Background:
-
Using SecureXL Templates for NAT traffic is critical to achieve high session rate for NAT.
-
SecureXL Templates are supported for Static NAT and Hide NAT using the existing SecureXL Templates mechanism.
-
SecureXL NAT Templates are supported in cluster in High Availability / VRRP, and Load Sharing modes.
-
SecureXL Templates are supported by VSX Virtual Systems.
-
SecureXL NAT Templates feature in SecureXL is disabled by default on Check Point Security Gateway R80.10 and below. All template handling in versions R80.20 and above has moved to the Firewall, and is not relevant to SecureXL .
-
SecureXL implements NAT Templates only once these templates are offloaded by FireWall kernel.
Procedure:
SecureXL NAT Templates feature is controlled via the following global kernel parameters:
Kernel Parameter |
Accepted values |
Description |
cphwd_nat_templates_support |
|
Indicates whether the SecureXL device should support NAT templates:
- 0 = SecureXL device should not support NAT templates (default)
- 1 = SecureXL device should support NAT templates
|
cphwd_nat_templates_enabled |
|
Enables / disables the NAT templates feature
- 0 = Disables the NAT templates feature (default)
- 1 = Enables the NAT templates feature
|
Relevant in R76SP.x versions: |
cphwd_nat_templates_user_force |
|
Indicates whether the SecureXL device will enforce NAT templates:
- 0 = NAT templates will be enabled automatically (distribution dependent)
- 1 = Force SecureXL Nat templates enablement
- 2 = Force SecureXL NAT templates disablement
|
Important Note: The only officially supported way to enable / disable the SecureXL NAT templates is by setting the relevant kernel parameters in $FWDIR/boot/modules/fwkern.conf
file. Enabling / disabling the SecureXL NAT templates on-the-fly with 'fw ctl set int
' command is NOT supported.
Configuration steps:
Note: In cluster environment, this procedure must be performed on all members of the cluster.
Limitations:
- There are factors that disable SecureXL Templates.
Refer to sk32578 - SecureXL Mechanism - section "Connection establishment acceleration ("templates" mechanism)".
Related documentation:
- Performance Pack Administration Guide (R75.40, R75.40VS).
- Performance Tuning Administration Guide (R76, R77).
Related solutions:
Applies To: