sk166056 - MaaS (Management as a Service) Tunnel Release Updates

MaaS (Management as a Service) Tunnel Release Updates

Product: Smart-1
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
Last Modified: 2026-05-17

Solution

Introduction | Manual Installation | Availability | Documentation | List of Resolved issues

Introduction

This article lists all released automatic updates for Smart-1 Cloud MaaS (Management as a Service) tunnel.

The MaaS (Management as a Service) tunnel is a secure HTTPS connection between a Check Point Security Gateway and the Smart-1 Cloud service. It enables all communication between the Security Gateway and the cloud management platform, ensuring secure and dependable management of the gateway via the cloud.

The MaaS tunnel package is installed automatically on all relevant Check Point devices when Automatic Update downloads are enabled (see sk175504, section 2-B).

If Automatic Updates are disabled, you must first manually install the latest AutoUpdater Take and then install the MaaS tunnel package manually using the steps below.

Manual Installation (Offline)

Install a new package manually

  1. Download the applicable TAR package for your Security Gateway / Cluster Members / Scalable Platform Security Group.

  2. Transfer the TAR package to the Security Gateway / each Cluster Member / Scalable Platform Security Group.

  3. Connect to the command line on the Security Gateway / each Cluster Member / Scalable Platform Security Group.

  4. Log in to the Expert mode:

    expert

  5. On the Scalable Platform Security Group, copy the TAR package to all Security Group Members:

    asg_cp2blades

  6. Install the package:

    • On the Security Gateway / each Cluster Member:

      autoupdatercli install

    • On the Scalable Platform Security Group:

      g_all autoupdatercli install

Check which version is currently installed on the Security Gateway

  1. Connect to the Security Gateway / each Cluster Member / Scalable Platform Security Group.
  2. Log in to the Expert mode.
  3. Get the information about all installed Release Updates and filter the output only for the Smart-1 Cloud Release Updates (MaaS):
    • On the Security Gateway / each Cluster Member:

      autoupdatercli show | grep -A 25 'product-name: maas'

    • On the Scalable Platform Security Group:

      g_all autoupdatercli show | grep -A 25 'product-name: maas'

  4. In the 'MaaS' section of the output, refer to these lines:
    • The line ' package-version' shows the version number
    • The line ' package-installed' must show the value ' true'.

Example output:

Availability

Latest Take Release Date Package Download Security Gateway
Version
Take 13 17 May 2026 (TAR) For Check Point Firewall
3900 Appliances
(TAR) R82.10 and higher
Take 75 17 May 2026 (TAR) R80.40 (EOS), E81 (EOS), R81.10 (EOS), R81.20, R82

Documentation

List of Resolved issues and New Features per MaaS tunnel Update

ID Release Version Description
Update 9 - Take 13/Take 75 - Gradually released from 17 May 2026
ODU-4100,
ODU-4093
R80.40 and higher - Enhancement: Proxy requests through the MaaS Tunnel now enforce the HTTP Host header requirement, improving security and system performance by dropping non-RFC-compliant traffic at the Gateway.
- Enhancement: Improvements in error handling.
- Minor fixes.
Update 8 - Take 68 (29 Jan 2025)
ODU-2227 R80.40 and higher - Enhancement: Added support for VSNext.
Update 7 - Take 60 (7 Jan 2024)
ODU-1408 R80.40 and higher - Enhancement: Added support for Maestro Security Groups. Refer to sk181495.
- VRRP cluster vtunnel may crash due to a different "cphaprob state" output.
- Prolonged recovery time in handling communication error with cloudinfra.
- When the auto SIC feature is enabled, maas on may reset the SIC.
Update 6 - Take 49 (31 Aug 2022)
ODU-608,
MAAS-2782
R80.40 and higher - Enhancement: The ca-bundle-public-cloud.crt file is now used for tunnel communication by default.
MAAS-2785 -  Enhancement: It is now possible to change the default crt file for maas communication. To do so, run the "maas on -f " command.
Update 5 -Take 47 (28 Jul 2022)
ODU-518 R80.40 and higher - Static route for cluster VIP may not be established on a Security Gateway with R81.10 Jumbo Hotfix Accumulator Take 55 installed.
MAAS-2562 - Standalone Security Gateways are not supported. When trying to add such a Gateway into the cloud, MaaS tunnel will be blocked immediately.
Update 4 - Take 45 (22 Feb 2022)
ODU-286 R80.40 and higher - Enhancement: Enhanced tunnel's stability in edge cases when the Management API Server is not responsive.
Update 3 - Take 44 (15 Dec 2021)
ODU-200 R80.40 and higher - Enhancement: Added support for R81.10 automatic updates 
- After a cluster failover CloudGuard Controller may not be able to find cloud objects.
Update 2 - Take 40 (for R80.40 and higher) - Take 61 (for R80.10 - R80.30) (17 Aug 2021)
ODU-103 R80.10 - R80.30 - Tunnel’s process remains alive even when it cannot connect to Infinity Portal.
ODU-104 R80.40 and higher - Enhancement: Added support for R81 Security Gateways
- Enhancement: Added support on on-premises database migration without reset SIC. 
- Tunnel’s process remains alive even when it cannot connect to Infinity Portal.
Update 1 -  Take 31 (for R80.40 and higher) - Take 53 (for R80.10 - R80.30) (1 Mar 2021)
ODU-83
ODU-84
R80.40 and higher
R80.10 - R80.30
- Enhancement: Preserve token during Gateway's version upgrade
- Enhancement: SIC Certificate auto-renewal
- Enhancement: Configurable timeout of our tunnel (in case of latency)
- Enhancement: Proxy code limitation fixes

Article Properties

Access Level: General
Status: Approved
Date Created: 2021-03-13
Last Modified: 2026-05-17