# R82 Release Notes

## What's New in R82

### Introduction

**R82** is Check Point's major software release for Quantum products and Cloud Firewall Security. It introduces 50 innovative capabilities to strengthen threat prevention, greatly streamline operations and provisioning, and troubleshoot network connections with integrated diagnostics tools.

This release provides access to new AI-powered threat prevention engines that strengthen defense against zero-day phishing, brand spoofing, malware, and more. R82 also adds DNS protection against NXNS, offers DNS configuration granularity, and supports DNS-over-HTTPS Inspection on a Security Gateway.

Check Point offers the industry's first complete protection for HTTP/3 over QUIC. R82 also enables effortless and automated HTTPS Inspection deployment with granular controls and exceptional performance.

## Threat Prevention

### AI-based prevention engines

Check Point's new AI security engines represent a shift in how we utilize data, transitioning from mostly a single indicator perspective to a multi-dimensional approach.

- **[ThreatCloud Graph](https://blog.checkpoint.com/security/introducing-threatcloud-graph-a-multi-dimensional-perspective-on-cyber-security/)** - Leverages AI knowledge base to form relationship graph, identifying attacks patterns to prevent zero-day threats.
- **Kronos** - Inspects behavior over time to detect malicious activity, preventing zero-day C2, phishing campaigns and other threats.
- **[Deep Brand Clustering](https://blog.checkpoint.com/security/deepbrand-clustering-an-evolution-in-brand-spoofing-prevention/)** - Prevents zero-day brand phishing campaigns with a patent-pending unsupervised deep learning engine.
- **Dynamic classification of uncategorized websites** - An AI-based engine that categorizes URLs to block dangerous or inappropriate websites.

### Improved DNS Security Capabilities

This release provides new and enhanced DNS security capabilities:

- **Advanced DNS protection against Non-Existent Domain (NXNS) Attack**.
- **Support for DNS over HTTPS (DoH) protocol**.
- **[Configuration Granularity](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ThreatPrevention_AdminGuide/Default.htm#cshid=ID001)** - Advanced DNS Security settings.
- **Detailed DNS Security statistics** - Now available in the SmartView Dashboard.

### Automatic Security Services Configuration

[Zero Phishing](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RN/Skins/Default/Stylesheets/Images/transparent.gif), [Anti-Virus](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RN/Skins/Default/Stylesheets/Images/transparent.gif), [Anti-Bot](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RN/Skins/Default/Stylesheets/Images/transparent.gif) and [IPS](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RN/Skins/Default/Stylesheets/Images/transparent.gif) Software Blades are now easier to configure, offering a more user-friendly experience.

- **Automatic mode** - This significantly simplifies the configuration process, providing a seamless experience.
- Software Blades like Anti-Virus and Anti-Bot are now activated by default in newly created Security Gateway and Cluster objects.

### Web Security

- Added support of HTTP/3 protocol over QUIC transport for Network Security, Threat Prevention, and Sandboxing.

### HTTPS Inspection

This release sets a new standard with breakthrough performance, unmatched simplicity, and effortless deployment of HTTPS Inspection. You can significantly increase your security without sacrificing speed or user experience.

- **Enhanced HTTPS Inspection UI** - Fully managed in SmartConsole, with a dedicated policy for inbound inspection and enhanced settings.

## Security Gateway

### New Clustering Technology

- **[ElasticXL](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_ScalablePlatforms_AdminGuide/Default.htm#cshid=ID001)** - A new clustering technology delivering simplified operations.

### Dynamic Policy Layer

- Fully automated, API-controlled policy layer that allows dynamic policy changes to be implemented directly on the Security Gateway.

### Identity Awareness

Security Gateways can now use multiple external Identity Providers, providing a cross product unified identity management.

### IPSec VPN (Site to Site VPN)

- Added support for ML-KEM (Kyber768) as required by the FIPS 203 standard.

- Enhanced Link Selection with redundancy and granularity.

### Remote Access VPN

Security Gateway supports the IKEv2 protocol for connections from Remote Access VPN Clients.

### Mobile Access

Policy and Capsule Workspace configurations are now available in SmartConsole.

### Dynamic Routing

Added support for new Dynamic Routing capabilities and REST API calls for BGP and other functions.

### Performance and Infrastructure

- **HyperFlow** acceleration of elephant flows.
- Increased log rate output capacity.

### Maestro, Scalable Chassis, and ElasticXL

This release features improvements in managing and monitoring Scalable Platform clusters.

### Tools and Utilities

- New tool `connview` to view connection information.
- New tool `fw up_execute` for virtual Access Control / NAT execution.

## Gaia Operating System

This release boosts Gaia OS with a new OS kernel and multiple new configuration options for better security and enhanced networking.

### Security Management Server Enhancements

Support for Management API to run operations and manage multiple gates with concurrent policy installations.

### SmartConsole

Added the ability for system accounts to install SmartConsole and integration of HealthCheck Point tests.

### Multi-Domain Security Management Server

Ability to clone existing Domain and improved upgrade time.

### Compliance

Added support for new regulations and best practices.

## Cloud Firewall Security

### CloudGuard Controller

Now supports Identity Awareness and VMware NSX-T integration.

## Endpoint Security Web Management

- Client optimization for Windows servers.
- Exclusions enhancements.
- New Asset Management view.
