| OS | Gaia |

## Solution

Note - For the R81.20 and R82 versions, see [sk175006](https://support.checkpoint.com/results/sk/sk175006).

**Table of Contents:**

* Introduction
* Limitations
* Enabling Firewall Drop Templates
* CLI Commands
* Kernel Parameters
* Common Issues
* Kernel Debug

### Introduction {#TOC01}

If you configure explicit rules in an Access Control policy with the Action "Drop", then Firewall updates SecureXL (by offloading Firewall Drop Templates) about each new connection that it dropped based on these rules. SecureXL drops all subsequent packets in these and similar connections (from the same Source IP address to the same Destination IP address, to the same Destination Port, over the same Protocol). This way, Security Gateway does not spend its resources to match packets of such connections.

R82.10 introduces the redesigned Drop Optimization feature for Access Control policy. The new design supports more acceleration use cases (such as Security Zones, Access Roles, Time) and offloads the traffic to ASIC-powered network cards.

Note - In R82.10, the Drop Templates feature is part of the Firewall kernel (the "VM" chain).

### Limitations {#TOC02}

* The Security Gateway cannot offload drop templates for all rules starting from the first rule that in the column "Services and Applications" contains a service of type "Other Service" in which a "Match" expression is configured.
* The Security Gateway cannot offload a drop template for a rule that in the column "Services and Applications" contains one of these services: traceroute, DHCP services.

### Enabling Firewall Drop Templates {#TOC03}

By default, this feature is disabled.

1. From the left navigation panel, click **Gateways \& Servers**.
2. Double-click the Security Gateway / Cluster object.
3. In the left panel, click **Optimizations**.
4. In the **Firewall Policy Optimization** section, select **Enable drop optimization**.
5. Click **OK**.
6. Install the Access Control Policy.

### CLI Commands {#TOC04}

Use the commands below on the Security Gateway to see the applicable information about Firewall Drop Templates.

|-----------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Command                                       | Description                                                                                                                                                                                                                                       |
| `fw templates`                                | Recommended command. Shows existing Firewall Drop Templates in the global kernel table.                                                                                                                                                           |
| `fwaccel templates -c`                        | Alternative command. Shows existing Firewall Drop Templates in the global kernel table.                                                                                                                                                           |
| `fw tab -t fw_generic_mode_drop_templates -u` | Prints the global kernel table with drop templates.                                                                                                                                                                                               |
| `fwaccel stat`                                | Shows if any Access Control rules are preventing the offloading of drop templates from the Firewall to SecureXL. This output helps identify Access Control rules that contain services with match expressions that disable template optimization. |
| `cpview`                                      | Shows comprehensive statistics for Drop Templates: Network \> Templates \> Drop-Templates See [sk101878](https://support.checkpoint.com/results/sk/sk101878).                                                                                     |

### Kernel Parameters {#TOC05}

The table below describes kernel parameters on the Security Gateway that control the Drop Optimization feature.

For procedures about working with kernel parameters, see the *Security Gateway Administration Guide* for your version.

**Important** - Do not change these values unless Check Point Support explicitly tells you to do so.

|---------------------------------------------------------|---------------|---------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Kernel Parameter                                        | Default Value | Valid Values  | Description                                                                                                                                                                                                                                                                                                                                                                                                                |
| `fw_generic_mode_drop_templates_enabled`                | 1             | 0, 1          | Enables (1) and disables (0) the Generic Mode Drop Templates.                                                                                                                                                                                                                                                                                                                                                              |
| `fw_generic_mode_drop_templates_expire_time`            | 3             | 0 - (2^32^-1) | Specifies the entry expiration time (in seconds) in the kernel table that holds Drop Templates. 1. When the Security Gateway drops the first packet of a connection, it offloads the Drop Template. 2. During this expiration time, the Security Gateway continues to drop packets of this connection. 3. After this time expires, the Drop Template expires, and the Security Gateway performs full rulebase match again. |
| `fw_generic_mode_drop_templates_keep`                   | 1             | 0, 1          | Specifies whether to keep (1) or delete (0) all existing Drop Templates during the policy installation. Important - Do not change this value unless explicitly instructed by Check Point Support.                                                                                                                                                                                                                          |
| `fw_generic_mode_drop_templates_table_limit_size`       | 0             | 0 - (2^32^-1) | Specifies the size of the global kernel table that holds Drop Templates. 0 = unlimited.                                                                                                                                                                                                                                                                                                                                    |
| `fw_generic_mode_drop_templates_table_hashsize`         | 0             | 0 - (2^32^-1) | Specifies the size of the auto-calculated hash. Important: * 0 = automatically calculated. * Do not change this value unless explicitly instructed by Check Point Support. * The higher this value, the more memory is used.                                                                                                                                                                                               |
| `fw_generic_mode_drop_templates_stats_expire_time`      | 300           | 0 - (2^32^-1) | Specifies the entry expiration time (in seconds) in the global kernel table with statistics (for tools such as CPView, Skyline)                                                                                                                                                                                                                                                                                            |
| `fw_generic_mode_drop_templates_stats_table_limit_size` | 25000         | 0 - (2^32^-1) | Specifies the size of the global kernel table with statistics. Important: * Do not change this value unless explicitly instructed by Check Point Support. * The higher this value, the more memory is used.                                                                                                                                                                                                                |
| `fw_generic_mode_drop_templates_stats_table_hashsize`   | 512           | 0 - (2^32^-1) | Specifies the size of the kernel table with statistics hash. Important: * Do not change this value unless explicitly instructed by Check Point Support. * The higher this value, the more memory is used.                                                                                                                                                                                                                  |

### Common Issues {#TOC06}

|---|-------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| # | Issue                                     | Description                                                                                                                                                                                                                                                                                                                                                                                                          |
| 1 | Drop Templates are not being created      | Symptoms: The expected drop template is not found in the global kernel table. Possible Causes: * The connection matches a service or a rule with specific restrictions (e.g., traceroute, DHCP). * Memory allocation failure during template creation. Next Steps: Check if the connection matches any restrictive services or rules. Ensure the Security Gateway has enough available memory for template creation. |
| 2 | Traffic is not matched to a Drop Template | Symptoms: Traffic that should be dropped is not being matched by the existing Drop Template. Possible Causes: * Drop Template expired. * Connection parameters do not match exactly. Next Steps: 1. Check template expiration settings. Verify the connection parameters against the expected template parameters.                                                                                                   |
| 3 | Memory Issues                             | Symptoms: Memory allocation failures, high memory usage. Possible Causes: * Excessive memory consumption by other processes. * Memory leaks in software. * Insufficient RAM. Next Steps: 1. Optimize or restart processes that consume memory at an excessive level. 2. Install more RAM.                                                                                                                            |

### Kernel Debug {#TOC07}

For complete explanations about the kernel debug procedure, see the *Security Gateway Administration Guide* for your version.

1. `fw ctl debug 0`
2. `fw ctl debug -buf 8200`
3. `fw ctl debug -m UP + sec_rb probtrc info`
4. `fw ctl debug -m fw + conn vm log drop drop_tmpl`
5. `fw ctl kdebug -T -f >& /var/log/debug.txt &`
6. Replicate the issue - pass the traffic that explicit rules must drop
7. `fw ctl debug 0`
8. Examine the output file `/var/log/debug.txt`

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
