What's New in R82.20
AI Security
-
Workforce AI Security empowers organizations to safely adopt generative AI tools while protecting sensitive data and ensuring compliance. By inspecting prompts and files uploaded to AI applications, it provides full visibility into how AI is used across your environment. Granular policies help prevent data leakage, reduce risk, and promote responsible, compliant use of AI, so every user in the network can work confidently with AI tools without compromising security.
-
Introducing AI Agent Security for Large Language Model (LLM) applications. Check Point Firewalls can now leverage Check Point AI Guardrails to protect generative AI and agentic AI traffic with advanced AI-based security controls, including Prompt Injection protection, Content Moderation, and protection for MCP tool responses. AI Guardrails helps prevent malicious prompts, detect unsafe or non-compliant content, and identify suspicious tool responses before they reach AI applications.
Threat Prevention
Threat Prevention Blades
-
SNORT 3.x rules syntax is now supported in IoC Feeds. This increases coverage of supported SNORT rules and enables compatibility with the latest threat detection content.
-
DNS Trap now supports IPv6 connections, enabling DNS-based threat prevention capabilities in IPv6 environments.
HTTPS Inspection
-
New TLS Inspection Block page – When HTTPS Inspection
Feature on a Check Point Firewall that inspects traffic encrypted by the Secure Sockets Layer (SSL) protocol for malware or suspicious patterns. Synonym: SSL Inspection. Acronyms: HTTPSI, HTTPSi. blocks a TLS connection because of server certificate issues (revoked, expired, or untrusted), a notification page explaining the reason for the block is now displayed.
Security Hardening
-
Enhances Frontier AI protection with an independent IPS
Software Blade on a Check Point Firewall that inspects and analyzes packets and data for numerous types of risks (Intrusion Prevention System). engine that safeguards the Check Point Firewall
Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. Formerly: Security Gateway. against direct attacks, without requiring IPS activation or an IPS subscription.
Check Point Firewall
Identity Awareness
-
Check Point Firewalls now support Cisco SGT (TrustSec) tagged traffic for pass-through and identity enforcement. Access Role
Access Role objects let you configure network access according to: Networks, Users and user groups, Computers and computer groups, Remote Access Clients. After you activate the Identity Awareness Software Blade, you can create Access Role objects and use them in the Source and Destination columns of Access Control Policy rules. objects can now match a specific Cisco SGT for access control directly from the network traffic.
Check Point Firewall Enhancements
-
Introducing the FedRAMP mode for Check Point Firewalls. This new mode directs cloud-dependent services to use FedRAMP authorized endpoints. The supported services are: URL Filtering
Software Blade on a Check Point Firewall that allows granular control over which web sites can be accessed by a given group of users, computers or networks. Acronym: URLF., Application Control
Software Blade on a Check Point Firewall that allows granular control over specific web-enabled applications by using deep packet inspection. Acronym: APPI., Anti-Bot
Software Blade on a Check Point Firewall that blocks botnet behavior and communication to Command and Control (C&C) centers. Acronyms: AB, ABOT., Anti-Virus
Software Blade on a Check Point Firewall that uses real-time virus signatures and anomaly-based protections from ThreatCloud to detect and block malware at the Check Point Firewall before users are affected. Acronym: AV., Zero Phishing
Software Blade on a Check Point Firewall (R81.20 and higher) that provides real-time phishing prevention based on URLs. Acronym: ZPH., and Threat Emulation
Software Blade on a Check Point Firewall that monitors the behavior of files in a sandbox to determine whether or not they are malicious. Acronym: TE..Note: Threat Extraction
Software Blade on a Check Point Firewall that removes malicious content from files. Acronym: TEX. and IPS do not rely on cloud services and are, therefore, compliant by default. -
Introducing DNS TTL-Aware Domain Enforcement - Domain object lookups and caching now follow the DNS Time to Live (TTL) value instead of fixed refresh intervals. This improves enforcement accuracy and reduces DNS query load by approximately 80%. This feature is disabled by default.
-
Gaia Portal
Web interface for the Check Point Gaia operating system. now allows Check Point Firewalls to automatically establish Secure Internal Communication (SIC
Secure Internal Communication. The Check Point proprietary mechanism with which Check Point computers that run Check Point software authenticate each other over SSL, for secure communication. This authentication is based on the certificates issued by the ICA on a Check Point Management Server.) to initiate a connection to the Management Servers (both on-premises and Smart-1 Cloud deployments) and fetch a predefined Security Policy
Collection of rules that control network traffic and enforce organization guidelines for data protection and access to resources with packet inspection.. See sk184397. -
Check Point Firewalls can now have more than one interface with a Dynamically Assigned IP Address (DAIP).
Upgrade
-
Introducing a new way to perform major upgrades on your Check Point Firewalls, either locally through CPUSE
Check Point Upgrade Service Engine for Gaia Operating System. With CPUSE, you can automatically update Check Point products for the Gaia OS, and the Gaia OS itself. or centrally through SmartConsole
Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on. using the Version Upgrade workflow. You can now split the upgrade process into two phases: Prepare and Complete. -
The Prepare phase advances the upgrade process as far as possible without introducing downtime. Depending on the platform and upgrade scenario, this phase can download the upgrade package, verify it, and install it on a parallel partition, stopping just before the actions that require service interruption.
-
During the Complete phase, the remaining upgrade steps are performed, including configuration migration and the final reboot into the new version. By separating preparation from completion, administrators can significantly decrease the maintenance window and downtime associated with major upgrades.
-
Hardware Acceleration
-
Hardware Acceleration support is now available for SecureXL
Performance-enhancing technology on a Check Point Firewall that accelerates IPv4 and IPv6 traffic that passes through the Check Point Firewall. "Penalty Box" and "IP Deny List" features, enhancing Check Point Firewall resilience to DDoS attacks. -
Traditional VSX
Virtual System Extension. Check Point virtual networking solution, hosted on a computer or cluster with virtual abstractions of Check Point Firewalls and other network devices. These Virtual Devices provide the same functionality as their physical counterparts., GRE pass-through traffic, and IPsec can now be accelerated in hardware when using 40/100GbE and 10/25GbE acceleration cards, supporting line-rate throughput and low latency.
Gaia OS
-
Gaia
Check Point security operating system that combines the strengths of both SecurePlatform and IPSO operating systems. OS introduces Unified Configuration, expanding and streamlining advanced configuration management across the platform and related products, and deprecating the use of Expert mode. Advanced system and feature configurations, including kernel parameters and cross-feature settings, are now managed using the Gaia Portal, Gaia Clish
The name of the default command line shell in Check Point Gaia operating system. This is a restricted shell (role-based administration controls the number of commands available in the shell)., or the Gaia RESTful API, providing consistent access.A new Advanced Configuration page in Gaia Portal delivers a simplified, efficient experience for managing all settings across multiple features. All configuration changes are processed through a unified API framework, ensuring configuration persistence across reboots and upgrades, with full auditability and traceability.
-
Check Point Firewall 3900 Appliances now support integrated switching. Multiple LAN ports can be grouped into Layer 2 segments, allowing traffic between devices in the same segment to be switched directly, improving performance. Traffic between different segments or to external networks continues to be processed by the firewall and enforced according to the configured security policy.
Dynamic Routing
Introducing these enhancements:
OSPFv3 enhancement:
-
OSPFv3 authentication using ESP, providing secure routing exchanges and protection against unauthorized route injection.
BGP enhancements:
-
BGP support over multiple Virtual Tunnel Interfaces (VTIs) with the same local address, enabling flexible routing across multiple tunnels.
-
AS-path prepend on import, allowing control of inbound traffic by influencing path selection.
-
BGP peer groups with auto-discovery, simplifying configuration for large-scale BGP deployments.
General routing enhancements:
-
Wildcard mask support for more flexible route matching and filtering.
-
IGMP and MLD blocked groups, preventing joins to restricted multicast groups and improving multicast security.
-
Route-map configuration via WebUI, improving usability and simplifying the configuration of the routemaps feature.
-
Monitoring of NAT Pools.
-
Monitoring of IPv4 static multicast routes (static mroutes).
Cluster and Scalability
-
ElasticXL synchronization traffic is now encrypted using Layer 2 encryption (MACsec). This protects all traffic between ElasticXL Cluster
Two or more Check Point Firewalls that work together in a redundant configuration - High Availability, or Load Sharing. Members. -
In VSNext VSLS mode, each Virtual Gateway now has an independent clustering state. A "Down" cluster state on a specific Virtual Gateway does not affect the other Virtual Gateways in the cluster; they remain "Active" and can continue processing traffic.
-
Maestro, ElasticXL, and ClusterXL clustering health status have been refined to include critical states such as high memory, low disk space, or packet drops because of congestion. This triggers an alert that is visible in SmartConsole. By default, this feature is enabled in monitor mode.
IPv6 Enhancements
Check Point Firewall
-
Suspicious Activity Monitoring (SAM) has been redesigned and integrated with the Gaia API, enabling dynamic, API-driven configuration similar to Dynamic Policy Layers. This enhancement includes full IPv6 support alongside the existing SAM commands.
-
You can now configure the Check Point Firewall management interface for IPv4-only, IPv6-only, or Dual-Stack (both IPv4 and IPv6) operation during the Gaia OS installation or in the Gaia First Time Configuration Wizard, supporting single-stack IPv6 deployments from initial setup.
-
Added support for IPv6 Dead Peer Detection (DPD)-based Tunnel Monitoring for Permanent Tunnels and IPv6 DPD-based Multiple Entry Point (MEP) topology. These enhancements enable reliable VPN resilience and liveness checks over IPv6, including mixed IPv4/IPv6 tunnels in redundant and multi-entry point deployments.
-
IPv6 support for identity enforcement in Identity Awareness
Software Blade on a Check Point Firewall that enforces network access and audits data based on network location, the identity of the user, and the identity of the computer. Acronym: IDA. using Identity Agent
Check Point dedicated client agent installed on Windows-based user endpoint computers. This Identity Agent acquires and reports identities to the Check Point Firewall with Identity Awareness enabled. The administrator configures the Identity Agents (not the end users). There are two types of Identity Agents - Full and Light. You can download the Full and Light Identity Agent package from the Captive Portal - 'https://<Gateway_IP_Address>/connect' or from Support Center. was extended to include multiple address types, including link-local, Global Unicast Address (GUA), and Unique Local Address (ULA). It also fully supports Privacy Extension (RFC 8981), ensuring consistent identity-based policies even as IPv6 addresses change dynamically. -
Added support for Route-based VPN over IPv6.This enables BGP and numbered VTI-based VPN tunnels in IPv6 environments for improved flexibility and compatibility.
Dynamic Routing
Added support for IPv6 for:
-
Equal-Cost Multi-Path (ECMP) for static and dynamic routing protocols.
-
Policy-Based Routing (PBR) now supports IPv6. This enables administrators to define custom routing decisions for IPv6 traffic based on source, destination, or other packet attributes.
-
Static multicast routes (static mroutes).
-
Multicast Listener Discovery (MLD) Group Limit, protecting against DoS attacks by preventing excessive group joins.
-
MLDv1 SSM mapping, bridging legacy MLDv1 hosts to Source-Specific Multicast (SSM
In Maestro - a role of the Maestro Orchestrator that manages the flow of network traffic to and from the Security Groups. For Scalable Chassis - see "Security Switch Module".). -
IPv6 PIM Embedded RP eliminating the need for external RP-mapping mechanisms and simplifying IPv6 PIM-SM multicast deployment.
VoIP
-
Added support for SIP traffic over IPv6.
Licensing
-
Added support for IPv6 licenses.
Tools
-
Improved performance of FW Monitor troubleshooting utility on Check Point Firewall 19100, 19200, 29100, and 29200 Appliances. The new CLI flag provides exclusion filtering capabilities, such as exclusion expression.
Hybrid Mesh, SASE and SD-WAN
SASE
-
Introducing Unified Management of Internet Access policies for Check Point Firewalls and Check Point SASE environments. You can now manage SASE Internet Access directly from Check Point SmartConsole, providing a single point of policy management across your hybrid infrastructure.
-
Introducing SmartConsole single-click IPsec tunnel setup between a Check Point Firewall and Check PointSASE. Providing best practices for both full mesh and hub-and-spoke (star) topologies and supporting policy-based and route-based modes.
SD-WAN
-
Dynamic Routing with Equal-Cost Multi-Path (ECMP) is now supported. It allows SD-WAN
Software Defined – Wide Area Network (WAN), more information on this solution:
https://www.checkpoint.com/cyber-hub/network-security/what-is-sd-wan/ to use the best path to a destination out of multiple routes with the same metric. -
Backhaul Data Center failover for local breakout link degradation - SD-WAN can fail over to a Data Center
Virtual centralized repository, or a group of physical networked hosts, Virtual Machines, and datastores. They are collected in a group for secured remote storage, management, and distribution of data. backhaul connection upon ISP links quality degradation, and not only when the ISP links are completely unavailable. -
Layer 2 Overlay Support - Overlay networks can now operate without requiring a next-hop configuration, enabling direct peer-to-peer VPN connections between Check Point Firewalls on the same local network, such as in VPLS deployments.
-
Simplified Carrier Grade NAT (CGNAT) Configuration - CGNAT no longer requires Dynamic IP object configuration when a Management Server
Check Point Single-Domain Security Management Server or a Multi-Domain Security Management Server. can reach a Check Point Firewall directly, enabling ClusterXL support and simplified Smart-1 Cloud deployments. -
IPv6 - SD-WAN can now intelligently route IPv6 traffic to the local internet breakout and VPN Overlay.
-
Link Quality Threshold now includes bandwidth - Configuring bandwidth requirements per application is now optional to ensure SD-WAN selects interfaces that meet traffic capacity needs. Set minimum bandwidth threshold alongside latency, jitter
Variation in the delay of received packets. On the sending side, packets are spaced evenly apart and sent in a continuous stream. On the receiving side, the delay between each packet can vary according to network congestion, improper queuing or configuration errors., and packet loss requirements for interface selection. -
Symmetric Return for Gateway Traffic - Traffic destined to a Check Point Firewall, such as SSH sessions and policy installations, now returns through the same interface it arrived on, ensuring compatibility with ISP policies that restrict traffic with external IP addresses.
-
Application-Based Quality of Service - Define bandwidth guarantees and limits per application in SD-WAN policies. Prioritize critical applications with minimum bandwidth reservations while capping less important traffic, with automatic traffic shaping across both overlay and local breakout paths.
Cloud Firewall
-
Introducing Unified Management with Native AWS Network Firewall that enables administrators to manage cloud-native Firewall policies directly from SmartConsole alongside the existing Access Control Policy. After connecting an AWS
Amazon Web Services. Public cloud platform that offers global compute, storage, database, application and other cloud services. account, administrators can create, install, and monitor Cloud Policy across AWS Network Firewalls from a single console, with direct access to the AWS Console for additional firewall details, logs, and AWS resources.
Cloud Firewall Controller
Cloud Firewall Controller now supports:
-
Sending identities to VSNextCheck Point Firewalls where the PDP
Check Point Firewall with Identity Awareness enabled that acts as Policy Decision Point: acquires identities from identity sources; shares identities with other gateways.Check Point Firewall is part of the VSNext and operates as one of the Virtual Systems. -
Azure Managed Identity authentication method for Azure Data Centers.
-
Network CIDRs for Data Center Objects such as VPCs, VNets, and NSGroups. When these assets are used in the rule base
All rules configured in a given Security Policy. Synonym: Rulebase., the Cloud Firewall Controller sends the entire CIDR to the Check Point Firewall in a single update and improves policy enforcement coverage by matching the full CIDR to a specific policy rule
Set of traffic parameters and other conditions in a Rule Base (Security Policy) that cause specified actions to be taken for a communication session..
Supported Data Centers: AWS, Azure, GCP
See "Google Cloud Platform"., VMware NSX-T
A network virtualization and security platform that operates within a single data center or cloud environment. It provides software-defined networking, security (like distributed firewall and micro-segmentation), and load balancing for virtualized workloads, containers, and bare-metal servers., VMware Global NSX-T, Cisco ACI
Cisco Application Centric Infrastructure. Comprehensive SDN architecture, policy-based automation solution for increased scalability through a distributed enforcement system with greater network visibility. Trademark of Cisco., and Oracle OCI.
Smart-1 and Smart-1 Cloud Management
Management Enhancements
-
Introducing these features in the AI Auditor (formerly Policy Auditor):
-
Assigned Global Policy - Enables AI Auditor guidelines to seamlessly work with Global Policy
On a Multi-Domain Security Management Server, a policy defined in the Global Domain. You can assigns this Global Policy to Domains., incorporating global rules for enhanced functionality. -
Allowed / Non-Violating Services - Provides the ability to define services within each Guideline cell that are exempt from causing violations.
-
Enhanced Audit Log & Change Report - Delivers improved accuracy in reflecting changes made to Guidelines, ensuring a more reliable audit trail.
-
Support of IPv6 network objects.
-
-
Introducing new integrations:
-
Configuration Management Database (CMDB) Integration - An integration between the Security Management Server
Dedicated Check Point server that runs Check Point software to manage the objects and policies in a Check Point environment within a single management Domain. Synonym: Single-Domain Security Management Server. and ServiceNow CMDB that enables the import of Configuration Items (CIs) and tags into SmartConsole for direct use in the Access Control Policy. -
Microsegmentation Integration - An integration between the Security Management Server and Illumio or Akamai Guardicore that enables the import of workloads, assets, and segmentation labels into SmartConsole for direct use in the Access Control Policy.
Supported objects include Illumio workloads and labels, as well as Akamai Guardicore assets and labels. -
Operational Technology (OT) Integration - An integration between the Security Management Server and Nozomi or Claroty CTD that extends Check Point OT capabilities by importing OT assets and associated metadata into SmartConsole for direct use in the Access Control Policy.
Supported objects include Nozomi assets and tags, and Claroty CTD assets.
These integrations simplify policy management, improve visibility into application and workload segmentation, reduce object maintenance, and enable automatic policy enforcement on the Check Point Firewall without requiring an additional policy installation.
-
-
Centralized .def file Management -
.deffile settings can now be configured directly through SmartConsole and APIs. The settings are stored centrally in the database, enabling full auditing and revision history, centralized management, and seamless persistence across upgrades and backups.
Web SmartConsole
-
Added support for these features and capabilities:
-
Full support for Remote Access VPN Community, including Advanced Encryption settings, User groups, and the VPN Domain.
-
Threat Prevention - Profiles and Protections.
-
Firewall Settings - HTTPS Inspection, Logs, Fetch Policy, IPS, NAT, and Proxy.
-
Manage Settings - Administrators, Permission Profiles, Sessions.
-
Additional capabilities - Install/Uninstall of Jumbo Hotfix
Software package installed on top of the current software version to fix a wrong or undesired behavior, and to add a new behavior. Accumulators, Manage Policies, Changes Report
Summary of network activity and Security Policy enforcement that is generated by Check Point products, such as SmartEvent., Clone Objects.
-
For the updated list, see sk170314.
-
Natural Language Rule Base Search - You can now enter search requests in natural language. The AI will automatically convert your input into a structured Rule Base query and apply the relevant filter, streamlining the search process.
-
Object Assistant - Easy interaction with AI to inquire about objects and configure them directly using natural language. This functionality is integrated into the object editor to provide a smoother, more intuitive experience within the editor context.
Upgrade
-
Introducing a new background upgrade capability designed to significantly minimize downtime to a few minutes during Management Server upgrades.
The "Prepare Upgrade" phase runs seamlessly in the background, allowing administrators to continue working in SmartConsole, Web SmartConsole, or API without disruption.
The "Complete Upgrade" phase then finalizes the changes, significantly reducing downtime compared to traditional upgrade methods.
Logging and Monitoring
-
New Logs and Dashboard Views - Introducing a modern, intuitive interface designed to make security monitoring faster, easier, and more effective. This new feature includes AI-powered search and advanced capabilities, enabling users to investigate events, uncover insights, and take actions more efficiently.
-
Log Exporter can be configured to export only the first and/or the latest update per event
Record of a security or network incident that is based on one or more logs, and on a customizable set of rules that are defined in the Event Policy. or connection. This enables more efficient log processing by external SIEM (Security Information and Event Management) tools. -
Log Exporter can now be configured with the Management API. This enables you to automate Log Exporter deployment and configuration within your infrastructure-as-code workflows.
-
Log Exporter can now be configured to send logs directly to AWS S3 buckets. This enables seamless integration with your existing cloud storage and log analytics workflows.
-
In the SmartConsole Gateways & Servers view, the Check Point Firewall status now changes to warning (yellow triangle icon) if the Check Point Firewall is writing logs locally for more than 5 minutes. This helps you quickly identify connectivity issues between the Check Point Firewall and its Log Server
Dedicated Check Point server that runs Check Point software to store and process logs..