sk166056 - MaaS (Management as a Service) Tunnel Release Updates
MaaS (Management as a Service) Tunnel Release Updates
Product: Smart-1
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
Last Modified: 2026-05-17
Solution
Introduction | Manual Installation | Availability | Documentation | List of Resolved issues
Introduction
This article lists all released automatic updates for Smart-1 Cloud MaaS (Management as a Service) tunnel.
The MaaS (Management as a Service) tunnel is a secure HTTPS connection between a Check Point Security Gateway and the Smart-1 Cloud service. It enables all communication between the Security Gateway and the cloud management platform, ensuring secure and dependable management of the gateway via the cloud.
The MaaS tunnel package is installed automatically on all relevant Check Point devices when Automatic Update downloads are enabled (see sk175504, section 2-B).
If Automatic Updates are disabled, you must first manually install the latest AutoUpdater Take and then install the MaaS tunnel package manually using the steps below.
Manual Installation (Offline)
Install a new package manually
Download the applicable TAR package for your Security Gateway / Cluster Members / Scalable Platform Security Group.
Transfer the TAR package to the Security Gateway / each Cluster Member / Scalable Platform Security Group.
Connect to the command line on the Security Gateway / each Cluster Member / Scalable Platform Security Group.
Log in to the Expert mode:
expert
On the Scalable Platform Security Group, copy the TAR package to all Security Group Members:
asg_cp2blades
Install the package:
On the Security Gateway / each Cluster Member:
autoupdatercli install
On the Scalable Platform Security Group:
g_all autoupdatercli install
Check which version is currently installed on the Security Gateway
- Connect to the Security Gateway / each Cluster Member / Scalable Platform Security Group.
- Log in to the Expert mode.
- Get the information about all installed Release Updates and filter the output only for the Smart-1 Cloud Release Updates (MaaS):
On the Security Gateway / each Cluster Member:
autoupdatercli show | grep -A 25 'product-name: maas'
On the Scalable Platform Security Group:
g_all autoupdatercli show | grep -A 25 'product-name: maas'
- In the 'MaaS' section of the output, refer to these lines:
- The line ' package-version' shows the version number
- The line ' package-installed' must show the value ' true'.
Example output:
Availability
| Latest Take | Release Date | Package Download | Security Gateway Version |
|---|---|---|---|
| Take 13 | 17 May 2026 | (TAR) | For Check Point Firewall 3900 Appliances |
| (TAR) | R82.10 and higher | ||
| Take 75 | 17 May 2026 | (TAR) | R80.40 (EOS), E81 (EOS), R81.10 (EOS), R81.20, R82 |
Documentation
List of Resolved issues and New Features per MaaS tunnel Update
| ID | Release Version | Description |
|---|---|---|
| Update 9 - Take 13/Take 75 - Gradually released from 17 May 2026 | ||
| ODU-4100, ODU-4093 |
R80.40 and higher | - Enhancement: Proxy requests through the MaaS Tunnel now enforce the HTTP Host header requirement, improving security and system performance by dropping non-RFC-compliant traffic at the Gateway. - Enhancement: Improvements in error handling. - Minor fixes. |
| Update 8 - Take 68 (29 Jan 2025) | ||
| ODU-2227 | R80.40 and higher | - Enhancement: Added support for VSNext. |
| Update 7 - Take 60 (7 Jan 2024) | ||
| ODU-1408 | R80.40 and higher | - Enhancement: Added support for Maestro Security Groups. Refer to sk181495. - VRRP cluster vtunnel may crash due to a different "cphaprob state" output. - Prolonged recovery time in handling communication error with cloudinfra. - When the auto SIC feature is enabled, maas on may reset the SIC. |
| Update 6 - Take 49 (31 Aug 2022) | ||
| ODU-608, MAAS-2782 |
R80.40 and higher | - Enhancement: The ca-bundle-public-cloud.crt file is now used for tunnel communication by default. |
| MAAS-2785 | - Enhancement: It is now possible to change the default crt file for maas communication. To do so, run the "maas on -f |
|
| Update 5 -Take 47 (28 Jul 2022) | ||
| ODU-518 | R80.40 and higher | - Static route for cluster VIP may not be established on a Security Gateway with R81.10 Jumbo Hotfix Accumulator Take 55 installed. |
| MAAS-2562 | - Standalone Security Gateways are not supported. When trying to add such a Gateway into the cloud, MaaS tunnel will be blocked immediately. | |
| Update 4 - Take 45 (22 Feb 2022) | ||
| ODU-286 | R80.40 and higher | - Enhancement: Enhanced tunnel's stability in edge cases when the Management API Server is not responsive. |
| Update 3 - Take 44 (15 Dec 2021) | ||
| ODU-200 | R80.40 and higher | - Enhancement: Added support for R81.10 automatic updates - After a cluster failover CloudGuard Controller may not be able to find cloud objects. |
| Update 2 - Take 40 (for R80.40 and higher) - Take 61 (for R80.10 - R80.30) (17 Aug 2021) | ||
| ODU-103 | R80.10 - R80.30 | - Tunnel’s process remains alive even when it cannot connect to Infinity Portal. |
| ODU-104 | R80.40 and higher | - Enhancement: Added support for R81 Security Gateways - Enhancement: Added support on on-premises database migration without reset SIC. - Tunnel’s process remains alive even when it cannot connect to Infinity Portal. |
| Update 1 - Take 31 (for R80.40 and higher) - Take 53 (for R80.10 - R80.30) (1 Mar 2021) | ||
| ODU-83 ODU-84 |
R80.40 and higher R80.10 - R80.30 |
- Enhancement: Preserve token during Gateway's version upgrade - Enhancement: SIC Certificate auto-renewal - Enhancement: Configurable timeout of our tunnel (in case of latency) - Enhancement: Proxy code limitation fixes |
Article Properties
Access Level: General
Status: Approved
Date Created: 2021-03-13
Last Modified: 2026-05-17