> Source: [sk180557](https://support.checkpoint.com/results/sk/sk180557)

# sk180557 - Automatic Onboarding of Security Gateways to Infinity Portal - Release Updates

| Property | Value |
|----------|-------|
| Solution ID | sk180557 |
| Date Created | 2024-03-25 |
| Last Modified | 2026-03-18 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, R82.10, R81.20, R82 |
| OS | Gaia |

## Solution

**Introduction \| Availability \| Manual Installation \| Requirements \| Configuration Wizard \| Manual Uninstall of Nano Agents
Automatic Offboarding \| Configuration Wizard \| List of Resolved Issues**

Introduction {#Introduction}
----------------------------

The **Gateways Connector** feature allows administrators to configure automatic onboarding of Security Gateways to Infinity Portal as agents, eliminating the need for manual one-by-one connections.

Connecting Security Gateways to the Infinity Portal as agents provides centralized enforcement of security policies configured in Check Point Cloud applications such as SD-WAN, Infinity Identity, IoT, and more.

**Upon installing Take 50, Gateways Connector will be automatically disabled by default to ensure no gateways connect to the Infinity Portal without the administrator's explicit enablement.**   
**An audit log entry indicating this change may appear as:** `"WEB_API modified the object of type GatewaysOnboardSettings".`

Availability {#Availability}
----------------------------

> |----------|---------|--------------|--------------------------------------------------------------------------------------------------------------------------|
> | Update # | Take    | Release Date | Package                                                                                                                  |
> | 4        | Take 59 | 15 Mar 2026  | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/142140) (TAR) |

The Gateways Connector package is installed automatically if the Management Server is connected to the Internet and Automatic Update downloads are enabled (see [sk175504](https://support.checkpoint.com/results/sk/sk175504), section 2-B).

If Automatic Updates are disabled, you must first manually install the latest [AutoUpdater](https://support.checkpoint.com/results/sk/sk165653) Take and then install the Gateways Connector package manually using the steps below.

Manual Installation (Offline) {#Manual Installation}
----------------------------------------------------

Show / Hide this Section   
**To install the package manually**

1. Download the offline package.
2. Copy the offline package (*.tar* file) to your Management Server to some directory (for example, `/var/log/`).
3. Connect to the command line on your Management Server.
4. Log in to the Expert mode.
5. Run this command:  
   `autoupdatercli install <full path of the .tar file>`

<br />

**To check if the package is installed and which Take is installed**

1. Connect to the command line on your Management Server.
2. Log in to the Expert mode.
3. Run this command:  
   `autoupdatercli show json | jq -r '.products[] | select(.["product-components"] | type == "array") | .["product-components"][] | select(.["component-branch"] == "Gws_Onboard_AutoUpdate") | .["repository-packages"] | if type == "array" then .[] | select(.["package-installed"] == true or .["package-installed"] == "true") | .["package-version"] else empty end'`
   * If the *"Gws_Onboard_AutoUpdate"* package is installed, the output will show the installed Take. For example, Take 50.
   * If the *"Gws_Onboard_AutoUpdate"* package is not installed, there will be no output.

Requirements {#Requirements}
----------------------------

|---------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Product**                                                         | **Requirements**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Security Management Server, Multi-Domain Security Management Server | 1. Jumbo Hotfix Accumulator: * [R82 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm), Take 25 or higher * [R81.20 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm), Take 101 or higher 2. AutoUpdate Packages: * [Web SmartConsole](https://support.checkpoint.com/results/sk/sk170314), Take 142 or higher * "Gws_Onboard_AutoUpdate", Take 50 or higher (see "Availability")                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Security Gateway, Cluster, Maestro Security Group                   | **Immediate onboarding** * Supported: * Security Gateways R81.20 and higher * Not supported: * Maestro Security Groups R81.20 * Security Gateways of these types (that do not support the Management API call "`run-script`"): * VSX Gateways. * Quantum Spark Gateways. * Security Gateways with Dynamically Assigned IP (DAIP). * Security Gateways behind NAT. * Security Gateways managed with SmartProvisioning (SmartLSM).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Security Gateway, Cluster, Maestro Security Group                   | **Onboarding after subsequent policy installation** * Supported Versions: * R81.20 Jumbo Hotfix Accumulator Take 26 or higher (for the EU, US, AU, and IN regions) * Quantum Spark R81.10.05 and higher * Not Supported: * VSX Security Gateways running R81.20 * Maestro Security Groups running R81.20 **Note** - If the Management Server manages only VSX Gateways and Maestro Security Groups that are running the R81.20 Jumbo Hotfix Accumulator Take 99 (or higher), then you can enable the onboarding in this way: 1. Connect to the command line on the Management Server. 2. Create the following empty text files: * To onboard all VSX Gateways: `touch $MDS_FWDIR/conf/enable_81_20_vsx_onboarding.txt` * To onboard all Maestro Security Groups: `touch $MDS_FWDIR/conf/enable_81_20_maestro_onboarding.txt` 3. In SmartConsole, install the Access Control policy for the type of Security Gateways you want to onboard. |

Configuration Wizard {#Configuration Wizard}
--------------------------------------------

When connecting an on-premises Management Server to the Infinity Portal, these configuration options are available to control how the Security Gateways connect to the Infinity Portal:

1. **Connect your Security Gateways to Infinity Portal**

   Enables or disables the overall connection between Security Gateways and the Infinity Portal.
   * "**OFF**" (Default) - No connection is initiated. Security Gateways do not initiate automatic connection to the Infinity Portal.
   * "**ON**" - The selected Security Gateways establish a secure connection to the Infinity Portal.

   **Note** - On a Security Management Server (single Domain Management Server), enabling the Gateways Connector feature will automatically and immediately install the Nano Agent on the Security Management Server, in addition to the selected Security Gateways.  
   This behavior does not apply in Multi-Domain Security Management environments, where the Nano Agent is installed only on the Security Gateways, not on the Security Management Server.
2. **Select Security Gateways to connect**

   Specifies which Security Gateways initiate a connection to the Infinity Portal.

   **Best practice:** Include all relevant Security Gateways in this list, including those that were previously connected manually. If a Security Gateway is already connected, adding it here does not trigger any changes or duplicate actions.
   * "**All**" (Default) - All supported Security Gateways managed by the Security Management Server are connected to the Infinity Portal.
   * "**Specific**" - Only the selected Security Gateways establish the connection.
3. **Establish connection to Security Gateways**

   Determines when the selected Security Gateways should attempt the connection to the Infinity Portal. See the supported versions in the "Requirements" section.
   * "**Immediately**" (Default) - The Security Gateways attempt to establish a connection with the Infinity Portal immediately and during every subsequent policy installation.
   * "**After the policy installation**" - The Security Gateways attempt to establish a connection with the Infinity Portal only after the next policy installation.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180557/Screenshot202507141938241.png)

Manual Uninstall of Nano Agents {#Manual Uninstall}
---------------------------------------------------

If a Security Gateway is removed from the list of participating Security Gateways, or if the Gateways Connector feature is disabled, **previously connected Nano Agents are not uninstalled automatically**.

In such cases, to disconnect the Security Gateway from the Infinity Portal, you must manually uninstall the Nano Agent by running the "`cpnano -u`" command in the Expert mode on the relevant Security Gateway.

**Important Note** - If the Nano Agent is removed manually **without removing** the selection of the Security Gateway from the list of participating Security Gateways in the Gateways Connector configuration, the connection to the Infinity Portal is re-established based on the configured connection timing (either immediately or after the next policy installation). To disconnect the Security Gateway completely, make sure to remove it from the Gateways Connector list of participating Security Gateways **before** uninstalling the Nano Agent.

Automatic Offboarding of Security Gateways {#Automatic Offboarding}
-------------------------------------------------------------------

After disconnecting the Management Server from the Infinity Portal, as part of the disconnection process, its corresponding Quantum Profile is removed, and the Gateways Connector initiates the uninstall of Nano Agents from the Security Gateways.

This leads to the automatic offboarding of all Security Gateways from the Infinity Portal.

Note that the offboarding process does not occur instantly, it is triggered under specific conditions and completed only after a subsequent policy installation.

**Conditions for Automatic Offboarding**

Automatic disconnection of Security Gateways from the Infinity Portal occurs only when all these conditions are met:

1. The on-premises Security Management Server is disconnected from the Infinity Portal.
2. Gateways Connector is enabled at the time of the Security Management disconnection.
3. Policy installation is performed after the disconnection event.

**Behavior of Security Gateways**

* Once the Management Server is disconnected from the Infinity Portal, and the Security Policy is installed, all previously connected Security Gateways that installed the new policy are automatically offboarded from the Infinity Portal.
* Until the policy installation occurs, the connected Security Gateways remain in their current state and continue to communicate with the Infinity Portal.

**Behavior of Infinity Services during the process of disconnecting Security Gateways**

Each Infinity Service behaves differently during the disconnection process.

|-------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------|
| **Service Name**  | **Step 1: Communication Lost with Infinity Cloud**                                                                                                                                                                                                                     | **Step 2: Agents Uninstalled (After Policy Installation)**                                         |
| SD-WAN            | * SD-WAN continues to function using the last configuration fetched from Infinity Cloud. Status: Functioning                                                                                                                                                           | * SD-WAN is no longer applied. Status: Not functioning                                             |
| IoT               | * Discovery: New device updates stop, but existing discovery data remains * Enforcement: New policy updates stop, but current IoT policy continues to be enforced * Configurations: New profile updates stop, but current configurations remain active                 | * Discovery: Stops completely * Enforcement: Continues with current policy unless manually removed |
| AIOps             | * Stops receiving live data from monitored assets                                                                                                                                                                                                                      | * Same as Step 1                                                                                   |
| Infinity Identity | * Acquired identities (from Infinity Identity to Identity Awareness) behave per [sk181613](https://support.checkpoint.com/results/sk/sk181613) (deleted after 10 minutes or deleted upon expiration, depending on configuration) * New identities are no longer shared | * Same as Step 1                                                                                   |

List of Resolved Issues and New Features per Automatic Onboarding of Security Gateways to Infinity Portal Update {#List of Resolved Issues}
-------------------------------------------------------------------------------------------------------------------------------------------

|----------|--------------------------------------------------------------------------------------------------|
| ID       | Description                                                                                      |
| **Update 4 - Take 59 - Gradual deployment from 15 Mar 2026**                                               ||
| ODU-3859 | Enhancement: Added support for the Canada region.                                                |
| ODU-3859 | Enhancement: Added IPv6 support on Security Management Servers.                                  |
| ODU-3859 | During a Security Management Server upgrade, the Gateways Connector feature is getting disabled. |
| **Update 3 - Take 56 (10 Nov 2025)**                                                                       ||
| ODU-3103 | Enhancement: Added support for the UAE region and fixed several minor issues.                    |
| **Update 2 - Take 50 (27 May 2025)**                                                                       ||
| ODU-2387 | Enhancement: Enhanced configuration options.                                                     |
| **Update 1 - Take 41 (15 Sep 2024)**                                                                       ||
| ODU-1827 | Initial Release.                                                                                 |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
