> Source: [sk183506](https://support.checkpoint.com/results/sk/sk183506)

# sk183506 - Check Point Quantum R82.10 Release

| Property | Value |
|----------|-------|
| Solution ID | sk183506 |
| Date Created | 2025-05-28 |
| Last Modified | 2026-09-15 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82.10 |

## Solution

Click Here to Show the Entire Article

**Check Point Recommended version for all deployments is [R82.10](https://support.checkpoint.com/results/sk/sk183506) with its** **latest** **[Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) Take** **For more info about all Check Point releases, refer to [Release map](https://support.checkpoint.com/results/sk/sk152052) and [Release Terminology](https://support.checkpoint.com/results/sk/sk95746) articles**

##### Note: For Azure customers, R82.10 will become the recommended version in the coming weeks

**Introduction \| What's New \| Documentation \| Downloads and Installation \| Additional Downloads and Products \| Revision History**

|---|---|---|
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/8210_Release202511061712211.jpg) |||

<br />

|---|---|---|
| Introduction {#Introduction} ---------------------------- |||
| Enterprises are rapidly adopting AI to achieve impressive productivity gains. However, AI systems also introduce unprecedented new security challenges. Traditional detection and response frameworks are no longer enough to protect today's distributed, hybrid mesh networks. It is imperative that enterprises shift left to prevention-first security. R82.10 enables security for the **AI transformation** , **Hybrid Mesh Network** , and **advanced threats** . R82.10 delivers stronger threat prevention, higher scalability \& performance, and greater operational simplicity. **Architectural Updates:** R82.10 features an upgraded OS based on Linux kernel 5.14 versus 4.xx in previous releases. This release runs exclusively in UPPAK mode (User Space Performance Pack). **Stronger Threat Prevention** * **Threat Prevention Insights:**Provides administrators with clear insights into the effectiveness and coverage of Threat Prevention and IPS, featuring visualizations, metrics, and recommendations to refine rules and profiles. * **Advanced Zero Phishing:** Zero Phishing Software Blade now protects encrypted traffic from phishing attacks at the domain level - enabling domain analysis by ThreatCloud AI without requiring SSL Inspection or decryption. * **Protection from HTML Smuggling:** Zero Phishing Software Blade introduces a powerful new capability to detect and block HTML smuggling, an advanced cyberattack technique that avoids firewall detection by building malware locally within a target's web browser. * **Expanded DNS Protection:** Introduces DNS-over-TLS threat prevention to block malicious DNS activity over encrypted channels. * **Hardened Encryption:** HTTPS Inspection now supports Hardware Security Module (HSM) for TLS 1.3, making it considerably harder for attackers to compromise encrypted traffic. * **MCP Detection and Visibility:** Introduces MCP (Model Context Protocol) detection and visibility to ensure that only authorized MCP communications are allowed across the network. * **Enhanced Drop Templates:** New drop templates improve resilience by reducing CPU usage to enable blocking a much higher volume of denial of service (DoS) attacks while maintaining maximum throughput for permitted traffic. * **4 New ThreatCloud AI Engines:** PDF security with advanced image and text analysis, malicious GitHub-hosted account and repository detection, automatic creation of file and IPS protection rules, and a new web security model with enhanced decision-making capabilities. * **Adaptive IPS:** A new optimized IPS defense profile is tailored to fit an organization's exact requirements. This enables IPS to be turned on with minimal CPU performance impact, for improved resiliency and threat detection. **Scalability \& Performance** * **Scalable Identity Management:** Improved identity awareness across the enterprise for unified policy enforcement and scalable identity sharing. * Each Policy Decision Point (PDP) can now manage up to 1M identities, reducing the number of required PDPs by up to 5X. * A single PDP can share identities with up to 300 Policy Enforcement Point (PEP) gateways, even across multiple domains. * Direct PDP to PEP sharing works across Multi-Domain Security Management without an Identity Broker, simplifying configuration. * **Support for SD-WAN in Maestro Security Groups:** Enables higher scalability in branch office networks while providing the highest system reliability and redundancy. * **Quantum Security Management Scalability:** Increases the maximum number of managed Security Gateways to 1,500 per management domain. Users can further scale to 10,000 gateways in a Multi-Domain Security Management Server configuration. **Operational Simplicity** * **Centralized Identity Management:** Infinity Identity is a cloud service that integrates with Quantum network security, provides the option of integrating with multiple identity providers, and eliminates the need for separate management portals. It integrates endpoint device and device security posture data from Microsoft Intune, Microsoft Defender, CrowdStrike Falcon, Harmony Endpoint, and more for consistent and unified zero-trust access control. * **New Access Policy Log Generation Modes:** New logging mode enables streamlined control over daily log output, with improved granularity into log levels and analytics on high-volume rules. The Aggregated mode greatly reduces daily log volume by **up to 70%**, reducing storage needs accordingly. * **Simplified Route-Based VPN:**Automatically configures Site to Site VPN based on network topology, enabling one-click setup and dynamic routing with BGP. * **Enhanced Web-based UI:** New web-based UI allows users to manage common security use cases from the web for more flexibility. **Effective March 31, 2026, the GA version was updated to Take 467, which includes the certificates and CRL fix ([sk184766](https://support.checkpoint.com/results/sk/sk184766)).** |||
| What's New in R82.10 {#New} --------------------------- |||
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181127/ThreatPrevention202409191357592.png) Threat Prevention > ### [Threat Prevention Insights](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ThreatPrevention_AdminGuide/Default.htm#cshid=ID012) {#Toggle_Threat Prevention} > * Provides clear insight into Threat Prevention and IPS effectiveness and coverage, with visualizations, metrics, and recommendations to refine policy and profiles. A tuned policy enhances coverage, reduces noise, and maintains Security Gateway performance predictable and manageable. >   **Key Features:** >   * **Misconfigurations \& Optimizations:** >     * Detects misconfigured IPS profile for example, disabled protections, conflicting exceptions, and outdated profiles). >     * Surfaces overly permissive settings and hitless items, with guidance to remediate safely. >     * Prioritizes changes by security impact and performance benefit >   * **IPS Profile Tuning:** >     * Highlights noisy signatures, false-positive candidates, and protections generating excessive logs. >     * Suggests severity-aware tuning (move to Detect/Prevent, adjust performance impact, add targeted exceptions) to cut noise while preserving critical coverage. > ### Zero Phishing > * Zero Phishing Software Blade provides prevention for customers without HTTPS >   Inspection, utilizing [Server Name Indication (SNI)](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SecurityManagement_AdminGuide/Default.htm#cshid=ID007) in TLS handshake. > * Zero Phishing Software Blade introduces a powerful new capability to detect and block [HTML Smuggling](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ThreatPrevention_AdminGuide/Default.htm#cshid=ID011), a technique used by threat actors to bypass traditional Network Threat Prevention systems. > ### ThreatCloud AI Engines > * **Threat Emulation PDF Engine** The updated PDF engines combine advanced image and text analysis. >   * **Image analysis:** QR code extraction, page-layout parsing, brand misuse detection resilient to adversarial obfuscation, and adult-content heuristics. >   * **Text analysis:** an SLM (Small Language Model) flags social-engineering patterns in forms, lures, and conversational tone. >   * **Brand detection:**adversarial image obfuscation techniques. > * **GitHub Abuse Engine** - Designed to detect malicious GitHub-hosted accounts and repositories used for credential theft and drive-by malware downloads. The engine uses advanced algorithms and AI to analyze user behavior, repository structure, key files, and JavaScript content through deep code inspection. > * **AI Web Security (New model)**- The latest version of the AI web security engine features enhanced decision-making capabilities across web traffic by combining DNS metadata, certificate attributes, and behavioral signals. > * **Generative AI Protections Engine** - Automates the creation of File and IPS protection rules by processing open-source intelligence and ThreatCloud traffic. It generates protection rules automatically, eliminating manual effort and accelerating the protection delivery. By reducing analysis time from days to hours, it enhances threat response and expands coverage with minimal human intervention. > ### DNS Security > * Introducing [**DoT (DNS over TLS)**](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ThreatPrevention_AdminGuide/Default.htm#cshid=ID008) - Threat Prevention capabilities for malicious DNS activity over the TLS protocol. > ### HTTPS Inspection > * Added support for the hybrid PQC-safe key exchange group "X25519MLKEM768" (combining X25519 and ML-KEM768 algorithms) within HTTPS Inspection. > * HTTPS Inspection now supports Hardware Security Module (HSM) integration for TLS 1.3, ensuring secure storage and management of private keys during encrypted traffic inspection. > * [Rule Base Hit Count](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SecurityManagement_AdminGuide/Default.htm#cshid=ID007) is now available for HTTPS Inspection policies, improving visibility and administrative control. > ### IPS > * [New capability](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ThreatPrevention_AdminGuide/Default.htm#cshid=ID009) that automatically detects and remediates CPU-intensive IPS protections with a dedicated SmartView dashboard displaying IPS bypass statistics and CPU-intensive protection insights. *** ** * ** *** <br /> ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk170416/security_gateway_and_gaia202106131341411.png) Quantum Security Gateway > ### Identity Awareness {#Toggle_GW} > * Introducing [**Scalable Identity Sharing**](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_IdentityAwareness_AdminGuide/Default.htm#cshid=ID005) that allows more flexible and efficient identity distribution with two major enhancements: >   * **Scalable Identity management:** A single Policy Decision Point (PDP) gateway can now distribute identities to up to 300 Policy Enforcement Point (PEP) gateways, significantly improving scalability and performance. >   * **Cross-Management Domain Support:**Identities can now be seamlessly shared across multiple Domain Management Servers (CMAs), enabling unified and consistent identity-based policy enforcement throughout large and distributed environments. > * [Improved PDP Performance](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_IdentityAwareness_AdminGuide/Default.htm#cshid=ID006) - Policy Decision Point (PDP) gateways can now handle up to 1 million identities each, leveraging a new multi-process architecture that optimizes hardware utilization and boosts overall performance. > * Quantum Security Gateway integration with [Infinity Identity](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Identity-Admin-Guide/Default.htm) - Seamless integration with Infinity Identity, delivering centralized and unified Identity Awareness policy enforcement throughout the entire network infrastructure, and supports new identity integrations such as Microsoft Intune, Microsoft Defender, and Harmony Endpoint. > ### URL Filtering > * The URL Filtering Software Blade now supports automatic categorization of websites listed in the "Terrorism" category of the CTIRU (Counter-Terrorism Internet Referral Unit) list. > ### Site to Site VPN > * Added support for standard ML-KEM as required by the FIPS 203 standard to address Post-Quantum Cryptography (PQC). See [sk184080 - Post-Quantum Cryptography (PQC) algorithms in R82.10 and higher](https://support.checkpoint.com/results/sk/sk184080). > * [Simplified Route-based VPN](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SitetoSiteVPN_AdminGuide/Default.htm#cshid=ID005) - Automatically configures route-based VPNs on Check Point Security Gateways based on network topology, providing easy, one-click setup and saving configuration time. It also includes support for dynamic routing using BGP. > ### SD-WAN > * Added support for SD-WAN in Maestro Security Groups. See [sk180605 - Quantum SD-WAN](https://support.checkpoint.com/results/sk/sk180605). > ### Security Gateway Enhancement > * New [MCP Detection and Visibility feature](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SecurityGateway_Guide/Default.htm#cshid=ID002) designed to monitor and manage Model Context Protocol (MCP) traffic within your network. You can now instantly access detailed information about MCP traffic, including server names, versions, and tools in use. >   In addition to enhanced visibility, this feature empowers you to accept or drop MCP connections based on your organization's security policies. This gives you greater control over your network traffic and helps ensure only authorized MCP communications are allowed. > * Redesigned the Drop Optimization feature in Access Control policy. The new design supports more acceleration use cases, such as rules with Dynamic Objects and future offloads the traffic to ASIC-powered network cards. See [sk184356 - Firewall Drop Optimization in R82.10 and higher](https://support.checkpoint.com/results/sk/sk184356). > ### Dynamic Routing > Added support for these [Dynamic Routing features](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Gaia_Advanced_Routing_AdminGuide/Default.htm#cshid=ID1002): > * Support for up to 256 PIM interfaces, which allows greater flexibility and scalability in network configurations. > * Support for up to 500 BGP peers, ensuring robust and efficient routing capabilities. > * Support for BGP Large Communities, which provides enhanced control and management of routing policies across multiple networks. > ### Cluster and Scalability > * The ElasticXL clustering and Maestro Security Group now support SecureXL in the User Mode (UPPAK). > ### Internal CA > * Increased RSA Key Size for Internal CA -- The default RSA key size for the Root CA has been increased from 2048 bits to 3072 bits, enhancing cryptographic security for Internal CA, SIC, Site to Site VPN, Remote Access VPN clients, user certificates, and MultiPortal certificates. >   * In the clean installation, this is the default. >   * In the upgraded installation, this is the new default if you remove the current Internal CA and create the new Internal CA. > ### Gaia OS Security > * In Gaia Clish, you can configure the number of [hashing rounds](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Gaia_AdminGuide/Default.htm#cshid=ID091) for new passwords. >   Hashing rounds determine the number of iterations a hashing algorithm performs on a password before storing it. This process is used to enhance security by making it more computationally expensive for attackers to crack passwords through brute force attacks. > * Added the Bcrypt hash for [password encryption](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Gaia_AdminGuide/Default.htm#cshid=ID090) of local users in the Gaia OS. > * External RADIUS authentication servers can now be configured to use CHAP (Challenge-Handshake Authentication Protocol) or PAP (Password Authentication Protocol). *** ** * ** *** <br /> ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk170416/security_management202106131354392.png) Quantum Security Management > ### Logging and Monitoring {#Toggle_Management} > * **[New Access Policy Log Generation Modes](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_LoggingAndMonitoring_AdminGuide/Default.htm#cshid=ID001): Standard and Aggregated**. The Aggregated mode significantly reduces the daily log volume. > * The **Log Forwarding** feature is now easier to use. It now forwards locally stored logs to the primary Log Server without requiring a specific Log Server to be selected. The feature is enabled by default for new Gateways, making sure that locally stored logs will automatically upload to the Log Server. > * Additional logging enhancements in SmartConsole: >   * View the rules log level by hovering over the Track column in the Access Control rule. >   * Added the ability to customize the default Track value for new Access Control rules. >   * Enhanced the session log content with additional fields, including NAT details. >   * Introducing the per-session log level control for Implied Rules. > ### Compliance > * Added support for new regulations: >   * CSA CCoP 2.0 >   * DORA 2023 >   * ISO 27002 2022 >   * NIST800-82r3 > * Added new Management API commands for initiating new scans, showing Best Practices data, Compliance settings, and more. > * Update existing Best Practices for Firewall, IPS, Anti-Bot, and VPN Software Blades. *** ** * ** *** <br /> ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk170416/cloudGuard_iaas202106131355093.png) Cloud Firewall (formerly CloudGuard Network) > ### CloudGuard Controller {#Toggle_CloudGuard} > * New CloudGuard Controller scanner [for Proxmox Virtual Environment](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_CloudGuard_Controller_AdminGuide/Default.htm#cshid=ID024) data center. |||

<br />

|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Documentation {#Documentation} ------------------------------                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ||||
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181127/release_notes202504231345072.png) [**Release Notes**](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_RN/Default.htm) | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk170416/administration_guides202106131355505.png) **Administration Guides** | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk170416/resolved_issues202106131356136.png) **[Resolved Issues](https://support.checkpoint.com/results/sk/sk183508)** | ****![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk170416/known_limitations202106131356247.png)**** **[Known Limitations](https://support.checkpoint.com/results/sk/sk183507)** |
| View |--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | Quantum Security Management / Security Gateway                                                                                                                                       | Quantum Security Gateway                                                                                                                                                  | | [R82.10 Installation and Upgrade Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Installation_and_Upgrade_Guide/Default.htm)                          | [R82.10 Quantum Security Gateway Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SecurityGateway_Guide/Default.htm)                        | | [R82.10 Carrier Security Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_CarrierSecurity_AdminGuide/Default.htm)                       | [R82.10 ClusterXL Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ClusterXL_AdminGuide/Default.htm)                         | | [R82.10 CLI Reference Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_CLI_ReferenceGuide/Default.htm)                                                 | [R82.10 Threat Prevention Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ThreatPrevention_AdminGuide/Default.htm)          | | [R82.10 Gaia Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Gaia_AdminGuide/Default.htm)                                              | [R82.10 Data Loss Prevention Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_DataLossPrevention_AdminGuide/Default.htm)     | | Quantum Security Management                                                                                                                                                          | [R82.10 Gaia Advanced Routing Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Gaia_Advanced_Routing_AdminGuide/Default.htm) | | [R82.10 Quantum Security Management Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SecurityManagement_AdminGuide/Default.htm)         | [R82.10 Identity Awareness Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_IdentityAwareness_AdminGuide/Default.htm)        | | [R82.10 Multi-Domain Security Management Admin Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Multi-DomainSecurityManagement_AdminGuide/Default.htm) | [R82.10 Performance Tuning Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_PerformanceTuning_AdminGuide/Default.htm)        | | [R82.10 SmartProvisioning Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SmartProvisioning_AdminGuide/Default.htm)                    | [R82.10 QoS Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_QoS_AdminGuide/Default.htm)                                     | | [R82.10 CloudGuard Controller Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_CloudGuard_Controller_AdminGuide/Default.htm)            | [R82.10 Remote Access VPN Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_RemoteAccessVPN_AdminGuide/Default.htm)           | | [Cloud Management Extension (CME) Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm)                                              | [R82.10 Mobile Access Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_MobileAccess_AdminGuide/Default.htm)                  | | [R82.10 Logging and Monitoring Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_LoggingAndMonitoring_AdminGuide/Default.htm)            | [R82.10 Site to Site VPN Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SitetoSiteVPN_AdminGuide/Default.htm)              | | Harmony Endpoint                                                                                                                                                                     | [SSL Network Extender (SNX) Administration Guide](https://sc1.checkpoint.com/documents/SSL_Network_Extender_AdminGuide/Default.htm)                                       | | [R82.10 Harmony Endpoint Web Management Admin Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_HarmonyEndpointWebManagement_AdminGuide/Default.htm)    | [R82.10 VoIP Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_VoIP_AdminGuide/Default.htm)                                   | | [R82.10 Harmony Endpoint Server Administration Guide](https://sc1.checkpoint.com/documents/R82.10/SmartEndpoint_OLH/EN/Default.htm)                                                  | [R82.10 VSX Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_VSX_AdminGuide/Default.htm)                                     | | SmartConsole                                                                                                                                                                         | Scalable Platforms                                                                                                                                                        | | [R82.10 SmartConsole Help](https://sc1.checkpoint.com/documents/R82.10/SmartConsole_OLH/EN/default.htm)                                                                              | [R82.10 Scalable Platforms Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ScalablePlatforms_AdminGuide/Default.htm)        | | [R82.10 SmartConsole Help](https://sc1.checkpoint.com/documents/R82.10/SmartConsole_OLH/EN/default.htm)                                                                              | [Quantum Maestro Getting Started Guide](https://sc1.checkpoint.com/documents/Appliances/GSG_Maestro/EN/Default.htm)                                                       | ||||

<br />

{#Installation_SmartConsole}

|---|---|---|
| Downloads and Installation {#Installation} ------------------------------------------ |||
| We recommend upgrading to the latest [R82.10 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) and the latest [R82.10 SmartConsole Build](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10_SC/Default.htm) to benefit from the most recent improvements and fixes. <br /> |||
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk122485/arrow-transp1809060017.png) Upgrading Quantum Security Management and Multi-Domain Security Management > **If your Security Management Server / Multi-Domain Security Management is connected to the Internet (the common case):** > > 1. Connect to **Gaia Portal**. > > 2. In the left navigation tree, click **Software Updates** \> **Available Updates**. > > 3. Expand the section **Major Versions**. > > 4. In the applicable row, click **Upgrade**. > **If your Security Management Server / Multi-Domain Security Management is not connected to the Internet, click to see instructions:** > > 1. Download and install the latest [Upgrade Tools package](https://support.checkpoint.com/results/sk/sk135172) and [Gaia Deployment Agent (CPUSE)](https://support.checkpoint.com/results/sk/sk92449). > > 2. Download the **Fast Deployment Package (TGZ)** > >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511200913451.10_button-fast_deployment-sms.png)](https://support.checkpoint.com/results/download/144729) [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511200913582.10_button-Fast_Deployment_Package-MDS.png)](https://support.checkpoint.com/results/download/144732) > >    Note: On Multi-Domain Security Management, upgrade using Fast Deployment is supported starting from R81.10. > >    OR > >    Download the **CPUSE Offline Upgrade Package (TAR)** > >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511171503551.10_button-CPUSE-OUP.png)](https://support.checkpoint.com/results/download/144691) > > 3. Connect to **Gaia Portal**. > > 4. In the left navigation tree, click **Software Updates** \> **Available Updates**. > > 5. Import the Fast Deployment or the CPUSE Offline Package. > > 6. Expand the section **Major Versions**. > > 7. In the applicable row, click **Upgrade**. > <br /> > For more information and other upgrade methods, see the [R82.10 Installation and Upgrade Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Installation_and_Upgrade_Guide/Default.htm). *** ** * ** *** |||
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk122485/arrow-transp1809060017.png) Upgrading Quantum Security Gateway > **Best Practice:** Use Central Deployment in SmartConsole to upgrade one or more Security Gateways: > > **SmartConsole** \> **Gateways \& Servers** \> right-click a **Security Gateway or Cluster object** \> click **Actions** > > For more information, see the [R82.10 Security Management Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_SecurityManagement_AdminGuide/Default.htm) - Chapter "Managing Gateways" \> Section "Central Deployment of Hotfixes and Version Upgrades". > **If your Security Gateway is connected to the Internet (the common case):** > > 1. Connect to **Gaia Portal**. > > 2. In the left navigation tree, click **Software Updates** \> **Available Updates**. > > 3. Expand the section **Major Versions**. > > 4. In the applicable row, click **Upgrade**. > **For large scale fully automated Security Gateway upgrade using CDT, click to see instructions:** > > Upgrade your Security Gateway using [Central Deployment Tool (CDT)](https://support.checkpoint.com/results/sk/sk111158). > > Central Deployment Tool (CDT) is a utility that lets you manage a deployment of software packages from your Management Server to the multiple managed Security Gateways and cluster members at the same time. > **\*** This upgrade method is not supported on Check Point Firewall 3900 Appliances > **If your Security Gateway is not connected to the Internet, click to see instructions:** > > 1. Download the **Fast Deployment Package (TGZ)** > >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511200914243.10_button-Fast_Deployment_Package-SG.png)](https://support.checkpoint.com/results/download/144731) > >    OR > >    Download the **CPUSE Offline Upgrade package (TAR)** > >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511200914494.10_button-CPUSE-SG_v2dp.png)](https://support.checkpoint.com/results/download/144691) > > 2. Connect to **Gaia Portal**. > > 3. In the left navigation tree, click **Software Updates** \> **Available Updates**. > > 4. Import the downloaded Fast Deployment or the CPUSE Offline Package. > > 5. Expand the section **Major Versions**. > > 6. In the applicable row, click **Upgrade**. > <br /> > <br /> > **For Check Point Firewall 3900 Appliances, click to see instructions:** > > 1. Install the [Hotfix for Check Point Firewall 3900 Appliances Take 22](https://support.checkpoint.com/results/sk/sk183557). > > 2. Download the **Fast Deployment Package (TGZ)** > >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511171507583.10_button-Fast_Deployment-3900.png)](https://support.checkpoint.com/results/download/144725) > >    OR > >    Download the **CPUSE Offline Upgrade Package (TAR)** > >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511200915135.10_button-CPUSE-3900_v2dp.png)](https://support.checkpoint.com/results/download/144686) > > 3. Connect to Gaia Portal. > > 4. In the left navigation tree, click **Software Updates** \> **Available Updates**. > > 5. Import the downloaded Fast Deployment or the CPUSE Offline Package. > > 6. Expand the section **Major Versions**. > > 7. In the applicable row, click **Upgrade**. > <br /> > <br /> > For more information and other upgrade methods, see the [R82.10 Installation and Upgrade Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Installation_and_Upgrade_Guide/Default.htm). *** ** * ** *** |||
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk122485/arrow-transp1809060017.png) Clean Install of Security Gateway and Management Server > **Effective March 31, 2026, the GA version was updated to Take 467, which includes the certificates and CRL fix ([sk184766](https://support.checkpoint.com/results/sk/sk184766)).** > For **Security Gateway** , **Security Management** , or **Multi-Domain Management Server** > > 1. Download the **Fast Deployment Package (TGZ)** : > >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511200915386.10_button-Fast_Deployment_Package-SG.png)](https://support.checkpoint.com/results/download/143855) [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511200915567.10_button-fast_deployment-sm.png)](https://support.checkpoint.com/results/download/143857) [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511200916078.10_button-Fast_Deployment_Package-MDS.png)](https://support.checkpoint.com/results/download/143859) > >    OR > >    Download this **CPUSE** **Offline Upgrade Package (TAR)** : > >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511171509405.10_button-CPUSE-OUP.png)](https://support.checkpoint.com/results/download/140663) > > 2. Connect to **Gaia Portal**. > > 3. In the left navigation tree, click **Software Updates** \> **Available Updates**. > > 4. Import the downloaded Fast Deployment or the CPUSE Offline Package. > > 5. Expand the section **Major Versions**. > > 6. Click the three dots on the right and select **Clean Install**. > **If you use Bootable USB device:** > > 1. Download the **Gaia OS Clean Install ISO file** : > >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511200916229.10_button-Clean_Install_Image.png)](https://support.checkpoint.com/results/download/140658) > > 2. See [sk65205](https://support.checkpoint.com/results/sk/sk65205) to create a bootable USB device. > > 3. Run the Gaia First Time Configuration Wizard. > > For more information, see the [R82.10 Installation and Upgrade Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Installation_and_Upgrade_Guide/Default.htm) . > **For Check Point Firewall 3900 Appliances** **Effective March 31, 2026, the GA version was updated to Take 467, which includes the certificates and CRL fix ([sk184766](https://support.checkpoint.com/results/sk/sk184766)).** > > 1. Download the **Fast Deployment Package** **(TGZ)** > >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R82202511171510306.10_button-Fast_Deployment-3900.png)](https://support.checkpoint.com/results/download/143851) > >    OR > >    Download this **Offline Upgrade Package (TAR):** > >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R822025112009165410.10_button-Clean_Install-3900.png)](https://support.checkpoint.com/results/download/140665) > > 2. Connect to **Gaia Portal**. > > 3. In the left navigation tree, click **Software Updates** \> **Available Updates**. > > 4. Import the downloaded Fast Deployment or the CPUSE Offline Package. > > 5. Expand the section **Major Versions**. > > 6. Click the three dots on the right and select **Clean Install**. > > <br /> > > **If you use Bootable USB device on Check Point Firewall 3900 Appliances:** > > 1. Download the **Gaia OS Clean Install ISO file** : > >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R822025112009171011.10_button-Clean_Install_Image.png)](https://support.checkpoint.com/results/download/140660) > > 2. See [sk65205](https://support.checkpoint.com/results/sk/sk65205) to create a bootable USB device. > > 3. Run the Gaia First Time Configuration Wizard. > > For more information, see the [R82.10 Installation and Upgrade Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Installation_and_Upgrade_Guide/Default.htm) . *** ** * ** *** |||
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk122485/arrow-transp1809060017.png) ElasticXL and Quantum Maestro > **Important: Scalable Chassis 44000 / 64000 do not support R82.10 > <br /> > To upgrade your Maestro Orchestrator from R82:** > 1. Connect to **Gaia Portal**. > 2. In the left navigation tree, click **Software Updates** \> **Available Updates** > 3. Expand the section **Major Versions**. > 4. In the applicable row, click **Upgrade**. > <br /> > **To upgrade ElasticXL, Maestro Security Groups and Maestro Orchestrator from R81.10, R81.20, or R82:** > 1. Install the required Jumbo Hotfix Accumulator: >    * On R82 for Scalable Platforms - install the [R82 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) Take 60 or higher >    * On R81.20 for Scalable Platforms - install the [R81.20 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) Take 120 or higher >    * On R81.10 for Scalable Platforms - install the [R81.10 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) Take 183 or higher > 2. Install the CPUSE Deployment Agent 2691 or higher from [sk92449](https://support.checkpoint.com/results/sk/sk92449). > 3. Download and import this **Offline Upgrade Package (TAR)** : >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R822025112009173212.10_button-Upgrade_Package-Scalable_Platforms.png)](https://support.checkpoint.com/results/download/140663) >    For more information and other upgrade options, see [R82.10 Scalable Platforms Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ScalablePlatforms_AdminGuide/Default.htm). >    <br /> > **Clean install** > * Download and import this **Installation Image (ISO)** : >   [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R822025112009180513.10_button-Clean_Install_Image-Scalable_Platforms.png)](https://support.checkpoint.com/results/download/140658) >   For more information and other upgrade options, see the [R82.10 Scalable Platforms Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_ScalablePlatforms_AdminGuide/Default.htm). *** ** * ** *** |||
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk122485/arrow-transp1809060017.png) Cloud Firewall (formerly CloudGuard Network) > ### Deploying Cloud Firewall Gateway {#Toggle_Installation_CGNetwork} > > **Deployment Options** > > |-----------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| > > | Platform Type                     | Deployment                                                                                                                                                                                                                                                                                                                                             | > > | AWS (Amazon Web Services)         | [Marketplace (CloudFormation)](https://support.checkpoint.com/results/sk/sk111013) / [Terraform](https://support.checkpoint.com/results/sk/sk111013)                                                                                                                                                                                                   | > > | Microsoft Azure                   | [Marketplace](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/checkpoint.vsec?tab=PlansAndPrice) / [vWAN](https://marketplace.microsoft.com/en-us/product/azure-applications/checkpoint.cp-vwan-managed-app?tab=Overview) / [Terraform](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/azure/latest)     | > > | GCP (Google Cloud Platform)       | [Marketplace](https://console.cloud.google.com/marketplace/browse?pli=1&q=CloudGuard%20Network%20Security) / [Terraform Registry](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/gcp/latest/submodules/network-security-integration)                                                                                   | > > | OCI (Oracle Cloud Infrastructure) | [CloudGuard Network Security for Oracle Cloud Infrastructure](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Oracle_Cloud_Getting_Started/Default.htm)                                                                                                                                                          | > > | Private Cloud                     | [VMware ESXi, KVM, OpenStack, Nutanix AHV](https://support.checkpoint.com/results/sk/sk158292) [VMware Terraform templates](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/vmware/latest) [Nutanix Terraform templates](https://registry.terraform.io/modules/CheckPointSW/cloudguard-network-security/Nutanix/latest) | > > [](https://support.checkpoint.com/results/sk/sk158292)For the list of all CloudGuard Network Registry Modules, see [sk183294](https://support.checkpoint.com/results/sk/sk183294). > <br /> > ### Upgrading Cloud Firewall Gateway > 1. Download the relevant Fast Deployment Package from [sk177714 - In-Place Upgrade packages for Cloud Firewall](https://support.checkpoint.com/results/sk/sk177714). > 2. Import it into the SmartConsole package repository. > 3. Right-click the Fast Deployment Package and click **Upgrade**. *** ** * ** *** |||
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk122485/arrow-transp1809060017.png) SmartConsole > 1. Download the SmartConsole **installation EXE file** : >    [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk183506/R822025112009182714.10_button-SmartConsole_EXE.png)](https://support.checkpoint.com/results/download/144524) > 2. Transfer the SmartConsole installation file to a Windows-based computer you wish to use as a SmartConsole Client. > 3. Run the SmartConsole installation file with Administrator privileges and follow the on-screen instructions. > * For Web SmartConsole, see [sk170314](https://support.checkpoint.com/results/sk/sk170314) > * For Portable SmartConsole, see [sk116158](https://support.checkpoint.com/results/sk/sk116158) *** ** * ** *** |||

<br />

|---|---|---|
| Additional Downloads and Products {#Tools} ------------------------------------------ |||
| Show / Hide |-------------------------------------|---|---|---|---|---|---| | Product                             | Download         |||||| | **Fast Deployment Package (Blink)** | See [sk120193](https://support.checkpoint.com/results/sk/sk120193) |||||| | **Upgrade Tools package**           | See [sk135172](https://support.checkpoint.com/results/sk/sk135172) |||||| | **DLP Agent for Exchange Server**   | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk110426/arrow.png)](https://support.checkpoint.com/results/download/140672) For Windows (MSI) |||||| |||

<br />

**[Release map](https://support.checkpoint.com/results/sk/sk152052) \| [Upgrade and Backward Compatibility maps](https://support.checkpoint.com/results/sk/sk113113) \| [Releases Terminology](https://support.checkpoint.com/results/sk/sk95746)**

<br />

|---------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------|
| ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk111841/CHECKMATES1705110544.PNG) | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk170416/r81_release_notes202106131356408.png) | ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk181127/Education202504231341281.png) |
| **[Check Point CheckMates Community](https://community.checkpoint.com)**              | [**Early Availability (EA) Programs**](https://support.checkpoint.com/results/sk/sk183058)        | **[Education and Training](https://support.checkpoint.com/results/sk/sk163417)**          |

<br />

|---|---|---|
| Revision History {#History} --------------------------- |||
| Show / Hide <br /> |-------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | Date        | Description                                                                                                                                                                                             | | 12 Aug 2026 | R82.10 was declared as Check Point Recommended version for all deployments                                                                                                                              | | 10 Aug 2026 | * Fast Deployment Package: 3900 Appliances, Security Gateway, Security Management, and Multi-Domain Security Management were updated to Jumbo Take 40. * SmartConsole EXE file was updated to Build 426 | | 21 Jun 2026 | Fast Deployment Package: 3900 Appliances, Security Gateway, Security Management, and Multi-Domain Security Management were updated to Jumbo Take 24.                                                    | | 26 May 2026 | Fast Deployment Package: Security Gateway, Security Management, and Multi-Domain Security Management were updated to Jumbo Take 19.                                                                     | | 26 May 2026 | Updated SmartConsole package to Build 424.                                                                                                                                                              | | 20 Apr 2026 | Quantum Force 3900 Appliances have been renamed to Check Point Firewall 3900 Appliances. No functional changes were made.                                                                               | | 14 Apr 2026 | CloudGuard Network has been renamed to Cloud Firewall. No functional changes were made.                                                                                                                 | | 09 Apr 2026 | Fast Deployment Package: Security Gateway, Security Management, and Multi-Domain Security Management were updated to Jumbo Take 6.                                                                      | | 09 Apr 2026 | Added links to R82.10 Jumbo Hotfix Accumulator and R82.10 SmartConsole Releases.                                                                                                                        | | 06 Apr 2026 | Updated SmartConsole package to Build 422.                                                                                                                                                              | | 31 Mar 2026 | GA version was updated to Take 467.                                                                                                                                                                     | | 1 Mar 2026  | Added CloudGuard Network \> Deployment Options for OCI (Oracle Cloud Infrastructure)                                                                                                                    | | 21 Jan 2026 | Added CloudGuard Network \> Deployment Options for Microsoft Azure                                                                                                                                      | | 08 Jan 2026 | * Added CloudGuard Network \> Deployment Options for GCP (Google Cloud Platform) * Updated the upgrade instructions for Maestro Security Groups and Maestro Orchestrator                                | | 05 Jan 2026 | Added: * Note that Scalable Chassis 44000 / 64000 do not support R82.10 * CloudGuard Network \> Deployment Options for AWS and Private Cloud                                                            | | 29 Dec 2025 | First release of this document.                                                                                                                                                                         | |||

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
