> Source: [sk183199](https://support.checkpoint.com/results/sk/sk183199)

# sk183199 - Check Point Firewall 3900 Appliances

| Property | Value |
|----------|-------|
| Solution ID | sk183199 |
| Date Created | 2025-03-04 |
| Last Modified | 2026-09-09 |
| Technical Level | General |
| Products | Hardware |
| Versions | Not Version-Specific |
| OS | Gaia |

## Solution

**Overview \| Key Features \| Downloads \| Upgrade path \| Documentation \| Known Limitations \| Revision History**

Visit [Check Point CheckMates Community](https://community.checkpoint.com) to ask questions or start a discussion and get our experts assistance.  
See [Support Life Cycle Policy](https://www.checkpoint.com/support-services/support-life-cycle-policy/) for End-of-Support dates and successor appliance series.

|----------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------|
| **3920**                                                                                           | **3950**                                                                                           | **3970 / 3980**                                                                                    |
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183199/R29330-3920202504081002581.jpg "3920") | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183199/R29315-3950202504081004092.jpg "3950") | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183199/R29302-3980202504081005033.jpg "3980") |

Overview {#Overview}
--------------------

The Check Point Firewall 3900 Security Gateway appliance series is built to protect branch offices from both known and unknown threats with Anti-Virus, Anti-Bot, SandBlast Threat Emulation (Sandboxing), and SandBlast Threat Extraction technologies.  
The Check Point 3900 Security Gateway appliance series combines the most comprehensive security protections to safeguard your branch and small office deployments.   
The 3900 Security Gateway appliance series is available in a compact desktop form factor, while the latest generation offers a 1U form factor for enhanced scalability.  
Optimized for real-world threat prevention, this powerful Security Gateway secures critical assets and environments.  
The latest 3900 appliances, 3920, 3950, 3970, and 3980, come with a first-year subscription to the full SandBlast Prevention suite.  
For the 3920 appliances, these Sync ports are recommended: eth9 (default), eth10 and eth11.

Key Features {#Key Features}
----------------------------

* **High-Performance Security:** The Check Point 3900 series delivers industry-leading price/performance in an easy-to-deploy configuration.
* **AI-Based Threat Prevention:** Advanced artificial intelligence-driven security protects demanding branch office networks.

* **Industry-Leading Threat Prevention:** Provides the highest prevention rate in the industry, ensuring maximum protection against cyber threats.

Downloads {#Downloads}
----------------------

To download these packages, you will need to have a [Software Subscription or Active Support plan](https://www.checkpoint.com/support-services/support-plans/).

* **Image for Check Point Firewall Appliances:**

|-----------|--------------------------------------------------------------------|
| **Image** | **Link**                                                           |
| R82.20    | See [sk185039](https://support.checkpoint.com/results/sk/sk185039) |

Upgrade path {#Upgrade_path}
----------------------------

To upgrade the Check Point Firewall 3900 with **R82.10 Take 271** installed:  

1. Install the **[Hotfix for Check Point Firewall 3900 Appliances, Take 22](https://support.checkpoint.com/results/download/139085)** . For more information, see [sk183557](https://support.checkpoint.com/results/sk/sk183557).
2. Install **[R82.10 Take 467](https://support.checkpoint.com/results/download/140665)** . For more information, see [sk183506](https://support.checkpoint.com/results/sk/sk183506) \> Downloads and installation \> Upgrading Security Gateway \> For Check Point Firewall 3900 Appliances.

**Effective March 31, 2026, the GA version was updated to Take 467, which includes the certificates and CRL fix ([sk184766](https://support.checkpoint.com/results/sk/sk184766)).**

<br />

**Notes** :  

* For further Jumbo Hotfix Accumulator Takes for Quantum Force 3900 Appliances, refer to [R82.10 Jumbo Hotfix Accumulator.](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/R82.10/R82.10_Downloads.htm)   
  Note that if you choose not to upgrade to R82.10 Take 467, then to install R82.10 Jumbo Hotfix, you should use only the TGZ package.  

* To use the USB Type-C console port on the Quantum 3900 appliances, download and install the [3900 appliances USB Type-C](https://support.checkpoint.com/results/download/137962) console driver on the console client machine (desktop/laptop).

Documentation {#Documentation}
------------------------------

|------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Quick Start Guides                                                                                                                                               |
| [Check Point Firewall 3900 Appliances Quick Start Guide](https://sc1.checkpoint.com/documents/Appliances/PDF/CP_3900_Appliances_QuickStartGuide.pdf)             |
| [Check Point Firewall 3900 Appliances Getting Started Guide (English)](https://sc1.checkpoint.com/documents/Appliances/GSG_3900/EN/Default.htm)                  |
| [Check Point Firewall 3900 Appliances Getting Started Guide (Spanish)](https://sc1.checkpoint.com/documents/Appliances/GSG_3900/ES/Default.htm)                  |
| [Check Point Firewall 3900 Appliances Getting Started Guide (Portuguese - Brazil)](https://sc1.checkpoint.com/documents/Appliances/GSG_3900/pt-br/Default.htm)   |
| [Check Point Firewall 3900 Appliances Getting Started Guide (Chinese - Simplified)](https://sc1.checkpoint.com/documents/Appliances/GSG_3900/zh-CN/Default.htm)  |
| [Check Point Firewall 3900 Appliances Getting Started Guide (Chinese - Traditional)](https://sc1.checkpoint.com/documents/Appliances/GSG_3900/zh-TW/Default.htm) |
| Installation Guides                                                                                                                                              |
| [Rack Mounting for Check Point Appliances](https://sc1.checkpoint.com/documents/Appliances/Rails/Default.htm)                                                    |
| [Installing and Removing an AC Adapter](https://sc1.checkpoint.com/documents/Appliances/FRU_AC_Adapter/Default.htm)                                              |
| [Installing and Removing Transceivers and DAC Cables](https://sc1.checkpoint.com/documents/Appliances/FRU_Transceivers/Default.htm)                              |
| Administration Documentation                                                                                                                                     |
| [Zero Touch Administration Guide](https://sc1.checkpoint.com/documents/Appliances/Zero_Touch_Admin_Guide/EN/Content/Topics-AG/Overview.htm)                      |
| Additional Documentation                                                                                                                                         |
| [R82 Installation and Upgrade Guide](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_Installation_and_Upgrade_Guide/Default.htm)               |
| [Product Catalog](https://catalog.checkpoint.com/cat/quantum/security_gateway)                                                                                   |

Known Limitations {#Known Limitations}
--------------------------------------

|--------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------|
| ID                       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | Resolved In                                                                       |
| -                        | All R82 limitations apply as described in [sk181128 - R82 Known Limitations](https://support.checkpoint.com/results/sk/sk181128).                                                                                                                                                                                                                                                                                                                                                                                                           | -                                                                                 |
| -                        | By design, the 3900 appliances do not support the Standalone configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | -                                                                                 |
| PMTR-114921              | The 3900 appliances do not support the ElasticXL configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Resolved in [R82.10 take 464](https://support.checkpoint.com/results/sk/sk183506) |
| PMTR-106079, PMTR-114923 | The 3900 appliances do not support the Maestro configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | -                                                                                 |
| PMTR-114894              | The 3900 appliances do not support the VSNext mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | Resolved in [R82.10 take 464](https://support.checkpoint.com/results/sk/sk183506) |
| PMTR-115040              | The 3900 appliances do not support the Mail Transfer Agent (MTA) feature.                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Resolved in [R82.10 take 464](https://support.checkpoint.com/results/sk/sk183506) |
| PMTR-115051              | On the 3900 appliances, the Data Loss Prevention (DLP) Software Blade does not support email inspection and enforcement. Inspection of HTTP, HTTPS, and FTP is supported.                                                                                                                                                                                                                                                                                                                                                                   | -                                                                                 |
| PMTR-115010              | On the 3900 appliances, the Threat Emulation Software Blade does not support Local Emulation.                                                                                                                                                                                                                                                                                                                                                                                                                                               | -                                                                                 |
| PMTR-115468              | On the 3900 appliances, after you enable the Data Loss Prevention (DLP) Software Blade with the Management API "`set simple-gateway ... data-loss-prevention true`" or "`set simple-cluster ... data-loss-prevention true`", you must follow these steps in SmartConsole: 1. Open the Security Gateway / Cluster object. 2. Navigate to "Data Loss Prevention" \> "Protocols". 3. Select "Apply the DLP policy to these protocols only". 4. Clear the checkbox "SMTP (Outgoing Emails)". 5. Click OK. 6. Install the Access Control Policy. | -                                                                                 |
| PMTR-114608              | On the 3900 appliances, the Threat Extraction Software Blade does not support the action "Convert to PDF".                                                                                                                                                                                                                                                                                                                                                                                                                                  | Resolved in [R82.10 take 464](https://support.checkpoint.com/results/sk/sk183506) |
| PMTR-112848              | On the 3900 appliances, if in addition to the default Firewall Software Blade, you enable other Software Blades in the Security Gateway / Cluster object: 1. VxLAN traffic terminating on the Security Gateway will not be accelerated (will go through Slow Path instead of Medium Streaming Path). 2. GRE traffic terminating on the Security Gateway will not work.                                                                                                                                                                      | Resolved in [R82.10 take 464](https://support.checkpoint.com/results/sk/sk183506) |
| PMTR-114940              | On the 3900 appliances: 1. VxLAN over VPN is not supported. It is not supported to initiate encapsulation of VxLAN tunnel traffic from the Security Gateway and send it over a VPN tunnel. 2. GRE over VPN is not supported. It is not supported to initiate encapsulation of GRE tunnel traffic from the Security Gateway and send it over a VPN tunnel.                                                                                                                                                                                   | Resolved in [R82.10 take 464](https://support.checkpoint.com/results/sk/sk183506) |
| PMTR-114617, PMTR-115239 | By design, on the 3900 appliances, the LED of the Network Port that should receive IP address from DHCP for Zero Touch configuration does not blink.                                                                                                                                                                                                                                                                                                                                                                                        | -                                                                                 |
| PMTR-114598, GWAPP-2011  | On the 3900 appliances, the "Network test" in "HW Diagnostics" (in the Boot Menu) is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                         | -                                                                                 |
| PMTR-113632              | On the 3900 appliances, the ClusterXL Load Sharing modes are not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | Resolved in [R82.10 take 464](https://support.checkpoint.com/results/sk/sk183506) |
| PMTR-111169              | On the 3900 appliances, ClusterXL in the Active-Active mode is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                               | Resolved in [R82.10 take 464](https://support.checkpoint.com/results/sk/sk183506) |
| PMTR-113240              | By design, on the 3900 appliances, changing the value of any of these parameters on one of the interfaces will change this value on all switch interfaces: * rx-ringsize * tx-ringsize * mq This may briefly interrupt the traffic through the interfaces.                                                                                                                                                                                                                                                                                  | -                                                                                 |
| GWAPP-2213               | By design, on the 3900 appliances, the Power LED and other LEDs remain lit even after running shutdown or halt command. To shut down the appliance completely, you must also use the power switch.                                                                                                                                                                                                                                                                                                                                          | -                                                                                 |
| PMTR-115436, PMTR-115974 | On the 3900 appliances, the synchronization of Gaia Cloning Groups never completes (in Gaia Portal \> the "System Management" section \> the "Cloning Group" page \> in the "Cloning Group" section, the "Member Status" field constantly shows "Synchronizing").                                                                                                                                                                                                                                                                           | Resolved in [R82.10 take 464](https://support.checkpoint.com/results/sk/sk183506) |
| GWAPP-2229               | On the Check Point Firewall 3920 model, the 1 GbE SFP port (eth9) does not support the transceiver CPAC-TR-1SX-D.                                                                                                                                                                                                                                                                                                                                                                                                                           | Resolved in [R82.10 take 464](https://support.checkpoint.com/results/sk/sk183506) |
| PMTR-115198              | On the Check Point Firewall 3920 model, the 1 GbE SFP port (eth9) does not support the transceiver CPAC-TR-1T-D.                                                                                                                                                                                                                                                                                                                                                                                                                            | Resolved in [R82.10 take 464](https://support.checkpoint.com/results/sk/sk183506) |
| PMTR-113472              | * In the 3920 model, you must use only 10 Gbps transceivers in the interfaces eth10 and eth11. * In the 3970 and 3980 models, you must use only 10 Gbps transceivers in the interfaces from eth27, eth28, eth29, and eth30. * When replacing a 1Gbps transceiver with a 10Gbps transceiver, and the reverse, you must reboot the appliance.                                                                                                                                                                                                 | -                                                                                 |
| PMTR-115220              | By design, on the Check Point Firewall 3950, 3970, 3980 models, the 2.5 GbE RJ45 ports operate with the auto-negotiation enabled at the speeds of 1 Gbps and faster. This may lead to a mismatch between user-configured speeds and the actual speed.                                                                                                                                                                                                                                                                                       | -                                                                                 |

Revision History {#Revision History}
------------------------------------

Show / Hide the revision history

|-------------------|------------------------------------------------------------------------------------------------------------------------------|
| Date              | Description                                                                                                                  |
| 09 December 2025  | Updated the Downloads section                                                                                                |
| 29 December 2025  | Updated the Downloads and Known Limitations sections                                                                         |
| 14 September 2025 | Updated the Downloads and Known Limitations sections                                                                         |
| 01 September 2025 | Updated the Documentation section - Added 3900 Getting Started Guide links (Chinese - Simplified and Chinese - Traditional). |
| 13 July 2025      | Updated the Documentation section.                                                                                           |
| 08 June 2025      | Updated the Known Limitations section.                                                                                       |
| 04 June 2025      | Updated the Known Limitations section.                                                                                       |
| 01 June 2025      | First release of this article.                                                                                               |

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
