> Source: [sk184815](https://support.checkpoint.com/results/sk/sk184815)

# sk184815 - Kernel log flooding with "cphwd_create_template: cphwd_set_seczone_out_ifn failed" when Security Zones and NAT are combined

| Property | Value |
|----------|-------|
| Solution ID | sk184815 |
| Date Created | 2026-06-25 |
| Last Modified | 2026-07-01 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20 |

## Symptoms

- * Continuous kernel log entries (log flooding), for example in *$FWDIR/log/fwk.elg* or in */var/log/messages* :  
  `cphwd_create_template: cphwd_set_seczone_out_ifn failed`.

* In some environments, SecureXL connection templates are not created for the affected traffic flows.

## Cause

This behavior can occur when all of these conditions are true:

1. The traffic matches an Access Control rule that is located below a rule that uses a **Security Zone** object.
2. A NAT rule uses **Security Zones** in its decision.

In this scenario, during SecureXL template creation for some connections, the gateway may not yet have the required outgoing NAT interface value available. As a result, the gateway can treat the template-creation state as an error for the affected flows.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
