sk181698 - Check Point Firewall 9000 Appliances
Check Point Firewall 9000 Appliances
Product: Check Point Appliances
Version: R81.20, R82, R82.10
OS: Gaia
Last Modified: 2026-06-22
Solution
Introduction | Key Features | Notes | Downloads | Installation Instructions
Known Limitations | Documentation | Revision History
Introduction to Check Point 9000 Appliances
| Security Appliance | In this article |
| 9800 Base/Plus Security Appliance | 9800 |
| 9700 Base/Plus Security Appliance | 9700 |
| 9400 Base/Plus Security Appliance | 9400 |
| 9300 Base/Plus Security Appliance | 9300 |
| 9200 Base/Plus Security Appliance | 9200 |
| 9100 Base/Plus Security Appliance | 9100 |
| 9800/9700 | 9400/9300 | 9200/9100 |
Check Point 9000 series of Security Gateway appliances is the most advanced high-performance gateways that provide top price/performance in an easy-to-use configuration.
Check Point 9000 series of Security Gateways provide the most advanced AI-based Threat Prevention security for demanding enterprise networks.
The Check Point 9000 series comes with a first-year subscription to the full SandBlast Prevention suite.
Check Point 9000 series of Security Gateways provide the highest prevent rate in the industry.
The Check Point 9000 series comprises the following families of products:
| Security Appliance Series | Introduced In |
| 9800 series aimed at the large enterprise segment | 2024 |
| 9700 series aimed at the large enterprise segment | 2024 |
| 9400 series aimed at the mid-range enterprise segment | 2024 |
| 9300 series aimed at the mid-range enterprise segment | 2024 |
| 9200 series aimed at the small enterprise segment | 2024 |
| 9100 series aimed at the small enterprise segment | 2024 |
Notes
- By default, Check Point Firewall Appliances (9800, 9700, 9200, and 9100) and (9400, 9300 only in Security Gateway configuration) run SecureXL in the User Space (UPPAK) Mode:
- When the appliance runs the dedicated R81.20 Factory Image.
- When the appliance runs the R81.20 Jumbo Hotfix Take 54 and higher.
- By default, Check Point Firewall Appliances (9400 and 9300) with Standalone configuration run in User Space Firewall (USFW):
- When the appliance runs the R81.20 Jumbo Hotfix Take 111 and higher.
- When the appliance runs the R82 Jumbo Hotfix Take 36 and higher.
- Check Point Firewall Appliances in a Standalone deployment (9800, 9700, 9400, 9300, 9200, and 9100) run SecureXL in Kernel Mode (KPPAK).
Starting from R82.10 SecureXL runs only in UPAKK mode and Standalone configuration is supported.
- To manage Check Point Firewall appliances that run an R81.20 version with an R81.10 Management Server, you must install the R81.10 Jumbo Hotfix on the R81.10 Management Server. See the Downloads > Jumbo Hotfix Support section for details.
Downloads
To download these packages, you will need to have a Software Subscription or Active Support plan.
- Factory Image for Check Point Firewall 9700 and 9800 Appliances operating as Security Gateways:
| Image | Link |
| R82.10 | see sk183506 |
| R82 | see sk181127 |
| R81.20 Take 773 for Check Point Firewall Appliances | (ISO) |
Important Notes:
Effective 03 June 2024, the dedicated R81.20 image was replaced from Take 770 to Take 773 to protect against CVE-2024-24919 (see sk182336).
- To install this ISO image, you must use the ISOmorphic build 207 or higher (see sk65205).
Factory Image for Check Point Firewall 9100, 9200, 9300, and 9400 Appliances operating as Security Gateways:
| Image | Link |
| R82.10 | see sk183506 |
| R82 | see sk181127 |
| R81.20 Take 791 for Check Point Firewall Appliances | (ISO) |
Important Notes:
- Effective 03 June 2024, the dedicated R81.20 image was replaced from Take 781 to Take 791 to protect against CVE-2024-24919 (see sk182336).
- To install this ISO image, you must use the ISOmorphic build 207 or higher (see sk65205).
Known Limitations
| ID | Description |
| - | In Maestro configuration, you cannot use the onboard 10G Fiber ports. You must only use the ports on the supported line cards. |
| - | If you change the configuration of one 100G Card port (link up/down, MTU, and so on), it causes the link to go down and then up on the other 100G Card port. Therefore, schedule a maintenance window to make the required changes in the configuration of the 100G Ports. |
| - | When a faulty DIMM is detected on a 9100 / 9200 / 9300 / 9400 appliance, the appliance fails to boot and shows the message " ERROR: DIMM Failure found". This message appears when connected to the appliance through the console port or in LOM Card KVM. |
| PMTR-104982 | SecureXL UPPAK mode is not supported with SD-WAN. Note - SecureXL KPPAK mode is supported. Resolved in the R81.20 Jumbo Hotfix Accumulator, Take 96. |
Documentation
| 9000 Appliances |
| Check Point 9000 Appliances Getting Started Guide (English) |
| Check Point 9000 Appliances Getting Started Guide (Spanish) |
| Check Point 9000 Appliances Getting Started Guide (Russian) |
Revision History
| Date | Description |
| 19 Jan 2026 | Updated the Notes section |
| 29 Dec 2025 | Updated the Downloads section with links to the R82.10 Home Page to download the R82.10 ISO |