> Source: [sk87621](https://support.checkpoint.com/results/sk/sk87621)

# sk87621 - Bypass (Fail-Open) network interface card FAQ

| Property | Value |
|----------|-------|
| Solution ID | sk87621 |
| Date Created | 2012-11-13 |
| Last Modified | 2025-04-02 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |
| Platform | 15000, 5000, 7000, 28000, 16000, 26000, 6000 |

## Solution

Show All

* In which versions is the Bypass Card supported?  
  > This feature is supported for R7x and R80.x versions running on Gaia OS only, in Single Gateway configuration.
  > * For VSX R77 and above, the Bypass Card Hotfix is required. Contact Check Point Solution Center via local Check Point office to get a Bypass Card Hotfix.
* What Bypass Card models are available?  
  > Supported Bypass Cards:  
  > * 1 GbE Copper, 4 port
  > * 10 GbE SFP+ Line Card, 2 Port
  >
  > <br />
  >
  > For more information, refer to [Check Point Security Appliance Accessories Guide](https://www.checkpoint.com/downloads/product-related/datasheets/appliance-accessories-guide.pdf) and to the relevant Appliance Datasheet.
* How do I order a bypass card?  
  > Refer to the Check Point Product Catalog:
  > 1. Go to [User Center](https://usercenter.checkpoint.com/usercenter/index.jsp) - Log in
  > 2. At the top, click on the '`QUOTING TOOLS`' menu - click on the '`Product Catalog & Quoting`'
  > 3. Go to '`NETWORK SECURITY`' section - click on the relevant appliance
  > 4. Wait for the information to be loaded
  > 5. Scroll down to the '`Accessories & Add Ons`' - near '`More Add ons & Accessories`', click on a down-pointing triangle
  > 6. Wait for some short time for the information to be loaded
  > 7. Refer to '`Bypass (Fail-Open)`' item(s) - get the 'SKU' of the relevant card
* How do I install the card?  
  > For Download links, Installation Guides, Feature Descriptions, and additional information, refer to [sk85560 - Installing a Bypass (Fail-Open) network interface card on Check Point appliances](http://supportcontent.checkpoint.com/solutions?id=sk85560).
* What appliances support the Bypass Card?  
  > The Bypass feature is supported by the 4000, 5000, 12000, 13000, 15000, 23000, 6000, 7000, 16000, 26000 and 28000 appliance series.  
  > It is also supported on SandBlast Appliances TE100x, TE250X, TE1000X, TE2000X and TE2000X HPP.
* Can higher-end appliances models, such as 64000 / 44000, support the Bypass Card for IPS?  
  > This is currently not supported.  
  > If Bypass Card is required on other appliances, please open a Request for Enhancement (RFE) with Check Point (contact the *local Check Point office* to submit such RFE).
* When Bypass is enabled, can High Availability be supported?  
  > The Bypass Card is not supported in Cluster environments (High Availability mode or Load Sharing modes).  
  > This is an undesirable scenario and if required, it should be well investigated.   
  >
  > When Bypass kicks in, communication between the cluster members is not guaranteed. The traffic might pass through the first device in fail-open mode with no inspection and will be transparent to the switches on both sides. Again, this is an undesirable scenario in cluster environments.
* When Bypass is enabled, is performance degradation expected?  
  > The Bypass feature should not increase latency or any performance degradation.
* Does Bypass card support Link Aggregation (Bond)?  
  > Link Aggregation (Bonding) of ports on a Bypass card / of Bypass cards is not supported.
* Is Bypass card supported in VSX mode?  
  > Starting from R77, Bypass Card is also supported in VSX mode.  
  > Contact Check Point Solution Center via local Check Point office to get a Bypass Card Hotfix.
* How long does it take for the NIC to fail open?  
  > If bypass is initiated, the flipping is immediate as this is hardware bypass. Yet, the thresholds for each of the following states should be considered:  
  > * There is a power loss - Immediate
  > * The appliance is rebooting - Immediate
  > * Unable to allocate memory in kernel - Immediate
  > * High CPU and packet drops - Threshold is set to 5,000 drops and 85% CPU usage within 20 seconds.
  > * DLP process is crash - 20 crashes within 300 seconds
  > * FWD process is not responding - Threshold is set to 75 seconds
* Can the Bypass cards be configured to stay in bypass state?  
  > This is currently not supported.
* Are there any limitations when using this card?  
  > Refer to [sk85560](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk85560) (section: Known Limitations).
* Is there any limitation/degradation expected when Bypass card is installed, but bypass feature is not enabled?  
  > No. If bypass mode is not enabled, there should be no difference between using Bypass (Fail-Open) card and normal NIC.
* Is 10GbE ByPass supported?  
  > 10GbE ByPassis supported on all appliances

**Related Solution:** [sk96246 - Documentation For Check Point Appliances](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk96246)  

Solution was incorporated into R80.30 Jumbo Hotfix Take 217 (PRJ-12833), for additional information refer to [sk153152 -](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152)  
[Jumbo Hotfix Accumulator for R80.30 (R80_30_jumbo_hf)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
