sk179432 - Software Releases for LightSpeed QLS / MLS and Check Point Firewall 9000, 19000, 29000 Appliances

Software Releases for LightSpeed QLS / MLS and Check Point Firewall 9000, 19000, 29000 Appliances

Product: Check Point Appliances, SecureXL, Security Gateways
Version: R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Platform: 19000, 29000, 9000, LightSpeed MLS, LightSpeed QLS
Last Modified: 2026-07-07

Solution

Table of Contents:

Support for SecureXL User Space Mode (UPPAK)

SecureXL User Space Mode (UPPAK) is supported in these Check Point Appliances:

(For information about SecureXL modes and Firewall modes, refer to sk167052 - User Space Firewall (USFW) support.)

Enter the string to filter this table:

Appliance Models Version Configuration Requirement for SecureXL UPPAK
- Quantum Force 29100, 29200
- Quantum Force 19100, 19200
- Quantum Force 9100, 9200, 9300, 9400, 9700, 9800
- Quantum Force 3980, 3970, 3950, 3920
- Quantum LightSpeed QLS250, QLS450
R82.10 Security Gateway (all listed appliances) 
Maestro on all appliances other than Quantum Force 3980, 3970, 3950, 3920
As of R82.10, only UPPAK mode is supported
- Quantum Force 29100, 29200
- Quantum Force 19100, 19200
- Quantum Force 9400, 9700, 9800
- Quantum LightSpeed QLS250, QLS450
- Quantum LightSpeed MLS200, MLS400
R82 Maestro Support for Lightspeed on Maestro with R82 is not planned.  Customers should upgrade to R82.10
(Known Limitation MBS-17283)
- Quantum Force 29100, 29200
- Quantum Force 19100, 19200
- Quantum Force 9100, 9200, 9300, 9400, 9700, 9800
- Quantum LightSpeed QLS250, QLS450, QLS650, QLS800
R82 ElasticXL,
VSNext
ElasticXL and VSNext on R82 is only supported for Security Gateways. 
Support for VSNext on Maestro with R82 is not planned.  Customers should upgrade to R82.10
(Known Limitation MBS-17283)
- Quantum Force 29100, 29200
- Quantum Force 19100, 19200
- Quantum Force 9100, 9200, 9300, 9400, 9700, 9800
- Quantum LightSpeed QLS250, QLS450, QLS650, QLS800
R82 Security Gateway,
ClusterXL
Support for UPPAK is integrated for Security Gateway appliances as listed.
- Quantum Force 29100, 29200
- Quantum Force 19100, 19200
- Quantum Force 9700, 9800
- Quantum LightSpeed QLS250, QLS450
- Quantum LightSpeed MLS200, MLS400
R81.20 Maestro R81.20 Jumbo Hotfix Accumulator - Take 89 and higher (PRJ-56237, MBS-17283)
- Quantum Force 29100, 29200
- Quantum Force 19100, 19200
- Quantum Force 9100, 9200, 9300, 9400, 9700, 9800
R81.20 Security Gateway,
ClusterXL
R81.20 Jumbo Hotfix Accumulator - Take 54 and higher
To protect against CVE-2024-24919 (see sk182336),
install Take 65 and higher.
- Quantum Force 29100, 29200
- Quantum Force 19200
- Quantum LightSpeed QLS250, QLS450, QLS650, QLS800
R81.20 Security Gateway,
ClusterXL
R81.20 Jumbo Hotfix Accumulator - Take 38 and higher (PRJ-42434, PMTR-94471)
To protect against CVE-2024-24919 (see sk182336),
install Take 65 and higher.
- Quantum LightSpeed QLS250, QLS450
- Quantum LightSpeed MLS200, MLS400
R81.10 Maestro R81.10 Jumbo Hotfix Accumulator - Take 150 and higher
- Quantum LightSpeed QLS250, QLS450, QLS650, QLS800 R81.10 Security Gateway,
ClusterXL
R81.10 Jumbo Hotfix Accumulator - Take 81 and higher
To protect against CVE-2024-24919 (see sk182336),
install Take 150 and higher.

Important Notes for R82.10 (apply to Quantum Force and Quantum LightSpeed models)

Important Notes for R82 (apply to Quantum Force and Quantum LightSpeed models)

Support for the UPPAK mode in ElasticXL and VSNext in planned for one of R82 Jumbo Hotfix Accumulator Takes.

See the LightSpeed 10/25/40/100G QSFP28 Ports Administration Guide > Section "Known Limitations".

Important Notes for R81.20 (apply to Quantum Force and Quantum LightSpeed models)

Important Notes for R81.10 (apply only to the LightSpeed QLS models)

Supported Features and Acceleration

The tables below show the supported combinations.

Supported Features and Acceleration - Gateway Mode

- Supported and LightSpeed-accelerated - Supported (but not LightSpeed-accelerated) - Not supported
Feature R81.10 JHF
Take 150 or higher
R81.20 JHF
Takes 65 - 92
R81.20 JHF
Take 96 or higher
R82 R82.10
Supported Appliances LightSpeed QLS Appliances only Quantum Force Appliances
9100, 9200,
9300, 9400,
9700, 9800,
19100, 19200,
29100, 29200
LightSpeed Appliances
MLS200, MLS400,
QLS250, QLS450
Quantum Force Appliances
9100, 9200,
9300, 9400, 
9700, 9800,
19100, 19200,
29100, 29200
LightSpeed QLS Appliances
MLS200, MLS400,
QLS250, QLS450
Quantum Force Appliances
9100, 9200,
9300, 9400, 
9700, 9800,
19100, 19200,
29100, 29200
LightSpeed QLS Appliances
MLS200, MLS400,
QLS250, QLS450
Quantum Force Appliances
3980, 3970, 3950, 3920
9100, 9200,
9300, 9400, 
9700, 9800,
19100, 19200,
29100, 29200
LightSpeed QLS Appliances
MLS200, MLS400,
QLS250, QLS450
SecureXL Mode Kernel Mode
(KPPAK) -
Default
User Mode
(UPPAK)
Kernel Mode
(KPPAK)
User Mode
(UPPAK) -
Default
Kernel Mode
(KPPAK)
User Mode
(UPPAK) -
Default
Kernel Mode
(KPPAK)
User Mode
(UPPAK) -
Default
User Mode (UPPAK) - this is only supported mode
Firewall Blade with Hardware Acceleration
(Low latency / Elephant flow)
Security Blades support
IPv6
VSX
Jumbo Frames
QoS Blade
SD-WAN R82 JHF,
Take 14
and
higher
DDoS (SecureXL, IoC) See Notes 1 and 2 See Notes 1 and 2 See Notes 1 and 2
VXLAN interfaces
GRE interfaces
Bridge interfaces
see Note 3

see Note 3

see  Note 3

see  Note 3

see  Note 3
IP Reachability Detection
(Bidirectional Forwarding Detection, BFD)
see Note 4
GTP
(GPRS Tunneling Protocol)
SCTP
(Stream Control Transmission Protocol)
Monitor Mode

Notes:

  1. All DDoS features (SecureXL rate limiting, SecureXL penalty box, SecureXL deny list) are limitations in the UPPAK mode. IoC feeds are also not supported in the UPPAK mode. For more information, see LightSpeed 10/25/40/100G QSFP28 Ports Administration Guide > Known Limitations.

  2. The limitation for the SecureXL UPPAK mode when no Acceleration Card is installed has been resolved in R81.20 Jumbo Hotfix Accumulator Take 70 and in the R82 release. The limitation still applies when the Acceleration card is installed.

  3. SecureXL UPPAK mode does not support Cluster in these modes:

  1. BFD is first supported in R81.20 take 111

Supported Features and Acceleration - Maestro

- Supported and LightSpeed-accelerated - Supported (but not LightSpeed-accelerated) - Not supported
Feature R81.10 JHF
Take 150 or higher
R81.20 JHF
Takes 65 - 84
R81.20 JHF
Take 115 and higher
(see note 1)
R82 R82.10
Supported Appliances LightSpeed Appliances
MLS200, MLS400,
QLS250, QLS450
Quantum Force Appliances
9700, 9800,
19100, 19200,
29100, 29200
LightSpeed Appliances
MLS200, MLS400,
QLS250, QLS450
Quantum Force Appliances
9700, 9800,
19100, 19200,
29100, 29200
LightSpeed Appliances
MLS200, MLS400,
QLS250, QLS450
Quantum Force Appliances
9400, 9700, 9800,
19100, 19200,
29100, 29200
LightSpeed Appliances
MLS200, MLS400,
QLS250, QLS450
Quantum Force Appliances
9400, 9700, 9800,
19100, 19200,
29100, 29200
LightSpeed Appliances
MLS200, MLS400,
QLS250, QLS450
Quantum Force Appliances
9700, 9800,
19100, 19200,
29100, 29200
LightSpeed Appliances
MLS200, MLS400,
QLS250, QLS450
Quantum Force Appliances
9700, 9800,
19100, 19200,
29100, 29200.
LightSpeed Appliances
MLS200, MLS400,
QLS250, QLS450
SecureXL Mode Kernel Mode
(KPPAK) -
Default
User Mode
(UPPAK)
Kernel Mode
(KPPAK) -
Default
User Mode
(UPPAK)
Kernel Mode
(KPPAK) -
Default
User Mode
(UPPAK)
Kernel Mode
(KPPAK) -
Default
User Mode
(UPPAK)
Not supported with Maestro R82
UPPAK - only supported mode
Firewall Blade with Hardware Acceleration
(Low latency / Elephant flow)
Security Blades support
IPv6
VSX
Jumbo Frames
QoS Blade
SD-WAN
DDoS
VXLAN interfaces
(PMTR-60874)
GRE interfaces
(MBS-4098)
Bridge interfaces
IP Reachability Detection
(Bidirectional Forwarding Detection, BFD)
GTP traffic
(GPRS Tunneling Protocol)
SCTP traffic
(Stream Control Transmission Protocol)
Monitor Mode

Notes:

  1. Initial support for Maestro UPPAK was introduced via R81.20 JHF Take 89.  Use of Take 115 or higher is recommended