> Source: [sk183754](https://support.checkpoint.com/results/sk/sk183754)

# sk183754 - Microsoft Azure Network Adapter (MANA)

| Property | Value |
|----------|-------|
| Solution ID | sk183754 |
| Date Created | 2025-08-10 |
| Last Modified | 2026-08-24 |
| Technical Level | General |
| Products | SmartConsole, Multi-Domain Security Management Server, Cloud Firewall |
| Versions | R82.10, R82.10, R82.10, R82, R81.20, R81.10 (EOS), R81.10 (EOS), R81.10 (EOS), R81.20, R82, R81.20, R82 |
| OS | Gaia |

## Solution

**Table of Contents:**

* How to Opt Out
* Operations That Trigger MANA Allocation
* Affected Deployment Types
* Rollout Schedule
* Supported Releases
* FAQ
* Limitations

Click Here to Show the Entire Article

Microsoft Azure is deploying new network infrastructure that uses [Microsoft Azure Network Adapters (MANA)](https://learn.microsoft.com/en-us/azure/virtual-network/accelerated-networking-mana-overview).

### How to Opt Out {#TARGET_ID_3}

Show / Hide this section

> Applying the opt-out tag (`LegacyVMNVA`) keeps your instances on Mellanox-enabled infrastructure. Mellanox is the proven, validated path for Check Point deployments.  
>
> The opt-out mechanism is **retired on May 30, 2027**. After that date, Azure places all instances on MANA-enabled infrastructure regardless of opt-out status. Use the time before this date to complete validation and plan your migration.
>
> **Opt-out** is highly recommended before any of the triggering operations described in the next section.
>
> Follow the official Microsoft opt-out procedure: [MANA support for Network Virtual Appliances - Microsoft documentation](https://learn.microsoft.com/en-us/azure/virtual-network/accelerated-networking-mana-network-virtual-appliance-opt-out#temporary-mana-exception-with-legacyvmnva).
>
> **Note:** Newer Check Point templates automatically apply the `LegacyVMNVA` tag to opt VMs out of Azure's new MANA networking hardware.

### Operations That Trigger MANA Allocation {#TARGET_ID_4}

Show / Hide this section

> Azure places a VM on MANA-enabled hardware during the following operations, if you have not applied the opt-out tag beforehand:
>
> |-------------------------------------|-------------------------------------------------------------------------------------------------------------------------------|
> | Operation                           | Description                                                                                                                   |
> | New deployment                      | Any new VM provisioned in an affected region.                                                                                 |
> | Stop and start via the Azure portal | Stopping and restarting a VM through the portal (not a reboot) triggers reallocation. A reboot does not trigger reallocation. |
> | Scale-out                           | New instances added to a Virtual Machine Scale Set (VMSS) are provisioned fresh and are subject to MANA allocation.           |
>
> **IMPORTANT:**
>
> Already-running VMs that are not stopped, redeployed, or scaled out are not affected - until May 30, 2027.

### Affected Deployment Types {#TARGET_ID_5}

Show / Hide this section

> The table below shows which operations can trigger MANA allocation for each Check Point deployment type. This applies only when you have not applied the opt-out tag.
>
> |-------------------------------------------------|----------------|-----------------------|-----------|
> | Deployment type                                 | New deployment | Stop/start via portal | Scale-out |
> | Cloud Firewall Gateways and HA Clusters         | ?              | ?                     | -         |
> | Cloud Firewall Standalone                       | ?              | ?                     | -         |
> | Cloud Firewall Virtual Machine Scale Set (VMSS) | ?              | ?                     | ?         |
> | Cloud Firewall for Virtual WAN (vWAN)           | Automatically opted out --- no action required   |||
> | Security Management Server                      | ?              | ?                     | -         |
> | Multi-Domain Server                             | ?              | ?                     | -         |
> | Log Server                                      | ?              | ?                     | -         |
> | SmartEvent Server                               | ?              | ?                     | -         |
>
> **Action required:** Opt-out all deployment types listed above, except vWAN.   
> Azure opts out vWAN deployments automatically.

### Rollout Schedule {#TARGET_ID_6}

Show / Hide this section

> MANA is rolling out to all VM sizes and regions starting August 1, 2026.  
>
> **v5 VM Types - Rollout in Progress**   
> *(Updated May 27, 2026)*
>
> |--------------|-----------------|
> | Date         | Region          |
> | May 26, 2026 | West Central US |
> | May 27, 2026 | East Asia       |
> | May 28, 2026 | Norway West     |
> | May 29, 2026 | Spain Central   |
>
> Microsoft will announce additional regions via Microsoft Service Health notification on May 29, 2026.
>
> **All Other Instance Types**
>
> Apply the opt-out tag before August 1, 2026. VMs created or tagged after this date may be placed on MANA-capable hardware.

### Supported Releases {#TARGET_ID_7}

Show / Hide this section

> To enable operations with the MANA driver, the following Check Point releases are required as prerequisites:
>
> * [R82 Jumbo Hotfix Take 103 and higher](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/R82_Downloads.htm)
> * [R82.10 Jumbo Hotfix Take 19 and higher](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/R82.10/R82.10_Downloads.htm?tocpath=_____3)
>
> In these versions, the MANA driver is included but disabled by default, and must be explicitly enabled to be used.
>
> **Note:** For R82 Jumbo Hotfix Take 103 and higher, the MTU of MANA driver has a default value of 1500 and cannot be changed.
>
> **Important:** Releases earlier than R82 do not include the MANA driver. Upgrade to R82 or later before enabling MANA.
>
> **Note:** R81.20, R81.10 and earlier releases are also affected by MANA allocation - Azure may place instances running these versions on MANA-enabled hardware regardless of the Check Point release installed.  
>
> If your instances run R81.20, R81.10, or an earlier release, you have two options:
>
> 1. Opt out of MANA (recommended immediately) - Apply the Azure opt-out tag to keep your instances on Mellanox-enabled infrastructure until May 30, 2027.
> 2. Upgrade to R82 or later - This is the only path to eventual MANA support. After upgrading, make sure you are on a supported Jumbo Hotfix take before enabling the MANA driver.

### FAQ {#TARGET_ID_8}

Show / Hide this section

> Q: What happens if the tag does not take effect?
>
> A: VM placement is ultimately managed by Azure. Because of that, Microsoft is the best resource for understanding how these situations are handled. If you run into a case where the tag does not apply as expected, we recommend reaching out to Microsoft support - they can walk you through the specifics and help get this issue resolved.

### Limitations {#TARGET_ID_9}

Show / Hide this section

> 1. Mana driver does not support MTU change.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
