sk113113
Check Point Upgrade Path and Management Servers and Security Gateways Compatibility Maps
Product: ClusterXL, ElasticXL, Maestro HyperScale Firewall, Multi-Domain Security Management, Scalable Chassis, Security Gateways, Security Management, VSNext, VSX (Traditional)
Version: R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.20.X (EOS), R80.20SP (EOS), R80.30 (EOS), R80.30SP (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10
OS: Gaia
Last Modified: 2026-07-16
Solution
This article provides:
- Upgrade Path Map - The matrix of source versions, from which you can upgrade and target versions, to which you can upgrade.
- Backward and Forward Compatibility - The matrix of Management Server versions and Security Gateway versions they can manage.
- Link to the applicable documents.
Important - For the End-of-Support dates, see Support Life Cycle Policy.
Upgrade Path Map for Security Gateways, Management Servers, Log Servers, SmartEvent Servers
For complete information, refer to the Release Notes for the target version.
Below is the matrix of source versions, from which you can upgrade (appear in the left-most column) and target versions, to which you can upgrade (appear in other columns).
It not supported to upgrade or convert Security Gateways to another version for Scalable Platforms.
Legend:
- Yes = This upgrade path is supported
- Yes = This upgrade path is supported, with prerequisites or limitations
- No = This upgrade path is not supported
Enter the source version to filter this table:
| Source Versions | ← Target Versions → | ||||||||||
| ↓ | To R82.10 |
To R82 |
To R81.20 |
To R81.10 |
To R81 |
To R80.40 |
To R80.30 (3.10) |
To R80.30 (2.6) |
To R80.20 (3.10) |
To R80.20 (2.6) |
To R80.10 |
| From R82 | Yes | No | No | No | No | No | No | No | No | No | No |
| From R81.20 | Yes | Yes | No | No | No | No | No | No | No | No | No |
| From R81.10 | Yes | Yes | Yes | No | No | No | No | No | No | No | No |
| From R81 | Yes | Yes | Yes | Yes | No | No | No | No | No | No | No |
| From R80.40 | Yes | Yes | Yes | Yes | Yes | No | No | No | No | No | No |
| From R80.30 3.10 | Yes | Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| From R80.30 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No | No | No |
| From R80.20 3.10 | No | Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| From R80.20 2.6 | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No | No |
| From R80.10 | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| From R80 | No | Yes | Yes | Yes | Yes | Yes | No | Yes | Yes | Yes | Yes |
| From R77.30 | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| ↑ | To R82.10 |
To R82 |
To R81.20 |
To R81.10 |
To R81 |
To R80.40 |
To R80.30 (3.10) |
To R80.30 (2.6) |
To R80.20 (3.10) |
To R80.20 (2.6) |
To R80.10 |
| Source Versions | ← Target Versions → |
Notes:
This Management Server / Log Server / SmartEvent Server / StandAlone Server requires a 2-step upgrade path (does not apply to Security Gateways):
- From the current version to R80.40 (see the R80.40 Installation and Upgrade Guide).
- From R80.40 to R81.10 (see the R81.10 Installation and Upgrade Guide).
This Management Server / Log Server / SmartEvent Server / StandAlone Server requires a 2-step upgrade path (does not apply to Security Gateways):
- From the current version to R80.40 (see the R80.40 Installation and Upgrade Guide).
- From R80.40 to R81.20 (see the R81.20 Installation and Upgrade Guide).
This Security Gateway / Management Server / Log Server / SmartEvent Server / StandAlone Server requires a 2-step upgrade path:
- From the current version to one of these versions:
- R81.20 (see the R81.20 Installation and Upgrade Guide).
- R81.10 (see the R81.10 Installation and Upgrade Guide).
- R81 (see the R81 Installation and Upgrade Guide).
- R80.40 (see the R80.40 Installation and Upgrade Guide).
- Upgrade to R82 (see the R82 Installation and Upgrade Guide).
- From the current version to one of these versions:
This Security Gateway / Management Server / Log Server / SmartEvent Server / StandAlone Server requires a 2-step upgrade path:
- From the current version to one of these versions:
- R81.20 (see the R81.20 Installation and Upgrade Guide).
- R81.10 (see the R81.10 Installation and Upgrade Guide).
- R81 (see the R81 Installation and Upgrade Guide).
- Upgrade to R82.10 (see the R82.10 Installation and Upgrade Guide).
- From the current version to one of these versions:
This upgrade map applies to CloudGuard Network Security installation in Private Cloud.
This upgrade map applies to CloudGuard Network Security installation in Public Cloud with these notes:
AWS Cross-AZ Clusters can be managed only by a Management Server R81.20 and higher.
In-place upgrade is supported only for R80.30 and higher for the specific configurations listed in sk177714 - In-Place Upgrade packages for CloudGuard Network.
For documentation, see sk162365 - Upgrade/Update documentation for CloudGuard Network Security in Public Cloud.
Upgrade Path Map for Scalable Platforms
For complete information, refer to the Release Notes for the target version.
Below is the matrix of source versions, from which you can upgrade (appear in the left-most column) and target versions, to which you can upgrade (appear in other columns).
You can upgrade a Scalable Platform only to another version for Scalable Platforms.
Note - Releases R82.10 and higher do not support Scalable Chassis 41000 / 44000 / 61000 / 64000.
Legend:
- Yes = This upgrade path is supported
- Yes = This upgrade path is supported, with prerequisites or limitations
- No = This upgrade path is not supported
Enter the source version to filter this table:
| Source Versions | ← Target Versions → | |||||||
| ↓ | To R82.10 for Scalable Platforms |
To R82 for Scalable Platforms |
To R81.20 for Scalable Platforms |
To R81.10 for Scalable Platforms |
To R81 for Scalable Platforms |
To R80.30SP for Maestro |
To R80.20SP for Maestro |
To R80.20SP for Chassis |
| From R82 for Scalable Platforms |
Yes | No | No | No | No | No | No | No |
| From R81.20 for Scalable Platforms |
Yes | Yes | No | No | No | No | No | No |
| From R81.10 for Scalable Platforms |
Yes | Yes | Yes | No | No | No | No | No |
| From R81 for Scalable Platforms |
Yes | No | Yes | Yes | No | No | No | No |
| From R80.30SP for Maestro |
Yes | No | Yes | Yes | No | No | No | No |
| From R80.20SP for Maestro |
Yes | No | Yes | Yes | No | No | No | No |
| From R80.20SP for Chassis |
No | No | Yes | Yes | No | No | No | No |
| ↑ | To R82.10 for Scalable Platforms |
To R82 for Scalable Platforms |
To R81.20 for Scalable Platforms |
To R81.10 for Scalable Platforms |
To R81 for Scalable Platforms |
To R80.30SP for Maestro |
To R80.20SP for Maestro |
To R80.20SP for Chassis |
| Source Versions | ← Target Versions → |
Notes:
- Upgrade from these versions to R81.10 is supported only with the required Takes of Jumbo Hotfix Accumulators. See sk173363.
- Upgrade from these versions to R81.20 is supported only with the required Takes of Jumbo Hotfix Accumulators. See sk177624.
- Upgrade from these versions to R82 is supported only with the required Takes of Jumbo Hotfix Accumulators. See sk181127.
- Upgrade from these versions to R82.10 is supported only with the required Takes of Jumbo Hotfix Accumulators. See sk183506.
Management Servers and Security Gateways they can manage
Below is the matrix of Management Servers ( appear in columns) and Security Gateways ( appear in rows) they can manage.
For example, if you have a Security Gateway R81.10, then you can manage it with:
- Management Server R81.10
- Management Server R81 (12)
Legend:
- Yes = This Management Server can manage this Security Gateway
- Yes = This Management Server can manage this Security Gateway, but requires a software package, or limitations exist
- No = This Management Server can not manage this Security Gateway
Enter the Security Gateway version to filter this table:
| Security Management Servers and ← Multi-Domain Security Management Servers → |
||||||||||
| Security Gateways ↓ |
R82.10 | R82 | R81.20 | R81.10 | R81 | R80.40 | R80.30 | R80.20 | R80.10 | R80 |
| R82.10 (including Scalable Platforms) |
Yes | Yes | No | No | No | No | No | No | No | No |
| Spark Firewall R82.00.X | Yes | Yes | Yes | Yes | No | No | No | No | No | No |
| R82 (including Scalable Platforms) |
Yes | Yes | No | No | No | No | No | No | No | No |
| R81.20(including Maestro and Scalable Chassis) | Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| Quantum Spark R81.10.X(13) | Yes | Yes | Yes | Yes | No | No | No | No | No | No |
| R81.10(including Maestro and Scalable Chassis) | Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| R81(including Maestro and Scalable Chassis) | Yes | Yes | Yes | Yes | Yes | No | No | No | No | No |
| R80.40 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| R80.30SP for Maestro | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| R80.30 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| R80.20SP for Maestro | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| R80.20SP for Chassis | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| R80.20 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| Quantum Spark R80.20.X(13) | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | No |
| R80.10 | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No |
| R77.30 | No | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| SMB R77.20.X(2) | No | No | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| R76SP.50, R76SP.40, R76SP.30, R76SP.20, R76SP.10_VSLS, R76SP.10, R76SP for Chassis |
No | No | No | No | No | Yes | Yes | Yes | Yes | Yes |
| UTM-1 Edge(3) | No | No | No | No | No | No | Yes | Yes | Yes | Yes |
| ↑ Security Gateways |
R82 | R82 | R81.20 | R81.10 | R81 | R80.40 | R80.30 | R80.20 | R80.10 | R80 |
| ← Security Management Servers → and Multi-Domain Security Management Servers |
Notes:
- Supported with some limitations. Refer to R80.10 Jumbo Hotfix Accumulator - Take 167 (see PMTR-22521).
- "SMB" refers only to Small and Medium Business Centrally Managed appliances 1400 / 1200R / 1100.
- "UTM-1 Edge" refers only to "Edge N Industrial". (UTM-1 Edge of models X, X Industrial, W, and N are not supported).
- R80.20 Management Server requires these to manage R80.30 Security Gateways:
- R80.20 Jumbo Hotfix Accumulator - Take 91 or higher (see PRJ-645).
- R80.20 SmartConsole - Build 55 or higher (see PRJ-651).
- R80.10 Management Server requires these to manage R80.30 Security Gateways:
- R80.10 Jumbo Hotfix Accumulator - Take 225 or higher (see PRJ-601).
- R80.10 SmartConsole - Build 137 or higher (see PRJ-648).
- R80.30 Management Server requires these to manage R80.40 Security Gateways:
- R80.30 Jumbo Hotfix Accumulator - Take 166 or higher (see PRJ-9461).
- R80.30 SmartConsole - Build 62 or higher (see PRJ-9463).