> Source: [sk179512](https://support.checkpoint.com/results/sk/sk179512)

# sk179512 - VPN Configuration Engine (VCE) Release Updates

| Property | Value |
|----------|-------|
| Solution ID | sk179512 |
| Date Created | 2022-08-18 |
| Last Modified | 2026-03-19 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Solution

Show the Entire Article

**Introduction \| Manual Installation \| Availability \| Documentation \| List of Resolved Issues \| Known Limitations**

Introduction {#Introduction}
----------------------------

One-Click Site to Site VPN provides automatic configuration of a Site to Site VPN environment between Check Point solutions and supported peers.  

This feature has two capabilities:  

1. **One-Click Site to Site VPN with Public Cloud (R81.20 and higher)**   
   This capability automates configuration of a Site to Site VPN with pre-configured (third party) native cloud Gateways that reside in the cloud. It enables integration between Check Point solutions and public cloud platforms and is currently supported by three vendors: AWS (Amazon Web Services), Azure, and GCP (Google Cloud Platform).
2. **One-Click Site to Site VPN between Check Point solutions (R82.10 and higher)**   
   This capability automates configuration of a Site to Site VPN between two on-premises Security Gateways, including the ability to configure BGP automatically between the peers.

The VPN Configuration Engine (VCE) is an automated process that runs on Security Management Servers and Multi-Domain Management Servers deployed on-premises and is used to perform the automated configuration for both capabilities of the feature.  

The VCE package is installed automatically on all relevant Check Point devices when Automatic Update downloads are enabled (see [sk175504](https://support.checkpoint.com/results/sk/sk175504), section 2-B). A Jumbo Hotfix Accumulator is **not**required.

If Automatic Updates are disabled, you must first manually install the latest [AutoUpdater](https://support.checkpoint.com/results/sk/sk165653) Take and then install the VCE package manually using the steps below.

**Note:**

* The package is automatically installed on a Security Management Server / Multi-Domain Security Management Server R81.20 and higher.
* The feature supports on-premises Security Gateways R81.20 and higher.

Manual Installation (Offline) {#Manual Installation}
----------------------------------------------------

### Instructions:

1. Download the offline package to your computer. See the "Availability" section.

2. Copy the offline package from your computer to your Check Point device to some directory (for example, */var/log/*).

3. Connect to the command line on your Check Point device.

4. Log in to the Expert mode.

5. Go to the directory with the offline package.

6. Install the offline package:

   * On a Security Gateway / each Cluster Member / Management Server / Log Server:

     `autoupdatercli install <Name of Offline Package>.tar`
   * On a Scalable Platform Security Group (Maestro / Chassis):

     `g_all autoupdatercli install <Name of Offline Package>.tar`

**Note** : The installation does not require **`cpstop; cpstart`** or a reboot. Once installed, no further action is required, the update will be applied immediately.

Availability {#Availability}
----------------------------

<br />

|-------------|----------|------------------|--------------------------------------------------------------------------------------------------------------------|
| **Version** | **Take** | **Release Date** | **Download**                                                                                                       |
| ### R82.10  | Take 27  | 01 Mar 2026      | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/141654) |
| ### R82     | Take 6   | 01 Mar 2026      | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/141561) |
| ### R81.20  | Take 47  | 01 Mar 2026      | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/141560) |

Documentation {#Documentation}
------------------------------

* See the [Site to Site VPN Administration Guide](https://support.checkpoint.com/product/446) for your version

List of Resolved Issues and New Features per VCE Update {#List of resolved issues}
----------------------------------------------------------------------------------

### R82.10 Release

Show / Hide this section  
>
> |-------------|----------------------------------------------------------------------------------------------------------------------|
> | ID          | Description                                                                                                          |
> | **Take 27 - Gradual deployment from 01 Mar 2026**                                                                                 ||
> | PMTR-122863 | In VSX environments, two Virtual Systems of the same VSX Gateway may not be added to the same Route-Based community. |

### R82 Release

Show / Hide this section  
>
> |----------|------------------------------------------------------------------------------------------------------|
> | ID       | Description                                                                                          |
> | **Take 6 - Gradual deployment from 01 Mar 2026**                                                               ||
> | AAD-8083 | Enhancement: Added support for Diffie-Hellman groups: 15,16,17 in AWS, 14 in Azure and 15,21 in GCP. |

### R81.20 Release

Show / Hide this section  
>
> |----------|---------------------------------------------------------------------------------------------------|
> | ID       | Description                                                                                       |
> | **Take 47 - Gradual deployment from 01 Mar 2026**                                                           ||
> | AAD-8082 | Enhancement: Added support for Diffie-Hellman groups: 15,16,17 in AWS, 14 in Azure and 15 in GCP. |

Known Limitations {#Known Limitations}
--------------------------------------

|----|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID | Description                                                                                                                                                                         |
| -  | VPN Configuration Engine (VCE) is not supported in Domain-based VPN solutions.                                                                                                      |
| -  | Access ("Read" permissions) to the relevant Cloud Server via CloudGuard Controller is mandatory. * Applied only to One-Click Site to Site VPN with Public Cloud (R81.20 and higher) |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
