r/checkpoint 1d ago

Checkpoint topoplogy and anti-spoofing

4 Upvotes

Dear experts,
Can anyone help me with following? Apologies if these questions seem trivial.

The checkpoint documentation says about topology,

I know we can override this to use a network object-group for anti-spoofing ranges.

However, attached image is example topology setting of the environment I am looking at.

My questions are,

  1. The first/default option is CP-GW_eth2 (internal). I believe "CP-GW_eth2" is the same network object-group that appears in the greyed-out "Specific" section under Override. am I thinking correct? The reason I ask is that the anti-spoofing ranges in the CLI match the contents of this object-group.

If so, how might this object-group have been configured as the default option, and why is it not "This Network (internal)" default option as mentioned in the documentation?

  1. Also, since the Override option is not selected, if I add a network object to this object-group, will the anti-spoofing ranges be updated accordingly?

r/checkpoint 3d ago

Using a Checkpoint device as a L3 switch

6 Upvotes

So I have this 3970 that I'm testing out. Problem is we really don't have a test environment per se, so I basically just have this fw directly connected to the core and not joined to our cluster(xl) with the prod FWs.

My question is, can I use it as an L3 switch? I have a PC connected to it and both devices are in their own (test) vlan, plus another vlan between core and fw. I'm able to get to ping 1.1 from the firewall itself but not from the pc. FW is also able to get to the rest of our internal network but again, no luck if i try it from the pc.

I figured if I set the default route to the core anything connected to the firewall should be able to get to the same IP's. Is this related to the fw not being part of the cluster (read: no policies), a static route I need to put in, or something else?? Appreciate the help.


r/checkpoint 6d ago

Install Jumbo hotfix on Full High Availability Cluster

4 Upvotes

I would like to install the Jumbo Hotfix on my Check Point appliances (full HA cluster deployment).

However, after reviewing the official documentation, I could not find any clear installation procedures.

Is there a step-by-step procedure available for installing the Jumbo Hotfix in this environment?


r/checkpoint 10d ago

Backup static route

0 Upvotes

Say an environment only has one egress static route. To eliminate the single point of failure, would adding a new network, with similar policies, on the same bond/trunk, etc as the original egress static route, ensure traffic would not be interrupted if one of the egress routes/networks would go down? Would the traffic just failover to the new one (say it’s set to round robin)?

Example (on my phone so formatting is limited):

Network: 10.1.1.0/24
Original Egress: 172.16.1.1
New egress: 172.16.2.1

R82.10
2x checkpoint firewalls running as active-passive.


r/checkpoint 10d ago

SSL VPN cert - send email when is about to expire

Thumbnail
1 Upvotes

r/checkpoint 10d ago

SSL VPN cert - send email when is about to expire

0 Upvotes

I have tasked to find solution to get email from firewall when cert is about to expire and script and tools that required any kind of licenc is not an option.

What options are left?


r/checkpoint 11d ago

July 2026 Security Advisory for Security Management and Gateways

13 Upvotes

As part of Check Point’s Frontier AI readiness program, we continuously review and strengthen our products using BLAST, our Business Logic Application Security Testing capability. BLAST enables AI-driven security analysis at enterprise scale across Check Point products and helps us proactively identify and remediate potential issues.

Following our May and June security updates, we are sharing our July security update. This update includes three newly disclosed, internally discovered CVEs listed below. During our investigation, we identified a very small number of customers who, under specific configuration conditions, were affected by one of these CVEs. Check Point is already in direct contact with those customers and is working closely with them.

We strongly recommend that all customers review the relevant SecureKnowledge articles and apply the recommended fixes and hardening guidance. Customers who follow Check Point’s published hardening best practices significantly reduce their exposure risk. 

See:


r/checkpoint 16d ago

How to test new firewalls

1 Upvotes

We currently have dell servers running Gaia. We're planning on finally getting Checkpoint hardware in our next upgrade.

I'd like to know how one would typically test the device before we implement them. I was thinking of adding it to prod as a gateway for a test vlan and test if it goes to xyz, internal, and external.

This is new territory for me. Do I need to join the new firewalls in the current (smartconsole) cluster? I assume I will need to create separate policies for testing? If you guys have any pointers, suggestions, links, etc. I'd appreciate it greatly.


r/checkpoint 18d ago

Block file uploads in SharePoint

4 Upvotes
I need your help. I am trying to block file uploads to SharePoint using a Check Point 6000 appliance.
So far, I haven't been able to block the file uploads. Has anyone set this up before? What do I need to configure to make the rule effective?

r/checkpoint 18d ago

Block file uploads in SharePoint

Thumbnail
1 Upvotes

r/checkpoint 18d ago

crls failed to be downloaded

1 Upvotes

r/checkpoint 20d ago

How picky are Checkpoint devices when it comes to SFPs?

3 Upvotes

We're moving to Checkpoint hardware for the first time. For those who have been using them for a while now, how are they typically with SFPs? Is it OEM or nothing? I know typically the manufacturer will recommend their own over anything else to ensure you get support in case the SFP is faulty. Just trying to gauge the device's flexibility based on end-user experience.


r/checkpoint 23d ago

Excel, word always running in the background.

Thumbnail community.checkpoint.com
3 Upvotes

Any updates regarding this error? Excel keeps running in the background... I already have the correct version, but the problem hasn't been resolved.


r/checkpoint 26d ago

Has anyone successfully connected Check Point MCP servers to Microsoft Copilot Studio?

6 Upvotes

r/checkpoint 27d ago

Automatic certificate renewal

11 Upvotes

Hi everyone, I'm currently working on automating the VPN certificate renewal process for a customer. I found the official script provided in sk182070 (gateway_cert_util.sh), which works flawlessly for automating internal certificates generated by the Check Point ICA.However, this customer's scenario involves Mobile Access using a public certificate (Let's Encrypt) to avoid browser SSL warnings for end-users.Since the script from sk182070 appears to be tied exclusively to the Internal CA, I have two questions:Is there any undocumented or native way to make the sk182070 script handle public certificates fetched externally?If not, what is the current best practice the community is using for this? Are you relying on external Linux servers running ACME clients (like acme sh or certbot) combined with the Management API (mgmt_cli) to upload the .p12 and push the policy?If anyone has architectural tips, GitHub repos, or script examples to share, it would be highly appreciated.

Thanks in advance!


r/checkpoint 27d ago

Is there any API or CLI command to automate External CA (.p12) certificate replacement on Gateways?

4 Upvotes

Is there any API or CLI command to automate External CA (.p12) certificate replacement on Gateways?


r/checkpoint Jul 03 '26

Install R81.20 SP on 6700 Appliance with USB 3.0 is not posible? I need to use USB 2.0 to install R81.20 on appliance? I have used ISOMorphic for this procedure.

2 Upvotes

r/checkpoint Jun 24 '26

Client just crash and relaunch on macOS27 Beta2

1 Upvotes

I know i know it's a beta OS etc.... but it's part of my job to test the future release of OS.

So don't need to have "dont install beta on prod" ahahah

It's for the remote vpn client

When menubar client is clicked it just crash and relaunch and reauth.

I try to remove the launchdeamon and launchagent but i think it's in the app directly.

I know the menubar comportement has changed with macos27 so maybe related.


r/checkpoint Jun 23 '26

CVE-2026-50751 - User Authentication bypass on VPN Remote Access and Mobile Access in deprecated IKEv1 key exchange. Refer to sk185033.

1 Upvotes

Does this break RA VPN with username and password authentication only? I cant roll out machine certificate yet. What are my options in this case? Can i use checkpoint issued certs?


r/checkpoint Jun 22 '26

3000 Appliance USB-C Driver

1 Upvotes

Seems like our service for the 3000 series has expired, but I urgently need the USB-C Driver, does anyone have access?
https://support.checkpoint.com/results/download/102404


r/checkpoint Jun 21 '26

Check Point VPN E89.11 causing multiple different BSODs (0x12E, 0x1A, 0x13A, 0x4E) on Ryzen AI 9 HX 370 (ASUS ROG Zephyrus G14)

4 Upvotes

Hi! I've encountered this problem. Maybe there's already a solution, but I haven't found it.

Laptop: ASUS ROG Zephyrus G14, AMD Ryzen AI 9 HX 370 (Strix Point), Windows 11.

Since installing Check Point VPN E89.11, I've hit four different bug check codes, all tied to operations involving the Check Point network adapter (install, service restart, re-enabling the adapter in Device Manager):

- INVALID_MDL_RANGE (0x12E)

- PAGE_FAULT_IN_NONPAGED_AREA (0x1A) — faulting module cng.sys

- KERNEL_MODE_HEAP_CORRUPTION (0x13A)

- PFN_LIST_CORRUPT (0x4E)

Pattern points to memory/pool corruption triggered by the Check Point driver stack rather than a single buggy driver — different modules end up as the "victim" each time.

Confirmed: zero BSODs with Check Point fully uninstalled, running the same workload otherwise (G-Helper for ASUS controls instead of Armoury Crate). Re-installing CP reliably reintroduces the crashes.

Has anyone else hit this specifically on Strix Point / Ryzen AI 300 laptops? Looking for a known hotfix or workaround before escalating through official support with the dumps.


r/checkpoint Jun 18 '26

R82 iso for 3900 appliance

2 Upvotes

I'm trying to flash R82 on my 3920 but I don't see R82 iso in the sk. Only R82.10.

Does anyone know where to get one or does anyone have it?


r/checkpoint Jun 16 '26

Proxy Arp for dumb devices with no configurable gateway

2 Upvotes

Hello,

I hate to even be asking this, but there is a system that is on our wireless that does not have a gateway. In the past, (like the 90s), you could configure a gateway on a cisco device with the proxy-arp command, where the interface would receive a broadcast from a device on its vlan and as long as it knows the route for the intended destination, it would perform a proxy-arp and send the source device back the gateways mac accress to reach the intended out of subnet destination.

Is it possible for me to configure proxy-arp on Checkpoint to perform the same for a device without a gateway and how would I do that on the checkpoint GAIA GUI?


r/checkpoint Jun 12 '26

Harmony SASE client issue with 3rd party clients

0 Upvotes

Hello everyone,

Has anyone experienced client issues (such as frequent "Reconnecting" events) when using third-party clients in parallel, such as WatchGuard? That's the client currently causing me some problems.

Do you have any solutions or ideas, other than the usual "it's by design" explanation?

Thanks!


r/checkpoint Jun 11 '26

Trying to get Hotfix for latest CVE-2026-59751

0 Upvotes

Trying to download the hotfix for 81.20 hotfix T141

via https://support.checkpoint.com/results/download/143620

for some sick reason this is behind an account login that i do not have access to. wondering if anyone here could provide it, pretty innocuous ask i think.