Updates, Health, and Ongoing Protection

Upgrade to Latest Recommended Jumbo Hotfix Accumulator

Check Point periodically releases Jumbo Hotfix Accumulators (JHFs) for each supported version. These releases consolidate stability fixes, reliability improvements, performance enhancements, and security related corrections into a tested and supported package.

Running the recommended Jumbo Hotfix Accumulator is a foundational hardening step and should be treated as a baseline requirement for production Security Gateways and Management Servers.

Recommendation: Always run Check Point Security Gateways and Management Servers on:

  • A supported major release, and

  • The currently recommended Jumbo Hotfix Accumulator for that release

Delaying adoption of recommended Jumbo Hotfix Accumulators increases operational risk, reduces platform resilience, and limits the effectiveness of other hardening controls described in this document.

Recommended Jumbo Hotfix Accumulator Takes include important security and stability fixes that reduce exposure to known issues.

Implementation reference:

sk95746 - Check Point Recommended Version and Release Terminology.

Upgrades are available:

  • From the local Gaia Portal:

  • From SmartConsole:

Enable Dynamic Updates (AutoUpdater Utility)

Recommendation: This utility enables dynamic security updates including IPS updates and security fixes.

Dynamic updates keep protections current without requiring disruptive upgrades or reboots.

Ensure that you provide consent for Check Point to install security updates as following the instructions in sk175504:

  1. In SmartConsole top-left corner, click the Menu button > click Global properties.

  2. In the Data Access Control pane, select this checkbox:

    Automatically download and install Software Blade Contracts, security updates, and other important data (highly recommended)

  3. Click OK.

  4. Install the Access Control policy.

This will ensure only security updates will be installed and no other unnecessary updates.

Check Point uses this mechanism to mitigate vulnerability as interim preventative measure that helped protect many customers before they were even aware.

Implementation reference:

Enable Diagnostics and Telemetry (cpdiag)

Recommendation: Enable your Check Point Management Servers and Security Gateways to share essential non-PII, diagnostics data with Check Point cloud.

Check Point Diagnostics collects usage information and status telemetry of the product operation. This helps improve supportability and enable proactive identification of issues (without replacing your logging strategy). This is essential for Check Point to identify and proactively alert if your products are exposed to a known vulnerability. The collection and transmission of the data is not CPU-intensive and is shared every 24 hours.

Ensure that you provide consent for Check Point to install security updates by following the instructions in sk175504:

  1. In SmartConsole top-left corner, click the Menu button > click Global properties.

  2. In the Data Access Control pane, select this checkbox:

    Help Check Point improve the product by sending anonymous information

  3. Click OK.

  4. Install the Access Control policy.

Implementation reference:

sk184778 - CPDiag (Check Point Diagnostics) Release Updates.