> Source: [sk181433](https://support.checkpoint.com/results/sk/sk181433)

# sk181433 - Supported Security Appliance Models and Line Cards for the Maestro Solution

| Property | Value |
|----------|-------|
| Solution ID | sk181433 |
| Date Created | 2023-08-30 |
| Last Modified | 2025-04-25 |
| Technical Level | General |
| Products | Scalable Platforms |
| Versions | R82.20, R82.10, R82, R81.20 |
| OS | Gaia |
| Platform | 15000, 5000, 7000, 28000, 9000, LightSpeed QLS, LightSpeed MLS, 16000, 26000, 19000, 29000, 6000 |

## Solution

Below is a list of appliances officially approved for use with the Maestro solution.

### Important Notes

* For supported network cards, refer to the [Appliance Accessories Guide](https://www.checkpoint.com/downloads/products/check-point-appliance-accessory-guide.pdf).
* For the minimum software requirements for Line Cards, see the Home Page article for your appliance model. You can find the links in [sk96246](https://support.checkpoint.com/results/sk/sk96246).
* For information about Line Cards, see the [Installing and Removing Line Cards in Check Point Appliances](https://sc1.checkpoint.com/documents/Appliances/FRU_Line_Cards/Default.htm).
* **For mandatory guidelines for connecting the Downlinks to Maestro Security Appliances, refer to [sk158652: Configuration of Downlinks for Maestro Appliances](https://support.checkpoint.com/results/sk/sk158652).**
* For a list of supported transceivers, refer to [sk92755: Compatibility of transceivers for Check Point appliances](https://support.checkpoint.com/results/sk/sk92755).
* Although you cannot order Dual-Port 10 Gbps cards (marked with the asterisk "*" in the table below) as a separate option, these cards are supported if purchased in a "Gateway" bundle.
* **For all other appliance models that are not listed below, submit an RFE as described in [sk71840](https://support.checkpoint.com/results/sk/sk71840).**
* For supported combinations of different appliance models in the same Maestro Security Group, refer to [sk162373: Quantum Maestro supported combinations of mix-and-match appliances](https://support.checkpoint.com/results/sk/sk162373).

### Supported Security Appliance Models and Line Cards for Maestro

**Important** - To connect to Quantum Maestro Orchestrators, you must use the same Line Card ports on all appliances in the same Security Group (on each Maestro Site). See [sk158652](https://support.checkpoint.com/results/sk/sk158652).

Enter the string to filter this table:

|-----------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Model                             | Supported Versions                                                                                                                                                                                                                                    | Supported Cards                                                                                                                                     | Special Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **Quantum Force 19000 and 29000** | * [sk180520](https://support.checkpoint.com/results/sk/sk180520)                                                                                                                                                                                      | * CPAC-2-40/100F-D (2-Port Single-Width 40/100G QSFP28 Card) * CPAC-4-10/25F-D * CPAC-8-1/10F-D                                                     | <br />                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **LightSpeed QLS and MLS**        | * [sk176466](https://support.checkpoint.com/results/sk/sk176466)                                                                                                                                                                                      | * CPAC-2-40/100F-C (2-Port Dual-Width 10/25/40/100G QSFP28+ Card)                                                                                   | * To connect to Quantum Maestro Orchestrators, you must use **only** the 100G Ports. * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance.                                                                                                                                                                                                                                                                                                                                                                                     |
| **28600HS**                       | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363)                                                             | * Not applicable                                                                                                                                    | 28600HS appliance has two fixed 40G/100G downlink ports. Refer to the [appliance datasheet](https://www.checkpoint.com/downloads/products/28000-security-gateway-datasheet.pdf) for details.                                                                                                                                                                                                                                                                                                                                                                            |
| **28000**                         | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-C\* * CPAC-4-10F-C * CPAC-2-40F-C * CPAC-2-100/25F * CPAC-2-40/100F-C ([sk181064](https://support.checkpoint.com/results/sk/sk181064)) | Base and Plus models. For CPAC-2-100/25F: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance. * The minimum required card firmware version is 12.22.1002 To get the card firmware version, run this single long command in the Expert mode on the Security Appliance: `for NIC in $(ifconfig | grep ethsBP | awk '{print $1}') ; do echo $NIC: ; ethtool -i $NIC | grep firmware ; done` For CPAC-2-40/100F-C: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance.                |
| **26000**                         | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-C\* * CPAC-4-10F-C * CPAC-2-40F-C * CPAC-2-100/25F * CPAC-2-40/100F-C ([sk181064](https://support.checkpoint.com/results/sk/sk181064)) | Base, Plus, and Turbo models. For CPAC-2-100/25F: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance. * The minimum required card firmware version is 12.22.1002 To get the card firmware version, run this single long command in the Expert mode on the Security Appliance: `for NIC in $(ifconfig | grep ethsBP | awk '{print $1}') ; do echo $NIC: ; ethtool -i $NIC | grep firmware ; done` For CPAC-2-40/100F-C: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance.        |
| **23900**                         | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-B\* * CPAC-4-10F-B * CPAC-2-40F-B * CPAC-2-100/25F                                                                                     | For CPAC-4-10F-B: * Output of the "`lspci -v`" command must show: `Intel Corporation 82599ES 10-Gigabit SFI/SFP+ Network Connection` For CPAC-2-40F-B and for CPAC-2-100/25F: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance. * The minimum required card firmware version is 12.22.1002 To get the card firmware version, run this single long command in the Expert mode on the Security Appliance: `for NIC in $(ifconfig | grep ethsBP | awk '{print $1}') ; do echo $NIC: ; ethtool -i $NIC | grep firmware ; done` |
| **23800**                         | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-B\* * CPAC-4-10F-B * CPAC-2-40F-B * CPAC-2-100/25F                                                                                     | For CPAC-4-10F-B: * Output of the "`lspci -v`" command must show: `Intel Corporation 82599ES 10-Gigabit SFI/SFP+ Network Connection` For CPAC-2-40F-B and for CPAC-2-100/25F: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance. * The minimum required card firmware version is 12.22.1002 To get the card firmware version, run this single long command in the Expert mode on the Security Appliance: `for NIC in $(ifconfig | grep ethsBP | awk '{print $1}') ; do echo $NIC: ; ethtool -i $NIC | grep firmware ; done` |
| **23500**                         | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-B\* * CPAC-4-10F-B * CPAC-2-40F-B * CPAC-2-100/25F                                                                                     | For CPAC-4-10F-B: * Output of the "`lspci -v`" command must show: `Intel Corporation 82599ES 10-Gigabit SFI/SFP+ Network Connection` For CPAC-2-40F-B and for CPAC-2-100/25F: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance. * The minimum required card firmware version is 12.22.1002 To get the card firmware version, run this single long command in the Expert mode on the Security Appliance: `for NIC in $(ifconfig | grep ethsBP | awk '{print $1}') ; do echo $NIC: ; ethtool -i $NIC | grep firmware ; done` |
| **16600HS**                       | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * Not applicable                                                                                                                                    | 16600HS appliance has two fixed 40G/100G downlink ports. Refer to the [appliance datasheet](https://www.checkpoint.com/downloads/products/16000-security-gateway-datasheet.pdf) for details.                                                                                                                                                                                                                                                                                                                                                                            |
| **16200**                         | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-C\* * CPAC-4-10F-C * CPAC-2-40F-C * CPAC-2-100/25F * CPAC-2-40/100F-C ([sk181064](https://support.checkpoint.com/results/sk/sk181064)) | Base and Plus models. For CPAC-2-100/25F: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance. * The minimum required card firmware version is 12.22.1002 To get the card firmware version, run this single long command in the Expert mode on the Security Appliance: `for NIC in $(ifconfig | grep ethsBP | awk '{print $1}') ; do echo $NIC: ; ethtool -i $NIC | grep firmware ; done` For CPAC-2-40/100F-C: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance.                |
| **16000**                         | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-C\* * CPAC-4-10F-C * CPAC-2-40F-C * CPAC-2-100/25F * CPAC-2-40/100F-C ([sk181064](https://support.checkpoint.com/results/sk/sk181064)) | Base, Plus, and Turbo models. For CPAC-2-100/25F: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance. * The minimum required card firmware version is 12.22.1002 To get the card firmware version, run this single long command in the Expert mode on the Security Appliance: `for NIC in $(ifconfig | grep ethsBP | awk '{print $1}') ; do echo $NIC: ; ethtool -i $NIC | grep firmware ; done` For CPAC-2-40/100F-C: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance.        |
| **15600**                         | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-B\* * CPAC-4-10F-B * CPAC-2-40F-B * CPAC-2-100/25F                                                                                     | For CPAC-4-10F-B: * Output of the "`lspci -v`" command must show: `Intel Corporation 82599ES 10-Gigabit SFI/SFP+ Network Connection` For CPAC-2-40F-B and for CPAC-2-100/25F: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance. * The minimum required card firmware version is 12.22.1002 To get the card firmware version, run this single long command in the Expert mode on the Security Appliance: `for NIC in $(ifconfig | grep ethsBP | awk '{print $1}') ; do echo $NIC: ; ethtool -i $NIC | grep firmware ; done` |
| **15400**                         | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-B\* * CPAC-4-10F-B * CPAC-2-40F-B * CPAC-2-100/25F                                                                                     | For CPAC-4-10F-B: * Output of the "`lspci -v`" command must show: `Intel Corporation 82599ES 10-Gigabit SFI/SFP+ Network Connection` For CPAC-2-40F-B and for CPAC-2-100/25F: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance. * The minimum required card firmware version is 12.22.1002 To get the card firmware version, run this single long command in the Expert mode on the Security Appliance: `for NIC in $(ifconfig | grep ethsBP | awk '{print $1}') ; do echo $NIC: ; ethtool -i $NIC | grep firmware ; done` |
| **13800**                         | * [R81.20](https://support.checkpoint.com/results/sk/sk177624)                                                                                                                                                                                        | * CPAC-2-10F\* * CPAC-4-10F                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **13500**                         | * [R81.20](https://support.checkpoint.com/results/sk/sk177624)                                                                                                                                                                                        | * CPAC-2-10F\* * CPAC-4-10F                                                                                                                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **9400** **9700** **9800**        | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624)                                                                                                                            | * CPAC-2-40/100F-D (2-Port Single-Width 40/100G QSFP28 Card) * CPAC-4-10/25F-D * CPAC-8-1/10F-D                                                     | Base and Plus models. To connect to Quantum Maestro Orchestrators, you must use only the supported Line Cards (on-board interfaces are not supported).                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **9100** **9200** **9300**        | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624)                                                                                                                            | * CPAC-4-10/25F-D * CPAC-8-1/10F-D                                                                                                                  | Base and Plus models. To connect to Quantum Maestro Orchestrators, you must use only the supported Line Cards (on-board interfaces are not supported).                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **7000**                          | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-C\* * CPAC-4-10F-C * CPAC-2-40F-C * CPAC-2-40/100F-C ([sk139932](https://support.checkpoint.com/results/sk/sk181064))                  | Base and Plus models. For CPAC-2-40/100F-C: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance.                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **6900**                          | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-C\* * CPAC-4-10F-C * CPAC-2-40F-C * CPAC-2-40/100F-C ([sk181064](https://support.checkpoint.com/results/sk/sk181064))                  | Base and Plus models. For CPAC-2-40/100F-C: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance.                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **6800**                          | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-C\* * CPAC-4-10F-6500/6800-C * CPAC-2-40F-C                                                                                            | Base, Plus, and Turbo models. For CPAC-4-10F-6500/6800-C: * Output of the "`lspci -v`" command must show: `Intel Corporation 82599ES 10-Gigabit SFI/SFP+ Network Connection`                                                                                                                                                                                                                                                                                                                                                                                            |
| **6700**                          | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-C\* * CPAC-4-10F-C * CPAC-2-40F-C                                                                                                      | Base and Plus models.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **6600**                          | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-C\* * CPAC-4-10F-C                                                                                                                     | Base and Plus models.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **6500**                          | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-C\* * CPAC-4-10F-6500/6800-C                                                                                                           | Base, Plus, and Turbo models. For CPAC-4-10F-6500/6800-C: * Output of the "`lspci -v`" command must show: `Intel Corporation 82599ES 10-Gigabit SFI/SFP+ Network Connection`                                                                                                                                                                                                                                                                                                                                                                                            |
| **6400**                          | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-C\* * CPAC-4-10F-C                                                                                                                     | Base and Plus models.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **6200**                          | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-C\* * CPAC-4-10F-C                                                                                                                     | Base and Plus models.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **5900**                          | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-B\* * CPAC-4-10F-B * CPAC-2-40F-B                                                                                                      | For CPAC-4-10F-B: * Output of the "`lspci -v`" command must show: `Intel Corporation 82599ES 10-Gigabit SFI/SFP+ Network Connection` For CPAC-2-40F-B: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance. * The minimum required card firmware version is 12.22.1002 To get the card firmware version, run this single long command in the Expert mode on the Security Appliance: `for NIC in $(ifconfig | grep ethsBP | awk '{print $1}') ; do echo $NIC: ; ethtool -i $NIC | grep firmware ; done`                        |
| **5800**                          | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-B\* * CPAC-4-10F-B * CPAC-2-40F-B                                                                                                      | For CPAC-4-10F-B: * Output of the "`lspci -v`" command must show: `Intel Corporation 82599ES 10-Gigabit SFI/SFP+ Network Connection` For CPAC-2-40F-B: * You cannot use this Line Card with a splitter cable to split a port on a Security Appliance. * The minimum required card firmware version is 12.22.1002 To get the card firmware version, run this single long command in the Expert mode on the Security Appliance: `for NIC in $(ifconfig | grep ethsBP | awk '{print $1}') ; do echo $NIC: ; ethtool -i $NIC | grep firmware ; done`                        |
| **5600**                          | * [R82](https://support.checkpoint.com/results/sk/sk181127) * [R81.20](https://support.checkpoint.com/results/sk/sk177624) * [R81.10](https://support.checkpoint.com/results/sk/sk173363) * [R81](https://support.checkpoint.com/results/sk/sk169954) | * CPAC-2-10F-B\* * CPAC-4-10F-B                                                                                                                     | For CPAC-4-10F-B: * Output of the "`lspci -v`" command must show: `Intel Corporation 82599ES 10-Gigabit SFI/SFP+ Network Connection`                                                                                                                                                                                                                                                                                                                                                                                                                                    |

{#ModelsTable}

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
