> Source: [sk182554](https://support.checkpoint.com/results/sk/sk182554)

# sk182554 - Nano-Egg Agent Installation Package Updates

| Property | Value |
|----------|-------|
| Solution ID | sk182554 |
| Date Created | 2024-07-30 |
| Last Modified | 2026-04-19 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R81.10 (EOS) |

## Solution

**Introduction \| Usage \| Manual Installation \| Availability \| List of Resolved Issues**

Introduction {#Introduction}
----------------------------

This package is part of the **Gateways Connector** feature ([sk180557](https://support.checkpoint.com/results/sk/sk180557)), it streamlines the onboarding of Check Point Security Gateways to the Check Point Portal (formerly known as Infinity Portal). The Gateways Connector allows administrators to automatically deploy or uninstall Nano-Agents across all Security Gateways from a centralized location, eliminating the need for manual installation on individual devices.  
By connecting Security Gateways to the Check Point Portal, administrators can centrally enforce and manage security policies across various **Check Point Cloud applications** , such as:  

* SD-WAN
* Identity and Trust (formerly known as Infinity Identity)
* IoT Security

This package includes**two main components** needed on the **Gateway side** :  

**Nano-Egg Installation Script**   
A standardized method for installing the Check Point Nano-Agent on either a Security Gateway or a Security Management Server. To begin the process, the user must provide a profile token obtained from the Check Point Portal tenant. When executed, the script automatically performs these operations:  

1. Downloading the latest Check Point Orchestration Nano-Agent.
2. Registering the Nano-Agent to the Check Point Portal.
3. Downloading and installing the relevant Nano-Agents.

<br />

**Gateway-Side Auto-Onboarding Component**   
This component runs on the **Security Gateway** and is responsible for automating the onboarding process to the Check Point Portal (alongside the Management package), using the Nano-Egg Installation Script. It eliminates the need for manual steps by:  

* Detecting the onboarding status
* Communicating with the Nano-Agent installed on the system
* Initiating and managing the registration flow to the Check Point Portal using the provided profile token

By automating these tasks, this component ensures a full hands-off, consistent onboarding experience, for each deployed Gateway, reducing operational overhead and configuration errors.  

As part of the automatic agent installation process, the system creates temporary scheduled jobs to ensure reliable completion. You may observe these temporary jobs:  
`NEST_JOB / NEST_JOB_VS<VS_ID> - Retry failed operations`  
`AFTER_REBOOT_NEST_JOB / AFTER_REBOOT_NEST_JOB_VS<VS_ID> - Continue installation after a system restart`  
**Note** : Do not delete these jobs. They are automatically removed once the operations are completed successfully.  

The Nano-egg Agent Installation package is installed automatically on all relevant Check Point devices when Automatic Update downloads are enabled (see [sk175504](https://support.checkpoint.com/results/sk/sk175504), section 2-B).

If Automatic Updates are disabled, you must first manually install the latest [AutoUpdater](https://support.checkpoint.com/results/sk/sk165653) Take and then install the Nano-egg Agent Installation package manually using the steps below, in the Manual Installation section.

Usage {#Usage}
--------------

There are two ways for the Nano-Agent to be installed:  

**Automatic agent installation** :  

1. Ensure the "*Gws_Onboard_AutoUpdate* " package is installed on the Management Server side (as per [sk180557](https://support.checkpoint.com/results/sk/sk180557)).
2. Connect the Security Management Server to a tenant.
3. In the connection window, select the desired method for connecting Gateways to Check Point Portal (default is set to "Automatically").
4. After establishing the connection with Check Point Portal, select "After install policy" and perform policy installation on the target Gateways.
5. The agent will be installed on the Gateway automatically.  
   To verify installation results, navigate to SmartConsole \> Logs and Events \> Logs. A log entry indicates whether the agent is installed successfully.

**Manual agent installation** :  
The agent can also be installed manually using these steps:  

1. Obtain the Authentication Token from the Quantum Profile in the SD-WAN application.
2. Connect to the command line on the Security Gateway or each Cluster Member.
3. If the default shell is Gaia Clish, enter Expert mode by running the "`expert`" command.
4. Install the Nano-Agent using the appropriate command for your platform:  
   **Gaia** :  
   `nano-egg --install --token <Authentication Token you copied earlier from your Quantum Profile>`  
   **Scalable Platforms** :  
   `nano-egg --install --token <Authentication Token you copied earlier from your Quantum Profile> --run-all-members`  
   **VSX** :  
   1) Get the ID of each configured Virtual System by running the "`vsx stat -l`" command  
   2) Run `nano-egg --install --token <Authentication Token you copied earlier from your Quantum Profile> --vs_id <ID>`
5. Examine the status of the required Nano-Services using the appropriate command:  
   **Gaia** :  
   `cpnano -s`  
   **Scalable Platforms** :   
   `g_allc cpnano -s`  
   **VSX** :  
   `cpnano-vs<ID> -s`

<br />

****Nano-Egg Agents support****

|---------|-----------|---------------------------------------------------|
| Version | Supported | Requirements                                      |
| R82.10  | Yes       | -                                                 |
| R82     | Yes       | -                                                 |
| R81.20  | Yes       | R81.20 Jumbo Hotfix Accumulator Take 99 or higher |

Manual Installation (Offline) {#Manual Installation}
----------------------------------------------------

Show / Hide this section  
>
> ### Instructions:
>
> 1. Download the offline package to your computer. See the "Availability" section.
>
> 2. Copy the offline package from your computer to your Check Point device to some directory (for example, */var/log/*).
>
> 3. Connect to the command line on your Check Point device.
>
> 4. Log in to the Expert mode.
>
> 5. Go to the directory with the offline package.
>
> 6. Install the offline package:
>
>    * On a Security Gateway / each Cluster Member / Management Server / Log Server:
>
>      `autoupdatercli install <Name of Offline Package>.tar`
>    * On a Scalable Platform Security Group (Maestro / Chassis):
>
>      `g_all autoupdatercli install <Name of Offline Package>.tar`
>
> **Note** : The installation does not require **`cpstop; cpstart`** or a reboot. Once installed, no further action is required, the update will be applied immediately.

Availability {#Availability}
----------------------------

> |------------------|------------|------------------|-------------------------------------------------------------------------------------------------------------------------|------------------------------------------|
> | **Release Type** | **Take #** | **Release Date** | **Offload Package Link**                                                                                                | **Comments**                             |
> | Latest Take      | Take 41    | 11 Feb 2026      | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/141585)(TAR) | For R81.20, R82                          |
> | Latest Take      | Take 41    | 11 Feb 2026      | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/141586)(TAR) | For R82.10 and higher                    |
> | Latest Take      | Take 41    | 11 Feb 2026      | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/141584)(TAR) | For Check Point Firewall 3900 Appliances |

List of Resolved Issues and New Features per Nano-egg Agent Installation Update {#List of Resolved Issues}
----------------------------------------------------------------------------------------------------------

|--------------|---------------------------------------------------------------------------------------------------------------------|
| ID           | Description                                                                                                         |
| **Take 41 (11 Feb 2026)**                                                                                                         ||
| SDWANGW-4569 | Enhancement: Added support for new regions: UAE, Canada.                                                            |
| **Take 38 (10 Nov 2025)**                                                                                                         ||
| SDWANGW-4048 | Enhancement: Added support for R82.10 EA and ARM processor platforms.                                               |
| **Take 23 (21 May 2025)**                                                                                                         ||
| SDWANGW-3017 | Enhancement: Added Gateway-Side Auto-Onboarding Component module, including Offboarding support and VSX flow fixes. |
| PMTR-105717  | Onboarding installation VSX fix in the Nano-Egg script.                                                             |
| **Take 13 (15 Jul 2024) - Initial Release**                                                                                       ||
| SDWANGW-2671 | Enhancement: Added a validation that the script is installed on Quantum Maestro.                                    |
| SDWANGW-2646 | Enhancement: Added support for VSX.                                                                                 |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
