> Source: [sk184658](https://support.checkpoint.com/results/sk/sk184658)

# sk184658 - PCI Compliance scan fails on Spark Firewall appliances running R81.10.17

| Property | Value |
|----------|-------|
| Solution ID | sk184658 |
| Date Created | 2026-02-10 |
| Last Modified | 2026-05-03 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1500, 1900, 2000, 1600, 1800, 15x5 |

## Symptoms

- * PCI compliance scan fails with the error message "*Weak Diffie-Hellman groups on UDP/500*."

* PCI compliance scan fails with the error message "*3DES encryption on UDP/500.*."

## Cause

Note that there are multiple possible causes for the PCI compliance scan failure, including:

* Weak Diffie-Hellman (DH) groups (Groups 1-4) are detected over UDP/500.

* 3DES encryption is no longer considered secure.

## Solution

This problem was fixed. The fix is included starting from:

* [R82.00.10 (Build 998002133)](https://support.checkpoint.com/results/sk/sk183419?server=us)

For R81.10.17:

1. Contact [Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to request the custom R81.10.17 firmware build 996004834.

2. Install the new firmware on the Spark Firewall appliance.

   To perform a manual firmware upgrade, refer to the R81.10.X Locally Managed Administration Guide \> [System Operations](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Backup-Restore-Upgrade-and-Other-System-Operatons.htm)page.
3. **If relevant**:

   Configure strong Diffie-Hellman Groups for Remote Access VPN in Advanced Settings:
   1. Log in to the Spark Firewall WebUI as an administrator and navigate to the **Device** View \> **Advanced** section \> **Advanced Settings** page.

   2. Search for the attribute **DH Group used for Phase 1**.

   3. Set the Diffie-Hellman group to Group 14 or higher.

   4. Enable the option **Force selected DH Group for Phase 1**.

   5. Click **Save**.

4. Run a new PCI compliance scan.

5. Confirm that the scan no longer reports weak Diffie-Hellman groups or 3DES support on UDP/500.

6. Check that Remote Access VPN connections function as expected.  

   <br />

   <br />

   <br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
