What's New in R82.20

AI Security

  • Workforce AI Security empowers organizations to safely adopt generative AI tools while protecting sensitive data and ensuring compliance. By inspecting prompts and files uploaded to AI applications, it provides full visibility into how AI is used across your environment. Granular policies help prevent data leakage, reduce risk, and promote responsible, compliant use of AI, so every user in the network can work confidently with AI tools without compromising security.

  • Introducing AI Agent Security for Large Language Model (LLM) applications. Check Point Firewalls can now leverage Check Point AI Guardrails to protect generative AI and agentic AI traffic with advanced AI-based security controls, including Prompt Injection protection, Content Moderation, and protection for MCP tool responses. AI Guardrails helps prevent malicious prompts, detect unsafe or non-compliant content, and identify suspicious tool responses before they reach AI applications.

Threat Prevention

Threat Prevention Blades

  • SNORT 3.x rules syntax is now supported in IoC Feeds. This increases coverage of supported SNORT rules and enables compatibility with the latest threat detection content.

  • DNS Trap now supports IPv6 connections, enabling DNS-based threat prevention capabilities in IPv6 environments.

HTTPS Inspection

Security Hardening

Check Point Firewall

Identity Awareness

Check Point Firewall Enhancements

Upgrade

Hardware Acceleration

Gaia OS

Dynamic Routing

Introducing these enhancements:

OSPFv3 enhancement:

  • OSPFv3 authentication using ESP, providing secure routing exchanges and protection against unauthorized route injection.

BGP enhancements:

  • BGP support over multiple Virtual Tunnel Interfaces (VTIs) with the same local address, enabling flexible routing across multiple tunnels.

  • AS-path prepend on import, allowing control of inbound traffic by influencing path selection.

  • BGP peer groups with auto-discovery, simplifying configuration for large-scale BGP deployments.

General routing enhancements:

  • Wildcard mask support for more flexible route matching and filtering.

  • IGMP and MLD blocked groups, preventing joins to restricted multicast groups and improving multicast security.

  • Route-map configuration via WebUI, improving usability and simplifying the configuration of the routemaps feature.

  • Monitoring of NAT Pools.

  • Monitoring of IPv4 static multicast routes (static mroutes).

Cluster and Scalability

IPv6 Enhancements

Check Point Firewall

Dynamic Routing

Added support for IPv6 for:

VoIP

  • Added support for SIP traffic over IPv6.

Licensing

  • Added support for IPv6 licenses.

Tools

  • Improved performance of FW Monitor troubleshooting utility on Check Point Firewall 19100, 19200, 29100, and 29200 Appliances. The new CLI flag provides exclusion filtering capabilities, such as exclusion expression.

Hybrid Mesh, SASE and SD-WAN

SASE

  • Introducing Unified Management of Internet Access policies for Check Point Firewalls and Check Point SASE environments. You can now manage SASE Internet Access directly from Check Point SmartConsole, providing a single point of policy management across your hybrid infrastructure.

  • Introducing SmartConsole single-click IPsec tunnel setup between a Check Point Firewall and Check PointSASE. Providing best practices for both full mesh and hub-and-spoke (star) topologies and supporting policy-based and route-based modes.

SD-WAN

Cloud Firewall

Cloud Firewall Controller

Cloud Firewall Controller now supports:

Smart-1 and Smart-1 Cloud Management

Management Enhancements

  • Introducing these features in the AI Auditor (formerly Policy Auditor):

  • Introducing new integrations:

    These integrations simplify policy management, improve visibility into application and workload segmentation, reduce object maintenance, and enable automatic policy enforcement on the Check Point Firewall without requiring an additional policy installation.

  • Centralized .def file Management - .def file settings can now be configured directly through SmartConsole and APIs. The settings are stored centrally in the database, enabling full auditing and revision history, centralized management, and seamless persistence across upgrades and backups.

Web SmartConsole

  • Natural Language Rule Base Search - You can now enter search requests in natural language. The AI will automatically convert your input into a structured Rule Base query and apply the relevant filter, streamlining the search process.

  • Object Assistant - Easy interaction with AI to inquire about objects and configure them directly using natural language. This functionality is integrated into the object editor to provide a smoother, more intuitive experience within the editor context.

Upgrade

  • Introducing a new background upgrade capability designed to significantly minimize downtime to a few minutes during Management Server upgrades.
    The "Prepare Upgrade" phase runs seamlessly in the background, allowing administrators to continue working in SmartConsole, Web SmartConsole, or API without disruption.
    The "Complete Upgrade" phase then finalizes the changes, significantly reducing downtime compared to traditional upgrade methods.

Logging and Monitoring

  • New Logs and Dashboard Views - Introducing a modern, intuitive interface designed to make security monitoring faster, easier, and more effective. This new feature includes AI-powered search and advanced capabilities, enabling users to investigate events, uncover insights, and take actions more efficiently.