# Upgrade packages for Cloud Firewall

## Solution

This article provides CPUSE packages for an in-place upgrade of Cloud Firewall (formerly CloudGuard Network Security) in Public Cloud.

**Important:** Before upgrade, make sure your Security Management Server version can manage your Cloud Firewall version (see [sk113113](https://support.checkpoint.com/results/sk/sk113113)).

### Prerequisites

- **Security Management / Multi-Domain Security Management Server:**
  
  Verify that your Security Group allows connections to TCP port 18208.
- **HA / Cluster deployments:**
  
  Install the applicable Jumbo Hotfix Accumulator:
  
  - R81.10 (EOS)  Jumbo Hotfix Accumulator Take 79 (or higher)
  - R81 (EOS) Jumbo Hotfix Accumulator Take 77 (or higher)
  - R80.40 (EOL) Jumbo Hotfix Accumulator Take 180 (or higher)

### CPUSE packages

| Upgrade to version | Upgrade from version | CPUSE identifier | Download | Installation and Upgrade Guide |
| --- | --- | --- | --- | --- |
| **R82.10** | R82, R81.20, R81.10, R81 | aio_Check_Point_R82.10_T467_Gaia_Install_and_Upgrade.tgz ⧉ |  |  |
| **R82** | R81.20, R81.10, R81 | aio_Check_Point_R82_T779_Gaia_Install_and_Upgrade.tgz ⧉ |  |  |
| **R81.20** | R81.10, R81, R80.40 | aio_Check_Point_ivory_main_T634__R81.20_Gaia_3_10_Install_and_Upgrade.tgz ⧉ |  |  |
| **R81.10** | R81, R80.40, R80.30 | aio_Check_Point_ignis_main_T335_R81.10_Gaia_3_10_Install_and_Upgrade.tgz ⧉ |  |  |

### Instructions

- [sk92449 - Check Point Upgrade Service Engine (CPUSE) - Gaia Deployment Agent](https://support.checkpoint.com/results/sk/sk92449).
- For upgrade instructions, refer to the Installation and Upgrade Guide for the target version (for example, [R82.10 Installation and Upgrade Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Installation_and_Upgrade_Guide/Content/Topics-IUG/Getting-Started.htm)).
- For supported upgrade methods, refer to the Release Notes for the target version (for example, [R82.10 Release Notes](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_RN/Content/Topics-RN/Supported-Upgrade-Methods.htm)).

After the upgrade, on a Security Gateway / Cluster:

1. Connect with SmartConsole to the Management Server.
2. From the left navigation panel, click Gateways & Servers.
3. Double-click the Security Gateway object.
4. In the Version field, select the new version value.
5. Click OK.
6. Install the Access Control policy on the Security Gateway / Cluster object.

### Important Notes

- Cloud Firewall for AWS:
  
  Revert from R81.20 is not supported.

### Supported Configurations

- Single Security Gateway / Cluster Security Gateway (including Azure VWAN gateways as per [Cloud Firewall for Azure Virtual WAN Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_Azure_vWAN/Content/Topics-Azure-vWAN/Upgrade.htm))
- Security Management Server / Multi-Domain Security Management Server

### Non-Supported Configurations

- Standalone (All-in-One Management + Gateway) deployments
- Azure VMSS / AWS Auto Scale Groups / GCP MIG
- Upgrading AWS Geo Cluster to R81.20

## Article Properties

**Access Level:** General  
**Status:** Approved  
**Date Created:** 2022-02-01  
**Last Modified:** 2026-07-07
